By NHI Mgmt Group Editorial TeamBased on WorkOS: “AI agents now make up the majority of web traffic: What developers need to change” (June 18, 2026)

TL;DR: AI agents now make up 57.5% of HTML web traffic versus 42.5% from humans on Cloudflare Radar, while HUMAN Security says agentic AI traffic grew roughly 7,851% year over year, according to WorkOS. Apps, APIs, analytics, and commerce flows now need to be designed for machine actors that complete tasks faster and at far greater request volume than people.


At a glance

What this is: WorkOS argues that web traffic has become machine-majority, with AI agents now outnumbering human visitors and forcing changes in how applications, APIs, analytics, and commerce are built.

Why it matters: IAM and platform teams need to treat agent traffic as a distinct identity and access class, because human-centred assumptions in measurement, form handling, and transactional control no longer hold.

By the numbers:

  • AI agents now make up 57.5% of HTML web traffic versus 42.5% from humans on Cloudflare Radar.

Context

Web traffic is no longer a human-only signal. AI agents are now generating a majority of HTML requests in the measured sample, which breaks the old assumption that sessions, clicks, and conversion funnels represent direct human behaviour.

For identity and access teams, the issue is not just analytics noise. Machine visitors increasingly act on behalf of people, which means applications need to distinguish human intent from agent execution without treating every automated request as hostile.

The governance problem is broader than bot filtering. When agent traffic can browse, compare, submit forms, and complete transactions, the application layer becomes part of identity control, not just a presentation surface.


Key questions

Q: What breaks when AI agents are counted the same way as human visitors?

A: Session-based analytics break first because bounce rate, dwell time, and conversion assumptions all depend on human browsing patterns. Agent activity can be successful even when it looks short, repetitive, or unusually dense. Teams need separate classification so operational reporting does not turn useful machine-mediated work into false noise.

Q: Why do AI agents change how applications should handle access and transactions?

A: Because they can execute delegated tasks at machine speed and across many more requests than a person would. That means the application is no longer just presenting information, it is authorising actions. Teams must decide which flows are human-only, which are agent-enabled, and which need explicit machine credentials.

Q: What signs show that a website is not agent-ready?

A: Common signs include unlabeled inputs, hover-dependent controls, custom JavaScript submit buttons without native form semantics, infinite scroll without pagination, and heavy client-side rendering with no structured data. These patterns make legitimate delegated actions fail even when the site looks fine to people.

Q: How should teams govern AI agent traffic without blocking legitimate automation?

A: By separating delegated agent sessions from unauthorised automation and setting different rules for read-only crawling, structured interaction, and transactional access. Governance should be based on intent and permitted action scope, not on whether traffic is automated. That keeps useful agent activity from being treated as generic bot noise.


Technical breakdown

How AI agents change web traffic patterns

AI agents are not classic crawlers. They are software actors that browse pages, extract content, fill forms, and complete tasks on a user's behalf, often generating far more requests than a person would. That creates a traffic pattern where one human intent can expand into hundreds or thousands of HTTP requests. For developers, that matters because traffic volume no longer maps cleanly to user volume. The meaningful unit becomes task completion, not page visit count. In practice, this shifts application design toward machine-readable flows, request attribution, and explicit separation between human sessions and delegated agent sessions.

Practical implication: Treat agent traffic as a separate interaction class and redesign reporting, throttling, and conversion logic around task completion rather than raw visits.

Why analytics break when agents become first-class visitors

Traditional web analytics assume a visitor is human unless proven otherwise. Metrics such as bounce rate, time on page, and session length all lose meaning when an AI agent can land, extract the needed data, and leave in seconds with a successful outcome. The problem is not that metrics are wrong, but that they are measuring the wrong subject. If a machine completes a booking or product search faster than a person, that is not failure, it is an alternate transaction path. The control issue is attribution: teams need a way to segment agent activity without misclassifying useful machine actions as low-quality engagement.

Practical implication: Separate agent and human analytics so operational reporting does not punish successful machine-mediated interactions or overstate human engagement.

What structured interfaces mean for AI agent access

Agent-friendly design depends on structure. Forms exposed through the DOM, server-rendered HTML, schema.org markup, and machine-readable tool surfaces are easier for agents to use than visually oriented interfaces with hover states, unlabeled controls, or custom JavaScript-only submit paths. The same accessibility defects that hurt screen readers also frustrate agents because both depend on semantic structure rather than visual inference. On the commerce side, protocols such as WebMCP and agent-mediated checkout flows point to a future where sites expose controlled machine interfaces instead of forcing agents to imitate humans click by click. That changes the application perimeter from page design to action design.

Practical implication: Make high-value flows semantically accessible and expose controlled machine interfaces where you want agents to transact reliably.


NHI Mgmt Group analysis

Agent traffic is becoming an identity problem, not just a web traffic problem. Once a software actor can browse, compare, and transact on behalf of a person, the real question is who or what the application is authorising. That pulls web access into the same governance conversation as delegated identity, scoped privileges, and transaction-level trust. For practitioners, this means application identity boundaries now matter as much as user interface boundaries.

Human-centred analytics are now structurally incomplete. Metrics built for direct human sessions will misread machine-mediated activity as abnormal, low-quality, or suspicious even when the agent successfully completes the intended task. That does not make analytics useless, but it does mean the programme needs a new attribution model that separates intent, actor type, and outcome. The implication is that reporting, fraud signals, and conversion logic must be redesigned for mixed human-agent traffic.

Machine-majority traffic creates a new identity blast radius. When one user action fans out into hundreds of agent requests, the access surface expands far beyond the original person’s intent. Identity blast radius: the amount of application and API surface that becomes reachable from one delegated action. The smaller that radius, the easier it is to govern agent behaviour without overexposing the application. Practitioners should treat every agent-enabled workflow as a contained delegation domain, not an open-ended browsing session.

Web access controls now have to distinguish delegation from abuse. Blocking every automated request is no longer a workable policy because many of those requests are legitimate user-delegated actions. At the same time, permissive treatment of machine traffic creates a path for extraction, abuse, and unauthorised transaction execution. The field is moving toward explicit machine-friendly endpoints, scoped credentials, and observable transaction boundaries. Teams that still treat all automation as the same problem will miss the governance distinction that now matters most.

The web stack is absorbing part of the authorisation layer. When agents complete checkout, booking, or lookup flows directly, the application itself becomes a decision point in identity governance. That pushes teams to ask which actions should be available to delegated agents, which should require stronger controls, and which should remain human-only. The practical conclusion is that identity architecture must extend into app design, analytics, and commerce pathways together, not as separate concerns.

From our research library:

What this signals

Identity teams should stop treating agent traffic as a niche edge case. Once software actors can complete delegated tasks end to end, the control question becomes whether the application can distinguish a human session from an authorised machine session without collapsing both into generic bot handling. That is an access design problem as much as a web design problem.

Machine-majority traffic creates an identity blast radius that traditional funnels do not capture. One user request can now fan out into many machine interactions, which means the governance unit is the delegated task, not the page visit. Teams that keep optimising only for human UX will miss where authorisation, attribution, and conversion are actually happening.


For practitioners

  • Segment agent traffic from human traffic Update analytics pipelines to classify browser-based agents separately from human sessions so pageview, bounce, and conversion metrics reflect actual actor type.
  • Audit forms for semantic accessibility Review critical forms for native labels, DOM-based submission, and server-rendered fallbacks so agents can complete intended tasks without brittle client-side workarounds.
  • Expose machine-readable transaction paths Define controlled APIs or structured endpoints for booking, checkout, and lookup flows so delegated agents do not have to imitate human clicks.
  • Rethink attribution for agent-mediated commerce Add API-level transaction source tracking and correlate it with web analytics so purchases completed inside agent sessions are not invisible to reporting.
  • Set policy for crawler and agent access Decide which automated visitors may read, transact, or only crawl, and align robots.txt, access controls, and content licensing rules to that policy.

Key takeaways

  • AI agent traffic is now large enough to invalidate human-only assumptions in analytics, conversion measurement, and application design.
  • The practical issue is not just more automation, but delegated machine action that can browse, compare, and transact at scale.
  • Teams need separate controls for agent classification, semantic form handling, and machine-readable transaction paths if they want reliable governance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAgent traffic depends on delegated identity and scoped privilege at runtime.
ASI02 — Tool MisuseBrowser automation and transaction flows can misuse exposed tools or forms.
Recommendation — Scope delegated agent credentials tightly and prevent privilege from exceeding the intended task. Restrict which tools and actions agents can invoke in each workflow.
NIST SP 800-53 Rev 5IA-9 — Identification and Authentication (Service and Organization Users)Agent sessions act like service-oriented non-human users on the open web.
Recommendation — Apply service-user authentication controls to separate agent sessions from human sessions.
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIUsers increasingly rely on software actors to carry out human intent on their behalf.
Recommendation — Govern delegated machine actions as non-human identity activity with explicit approval boundaries.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsAgent access to forms, APIs, and checkout paths depends on explicit permission boundaries.
Recommendation — Define separate authorisation rules for human visitors and delegated machine actors.

Key terms

  • Agent Traffic: Requests generated by software acting on behalf of a person rather than by a person directly. In this context, agent traffic includes browsing, form submission, and transaction flows that should be governed as delegated activity, not generic bot noise.
  • Machine-Readable Transaction Path: A structured application flow that allows a software actor to complete a task through semantic markup, native forms, or explicit APIs. For autonomous or delegated agents, the design goal is controlled execution, observability, and clear permission boundaries.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org