Bots persist because they are cheap, scalable, and easy to redeploy across many abuse cases. They can probe login pages, create fake accounts, test payment instruments, and amplify social engineering at volume. AI agents may expand the attack surface, but mature bot operations already exploit weak identity signals, low-friction onboarding, and inconsistent fraud controls.
Why Bots Stay Effective Even When AI Agents Improve
Bots continue to work because the fraud economy rewards scale and repetition more than sophistication. The best bot operations do not need to “beat” every control, they only need enough weak signals, inconsistent friction, and reusable infrastructure to keep finding profitable paths through login, signup, checkout, and recovery workflows.
That is why stronger AI agents do not automatically displace bots. In many environments, AI mainly expands the total attack surface while the older bot playbook still exploits the parts of the stack that remain easy to automate: low-trust onboarding, credential stuffing, account farming, payment testing, and scripted social engineering.
The persistence of bots is also a measurement problem. Many organisations can detect obvious volume, but they struggle with higher-quality automation that blends into normal traffic, rotates infrastructure, or stays just below thresholds that would trigger throttling, challenge escalation, or fraud review.
What Makes Bot Fraud Hard to Eliminate
Bot fraud is durable because the defender’s problem is not just blocking automation, it is distinguishing legitimate high-volume behaviour from malicious repetition. Attackers can retool quickly, distribute requests across proxies or compromised devices, and shift between abuse cases without rebuilding the underlying tooling.
Controls often fail at the seams between identity, application security, and fraud operations. A login system may slow credential attacks, but the same bot can pivot to fake account creation, password reset abuse, referral abuse, gift-card testing, or carding. If fraud decisions are made in separate silos, the adversary only needs one weak workflow to remain profitable.
- Cheap infrastructure lowers the cost of retries and attrition.
- Automation allows rapid rotation of accounts, IPs, devices, and payloads.
- Weak identity assurance makes it easier to present synthetic or stolen trust signals.
- Inconsistent controls across channels create fallback paths when one abuse route closes.
Risk and Threat Considerations
Bots remain a persistent fraud risk because they are not dependent on a single breakthrough technique. They can keep probing for weak enrolment, weak recovery, weak rate limiting, or weak transaction checks, and they benefit from any gap between identity assurance and fraud scoring. As AI agents become more capable, the concern is less that bots disappear and more that both human-operated and AI-assisted abuse become harder to separate from ordinary customer activity.
Failure mechanism: Attackers automate high-frequency attempts across the full customer lifecycle, then adapt quickly when one control starts to bite. They use scale, rotation, and workflow switching to stay inside policy thresholds while continuing to search for the cheapest successful path.
Impact: Organisations face account takeover, fake account inflation, payment abuse, referral and promotion loss, support load, and distorted risk signals. Once defenders lose trust in traffic quality, every subsequent control becomes slower, more expensive, and more likely to create customer friction.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A2 — Agent Identity and Privilege Abuse | AI agents can widen abuse paths when authority is weak. |
| Recommendation — Constrain agent actions to the minimum authority needed and audit every tool-bound decision. | ||
| NIST AI RMF | GOVERN — Govern | Bot fraud now intersects AI-assisted abuse and enterprise risk governance. |
| Recommendation — Assign accountability for automation abuse risk and define governance for high-impact workflows. | ||
| MITRE ATT&CK | T1110 — Brute Force | Bots commonly automate repeated login attempts and credential testing. |
| Recommendation — Detect repeated authentication abuse and tune throttling for distributed retry patterns. | ||
| CIS Controls v8 | 6 — Access Control Management | Fraud bots exploit weak access decisions, onboarding, and account recovery. |
| Recommendation — Restrict and review access paths that enable account creation, login abuse, and recovery misuse. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Bot fraud thrives where identity assurance and access controls are weak. |
| Recommendation — Strengthen authentication and access controls on user-facing journeys that bots target most. | ||
Practitioner Guidance
What to prioritise: Treat bot defence as a cross-functional control problem, not just a perimeter or fraud-team issue. The most valuable improvements usually come from the highest-volume workflows first: login, signup, password reset, checkout, and any flow that creates or changes trust.
What to verify: Confirm that your controls can distinguish one-off legitimate spikes from repeatable abuse patterns across accounts, devices, sessions, and payment instruments. If your only signal is request rate, you are probably measuring volume rather than intent.
Common mistake: Teams often respond to bots by adding a single challenge or rule, then assume the problem is contained. In practice, mature bot operators adapt quickly, so the real test is whether the control stack forces the attacker’s cost higher across multiple workflows, not whether it blocks one campaign.
Practitioner takeaway: The durable defence is not “stop bots” in the abstract, it is to make repeated abuse uneconomic by raising cost, improving identity confidence, and removing easy fallback paths across the customer journey.
Related resources from NHI Mgmt Group
- Why do AI shopping agents create a fraud risk beyond normal e-commerce bots?
- Why does employee negligence remain such a persistent security risk even when staff understand their role?
- Why do AI agents and bots increase payment fraud risk for merchants?
- Why do leaked secrets remain such a persistent NHI risk?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org