← Back to Benchmarks

Why your ad fraud detection misses 57% bot traffic

With bot traffic now exceeding 57% of web requests, standard ad platform fraud detection catches less than 40% of sophisticated AI bot traffic. This article shows media buyers the verifiable numbers and where their measurement model is broken.

Editorial TeamLOSS
Platform
Google Ads
Campaign type
Display
Spend range
All levels
Timeframe
2025-2026
Detection rate
<40%
Verdict
loss
Industry vertical
ecommerce
Last reviewed
2026-07-25

The uncomfortable part of the dead internet theory’s impact on ad fraud is no longer the theory. It is the measurement. Cloudflare reported that bots made up 57.5% of web traffic in June 2026, while other security estimates cited in the same coverage put bot share around 53% and roughly 51% depending on methodology.[1][2] HUMAN Security, looking at more than 1 quadrillion interactions, reported that agentic AI traffic grew 7,851% year over year and AI scraper traffic grew 597%.[3] A vendor-sourced 2026 analysis cited by Modern Diplomacy puts standard-tool detection of sophisticated bot traffic at less than 40%, which is not an audited universal constant, but it is directionally useful if you are the person reconciling spend after the money has already left the account.[4]

Those numbers do not all measure the same thing. That matters. Total bot traffic is not the same as ad fraud. Invalid traffic is not the same as a refunded click. A scraper, a monitoring tool, an AI shopping agent, a credential-stuffing bot, and a click farm do not create the same business damage. But when the majority of measured web requests are no longer clearly human, the quiet assumption underneath ad measurement starts to fail: the dashboard treats traffic as an audience unless a filter can prove otherwise.

Human web activity visually outweighed by a much larger crowd of bot silhouettes

The Crossing Point Is Real Enough To Change The Audit

No single provider sees the whole internet. Cloudflare sees what passes through its network. Thales, Imperva, Anura, HUMAN Security, and fraud vendors each measure from different positions in the stack. Their numbers should not be flattened into one perfect global bot percentage.

Still, the convergence is what makes the benchmark hard to ignore. Cloudflare’s 57.5% figure, Thales at about 53%, and Imperva/Anura around 51% are not identical, but they point in the same direction: bot-majority traffic is now plausible across major measurement surfaces.[1][2] HUMAN’s agentic AI growth figure gives that crossing point a current mechanism rather than just a recycled internet-culture argument.[3]

BenchmarkWhat it measuresWhy media buyers should care
Cloudflare: 57.5% bot traffic in June 2026Share of web traffic observed through Cloudflare’s measurement positionShows that human-majority traffic can no longer be assumed at the request level
Thales: about 53%; Imperva/Anura: about 51%Separate bot-share estimates from different security and fraud-measurement contextsSupports the direction of travel without pretending one vendor owns the full web
HUMAN Security: 7,851% YoY agentic AI traffic growthGrowth in AI-agent traffic across more than 1 quadrillion interactionsExplains why old bot patterns are becoming less useful as the only detection model
ClickFortify analysis cited via Modern Diplomacy: standard tools catch less than 40% of sophisticated bot trafficVendor-sourced detection-gap estimateUseful as a warning signal, but not strong enough to treat as independently audited truth

The practical takeaway is not that every second impression is fraudulent. It is that the population entering analytics, bidding systems, retargeting pools, lead forms, and attribution paths now contains enough automation that default platform filters should be treated as one layer of evidence, not the control system.

Bot Traffic, IVT, And Refunds Are Different Buckets

A lot of ad fraud writing becomes useless because it throws every non-human event into one bucket. That makes the number scarier and the audit worse.

Total bot traffic is the broadest layer. It includes benign automation, commercial scraping, AI agents, security tools, malicious bots, and traffic whose intent is hard to classify. HUMAN’s report is especially annoying for buyers because it says only 0.5% separates benign automation from malicious automation in its AI traffic benchmark, which means detection cannot rely only on whether a request looks automated.[3]

Invalid traffic, or IVT, is narrower. It is the portion of ad-exposed activity that measurement systems classify as invalid under their rules. Fraudlogix reported 20.64% global IVT across 105.7 billion ad impressions in 2025, with APAC at 27.85%, the US at 23.69%, and Europe at 7.80%.[5] Those are ad-impression benchmarks, not a claim that 20.64% of every advertiser’s spend is fake.

Refunded fraudulent clicks are narrower again. A platform refund is the portion the platform detects, classifies under its refund rules, and credits back. The cited ClickFortify analysis says Google refunds 40% to 60% of fraudulent clicks after the fact.[4] That is not the same as saying the remaining share is always recoverable fraud. It means the refund line in a billing interface is a bad proxy for total contamination.

Bot network traffic flowing past a small filter with only a thin clean stream passing through

Where The Dashboard Looks Cleaner Than The Account

Platform-side fraud controls are built to remove known invalid activity, protect marketplace trust, and apply credits under platform policy. They are not built to answer the buyer’s month-end question: did this traffic create customers, or did it teach the bidding system to chase garbage?

That gap shows up in ordinary account work. Google Ads can exclude invalid clicks from billing while GA4 still shows sessions that do not behave like prospects. Meta can report conversions that pass event rules while downstream sales quality deteriorates. A fraud tool can flag an IP range after spend has already accrued. Finance sees the invoice; sales sees the lead quality; the platform sees a filtered version of its own marketplace.

The refund model is especially weak when automation pollutes post-click signals. A click that is later credited still may have entered analytics, audiences, remarketing lists, attribution paths, or conversion modeling before the credit arrives. A non-refunded click can still be economically useless if the visitor creates shallow engagement, fake form activity, low-intent microconversions, or polluted lookalike signals.

This is where Smart Bidding becomes part of the risk instead of a separate solution. Automated bidding is not bad because it is automated. It becomes fragile when the conversion events it optimizes toward are contaminated. If a campaign trains on form fills that sales later disqualifies, or purchases that later cancel, or engagement events inflated by bots, the system can improve against the wrong objective with impressive confidence.

The checks platform filters rarely answer by themselves

  • Whether invalid activity was removed before or after it entered analytics, audiences, attribution, and bidding feedback loops.
  • Whether conversion quality declined in CRM, payment, retention, or sales-accepted-lead data while platform CPA looked stable.
  • Whether IVT clusters by placement, app, publisher, geo, device type, hour, or campaign subtype.
  • Whether refunded invalid clicks are being treated as the total fraud universe instead of the detected-and-creditable subset.
  • Whether aggressive exclusions are blocking real users along with bots, especially in high-value but noisy traffic segments.

Programmatic And Display Deserve A Harder Look

The highest-risk audit surface is usually not branded search. It is the messy inventory where impressions are cheap, supply paths are layered, placements are numerous, and the buyer often sees aggregated performance after several systems have already made decisions.

Fraudlogix’s regional IVT split is useful here because it reminds buyers not to audit globally averaged traffic and call it done. A campaign buying APAC, US, and Europe inventory should not use one fraud assumption across all three regions when the 2025 benchmark shows 27.85%, 23.69%, and 7.80% IVT respectively.[5] The Europe figure may be lower partly because GDPR compliance costs make some fraud less profitable there, but that is still a directional explanation, not a guarantee that European inventory is clean.

Platform and channel variance matters too. A PPC Hero/Lunio analysis of March 2025 datasets found average IVT rates between 10.5% and 17.1% depending on platform, after an earlier figure around 20% was corrected downward when the sample broadened.[6] Q1 2026 user-sourced platform figures discussed on Reddit put Google Display around 27% IVT and YouTube around 5%, but those should be treated as directional anecdotes rather than definitive platform benchmarks.[7]

The right response is not to declare display dead. It is to stop buying broad display as though auction access, platform filters, and post-campaign invalid-click credits are a complete control environment. The more a plan relies on open-web reach, low-cost impressions, broad audiences, and automated optimization, the more it needs independent IVT monitoring and placement-level review. For buyers building or cleaning up that channel, the AI in programmatic display advertising channel guide is the better place to go deeper on programmatic mechanics.

The Vertical Risk Is A Targeting Problem, Not A Panic Ranking

HUMAN reported that 95% of AI-driven traffic in its benchmark hit three verticals: retail/e-commerce at 46.6%, plus streaming/media and travel.[3] That does not prove every retailer, publisher, or travel advertiser has the same fraud rate. It does mean buyers in those sectors should be more skeptical of clean-looking top-line traffic growth, especially when campaigns reward page views, product views, account creation, add-to-cart behavior, or low-friction lead events.

Retail and e-commerce are particularly exposed because the same behavioral signals that help ad platforms optimize can be mimicked or polluted: product browsing, cart activity, price checking, coupon paths, account creation, and repeat visits. Streaming and media properties attract automation because content access, ad impressions, and engagement metrics can be monetized. Travel attracts scraping and agentic activity because inventory, pricing, and availability change constantly.

The useful buyer action is segmentation. Compare new versus returning users, paid versus organic post-click quality, conversion-to-revenue lag, cancellation or refund behavior, and placement-level assisted conversions. If the platform reports efficient acquisition while the business system reports weak order quality, high reversals, or dead leads, the ad account is not the source of truth.

Aggressive Blocking Has A Cost

There is an operational trap on the other side of this problem: treating every suspicious session as disposable. A University of Bamberg study found 7% to 15% false-positive block rates on real traffic when using aggressive filters.[8] That is the part fraud vendors tend to underplay and operators discover when a good geo, device class, office network, VPN-heavy audience, or B2B account suddenly stops converting.

False positives are not a reason to accept polluted traffic. They are a reason to separate monitoring from enforcement. Start by measuring suspicious traffic independently, then decide where to exclude, bid down, require stronger conversion evidence, or remove signals from optimization. The blunt version of fraud control can make the account look safer while quietly cutting into legitimate demand.

What To Audit Before The Next Budget Review

The Juniper Research projection of $100 billion in global ad fraud losses for 2026, rising to $172 billion by 2028, is useful context but not a number to build an account-level business case around without caveats, because the methodology is cited through secondary sources and is not independently crawlable from available public materials.[9] A CFO does not need a global loss projection as much as a reconciliation of where the company’s own spend, traffic, conversions, and revenue stop matching.

  • Compare platform invalid-click and IVT reports against independent IVT monitoring, especially for display, programmatic, paid social audience expansion, and partner inventory.
  • Segment IVT and post-click quality by region, channel, campaign type, placement, device, hour, and new-versus-returning status.
  • Review conversion quality outside the ad platform: CRM acceptance, order value, refunds, chargebacks, trial activation, retention, and sales notes.
  • Separate optimization events from business outcomes. If Smart Bidding trains on soft conversions, test stronger value rules or offline conversion imports before scaling.
  • Track what gets refunded, what gets excluded, and what remains only suspicious. Those are three different accounting categories.

Default filters should sit inside a broader governance model, not replace one. The same principle applies to AI-targeted marketing more generally: controls have to define which signals are trusted, which are monitored, and which are allowed to train automated systems. The AI targeted marketing governance framework is the relevant companion for that operating model.

The practical line is simple enough to defend: do not rely on platform refunds or default filters as the fraud-control model, especially where automated bidding depends on conversion signals that bots can contaminate. Verify the traffic. Reconcile it against business outcomes. Then decide what the bidding system is allowed to learn from.

References

  1. Dead internet theory says bots have taken over the web. The latest data suggests it’s no longer just a theory, Fortune, July 23, 2026
  2. Bot web traffic has overtaken human web traffic, data shows, NBC News
  3. 2026 State of AI Traffic & Cyberthreat Benchmark Report, HUMAN Security
  4. ClickFortify 2026 analysis cited via Modern Diplomacy
  5. 2025 global IVT benchmark, Fraudlogix
  6. March 2025 platform IVT analysis, PPC Hero/Lunio
  7. Q1 2026 Reddit-sourced platform IVT discussion
  8. False-positive blocking study, University of Bamberg
  9. Ad fraud loss projection cited through Business of Apps and Modern Diplomacy, Juniper Research

No Bidding tactic or Creative record currently cites this case file. Compare it against other results in Benchmarks.

Related benchmark reading

Report a corroborating or contradicting result

Seeing something different in your own account? Feed the data-integrity loop instead of leaving an open comment.