Last Updated: 4 June 2026

New research report supported by Hydrolix, The AI Bots in 2026: Risk, Readiness and Governance, shows a gap in how well-prepared enterprise security leaders think they are to detect bot activity versus what's real today.
79% of enterprise security leaders say they are confident in their ability to detect bot activity. Only 23% actually have proactive, governance-driven programs in place. That's a 56-point difference between confidence and capability. This means businesses are not ready to identify, understand, and make decisions about AI bot activity, even though they think they are.
The report also shows that legacy bot-detection models do not work in today's AI-driven threat landscape. In the past, malicious traffic was easy to spot because it came in volumes or had recognizable signatures. Web Application Firewalls (WAF) would quickly catch it. With AI, however, attackers can create automated attacks, like IP rotation. This lets them launch targeted attacks with more speed and scale. As the report notes, credential-based attacks (74%), DDoS attacks (51%), and AI-driven scraping (40%) remain the top threat vectors, but their speed, scale, and sophistication have been transformed. The report also shows that only 25% of organizations update detection rules continuously, while 45% do so only weekly.
Behaviorally, this is a sophistication change with AI-enabled bots. Modern AI bot development includes mimicking user sessions to blend in with end-user behavior. This helps them avoid detection. These sophisticated bots use behaviors to stay in a "gray area" between harmless and malicious.
For enterprises, the sophisticated nature of AI bots presents several distinct challenges.
A significant portion of organizations struggle to effectively manage bot traffic, with 33% reporting that their detection solutions blocked more than half of all AI bot traffic last year.
Outdated security measures compound this issue. As mentioned above, 45% of enterprises update their detection rule sets once a week, while only 25% update them continuously. This slow cadence gives AI bot operators enough time to execute their plans before new rules are implemented.
“If anything, AI-driven bots demand even more rigorous identity verification than humans do, because they’re faster, more persistent, and harder to distinguish from legitimate traffic. Organizations need to stop treating bots as a traffic category and start treating them as identity-bearing actors that require the same authentication, authorization, and continuous verification as any human user.”
Dr. Chase Cunningham (Dr. Zero Trust), Principal Analyst and Cybersecurity Strategist
Finally, a fundamental challenge remains in classification: 23% cite difficulty distinguishing between legitimate and malicious bots as a major barrier to managing bots. Blocking everything can cost companies millions, yet operators also don’t want to miss bots with malicious intent. The trick is to understand good vs. bad bot behavior, and then make decisions that benefit the business accordingly.
"the biggest risk in bot management is between what we define as 'good' and 'bad' AI-bot."
Hydrolix VP of Products Simon Ouderkirk
Without clear attribution, understanding who or what is acting within their systems, organizations cannot confidently enforce policies, prioritize threats, or optimize user experiences.
Immediate cyberattacks are the concern for 50% of organizations now. Although the report states that 54% of organizations think the biggest negative impact within the next 12 months from AI bot-related issues will be on customer experiences, while one-third (33%) anticipate increased data exposure risks. This shows that the concern over business impact is significant. If the customer experience erodes, companies can face customer abandonment, brand damage, and financial losses.
Organizations must focus on:
By focusing on these areas, organizations may close the 56-point gap between perceived preparedness and actual capability. They can develop a bot management strategy that addresses AI-driven blended threats while supporting beneficial bots.