Most Traffic Isn’t Human
The audience for your clients’ websites changed, and nobody sent a notice.
Start with Cloudflare, which sits in front of a large share of the world’s web traffic and can see what actually arrives. In June, automated traffic crossed a line it had never crossed before: more than half of all page loads. The number has kept climbing since, to nearly fifty-eight percent. Most of what visits a website is now software. Cloudflare’s explanation for the flip is arithmetic. A person shopping for a camera might open five tabs. An agent running the same errand can hit thousands of pages in seconds.
The composition of that software matters more than the total. A separate report, from the cybersecurity firm HUMAN Security, looked specifically at AI agents — programs that click links and fill out forms on someone’s behalf — and found that category of traffic grew nearly eight thousand percent in a year. Not eight percent. Eight thousand.
Now the human side of the same shift. TechCrunch reported on data from Similarweb showing that Google’s AI-generated answers now appear in roughly forty-three percent of searches. A year ago that figure was fifteen. And visits to Google’s dedicated AI Mode went from a hundred and twenty-six million to two hundred and seventy-nine million in eleven months. More than doubled.
Read what those two numbers do together. On one side, machines arriving at the site directly. On the other, people who used to arrive by clicking a link, now getting the answer from a machine and never making the trip at all.
Then the part that tells you these machines are not just reading. A company called ESW announced — and this is the company’s own announcement about its own product, so weigh it accordingly — that it has launched what it calls agentic commerce, integrating first with Microsoft Copilot. The claim is a path that runs from AI-driven product discovery straight through to checkout. A purchase, start to finish, with no person in the path.
So: most of the traffic is machine. A growing share of the humans never arrive. And the machines that do arrive can now buy something.
Every one of your clients paid somebody to build a storefront for people. That storefront is now serving a different audience, and nobody told it. To understand why the machines showed up now, you have to look at something that changed underneath them — and it isn’t the machines.
Why the Login Is Breaking
For thirty years, a machine on the web was anonymous by construction. There was no way for software to say who it was or on whose behalf it was acting, so the only question you could ask about non-human traffic was behavioral — is this hitting us too fast, does the pattern look like a crawler. And there were only ever two answers. Block it, or let it through. A firewall decision, made about a stranger.
What’s changing is where authorization lives. And it comes down to one thing: the session is dying as the unit of trust.
Think about how signing in has always worked. You authenticate once, at the beginning. A session opens. Everything you do for the next hour inherits the trust you established at the door. That design assumes a person who signs in, does a sequence of related things, and leaves. It has worked fine for decades.
It falls apart when the actor is an agent. An agent doesn’t sign in and work for an hour. It performs thousands of operations, in bursts, on behalf of many different parties — and the question of what any single one of those operations was permitted to do cannot be answered by pointing back at a door it came through an hour ago.
So the plumbing is being rebuilt to carry authorization on every request instead. Watch the Model Context Protocol — the standard AI applications use to connect to tools and data — take exactly that step. In its largest revision to date, the protocol deprecated the session handshake and the initialization step that servers had been built around, moved state into handles the client supplies with each call, hardened authentication, and attached metadata to individual requests. It also adopted a twelve-month deprecation policy for what it removed.
Yubico is making the same move in hardware. In its own product announcement — so weigh the framing accordingly — the company shipped a firmware update that extends its security key past the login. The old job was proving who you are at the door. The new one is proving that a specific action was authorized, at the moment it happens. Their own example is an AI agent ordering a change to a database, and a person physically touching a key to approve that one action. Not the session. The action.Here is what that changes. A machine that can present credentials for a specific action, on behalf of a specific party, is not traffic anymore. It is a party.
And parties don’t get filtered. They get admitted — by somebody. That somebody is not a small company, and it is not you.
Microsoft Wants the Doorway
So bring this to the party who ends up making that decision.
Watch Microsoft. It announced its first security-specialized model, MAI-Cyber-1-Flash, alongside a new agentic security platform called Project Perception. The claim, reported by CyberScoop and The New York Times, is a score of about ninety-six percent on a vulnerability-detection benchmark called CyberGym — roughly ten points clear of the next best system, at about half the cost of Microsoft’s own previous configuration. Worth noting what produced that score. Not the new model on its own, but Microsoft’s scanning harness running it alongside an OpenAI model. The Register covered the same launch and was considerably less impressed with the acronyms.
Set aside whether the benchmark holds. Look at who is making the claim. This is the company that already runs your clients’ identity — the directory, the sign-ins, the permissions. It is now positioning to run security for machine actors on top of that. The same vendor that decides which agents are admitted is selling the product that decides which agents are safe.
And that position is valuable enough that the rest of the industry is organizing around it. Nvidia launched what it’s calling the Open Secure AI Alliance — thirty-seven companies, including Cisco, IBM, Salesforce, and Microsoft itself — arguing that cyber defense should run on open models rather than closed ones. Look at who is missing. OpenAI, Anthropic, Google, Meta, and Amazon. Between them they build most of the frontier models the alliance says defenders need, and not one is a founding member. Thirty-seven companies do not organize over a technical preference. They organize when a layer is being claimed.
Here is what that means for the businesses you serve. Somebody is going to set the default terms on which machines can find your client’s business, reach it, and buy from it. That decision is being made at platform scale, and the default will arrive already switched on.
So here is the choice, and it is not about your own tooling. You can own the admission policy for your clients’ machine customers — decide which agents each client wants to be discoverable by, which ones may transact, on what terms, and sell that as the commercial judgment it is. Or you can let the platform set it, and find out at a renewal that your client’s reach into a machine-majority market is a checkbox in somebody else’s console. One you didn’t set, can’t explain, and were never paid for.
Which puts a question in front of you that your competitors have not thought to ask yet.
Why Do We Care?
Because there is a question sitting on the table right now that almost nobody in your market knows to ask, and the first provider who asks it out loud owns the conversation that follows. Not “is your site secure” or “are you found on Google” — but “which machines do you want finding and buying from this business, and which ones don’t you.” The separator isn’t having a better answer than your competitors. It’s being the only firm in the room that understood there was a decision to make.
What to Consider
• Find out what each client’s site does with agents right now, because it is already doing something. A bot-management setting, a CDN default, or a robots file is currently admitting or refusing machine traffic on that client’s behalf — and in nearly every case nobody chose it, it simply shipped that way. Pull the current state for your top ten clients and write it down, because that inventory is the entire basis for charging to change it. And watch what this does to the reporting you already send them. Machine traffic inflates pageviews without producing a single lead, so a client’s numbers can look healthier every quarter while the revenue behind them flattens. That gap is the symptom, and you will see it before they do.
• Separate discoverability from transactability, because clients will hear them as one thing. Being findable by a customer’s AI assistant is a marketing decision with almost no downside. Letting an agent complete a purchase, submit a form, or open a ticket is a commercial and fraud decision with real exposure — and the two should never be governed by the same switch or sold in the same sentence.
• Track the platform defaults, because that is where this actually gets decided. The identity and security vendors will ship an agent-admission default, then change it again without an announcement anybody reads, and your client’s reach will move without them noticing. Put that review on a standing cadence tied to each client’s renewal, so you are the one who can say what changed, when, and what it cost them.
If this trend continues, within twelve to eighteen months, whether a small business is reachable by an AI agent becomes a measurable input to its revenue — and the provider who never raised the question is left explaining to a client why competitors are being found by buyers neither of them can see.

