AI bots just made things even harder for digital marketers

With over 50% of web traffic now non-human, what does this means for your marketing strategy?

By 

published on 

If you’ve been working in digital marketing for a while, you might remember the olden days of setting up absolutely mad RegEx filters in Google Analytics (UA) to exclude known bot traffic. It was a constant battle, but you’d end up with a pretty clean filtered profile alongside the one collecting the raw data. With the advent of GA4, those days are thankfully over; however, identifying bot traffic has become even more difficult with the advent of AI bots, some ‘good’ bots, and some ‘bad’ ones.

This is something I’ve come across in client data twice in just the last month alone. And it was a major headache for reporting. In one instance, when looking at year on year data, at first glance it appeared that a new landing page, which was ranking well, had a massive increase in page views. Well done, I thought, giving myself a pat on the back. But it turned out to be bot traffic (which I could see in the overall traffic report as a whopping spike) and due to the way this data is now reported in GA4, it was a real pain in the ass to ascertain what was a real gain in traffic, and what percentage of it was bot traffic, where the bot picked this landing page as the entry point to then go on to inflate the numbers across a whole range of other pages.

A second client, just this week, saw 1,000s of key events fire for a click on a specific button. Session data indicated that there was just no possible way even a complete lunatic would’ve clicked on that button a load of times, but now, that bot activity is going to skew conversion reporting metrics massively.

And that’s just one small part of a much wider issue when it comes to being able to report on digital marketing metrics – everything from GA4 data, Google Search Console (GSC) data, ad platform data, social media, and content is all impacted. And most of it is down to AI bots. And it gives me a headache.

Here’s why it’s happening.

AI bots now represent more than 50% of web traffic 

Before AI became mainstream and the hot new thing for every platform to shove in our faces (whether we like it or not), you could assume that, for the most part, digital marketing measurement was based on human interaction on the other end of every request. However, as of 2026, somewhere between 53% and 57.5% of web traffic is now automated.

Alongside the annoying bot referrer traffic I already mentioned popping up in Google Analytics, back in the day, bot traffic, especially for paid search clicks, used to be an ad-fraud story, but now it is a ‘total measurement shitshow” story where SEO, content, and brand are all being affected. Here is what is actually happening, how it impacts metrics, and what you can do about it.

Types of bots

Not all bots are a problem in the same way. We have moved from simple legacy bots to agentic AI that acts autonomously on a user’s behalf.

  • Legacy bots: Scrapers, spam, and click farms that have been around for years, largely impacting paid media and security.
  • Agentic AI: Traffic from agents that click, fill forms, and transact grew approximately 7,851% year-on-year by 2026.
  • Training and citation bots: These include GPTBot and ClaudeBot, which feed LLMs and index your site for AI answers with minimal referral value.

These types of bots all impact digital marketing channels in different ways.

SEO and content marketing

SEO is perhaps the discipline most disrupted by the rise of the ‘zero-click’ reality, and it’s all thanks to massive tech companies scraping all that lovely content humans have created and regurgitating it (sometimes correctly, sometimes not). With LLMs and Google’s AI Overviews (AIOs)/AI Mode, users are seeing answers to questions that used to drive significant traffic to your website, giving users information written by your experts, helping to build trust with your brand. Now, all of that hard work is presented in seconds without them even having to click through, and chances are, your brand isn’t cited either. 

When an AI Overview is present, CTR for the top organic result can drop by up to 58%, making ranking #1 no longer a guarantee of traffic. Furthermore, 74% of new web pages now contain AI-generated content, and while slop content is starting to perform poorly, it probably won’t be long before someone finds another vulnerability to exploit. It’s like going back to the early days of SEO, where spam was rife – and it worked (until it didn’t).

Google Search Console (GSC) also has a reputation for subpar data plagued with errors, such as the 2025 logging error that inflated impressions, and the fact that AI Overview appearances count as impressions regardless of clicks. This has made it harder than ever to analyse which pages and keywords are performing well, and which are not.

Some sites are choosing to block bots from accessing their sites, but it’s a bit of a ‘damned if you do, damned if you don’t’ situation. Block bots, and your content won’t be included in AIOs and LLMs, don’t block it, and it will probably be scraped from your site and hundreds of others – with no reference to your content at all. 

Publishers and blogs have been especially hard hit, with some cutting their workforce to close the gap due to lost ad revenue, and others deciding to shut down entirely, with some reporting that up to 80% of traffic disappeared in the months after the Google AI Overview rollout.

This led to more and more marketers thinking, ‘well, why don’t I just start optimising for AIOs and LLMs instead?’

Why GEO doesn’t replace SEO as a channel

As AI became more integrated with search engines, LLMs increased in popularity, and SEO was proclaimed to be dead for the 4 millionth time; a new discipline emerged. 

Generative Engine Optimisation (GEO) or Answer Engine Optimisation (AEO) is all about getting your brand to be linked, cited, or mentioned across LLMs like ChatGPT, Claude, and Gemini, as well as AI search engines, which include Google, Bing, and Perplexity. 

But getting featured doesn’t replace that good old traffic you used to get by ranking top of page in traditional SERPs. You might see a small increase in direct traffic or branded search queries if your brand is included in an LLM/AIO response after someone then does an old skool search on your brand, and a handful of referrals when a link is actually included, but it likely won’t close the gap. 

Much of the groundwork for ‘good’ GEO is just ‘good’ SEO – but unfortunately, despite the same (or greater effort and budget), the results just ain’t the same.

Another huge issue is visibility. Because prompts are more conversational, and users ask follow up questions to refine their searches, the behaviour is completely different to searching a couple of keywords. And this behaviour, including what people search for, is pretty much impossible to track – no matter what AI visibility tools might say.

Paid media has a new bot challenge

A whopping $63B in global ad spend is wasted on invalid traffic annually

It goes way beyond the crude bot clicks we saw back in the day, designed to waste ad spend and drive up CPC, too. Automated bid strategies have become the norm, ‘optimised’ by the platforms’ AI-driven algorithms. And that creates a massive problem if you’re relying on that platform to adjust bids and budgets for what it considers to be a high-quality visitor based on behaviour signals that could well be a bot, and not a human. 

Let’s say your bid strategy is optimised for conversions. When a bot fires that conversion, smart bidding reads it as success and teaches the algorithm to chase more bots with similar patterns – and chuck a shit load more of your budget towards it instead of at real potential customers. Modern bots can mimic realistic mouse movement and run on residential IPs, making them nearly impossible to detect, meaning that the platforms struggle to filter them out.

But that’s not all! As such a high percentage of total web traffic is now bots, if you’re running a reach/awareness campaign based on cost per view/impressions, how do you know your ads are actually being seen by humans? Well, you don’t. 

Social media – does anyone really like your brand?

Social media algorithms do not have any incentive to help brands that are trying to engage with their followers (unless you want to pay for it, of course). 

The content appearing in people’s feeds is more frequently being pushed with the sole aim of getting people roped into arguments in the comments sections to keep them on the platform. Clickbait works, because so few bother to read past a headline. And in the comments under these posts, a high percentage of them are just bots arguing with bots.

Engagement metrics like likes, shares, and follows are increasingly inflated by automated agents. You might think a post has done really well, only to dig into the comments or see who has interacted with your content, to find a sea of AI-generated PFPs or blank profiles. 

There is also the issue of brand safety. With the rise of AI deepfakes, it is now easier than ever for scammers to mimic real brands, including well-known companies and public figures like Martin Lewis, to deceive audiences. So if you’re measuring brand sentiment, that might also be borked if a fake profile has been set up, and is being used to scam people or spread false information about your company.

So what can you actually do about it?

Well, honestly, not much. As long as big tech companies are pushing AI into every feature imaginable so they can tout impressive figures on usage to the board, and ad platforms are doing little to combat metrics being inflated by bots because they don’t care as long as they are getting paid, this issue will continue to snowball.

But that doesn’t mean your data is completely bunk; it just means the job now involves a lot more scepticism and a lot less trust in the numbers on the dashboard. This means looking for trends and patterns, rather than focusing on raw numbers.

Here’s what’s realistically in your control, and what isn’t.

What you can do:

  • If possible, filter known bots at the server/CDN level (not just GA4). Tools like Cloudflare’s bot management catch a lot more than GA4’s built-in bot filtering ever will
  • If you can get hold of it, cross-reference GA4 anomalies against server log data before reporting a win to a client. If a landing page spikes, check the raw logs, not just the nice graph
  • Set up alerts for unusual event-firing patterns (like that button click nonsense), so you catch it before it skews a month’s reporting, not after
  • Where ad platforms allow, push back on smart automated bid strategies with manual guardrails and stricter conversion definitions, rather than handing full control to the platform
  • Treat GSC impression data with a large pinch of salt, especially when considering AI Overview data is now included
  • Report on ranges and trends rather than single hero numbers. It’s more honest, and it protects you when the data inevitably wobbles

What you can’t do:

  • Fully separate bot traffic from human traffic or engagement. The good bots and bad bots increasingly look identical, and some are designed specifically to evade detection
  • Reliably track what people are actually asking LLMs about your brand. There’s no GSC equivalent for ChatGPT or Gemini queries, whatever any AI visibility tool tells you
  • Stop AI Overviews or LLMs from scraping and repackaging your content, short of blocking bots entirely, which comes with its own trade-offs
  • Guarantee referral traffic from GEO/AEO efforts, even when the strategy is working exactly as intended
  • Trust platform-reported quality metrics at face value, because the platforms themselves can’t always tell a bot from a human either

The uncomfortable truth is that measurement is getting messier, not cleaner. The best move right now is adapting how to analyse the data in your reports, adjusting KPIs, and being upfront about what the numbers can and can’t tell you anymore.

Enjoy this post?

Sign up to Browser Media Bytes for similar posts straight to your inbox.

BM Bytes Sign Up