Drooid Logo
Back to story perspectives

Full Breakdown

AI Agents Reshape the Internet: Traffic Surge, Security Risks, and Emerging Governance

6/23/2026, 11:23:56 AM

Automated Traffic Surge and AI-Generated Content

An Imperial College, Stanford and Internet Archive analysis found over one-third of new sites are AI-generated. Cloudflare estimates a third of traffic is bot-driven, while bunny.net’s 2026 Edge Security Report recorded automated requests at 20 % of traffic during a 53 % rise. AI crawlers accounted for 0.54 % of requests, edging out search bots (0.50 %), and ByteDance’s Bytespider contributed half of AI-crawler traffic.

Security Risks and Operational Impact

bunny.net logged a DDoS peak of 16.5 million requests per second from 392 000 IPs and a 4.2 Tbps volumetric attack. Injection-type threats—SQL injection, XSS, remote code execution—made up 45.5 % of firewall blocks; Log4Shell triggered over 184 000 events. Analysts note that rising automated traffic lowers attacker barriers and magnifies breach scale.

AgentOps and the Internet of Agents

Enterprises are adopting AgentOps, a framework that adds monitoring and audit to AI agents to curb rogue behavior. The French startup Moderering uses AI agents to block illegal content—hate speech and child sexual-abuse material—in line with the EU Digital Services Act. Surveys show 12 % of SMEs use AI, underscoring a need for data quality, governance and human oversight.

Official Statements & Responses

Dejan Grofelnik Pelzel, bunny.net’s CEO, called automated traffic the new foundation of internet operation. Joe Connolly, bunny.net’s head of Content Delivery & Security, warned that server-based security models are obsolete and urged protection. Alexandre Sossou, Moderering’s founder, highlighted the system’s ability to automatically detect illicit videos and the necessity of human supervision.

Criticism & Opposition

Security researchers say the automated footprint lowers entry barriers for attackers, making DDoS and injection attacks easier, while critics of AgentOps warn that without oversight agents could act unpredictably. SME advocates caution that AI-driven errors can disproportionately harm small firms, reinforcing the need for human review.

Conflicting Reports & Gaps

Studies use metrics: AI-generated sites exceed 33 % while automated requests are reported at 20 %; AI-crawler traffic is cited as 0.54 % of total requests and as half of bot traffic (Bytespider). No single definition of “automated” traffic is applied, limiting comparison.

Verbatim Quotes

  • “Automated traffic is no longer the exception, it’s becoming the foundation of how the internet operates,” — Dejan Grofelnik Pelzel, CEO, bunny.net
  • “ Joe Connolly, Head of Content Delivery & Security, added, “The findings from this report clearly show that isolated, per-server security models are no longer fit for purpose against modern traffic patterns.” — Joe Connolly, Head of Security, bunny.net
  • “We discovered that we had automatically identified websites hosting rape videos,” — Alexandre Sossou, Founder, Moderering
  • “Turning AI agents loose without a plan in place to audit their behaviour is akin to handing teenagers credit cards and not looking at the resulting account statements.” — Analyst, AgentOps

What's Next

Edge security firms plan to expand mitigation for AI-driven attacks, while AgentOps platforms will broaden to manage agent fleets. European regulators are testing AI moderation tools for wider DSA enforcement, and SMEs are expected to raise AI adoption as governance matures.