Skip to content

Your website traffic jumped. Here’s why that number is lying to you.

    Have you seen an unexplained lift in sessions in your recent monthly reports? We’ve had a handful clients flag the same thing just this month – a sudden jump in sessions, new users up two or three times on a normal month, and no campaign to explain it. Every time, the instinct is the same. Celebrate first, ask questions later.

    Don’t. Check your traffic acquisition report first.


    TL;DR

    • Bots now generate more web traffic than humans, 57.5% to 42.5% on HTML content, according to Cloudflare.
    • If your GA4 sessions or new users spiked with no clear cause, bot traffic is a more likely explanation than organic growth. Sessions are a weaker metric than ever.
    • Track active users, engagement rate, and conversion events instead.
    • Not every bot is bad news: some AI crawlers are why your content gets cited in AI answers. The fix is better filtering and management, not blocking everything.

    The internet just crossed a line

    In June 2026, Cloudflare CEO Matthew Prince confirmed something the industry had been circling for a while: automated traffic now outweighs human traffic online. Cloudflare’s own Radar data puts it at 57.5% bot requests to 42.5% human, on HTML content specifically. Prince had predicted that crossover for late 2027. It arrived eighteen months early.

    The driver isn’t the old wave of scrapers and search crawlers. It’s agentic AI, tools acting on a person’s behalf rather than just indexing pages for training data. HUMAN Security tracked that category growing 8,000% through 2025. A person shopping for a camera might visit five sites. Their AI agent doing the same task might visit five thousand.

    This isn’t a niche problem for enterprise. It shows up in GA4, in your server logs, and increasingly, in the load of your hosting infrastructure.

    Four things this actually means for your webiste

    Your session count is a worse metric than you think

    GA4 filters out the obvious bots automatically. It misses the newer, harder ones – fake hits sent straight to your reporting with no real visit behind them, and bots sophisticated enough to fake scrolling and clicking. Imperva’s 2026 Bad Bot Report puts automated traffic at 53% of the total web, up from 51% the year before.

    A spike with zero seconds of engagement time, no scroll depth, and a geography that has nothing to do with your customer base isn’t growth. It’s noise wearing a growth costume.

    Not every bot is the enemy

    Here’s where we’d push back on the instinct to block everything that isn’t human. AI crawlers like GPTBot, ClaudeBot, and PerplexityBot aren’t scraping your pricing page to steal it. They’re the reason your content might get cited in an AI answer instead of buried on page four of a search result. Blocking them wholesale to protect your analytics is like turning away Google’s crawler because you don’t like your bounce rate. Being crawled today functions a lot like being indexed did in 2010.

    The problem isn’t that bots visit your site. The problem is that your reporting can’t yet tell the difference between a crawler that might get you cited and a scraper that’s just wasting your server’s time.

    Hosting requests are a real line item now

    Every request, human or not, hits your server. WP Engine and similar hosts are already seeing the load. If your site is fielding thousands of extra requests a month from bots that aren’t converting, that’s infrastructure spend with no return attached. Worth checking your hosting reports alongside GA4, not just GA4 on its own.

    If a tool on your site runs on a paid API, bots cost you in dollars, not just load

    Plenty of interactive tools embedded in websites, maps, locators, lookups, run on metered third-party APIs. Google’s Maps Platform, for example, gives you a free allowance of loads per month and bills you per load after that. A bot doesn’t care that it’s burning through your quota, and it won’t convert once it has.

    We’ve seen this play out with clients running location-based or lookup tools, where a large share of usage traces back to regions with no real customer base and no meaningful engagement, a pattern much more consistent with automated requests than genuine visitors. If your site has anything calling a paid API, this is worth checking before it turns into a bigger monthly cost than the tool itself.

    If not sessions, then what should you report on?

    Sessions were never a great metric. They’re now actively misleading. Here’s what deserves the attention instead.

    SignalWhy it’s harder to fake
    Active users (not just new users)Requires sustained, repeat behaviour bots don’t bother with
    Engagement rate and average engagement timeBots tend to produce 0-second sessions or suspiciously uniform patterns
    Conversion events, including custom trackingA real form fill, demo request, or add-to-cart needs intent behind it
    Heatmap and session recording dataShows actual mouse movement and scroll patterns, not simulated ones
    Zero-party data (info the user hands over directly, like a quiz answer or a preference form)Only exists if a real person chose to give it to you

    The shift is from “how many people showed up” to “how many people did something that costs a bot more effort than it’s worth to fake.” Custom event tracking in GA4 and heatmapping tools like Hotjar do that work. Raw sessions don’t.

    It also helps to build your standard reports around filtered segments rather than the default all-traffic view. Set GA4 to show active users, not new users, and filter geography down to the countries you actually market in. It won’t catch every bot, but it strips out a lot of the noise before you even start analysing.

    A quick way to check if you’re affected

    Before you touch your budget or your content calendar based on last month’s numbers, run this check:

    • Open GA4’s Traffic Acquisition report. Look for any source with a 0% engagement rate or 0s average engagement time across the board, often hiding under the Direct channel or (not set).
    • Check Demographic Details by country and city. Are you seeing significant volume from locations outside of your actual market?
    • Pull the Hostname dimension with sessions in Explore. Any hostname that isn’t yours is a sign of Measurement Protocol abuse, meaning the “visit” never happened at all.
    • Check Tech Details for device and browser. A sudden, disproportionate spike in one or two specific OS, browser, or screen resolution combinations, out of step with your usual spread, is a common bot fingerprint.
    • Ask whether the spike lines up with a campaign, a PR mention, or nothing at all.

    If you’re seeing the pattern and can’t explain it, that’s the moment to build a clean segment and stop reporting on raw sessions until you have one.

    Worth saying plainly: if this means revisiting how you’ve framed recent growth to your board or leadership team, that’s not a mark against your reporting. It’s an industry-wide shift that most dashboards weren’t built to flag. “Here’s what changed in how the whole web measures traffic, and here’s how we’re adjusting for it” is a stronger story than pretending the numbers were never off.

    Your options for locking this down

    Once you’ve confirmed there’s a real problem, there’s a range of ways to respond, and they’re not mutually exclusive.

    Hero metrics that matter

    Instead of a default view stacked with sessions and new users, build reporting around active users, engagement, and conversion events, so what leadership sees each month is already the right number. Where GA4’s out-of-the-box events don’t capture what actually matters for a business, like a specific form step or a product configurator interaction, custom event tracking fills that gap so the dashboard reflects real intent, not just default clicks.

    Segments & exclusions in GA4

    Filter out known bot geographies, hostnames, and traffic sources so day-to-day reporting only reflects the users you actually care about, without needing to remember to do it manually every time.

    Bot management, at different levels

    This ranges from rate limiting, capping how often one source can hit your site, through IP restrictions, up to blocking specific bots or entire categories of bots at the network level. Most sites already run a baseline level of rate limiting. The gap is usually that it isn’t tailored to a specific site’s risk and traffic profile.

    30-day request review

    If bot traffic is a genuine priority, a review of the last month of requests to a site gives a clearer picture than guessing, and leads to recommendations built around what’s actually hitting that site, not a generic policy applied across the board.

    Nothing here is permanent

    Worth being upfront about one thing. Bots are getting more sophisticated, and some can already fake scrolling, clicking, and session duration well enough to pass as human. Whatever mix of blocking, filtering, and rate limiting makes sense for a site today may need revisiting in a few months, not because the first fix was wrong, but because the bots on the other side of it won’t stay still either. This is worth treating as an ongoing setting to adjust, not a box to tick once.

    The takeaway

    If your last few months of analytics look too good to be true, they might be. That’s worth acting on, not just noting.

    If you’re an existing client, get in touch through our support desk via email and we’ll start with a short conversation about what your reports are actually showing. From there, we can help with a bot audit of your site, a custom event tracking and dashboard setup that surfaces the numbers bots can’t fake, or a review of how your bot management is set up so the crawlers worth having, the ones that drive AI discoverability, still find you. Whatever’s driving the numbers you’re seeing, we can help you get a clear read on it.

    Not an existing client? Reach out anyway. We may still be able to help, depending on your setup.


    Frequently asked questions

    Is bot traffic bad for my website?

    Not automatically. Some of it, like AI crawlers, can help you get cited in AI search results. The risk is in your reporting, not the crawl itself.

    Why did my GA4 sessions spike with no campaign running?

    Likely causes are ghost traffic (fake hits sent directly to GA4), a coordinated bot wave, or scrapers hitting your site in volume. Check engagement rate and geography before assuming it’s real growth.

    What should I track instead of sessions?

    Active users, engagement rate, conversion events, and any data a real person had to choose to hand over, like a form fill or quiz answer. Custom events can be configured bespoke to your website and what’s genuinely important to your bottom line.

    Can I fix bad historical data in GA4?

    No, GA4 doesn’t allow retroactive deletion. Build a clean segment going forward and treat contaminated periods as unreliable for decision-making. Use annotations in your GA4 property to mark these periods clearly.