The word bot often arrives carrying guilt before the evidence does.
That is understandable. Spam bots, credential-stuffing tools, fake engagement networks, and automated scams are real. But the same technical category also contains search crawlers, uptime monitors, feed fetchers, archive crawlers, API clients, accessibility services, and scripts doing routine work for actual people.
If a study counts automation without separating those roles, “bot prevalence” can become a much scarier number than “deceptive automation prevalence.”
Some bots are infrastructure
Google openly documents that Googlebot automatically requests pages so Google Search can discover and index them. Google also describes crawling more generally as automated software used to discover and understand pages across the web.
Those requests are machine-generated. They belong in a traffic report about automation. But their purpose is not to imitate a human participant.
The same is true for a service checking a site every minute to see whether it is offline. An RSS reader fetching a feed on behalf of a subscriber is automated. So is a script downloading public weather data every hour. A preservation crawler saving a website before it disappears can be extremely aggressive compared with ordinary browsing and still be doing something useful.
This creates a measurement problem.
Intent and function matter
A security provider may classify automated traffic according to whether it appears benign or malicious. A social-network researcher might instead care whether an account presents itself as a person. A publisher studying comment spam cares about automated posting. A server administrator may care only about load.
All four can use the word “bot” while measuring different things.
Imperva’s recent bot reports illustrate the scale issue. Its 2026 report says automated requests accounted for more than half of observed web traffic in 2025. The report also distinguishes malicious automation from the broader automated total.
That distinction is essential. The headline number is not a count of fake humans.
Useful automation can distort simple prevalence claims
Imagine a small technical website. Human readers visit it 10,000 times in a month. Search crawlers, monitoring systems, AI retrieval tools, and archive crawlers together make 20,000 requests.
A traffic-level measurement could correctly report that most requests were automated.
A reader-level claim that “most of the site’s audience was fake” would be unsupported.
This is one reason Dead Internet Theory needs narrower categories than human versus bot. Some automation is adversarial. Some is deceptive. Some is commercial. Some is maintenance. Some is preservation. Some is a human using a tool to avoid doing repetitive work by hand.
The interesting question is not merely how much automation exists.
It is what the automation is doing, who operates it, whether it represents itself honestly, and whether it affects what people believe they are interacting with.
Without those distinctions, a search crawler and a fake grassroots account wind up in the same bucket. Technically they are both automated. Socially, they are not remotely the same phenomenon.
