Piattaforma edge cloud di Fastly

Back to blog

Follow and Subscribe

Why SaaS and PaaS Infrastructure Leaders Are Facing 22% More Unwanted Bots

Alina Lehtinen-Vela

Responsabile del marketing dei contenuti

Between January and May 2026, data across our edge network showed that AI requests grew 6.5x faster than human traffic

This rapid growth of bot traffic is putting SaaS and PaaS platforms under far more pressure than almost any other industry. Our SaaS/PaaS-specific data from January 2026 reveals that baseline bot activity hitting your industry was 21% above the global average, and during that same period, unwanted bot traffic against SaaS/PaaS platforms was 22% higher than the global baseline.

The natural reaction to this can be to block bots aggressively, but more often than not, this is not the best approach. Managing modern platform infrastructure requires moving beyond raw IP blocking to granular, real-time visibility and adaptive mitigation strategies at the edge.

What Does High Bot Traffic Mean for Your Business?

Attackers operate like businesses, evaluating return on investment, resource costs, and financial return. As the low-hanging fruit in publishing and e-commerce gets picked, automated threats are moving to the next frontier: SaaS and PaaS platforms. Because these services sit behind authentication, attackers use automated tooling to target logins, attempt account takeovers, and extract value from behind your auth boundary.

More than 51% of AI requests hitting the Fastly platform require a trip back to origin infrastructure. This means infrastructure leaders face some hard choices. On one hand, legitimate AI crawlers, fetchers, and RAG agents can drive critical product discovery and LLM recommendations. On the other hand, uncached origin hits consume database connections, compute cycles, and egress bandwidth.

If you can't differentiate between high-value bot traffic and low-value or malicious scrapers, you risk burning your operational budget on traffic that offers zero return or accidentally blocking the bots that grow your business.

Take Control of Your Edge Traffic

Modern threat actors don't care about your static WAF rules or basic IP blocks. If you're responsible for keeping multi-tenant environments resilient, secure, and performant against the rising tide of bot traffic, you need telemetry that goes beyond basic bot counters.

Join Fastly’s security experts Omeed Nosrati and David King as they break down real-world data from over 5 trillion daily requests across Fastly's global network.

In the full session, you'll learn how to:

  • Implement Deception Strategies: Turn the tables on threat actors by feeding bad credentials back to automated scripts, forcing them to burn time and budget on dead-end attacks.

  • Master Traffic Granularity: Differentiate high-value AI retrievers and search indexers from unwanted or low-value scrapers probing your origin infrastructure.

  • Explore AI Monetization & Rate Limiting: Establish real-time edge controls that protect your platform's reliability while maintaining visibility across key LLM ecosystems.

Don't let unwanted bot traffic run up your operational overhead. Watch "AI, Bots, and the Agentic Future of Web" On-Demand Webcast Now.


Data Methodology: These insights are based on Fastly’s Next-Gen WAF and Bot Management products, derived from a trailing 6-month average of over 8 trillion requests inspected monthly as of 03/31/2026. Industry baseline metrics reflect data from January 2026, while AI growth trends span January 1 through May 31, 2026, using a fixed customer cohort and a 30-day trailing moving average to isolate organic activity. 



Pronto per iniziare?

Contattaci oggi