ArticleResearch / ReportAccess handlingWeb data collection

Inside antibot, the arms race you can't see

Only 18.5% of top sites run dedicated antibot, but every one of them chose to. Why it's the most intentional barrier in the stack, and the strongest signal of a hardened site.

Robert Andrews · Senior editor

Inside antibot, the arms race you can't see

There is one number in Zyte's State of Web Access 2026 that tells you something the WAF adoption rate cannot: 18.5%.

That is the share of sites running a dedicated antibot service - a named, purposefully procured platform whose sole function is to identify and challenge automated traffic.

Dedicated antibot services run on 18.5% of top sites, always a deliberate purchase

Unlike a WAF, which arrives bundled with a CDN and runs at whatever defaults the hosting provider ships, antibot is never accidentally present. Nobody signs up for web hosting and discovers they've quietly acquired a behavioral analysis engine. Every one of the 2,054 sites in our dataset running antibot made a deliberate decision to buy it, configure it, and maintain it.

That makes antibot the most intentional barrier in the stack - and the most revealing one.

What is 'antibot' technology?

The term "antibot" covers a specific category of product: a service that goes beyond WAF signature matching to analyze the behavior of individual sessions and make probabilistic judgments about whether they originate from a human.

The signals these systems draw on span the full surface of a browser session:

  • mouse movement entropy and keystroke timing distributions.
  • scroll behavior.
  • canvas fingerprints (the subtle variations in how different hardware and browser combinations render identical images).
  • TCP/IP stack characteristics.
  • whether the JavaScript environment carries the markers of a headless browser.
  • whether WebGL reports a GPU consistent with the claimed operating system.
  • whether fonts are installed in the pattern of a real consumer machine rather than a bare server.
  • the timing gaps between individual requests.

No single signal is definitive. The approach is ensemble: build a score from hundreds of signals, weight them by historical predictive value, and decide whether to serve, challenge, or block. The leading platforms retrain on billions of requests daily. The model running today is different from the one running last week.

This is not the kind of system that emerged from academic research and landed in enterprise software. It was built under fire, by companies responding to attacks that were actively evolving.

A market with one dominant player

The antibot vendor landscape is more concentrated than almost any other technology category in this dataset.

Antibot vendors: Cloudflare Bot Management dominates at 75.9% of deployments

Cloudflare Bot Management accounts for 75.9% of all antibot deployments we detected - three in four sites with bot management running on a single platform. Imperva takes 9.1%, Akamai Bot Manager 7.7%, PerimeterX (now part of HUMAN Security) 5.0%, DataDome 2.0%.

The Cloudflare dominance is structurally predictable given the WAF picture. With Cloudflare's WAF already running on 35% of all sites, upgrading to Bot Management is a configuration change within an existing commercial relationship, not a procurement decision involving new vendors and contracts. The friction of adoption is close to zero. For enterprises already on Cloudflare's Enterprise plan, bot management is often included or a modest uplift.

The rest of the market - Imperva, Akamai, HUMAN - competes for the buyers who need capabilities beyond Cloudflare's platform or have reasons to keep their bot management vendor separate from their CDN. These are typically large enterprises in heavily targeted sectors: financial services, retail at scale, gaming platforms.

HUMAN's origin story is illuminating: the company was founded as White Ops to fight ad fraud botnets, built its credibility by collaborating with the FBI on the "3ve" takedown in 2018 - the largest dismantling of an ad fraud operation in history - and has since expanded into web access protection. The institutional knowledge embedded in these platforms reflects years of research.

The arms race that built the industry

To understand why these platforms exist in the form they do, you need to understand the decade of escalation that preceded them.

1. Blocking bots

The first wave of bot management was trivial: block user-agents that identified as bots. The response was equally trivial: spoof a browser user-agent. Then came IP blocking: maintain lists of known datacenter IP ranges and reject them. The response: residential proxy networks, which route bot traffic through real consumers' internet connections, making the traffic indistinguishable from organic visitors by IP alone.

2. JavaScript challenges

Then came JavaScript challenges: require the client to execute JavaScript and return a token before serving content. Headless browsers - Selenium, Puppeteer, Playwright - can execute JavaScript. The response from bot developers was to build stealth wrappers that hide the headless markers. The response from antibot vendors was to look for the hiding itself: a browser that claims not to be headless but lacks the GPU telemetry of a real machine is telling you something.

3. Identifying scalpers

The 2020-2021 GPU shortage crystallized the commercial stakes. Scalper bots bought the entire allocations of RTX 3000-series graphics cards and PlayStation 5 consoles the moment they dropped for sale online, reselling them at multiples of retail price. Retailers deployed antibot specifically because the business cost of not having it was visible, quantifiable, and public. Nvidia's website was effectively inaccessible to real buyers for portions of several product launches. The same dynamic played out with Nike's SNKRS app - the sneaker resale ecosystem runs on sophisticated automation that has forced Nike to operate a genuine cat-and-mouse arms race with AIO (all-in-one) bot developers.

The result is an industry where the product roadmap is determined by what attackers deployed last quarter.

What the industry distribution reveals

The sectors leading on antibot adoption tell you which industries have felt this pain most acutely.

Antibot adoption by industry, led by adult content, furniture and gambling

  • Adult content at 36% and gambling at 31% face credential stuffing attacks and account takeover at volume - automated access in these sectors carries direct financial fraud risk.
  • Computer Hardware at 30% reflects the scalper-bot problem.
  • Beauty and Cosmetics at 30% is partly about competitive intelligence - brands and distributors monitoring each other's pricing and inventory - and partly about account fraud in loyalty programs.

Furniture at 33% is the counterintuitive one. The furniture industry doesn't carry the obvious fraud risk of gambling or the resale arbitrage dynamics of consumer electronics. What it does carry is intense price sensitivity among consumers who cross-shop extensively before purchasing. Price aggregators and competitor monitoring in furniture retail are widespread and systematic, and larger retailers have concluded that their pricing data has commercial value worth protecting.

Industries with the lowest antibot adoption, including newspapers at 8%

At the bottom - newspapers at 8%, public policy at 9%, consulting at 9% - you find sectors where the threat model is simply different.

A newspaper's content is meant to be read. A consulting firm's landing page is a marketing document. The commercial case for antibot doesn't clear the bar.

The stacking signal

The most analytically significant antibot finding in our data lies less in the adoption rate itself than in what co-occurs with it.

Sites running antibot deploy rate limiting, CAPTCHA and TLS far more than others

Sites running antibot deploy rate limiting at 61.5% - versus 13.2% on all other sites, a 4.5x difference. They run CAPTCHA at 56%, versus 15% elsewhere. TLS fingerprinting at 33.6% versus 9.3%.

Antibot is a posture marker. A site that has procured dedicated bot management has almost certainly already deployed everything else available to it.

The decision to buy antibot appears to come after, and as part of, a broader organizational commitment to access control - not as a standalone substitution for other measures.

Finding antibot in the wild is a signal that you're dealing with a site that has thought systematically about access, has budget allocated to defend it, and is running a layered stack that won't yield to any single evasion technique.

Try Zyte API

Build your first scraper in minutes

Free trial, no credit card. From a single request to production in an afternoon.

Get started

Robert Andrews

Senior editor

Robert is a journalist and editor turned content strategist who eats and sleeps the web. Previously senior editor at Google, News Corp, ContentNext and others. As Zyte's senior editor, Robert covers the state of the data-access industry — legal developments affecting AI and scra…

More from this author

The Community · Newsletter

The best of Zyte and the data web, in your inbox.

One curated edition — new articles, product updates, and the stories shaping the data web. No noise.