Ask most people what CAPTCHA looks like and they'll describe distorted letters, blurry numbers, or a grid of images asking you to identify fire hydrants.
Ask the same question of a modern web security engineer and they'll describe something quite different: a JavaScript snippet that silently observes your session behavior and returns a risk score before you've done anything at all.
Both are CAPTCHA. The second is increasingly what the term means in practice - and the gap between the popular image and the technical reality tells you something important about where this barrier category is heading.
Behind the puzzle piece
Zyte's State of Web Access 2026 finds CAPTCHA deployed on 22.5% of the world's most popular landing pages, making it the third most common web access control mechanism.

Two vendors between them account for 88.8% of all deployments.
And the pattern of where CAPTCHA appears - which industries lead, which trail, and how adoption scales with site size - reveals a technology in the middle of an identity change.
What is CAPTCHA? From von Ahn's text puzzles to invisible risk scores
The history of CAPTCHA is a useful lens on where it's going.
1. Text distortion
Luis von Ahn coined the acronym at Carnegie Mellon in 2000 - Completely Automated Public Turing test to tell Computers and Humans Apart. The original insight was elegant: find tasks that humans find trivial but automated systems find hard. Reading distorted text in noisy images was the first answer. When von Ahn launched reCAPTCHA in 2007, he turned this into a dual-use system: the CAPTCHAs were scanned book pages that computers couldn't OCR reliably, and the human responses were simultaneously solving verification puzzles and digitizing text for Google Books. Users were, unknowingly, doing useful work while proving their humanity. Google acquired it in 2009.
2. Human verification
The 2014 NoCAPTCHA reCAPTCHA - the "I'm not a robot" checkbox - was a conceptual shift. The checkbox itself does almost nothing; the system had already been analyzing mouse movement, browsing history, and behavioral signals before the click. The checkbox was UX theater, making users feel like they were doing something while the system had already decided.
3. Risk assessment
By 2018, reCAPTCHA v3 dropped the theater entirely. It returns a score between 0 and 1 assessing the likelihood of a human, based entirely on behavioral analysis, with no visible challenge at all unless the score falls below a threshold the site owner sets. The "puzzle" was gone. Cloudflare Turnstile operates similarly: an invisible or near-invisible challenge that runs behavioral checks and, for the vast majority of legitimate users, requires no interaction.
The category named "CAPTCHA" has actually become behavioral risk scoring with a legacy brand name.
Two vendors, nearly the whole market
The CAPTCHA market is dominated by a duopoly unlike almost anything else in web security.

reCAPTCHA, owned by Google, holds 49.4% of all CAPTCHA deployments in the dataset. Cloudflare Turnstile, launched in 2022, already accounts for 39.4%. Together they own 88.8% of a market measured across 11,100 of the world's most popular sites.
GeeTest, the Chinese challenger, takes 7.7% - a meaningful slice built largely on a different technical approach: slider and puzzle-based verification rather than image recognition, popular across Asia-Pacific markets and increasingly elsewhere.
hCaptcha, which positioned itself as a privacy-respecting reCAPTCHA alternative and briefly convinced Cloudflare to switch before Turnstile arrived, sits at 1.9%.
Arkose Labs (FunCaptcha), which uses interactive 3D challenges targeting fraud specifically rather than general bot detection, takes 1.5%.
Cloudflare Turnstile's growth rate is the striking number here. The product launched in beta in September 2022 and is already within 10 percentage points of reCAPTCHA's three-decade head start. The mechanism is the same one driving Cloudflare Bot Management's antibot dominance: the product integrates seamlessly with Cloudflare's existing infrastructure, and sites already on Cloudflare can activate it at near-zero procurement friction. This is platform economics playing out in a security context.
The smaller the site, the more CAPTCHA
One of the clearest patterns in the CAPTCHA data is an inverse relationship with site scale.

Small sites embrace the puzzle
CAPTCHA adoption is highest among the smallest sites (33.2% for sites under 350,000 monthly visits) and declines steadily as traffic grows, reaching 23.1% for major sites with over 21.5 million monthly visits.
This is counterintuitive only if you assume that security investment scales with site size. It makes complete sense once you understand what CAPTCHA is replacing and what it costs.
For a small site operator with no dedicated security team and a limited budget, CAPTCHA is an attractive option: it's inexpensive to deploy, requires no ongoing management, and provides visible, meaningful friction against the automated traffic that might otherwise abuse comment forms, account registration flows, or login pages. The cost in user experience - a few seconds of friction for legitimate visitors - is tolerable at small traffic volumes.
Large sites adopt alternatives
For a high-traffic site - a major e-commerce platform, a large media property, a busy financial services portal - that calculus inverts sharply. The conversion cost of CAPTCHA at scale is measurable and significant; A/B tests consistently show that visible verification challenges reduce completion rates.
The budget to deploy sophisticated invisible antibot alternatives is available. And the threat surface is, paradoxically, better addressed by behavioral systems than by visible challenges: at high traffic volume, statistical anomaly detection works well where it doesn't at low volume.
CAPTCHA, in this light, is not simply a less sophisticated version of antibot. It's the appropriate tool for the threat surface and budget of the sites that use it most.
Tobacco and the compliance use case
The industry leading CAPTCHA adoption in the dataset is tobacco, at 52% - more than double the global average. This has almost nothing to do with bot management.

Tobacco sites in most jurisdictions face legal requirements to verify that visitors are of legal age before displaying product information or allowing purchases. Age gates implemented through CAPTCHA are a pragmatic compliance choice: cheap, widely understood, and defensible as a good-faith verification effort even if they're trivially defeated by a user who simply lies about their age. The regulatory pressure to have something visible and auditable at the door is what drives the number, not threat modeling.
This points to something worth keeping in mind when reading CAPTCHA adoption data: the category spans radically different use cases. Tobacco at 52% and travel and tourism at 8% are both making rational decisions, but in response to completely different pressures. The CAPTCHA label conflates age-gate compliance, account security, scraping prevention, and form spam protection into a single detection event.
Why banks and travel sites hide their bot defenses
The industries with the lowest CAPTCHA adoption are equally revealing.

Banking sits at 10%, airlines at 11%, travel and tourism at 8%, government at 8%.
In each case, the low number reflects a decision to move away from visible verification rather than an absence of concern about automated access. Banking and financial services face severe conversion sensitivity: every additional friction point in account registration or login measurably reduces completion rates, and the competition for customers means that friction has a direct revenue cost. The major banks have invested heavily in invisible behavioral authentication - not because their bot problem is smaller, but because their budget and their user experience requirements demand it.
Travel and tourism operates similarly: booking flows are conversion-critical, and the industry has learned that visible CAPTCHAs in the checkout path are expensive mistakes. The bot problem in travel - inventory scraping, price aggregation, seat-holding - is substantial. It's addressed through other means.
What it means for web data access
CAPTCHA sits below antibot in sophistication, and the leading implementations are well-understood.
What makes CAPTCHA worth paying attention to is its role as a co-occurrence signal.

Sites running CAPTCHA are three to four times more likely to also be running rate limiting and antibot. Finding CAPTCHA on a site tells you you're in an elevated-security environment, not that CAPTCHA itself is the primary access control mechanism.
The trigger mode data reinforces this. In 96% of detections, CAPTCHA fired on the initial request with no prior interaction - consistent with an always-on posture where the site has made a policy decision to challenge all incoming traffic, not to respond to specific suspicious signals.
A site configured this way has made a deliberate choice about its security posture. Understanding what that choice reflects about the broader stack is more valuable than focusing on CAPTCHA in isolation.

