The Proxy Collapse: When Web Traffic Stops Being Human
Share
Key Points
- The proxies are breaking. Sessions, clicks, and devices no longer reliably represent people.
- AI agents are the new edge case. Block them and you may block revenue. Keep them and you may corrupt your data.
- User-agents are nearly useless. The signal is now in how traffic connects and behaves.
- Bots are no longer an analytics problem. They’re a business-wide classification problem spanning data, security, marketing, and finance.
Key Points
- The proxies are breaking. Sessions, clicks, and devices no longer reliably represent people.
- AI agents are the new edge case. Block them and you may block revenue. Keep them and you may corrupt your data.
- User-agents are nearly useless. The signal is now in how traffic connects and behaves.
- Bots are no longer an analytics problem. They’re a business-wide classification problem spanning data, security, marketing, and finance.
In 2024, automated software quietly outvoted people on the internet. Imperva's annual traffic study put bots at 51 percent of all web traffic that year, the first time machines had passed humans in a decade, and by 2025 the figure had climbed to 53 percent. The dashboards most analytics teams open every morning have not caught up, and they still treat a session as if a person sat behind it. For most of the web's history that was close enough to true, but it is now wrong more often than it is right, and that gap is where a surprising number of expensive decisions get made.
Every metric you track is a proxy for a human who may not be there
Peel back any metric and you find a stand-in: a session for a visit, a click for interest, a conversion for a human who decided to buy. That substitution worked because, for twenty-five years, one machine event reliably mapped to one person. Call the breakdown of that mapping the Proxy Collapse, the point at which a measurement stand-in stops corresponding to the human it was built to represent. The number on the screen keeps moving, but what it stands for has come loose from the person it once tracked.

Two very different machines are pulling the session away from the person
The two forces severing the session from the person arrived from opposite directions. The first is fraud that got good: bot toolkits built on ordinary browser automation now produce fingerprints that match real Chrome, so an account-takeover script or a coupon-harvesting bot looks, to your tags, like a shopper from Ohio. The second is stranger, because real customers are now handing their shopping to machines. Adobe Analytics measured AI-driven traffic to US retail sites rising 393 percent year over year in early 2026, and up 693 percent over the prior holiday season, while Salesforce estimated that AI and agents influenced 20 percent of global online sales during the 2025 holidays, worth about $262 billion. Caila Schwartz, its director of consumer insights, described that stretch as "a definitive shift to a new era of 'agentic' shopping."

The counterintuitive part is which traffic actually causes the most trouble. The fraud bots are, by now, a solved-enough problem, whereas the legitimate agent acting for a real customer is the one that breaks measurement, because you cannot delete it without deleting real revenue, and you cannot keep it without corrupting metrics built around human attention. In March 2025, AI-referred traffic converted about 38 percent worse than channels like paid search, and a year later it was converting better than they did, the same label carrying opposite meaning twelve months apart.
The only signals worth trusting now are the ones a bot cannot afford to fake
The old detection model asks a browser to identify itself through its user-agent string, a label the client reports about itself and can rewrite in a single line of code. The evolutionary biologist Amotz Zahavi argued in 1975 that the signals animals can trust are the ones too costly to fake, which is why a peacock's tail is so heavy and metabolically expensive that a weak bird cannot afford to grow one.
Cheap signals, by contrast, invite imitation: a harmless hoverfly wears the yellow-and-black bands of a wasp precisely because the pattern costs nothing to copy, and a spoofed user-agent is nothing more than the hoverfly's stripes. The signals worth trusting are the expensive ones, the byproducts of how a client actually connects and behaves that an operator would have to rebuild its whole system to forge.
That reframing is now the official line of the companies that sell bot defense. Tim Chang, who leads application security at Thales, wrote in Imperva's 2026 report that the challenge "is no longer identifying bots," but working out what a given piece of automation is doing and whether its intent belongs on your site. Detection stops being a yes-or-no gate at the door and becomes a running question about intent and permission.
Bot management is becoming an organizational-design problem
For years, bot filtering was a checkbox an analytics admin ticked once and forgot, but that era is closing. When a fifth of your demand arrives through agents and half your raw traffic is automated, the decision about what to count stops being hygiene and becomes strategy. Your attribution model was built to trace how a human moves across channels, and your A/B tests assume the visitor in the test cell brings human hesitation and a human attention span. The segments driving your best campaigns were trained on behavior, some of which is now a machine acting under a customer's identity, so if you train tomorrow's personalization on that blend, the model learns the habits of a shopper who is partly software following instructions (Also read: When the Model Learns from a Storm That Never Happened).
Picture a growth team that watches conversion climb after a campaign and doubles the budget, when most of the lift came from agent traffic that would have converted anyway. They end up paying more to reach machines that had already decided, which is what happens when a distorted metric drives a real budget.

So the cleanup instinct backfires: strip out everything non-human and you pull real, paying demand out of your numbers, while filtering on self-reported signals quietly removes the honest bots that announce themselves and keeps the sophisticated ones that lie. A dashboard that looks cleaner after filtering is often more corrupted, because you deleted the traffic that was easy to catch and kept the traffic that mattered. The work shifts from removal to classification: sorting the human, the machine acting for a human, and the machine acting against you into separate buckets and counting each differently, which is a governance and org-design question well before it is a tooling one (Also read: Enterprise AI Is an Organizational Design Problem in Disguise).
The next two years belong to classification over filtering
The figures above come from vendors with a product to sell, so read them as directional, while my predictions below carry their own confidence levels and the conditions that would prove each one wrong.
| Prediction | Confidence | Timeline | Evidence | Invalidated if |
|---|---|---|---|---|
| Large consumer brands maintain a distinct "agent" traffic class, separate from human and bot, as a standard part of reporting | 70% | End of 2027 | Adobe and Salesforce already report agent-influenced sales; platforms are adding AI-traffic tagging | Agent-influenced orders stall below ~10% and teams fold them back into "other" |
| Self-reported identity (the user-agent) loses most of its detection value; connection- and behavior-level signals become the default trust layer | 65% | 2028 | Browser-automation libraries now match real Chrome fingerprints | A signed agent-identity standard is adopted first, making declared identity trustworthy again |
| Bot management ownership moves out of analytics and marketing into a cross-functional remit spanning data, security, and finance | 55% | 2028 | Bot costs already span infrastructure, paid media, fraud response, and analyst time | Platforms absorb it natively and it stays a vendor-managed toggle |
| A verified-agent-identity standard (signed, attestable agent credentials) ships from at least one major platform and starts shaping traffic policy | 50% | 2027 to 2028 | OpenAI and Google are building agentic commerce; human-verification efforts are underway | No major platform ships attestation and agent traffic stays anonymous |
The customer you were trying to understand is now one layer away
Digital analytics grew up as a way to read people, to see where they slowed down and where they gave up, and the whole craft assumed a person on the other end whose behavior carried meaning. When a customer hands the visit to an agent, the human you were studying steps back a layer, and the trail you are reading now belongs partly to a machine following orders. The teams that stay useful will stop asking "human or bot" and start asking who a visitor is acting for and whether they want them there. It is a harder question, and it does not fit in a checkbox, but it is a truer picture of who is on your site now.
Key Takeaways
- Automated traffic passed human traffic on the web in 2024 and reached 53 percent in 2025, so a session can no longer be assumed to represent a person.
- The Proxy Collapse is the point where a measurement stand-in stops corresponding to the human it was built to represent, which breaks attribution, testing, and personalization at the assumption level rather than the tooling level.
- The hardest traffic to handle is legitimate AI agents acting for real customers, because filtering it deletes real revenue and keeping it corrupts human-behavior metrics.
- Self-reported identity signals like the user-agent are close to worthless for detection now, so only the costly-to-fake byproducts of how a client connects and behaves can be trusted.
- Bot management is turning into a strategic classification problem owned across data, security, and finance, not a filtering checkbox owned by one analytics admin.
FAQ
What is the Proxy Collapse? It is the point at which a measurement stand-in, such as a session or a click, stops reliably corresponding to the human it was built to represent. Analytics has always measured proxies for human intent, which worked while one machine event mapped to one person, and it fails once a large share of traffic is machines acting for humans or against them.
Should I filter AI agent traffic out of my analytics? Not as a blanket rule. Agent traffic acting for a real customer represents real revenue, so removing it understates demand and misreads your funnel. The better move is to tag it as its own class and decide inclusion report by report, rather than deleting it or letting it hide inside your human numbers.
Why doesn't standard bot detection catch modern bots? Most native detection relies on the user-agent string, which a bot can rewrite to look like any browser it wants. Automation libraries built on ordinary browsers now produce fingerprints that match real Chrome, so the self-reported label is no longer a reliable tell, and detection has to move toward signals a bot cannot cheaply fake, based on how a client actually connects and behaves.
About the Author
Martin Goetzinger has spent his career in enterprise software sales, helping large organizations such as Apple, Microsoft, and Verizon connect data, insight, and action. His work focuses on transforming how businesses measure success and create customer value through technology.
Outside the enterprise world, he writes about the five forces he believes are reshaping everything: AI, blockchain, energy, personalized health, and robotics. Not from a purely technical lens, but from a human one as to how these technologies will redefine work, wealth, and well-being.
He is based in the U.S. and publishes at www.MartinGoetzinger.com.
Disclaimer
The views expressed in this article are the personal opinions of the author and are provided for informational and educational purposes only. Nothing in this article constitutes investment advice, financial advice, legal advice, or any other form of professional advice. Do not make investment or financial decisions based on the content of this article. Always consult a qualified professional before making decisions that affect your finances, business, or livelihood.
