Dead Internet Theory: What Bot Traffic Actually Proves
AI-generated editorial illustration of automated online activity; the screen is conceptual and is not evidence of real accounts.
Who Is Behind The Screen?
Bots can dominate measured web requests without proving that most people, posts or conversations online are fake.
The dead internet theory takes a recognisable unease and turns it into a sweeping explanation. Replies sound interchangeable. Images look synthetic. A crowd appears to agree, but it is hard to know who is actually present. Perhaps, the theory suggests, much of the apparent human activity has been replaced by machines.
There is a real phenomenon underneath that suspicion: automated systems generate substantial online activity. But evidence that bots make many requests cannot establish that the majority of internet users are fictional, that most posts are AI-generated or that a single hidden organisation controls the conversation.
To assess the claim, separate four things: traffic, accounts, content and influence. They interact, but none is a reliable substitute for measuring the others.
What The Bot-Traffic Figure Actually Measures
Imperva’s 2026 Bad Bot Report summary says automated activity accounted for more than 53% of web traffic in 2025, compared with 51% the previous year. Those are the company’s reported figures, published within its commercial security research.
The essential distinction is between activity and population. A request is an interaction with a service. It is not a person, a unique account or a completed conversation. A system that sends requests very rapidly can account for a large share of the total while representing very few operators.
The published percentage should also be understood through its measurement coverage and classification methods. A security provider has a substantial view of the traffic passing through the systems it observes. That does not make its dataset a direct headcount of every human and machine on the internet.
The finding matters for infrastructure and security. It cannot carry all the additional claims commonly attached to it.
One Bot Can Outnumber A Room Full Of People
Consider a deliberately simplified example. One hundred people each make ten requests to a website, producing 1,000 requests. One automated program makes 9,000 requests. Automation accounts for 90% of the 10,000-request total.
It would be wrong to conclude that 90% of the visitors were artificial people. The example contains one program and one hundred people. The percentage describes their unequal activity, not their numerical representation.
Now imagine that the program is checking whether a page is available. Its requests do not necessarily produce a public post at all. A large traffic share could coexist with a discussion board where every visible contribution was written by a person.
The reverse is also possible in principle: a small amount of network activity might create a highly visible deceptive post. Volume and influence need separate measures. Neither can be derived simply by renaming the other.
Not Every Bot Is Trying To Deceive You
Google’s crawler documentation distinguishes systems used to discover material, specialised crawlers and fetchers triggered by users. These are examples of automation performing recognisable functions rather than pretending to be a friend in a comments section.
A crawler can help information appear in search. A monitoring service can check availability. An agent can retrieve material at a person’s request. The presence of automation does not establish malicious intent or an attempt to impersonate a human.
Taylor Tailored’s guide to AI agents and automation explains why a system’s permissions and task matter. “Automated” describes how an action is performed. Whether the action is useful, permitted or deceptive requires more context.
That distinction becomes especially important when a report uses “bad bot” as a defined security category. Its meaning should be checked in that report, rather than treated as a universal label for every machine-generated interaction.
Four Questions That Need Four Kinds Of Evidence
Traffic: How many requests were classified as automated within a stated dataset and period? Relevant evidence includes logs, coverage and detection methods.
Accounts: How many accounts are automated, deceptive or coordinated? That requires a method for analysing accounts, not simply counting server requests.
Content: How much material was generated or substantially transformed by AI? The answer depends on the sampled material and the reliability of the classification.
Influence: Did that activity change what people believed, bought or did? Visibility alone cannot settle a causal question about behaviour.
These distinctions do not excuse manipulation. They make it possible to investigate a specific claim. “This network coordinated identical replies” is a narrower, testable proposition than “the internet is dead”. A claim becomes more useful when someone can explain what evidence would support or weaken it.
Why Bot Detection Is Not A Perfect Census
Cloudflare describes its bot score as an assessment of how likely a request is to be automated. Its documentation discusses heuristics, machine learning and other signals. It also acknowledges false-positive issues and provides separate treatment for verified automated services.
This is a classification process, not a device that can see the person behind every keyboard. Detectors infer from observable behaviour and technical features. Their usefulness depends partly on the task, the available information and the consequences of an error.
A low-confidence classification should not become a confident public accusation against a person. Equally, a program behaving like a browser does not become human merely because it passes one test.
Security researcher Troy Hunt’s account of distinguishing legitimate requests from bots in operating Have I Been Pwned illustrates the practical balancing act. Blocking abuse matters, but so does allowing legitimate access. A defence that rejects every uncertain request may reduce some automation while also making the service harder for people to use.
A Synthetic Image Does Not Make Every Claim False
Authorship and accuracy are different questions. A human can publish an error or a lie. An automated system can retrieve a correct fact. An AI-generated illustration can accompany accurate reporting if its role is transparent and it is not passed off as documentary evidence.
That does not mean origin is irrelevant. If an image is presented as proof that an event happened, whether it is a genuine record is central. If it is clearly labelled as a conceptual illustration, the factual claims need their own supporting evidence.
The useful habit is to identify what work each element is doing. Is the picture decoration, explanation or evidence? Is the quoted document accessible? Does it support the sentence attached to it? Is a source independent, or another copy of the same original assertion?
For recordings and images, the deepfake verification checklist develops those checks beyond looking for visual glitches.
Content Credentials Help With Provenance, Not Universal Truth
The C2PA framework allows information about an asset’s provenance to be attached and checked using cryptographic techniques. Its explainer is careful about the distinction between validating recorded provenance information and judging whether the depicted claim is true.
An image with a verifiable history can still be misleadingly captioned. An authentic photograph from one year might be presented as though it shows a different event. Conversely, missing credentials do not establish that a picture was generated by AI.
Provenance is therefore one part of an evidence chain. It can answer useful questions about recorded creation or modification steps, while leaving questions about context, completeness and interpretation unresolved.
Treating every provenance feature as a universal truth badge would reproduce the original mistake: asking one measurement to answer several different questions.
Why A Feed Can Feel Less Human
There are several plausible routes to that experience. Repetition may come from automated posting, but it can also come from people imitating a successful format. A recommendation system can repeatedly show a narrow style of content even if the wider platform contains much more variety.
These are alternative explanations to investigate, not findings about every user’s feed. A person’s timeline is a selected view rather than a random sample of everything online. Its atmosphere can be real as an experience while remaining a poor basis for estimating global proportions.
Imagine a recommendation system showing you ten similar clips because you paused on the first. That hypothetical sequence would reveal something about selection, without establishing that all ten creators were bots. It would also explain why scrolling further does not necessarily broaden the sample.
The practical question becomes specific: what is being selected, by what signals, and what can you inspect outside that selected view?
What Would Convincing Evidence Look Like?
A strong account of automated activity would identify its dataset, time window and unit of measurement. It would explain classification uncertainty and separate the observed result from claims about unobserved populations.
A strong investigation of coordinated accounts would show the basis for connecting them. A strong claim about AI-generated material would explain how authorship was assessed and how errors were handled. A strong influence study would examine outcomes rather than treating exposure as persuasion.
Readers need not become specialists in every method. Asking “what exactly was counted?” eliminates a surprising amount of confusion. Asking “what would change this conclusion?” helps distinguish an investigation from a theory designed to absorb every possible result.
There is genuine work to do on deceptive automation, synthetic content and manipulated visibility. That work becomes harder when a dramatic slogan replaces the evidence. The internet contains machines and people, often acting through one another. The important task is establishing who is responsible for a claim and whether there is a sound reason to believe it.

