There is a quiet crisis playing out inside the dashboards of marketing teams across the world. Campaigns deliver strong click-through rates. Audiences look engaged. MQL numbers are hitting targets. And yet the sales pipeline remains anaemic, conversion rates disappoint, and finance wants answers. The culprit, increasingly, isn’t the creative. It isn’t the channel mix. It is the audience itself — or rather, the significant portion of it that was never human to begin with.
The scale of the problem is no longer deniable. Imperva’s 2025 Bad Bot Report found that malicious bots accounted for 37% of all internet traffic in 2024, up from 32% the year before. WP Engine’s 2025 Website Traffic Trends Report puts the figure even higher: nearly one in three web requests now come from bots, with AI-driven traffic consuming up to 70% of the most expensive dynamic resources. Depending on who you ask and which channel you examine, between 15% and 46% of programmatic ad impressions are delivered to non-human audiences.
For marketers who have spent years building sophisticated audience segmentation models, layering in third-party intent signals and behavioural data, this is a fundamental challenge. The inputs are contaminated. And if your audience data is contaminated, every targeting decision downstream — who you reach, what you say to them, how much you pay — is built on sand.
The fraud economy that advertisers are funding
The financial stakes are significant. Global digital ad fraud losses reached an estimated $41.4 billion in 2025, according to Spider AF — up from $37.7 billion the previous year. The World Federation of Advertisers has warned the figure could exceed $50 billion, making advertising fraud second only to the drugs trade as a source of criminal income globally.
Those numbers represent more than stolen budget. They represent corrupted signals. Bots do not just drain spend by generating fake impressions; they actively pollute the data layer that modern audience targeting depends on. When bots click ads, fill forms, download gated assets, and linger on pricing pages, they mimic the behavioural patterns that marketers use to identify intent. That pollution then flows upstream into retargeting pools, lookalike audience models, and conversion tracking — quietly degrading every campaign that follows.
Research by Spider AF found that fake leads are 4.5 times more prevalent in organic channels than in paid advertising, with organic sources producing a 4.06% fake lead rate versus 0.91% in paid. The implication is uncomfortable: much of the “free” inbound traffic that marketing teams celebrate may be carrying a hidden cost in wasted sales resources and false pipeline signals.
Programmatic’s transparency problem
The programmatic ecosystem has long promised efficiency through automation. Buy at scale, optimise in real time, reach the right person at the right moment. In practice, that automation has created significant blind spots — and fraudsters have learned to exploit them with precision.
A 2025 investigation by Adalytics — the ad measurement firm that has become one of the industry’s more uncomfortable truth-tellers — found that millions of ad impressions were being served to bots operating out of Google’s own cloud data centres. In one analysis from October 2024, Adalytics found that 90% of a subset of bot-served impressions were purchased via Google’s DV360 platform, with The Trade Desk and Amazon DSP accounting for much of the remainder.
Pixalate’s Q1 2024 benchmarks, drawn from analysis of 42 billion open programmatic transactions, found an overall click fraud rate of 18% across desktop web, mobile web, and mobile in-app. For desktop web alone, that figure rose to 26%. These are not edge cases confined to low-quality long-tail inventory. The fraud is embedded in mainstream programmatic supply chains.
The verification layer — the DoubleVerifys and Integral Ad Sciences that brands pay to pre-screen their buys — has also come under scrutiny. “I don’t have faith in any brand safety or verification platforms any further,” one brand media executive told AdExchanger following the Adalytics report. The concern is structural: verification vendors are paid by the impression, with incentives that do not always align with catching the fraud that the platforms they are rating are generating.
The AI agent complication
Just as the industry was beginning to grapple with traditional bot fraud, a new dimension has emerged. AI-powered agents — autonomous software systems that browse the web, consume content, and make decisions on behalf of users — are becoming an increasingly significant source of non-human traffic. This traffic is not malicious in the same way as click fraud. It is, in many respects, legitimate. But its implications for audience measurement are profound.
WP Engine’s data shows that AI-driven bots now account for a rapidly growing share of web requests, consuming up to 70% of the most expensive dynamic resources. Gartner has projected that traditional search engine volume will drop by 25% by 2026, driven in part by AI assistants mediating more discovery journeys on behalf of users. When a consumer asks an AI agent to research holiday insurance options, the agent may visit multiple sites, compare quotes, and return a recommendation — but the brand’s analytics team sees only bot traffic, with no visibility into the human intent that drove it.
For retail marketers especially, this creates a strategic imperative. Brands now effectively serve a dual audience: human shoppers and the AI agents increasingly influencing what those shoppers see and buy. A campaign that reaches humans effectively but is invisible to AI agents may be missing an expanding share of the discovery journey entirely.
What it means for audience targeting
The cumulative effect of fraud bots and AI agents is that the audience data underpinning most digital targeting is less reliable than it appears. Behavioural signals — page visits, content downloads, time on site, form completions — have always been used as proxies for intent. They are increasingly unreliable proxies.
This is driving a meaningful shift in how sophisticated marketing teams approach audience building. The movement away from third-party cookie-based targeting, which was already underway for privacy reasons, is being accelerated by bot contamination concerns. Third-party data pools — large, aggregated, assembled from across the open web — are particularly vulnerable, because the open web is where bot activity is most concentrated.
First-party data, collected through direct relationships with real, verified customers, is gaining strategic importance not just because of cookie deprecation but because it is inherently cleaner. A customer who has logged in, made a purchase, or engaged with a loyalty programme is demonstrably human. The behavioural signals they generate are trustworthy in a way that anonymous programmatic data increasingly is not.
What good practice looks like now
The marketing teams navigating this most effectively share a few common characteristics. They are investing in bot detection that goes beyond basic IP blocking and user-agent filtering. Sophisticated bots now rotate through vast networks of IPs and dynamic user agents, rendering simple filters obsolete. Behavioural analysis — examining scroll patterns, mouse movements, click sequences, and dwell times — is required to surface the anomalies that indicate non-human activity.
They are also becoming more deliberate about where they buy. The open programmatic exchange — where ad fraud rates in some networks reach 46.9%, according to Spider AF data — is increasingly viewed with scepticism. Private marketplace deals, direct publisher relationships, and walled garden environments, while more expensive on a CPM basis, offer meaningfully lower fraud exposure.
Pre-bid filtering, rather than post-serve reconciliation, is gaining traction. Catching invalid traffic before an impression is served — and before the budget is committed — is both more efficient and more protective of the optimisation algorithms that inform future campaign decisions. Cleaning data after the fact corrects the financial loss; it does not undo the targeting damage caused by bot signals entering the bidding model.
And increasingly, marketers are revisiting their measurement frameworks entirely. Impression volume, click-through rate, and even MQL count — all of which can be inflated by bot activity — are being supplemented or replaced by metrics that are harder to fake: pipeline conversion rates, revenue attribution, customer lifetime value. If the bots cannot buy, they cannot ultimately contaminate the metrics that matter most.
The uncomfortable conversation
There is a dimension of this problem that the industry has been reluctant to address directly: the incentive misalignment that allows it to persist. Publishers are paid per impression. Platforms take a percentage of spend. Verification vendors are paid by impression volume. In this structure, non-human traffic is not merely a technical problem — it is, for some participants in the supply chain, a revenue stream. As Jay Friedman of Goodway Group observed, brand procurement teams typically do not hold marketing accountable for wasted impressions, and agencies can deflect responsibility to their verification partners.
That dynamic is beginning to shift, slowly, under pressure from advertisers who are connecting the dots between bot contamination and disappointing business outcomes. The Adalytics reports — and the uncomfortable conversations they have generated at the most senior levels of major advertisers — are contributing to a more sceptical posture toward programmatic promises.
The bot problem is not going away. As AI capabilities improve, so will the sophistication of the automated systems that exploit digital advertising’s measurement gaps. The marketers who thrive in this environment will not be those who trust their dashboards most — they will be those who know exactly how much of what they are seeing is real.
