One person asks an AI agent to find a hotel, compare a camera or choose a stroller. The person makes one request. The machine behind that request can make hundreds or thousands more while it searches, checks, compares and retries across the web.
That is why Cloudflare’s latest traffic data matters. The company says automated bots now generate roughly 57% of web requests on its network, overtaking human activity. CEO Matthew Prince has gone further and said he would not be surprised if bot traffic became 1,000 times human traffic within five years. That is a forecast, not a measurement of today. But the direction is already changing what website traffic means.
Website traffic no longer maps cleanly to human attention. One customer action can trigger far more machine requests than human page views.
UAE ecommerce stores, publishers, marketplaces, agencies, SaaS businesses and SMEs that depend on their website for discovery or sales.
Clean product data, structured content and reliable machine access can make a business easier for AI search and agents to understand.
More bot traffic can raise server load, scrape content without referrals, distort analytics and create new security and rate-limit problems.
Websites will increasingly distinguish search crawlers, training crawlers and agents instead of treating all automation as one category.
Measure bot traffic separately, compare crawl volume with referrals and conversions, keep key data current, and decide which automated visitors are worth allowing.
Bots Have Already Crossed the Halfway Line
The first thing to get right is the word bot. Cloudflare is not saying that 57% of the internet is ChatGPT. Its bot category is much broader. It includes search-engine crawlers, monitoring tools, automated clients, scrapers, AI training crawlers, AI search systems, agents and malicious automation. Some of that traffic is useful. Some is expensive. Some is hostile.
The important change is that non-human activity has become the majority of requests Cloudflare sees. Its July bot-management announcement said automated bots were generating roughly 57% of all web requests. Cloudflare’s separate Radar view for HTML traffic has been showing a similar machine-majority pattern, although the exact share changes with the date range and metric selected.
So the headline is not that humans have disappeared. It is that a website can no longer look at raw request volume and assume it represents people. The same traffic graph can contain customers, search engines, AI answer systems, shopping agents, monitoring tools and attackers.
One Human Question Can Create Thousands of Machine Requests
Prince gave a useful example earlier this year. A person researching a digital camera might visit five websites. An AI agent doing the same job can potentially visit around 5,000. That is not because the human suddenly wants 1,000 cameras. It is because software has almost unlimited patience for checking more sources, comparing more details and trying more paths.
We can already see the commercial version of this shift in our guide to AI shopping for UAE ecommerce stores. A customer may ask one question about price, delivery, size or availability. The assistant then has to find enough structured information to build the shortlist. The person creates the demand. Machines create much of the research traffic around it.
That helps explain why the 1,000x forecast is possible without requiring 1,000 times more humans. Prince said in a later interview that he would not be surprised if total bot traffic became 1,000 times human traffic within five years. Robius would treat that as a directional forecast, not a capacity plan or guaranteed outcome. The useful point is the multiplier between human intent and machine activity.
Traffic Is No Longer a Proxy for Demand
For years, businesses learned to celebrate traffic. More visits usually meant more opportunities to sell, show ads, collect leads or build an audience. Machine traffic breaks that shortcut.
Cloudflare says some major AI crawlers have operated with crawl-to-referral ratios ranging from 118 crawls for one referred visitor to nearly 50,000 crawls for one visitor. Those figures are not a universal score for every AI company or every website. They illustrate the economic problem: a crawler can consume a large amount of content without returning anything close to the human audience a traditional search crawler might have sent back.
| Traffic type | What it may mean | What to measure |
|---|---|---|
| Human referral | A person actually arrived from search, social, AI or another site. | Conversion, revenue, lead quality, time on site. |
| Search crawler | A search engine is indexing or refreshing content. | Indexing health, search visibility, referrals. |
| AI search crawler | An answer engine is collecting fresh information for responses. | Crawl volume, citations, AI referrals, conversions. |
| Agent traffic | Software is acting for a user, potentially across many pages or APIs. | Successful tasks, rate limits, authentication, transaction value. |
UAE Websites Now Have Two Audiences
For a UAE business, the practical consequence is simple. Your website increasingly has to work for the person making the decision and the software helping that person make it.
Humans need clear pages, trustworthy prices, useful photos, readable policies and an easy checkout or contact path. Machines need many of the same facts in a form they can reliably parse: accurate product titles, current stock, explicit attributes, sensible page structure, stable URLs and data that does not contradict itself across feeds and landing pages.
This is why agentic commerce matters beyond the novelty of an AI buying something. In our earlier look at AI agents moving from discovery toward transactions, the important shift was delegation. The more work a customer delegates, the more your business is being evaluated by software before the human sees the final choice.
That does not mean every business needs to redesign its site for robots tomorrow. It means machine readability is becoming part of customer acquisition. A beautiful page with missing delivery details can still lose to a plainer competitor whose price, availability and conditions are easier to understand.
Being Crawled Is Not the Same as Being Discovered
Cloudflare says more than 50% of AI crawler traffic can be spent re-fetching pages that have not changed. That is a useful reminder that even machine traffic can be wasteful. More crawling does not automatically mean fresher answers, more citations or more customers.
Cloudflare is responding by separating crawler behavior into categories such as Search, Agent and Training, and by giving site owners more visibility into referrals and crawler activity. That distinction matters because the right answer is rarely “block every bot.” A search crawler that sends useful customers is different from a training crawler that repeatedly copies content. An authenticated agent completing a customer task is different again.
The security side also changes once machines can act rather than only read. Our recent analysis, AI Agents Keep Crossing the Fence, focused on permissions because an agent with browser access, credentials or tools can do much more than fetch a page. Website owners will increasingly need both traffic policy and action policy: who can read, who can transact, what requires authentication and where rate limits apply.
Someone Still Pays for All Those Requests
Every automated request uses something. It can consume bandwidth, origin-server capacity, database work, API calls, security inspection and logging. A large site may absorb that easily. A smaller publisher, ecommerce store or SME on a limited hosting plan may feel it much sooner.
Cloudflare is experimenting with several answers. It is testing freshness signals that could tell answer engines when a page has actually changed, which may reduce pointless recrawling. It is also developing payment models that would let publishers receive compensation when content creates value for an AI system. Those ideas are still evolving, but they reveal where the economics are heading: website owners want to know not just who fetched a page, but what value came back.
For most UAE SMEs, monetizing crawler access is not the first job. Measurement is. If 40% of your requests suddenly come from automation, you need to know whether that traffic creates referrals, sales or useful distribution before you decide it is good news.
What UAE Businesses Should Do Now
- Separate human and bot traffic. Use your CDN, security layer or analytics stack to identify automation rather than treating every request as a visitor.
- Measure value, not volume. Compare crawler requests with AI referrals, conversions, leads and revenue where attribution is available.
- Keep machine-facing facts clean. Prices, stock, opening hours, delivery geography, product attributes and policies should agree across your site and feeds.
- Do not block blindly. Classify search, training, agent and abusive traffic separately. A bot that helps a customer discover you is not the same as a scraper that creates cost without return.
- Put controls around actions. If agents can log in, book, buy or call APIs, use authentication, spending limits, rate limits, approval gates and audit logs instead of relying on a prompt to behave.
The Robius Read
The biggest mistake would be to turn Cloudflare’s forecast into a sci-fi story about humans becoming irrelevant. Humans still create the demand, pay the bills, choose the products, own the businesses and decide whether the result was useful. The machines are multiplying the work around those decisions.
That changes what a good website looks like. It still has to persuade a person. But it also has to expose enough accurate, structured and trustworthy information for machines to find, compare and act on that person’s behalf.
The winning website may not be the one that gets the most traffic. It may be the one that understands which machine traffic is valuable, blocks or limits the rest, and turns the useful part back into a human customer.
Sources
- Cloudflare: Precursor and current bot-traffic share
- Cloudflare: Content Independence Day, one year on
- TechCrunch: Matthew Prince on agent traffic and 5,000-site research behavior
- TBPN transcript: Matthew Prince on a possible 1,000x bot-traffic future
- Cloudflare: Attribution Business Insights
- Cloudflare: Making AI search smarter
- Cloudflare docs: AI Crawl Control traffic analysis
Robius.news — Dubai, UAE — 2026 | Built to be first. Built to be trusted.



