Grey boots from generative AI services is a growing threat to websites and applications. A new study shows report from Barracuda Networks. Gray bots are automated programs that are not overtly malicious, but that systematically crawl the internet to retrieve information. According to Barracuda have become increasingly active, often resulting in millions of requests. This can lead to problems such as overloads, longer response times and distorted web statistics.
Millions of requests per month
Between December 2024 and February 2025, Barracuda analyzed traffic from bots that ClaudeBot and TikTok's Byte SpiderIn one case, 9.7 million requests were registered in one month. Another web application received over 500,000 bot requests in a single day. The activity continued around the clock, with an average of 17,000 requests per hour.

AI bots distort decision-making data
– We are seeing a clear increase in AI-based bots that operate in the borderland between legitimate and malicious traffic. Their activity can overload systems, affect response times and lead to incorrect decision-making because web statistics are distorted, says Klas Palmér, security expert at Barracuda Networks.
Robots.txt provides no protection
Trying to stop bots by using robots.txt, a file that tells you which parts of a website are not allowed to be crawled, is not enough. It is a guideline, not a legal protection, and is rarely followed by AI actors.
The need for stronger bot protection
– Grey bots are blurring the boundaries of what is acceptable online. They collect large amounts of sensitive, commercial and proprietary data, and can significantly impact the functionality and reliability of websites. As a result, more and more organizations are seeing bott protection as an important part of its application security.

How to protect yourself against gray bots
To effectively protect against gray bots, advanced solutions are required that use AI and machine learningBy analyzing behavioral patterns, using adaptive models, and identifying digital fingerprints, unwanted bot traffic can be detected in real time – before it causes damage.
What is a bot?
Bots are automated software programs that perform online activities on a large scale. There are “good” bots, such as search engine crawlers, SEO bots, and customer service bots – and then there are “bad” bots, created to steal data, break into accounts or commit fraud.
Gray bots move in the borderland between these two. They are not necessarily harmful, but can have major negative consequences.
Read more here »