Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The Internet became more automated, more cryptographically resilient and more aggressively attacked during 2025. Cloudflare’s 2025 Radar Year in Review reports that global traffic visible across its network grew 19%, post-quantum encryption reached 52% of human-generated Web traffic, and AI user-action crawling increased more than 15 times. Separately, Cloudflare recorded 47.1 million DDoS attacks in 2025, including attacks measured in terabits per second.
These figures do not represent an independently audited census of the entire Internet. They describe traffic Cloudflare could observe and classify. Even with that qualification, they reveal a clear direction: software is accessing and acting on the Web at unprecedented scale, defenders are upgrading cryptography, and attacks are becoming too large and automated for traditional manual response.
What Cloudflare measured
The central source is The 2025 Cloudflare Radar Year in Review: The rise of AI, post-quantum, and record-breaking DDoS attacks, published December 15, 2025. It covers traffic observed from January 1 through December 2, 2025, across traffic, AI activity, adoption, connectivity, security and email security.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsCloudflare says its network spans 330 cities in more than 125 countries and regions. It handles more than 81 million HTTP requests per second on average, more than 129 million at peak, and about 67 million authoritative and resolver DNS queries per second. That gives it a valuable longitudinal view across many websites, networks and locations.
#1 Best Overall
It is not, however, a universal measurement instrument. Cloudflare does not see every connection, and its customers may overrepresent particular regions, industries and technical architectures. Different findings also use different denominators: some refer to HTML requests, some to human-generated traffic, some to verified bots and some to mitigated traffic. The safest wording is “Cloudflare observed” rather than “the Internet is.”
AI crawlers are changing the Web’s old bargain
Cloudflare found that Googlebot generated the largest request volume among the crawlers it observed. Googlebot represented 4.5% of HTML request traffic, while other AI bots collectively represented 4.2%.
Those categories are not perfectly separate. Googlebot supports conventional search indexing and also feeds Google’s AI-related services. Other crawlers may be collecting material for model training, indexing content for AI search or browsing pages in response to a user’s request.
Three types of AI crawler
- Training crawlers collect content that may be used to train or improve foundation models.
- Search and retrieval crawlers index material for AI search, retrieval-augmented generation or answer systems.
- User-action crawlers visit pages because a user has asked an AI system to find, compare, read or act on something.
Training traffic remained much larger than search and user-action traffic during the period measured by Cloudflare, but user-action crawling grew fastest. Cloudflare says AI user-action crawling increased more than 15 times during 2025. ChatGPT-User traffic also rose substantially, with peak request volumes as much as 16 times higher than at the beginning of the year.
This distinction matters because a crawler request is not the same thing as a successful referral. A bot can fetch an article without sending a reader to the publisher. It can request pages repeatedly, consume bandwidth and origin capacity, or retrieve material that is then summarized inside an AI product.
Cloudflare also found that AI crawlers were among the user agents most frequently fully disallowed in robots.txt files. That is evidence of publisher concern, not proof that every blocked crawler obeys the instruction. robots.txt is a policy signal, not authentication, access control or a guarantee of enforcement.
The publisher decision: visibility, control or compensation
Publishers now face a choice that did not exist in the same form when search engines primarily crawled pages and returned visitors. They can allow training crawlers, permit search crawlers while restricting training, allow user-action agents, block some or all automation, or attempt to charge for machine access.
Recommended Free Tools
| Approach | Potential benefit | Trade-off |
|---|---|---|
| Block all AI crawlers | Reduces unwanted extraction and infrastructure costs | May reduce visibility in AI search and future agent systems |
| Allow search but restrict training | Preserves some discovery while limiting model use | Mixed-purpose crawlers make enforcement difficult |
| Allow user-action agents | May create useful referrals or transactions | Agents can produce high request volumes and are difficult to authenticate |
| Monetize machine access | Could create a new revenue stream | Requires identity, metering, enforcement and willing buyers |
Cloudflare’s later 2026 report on the agentic Internet says more than half of traffic visible to its systems was non-human and that 52% of crawler requests in June 2026 were for AI training, up from 22% in spring 2025. Those figures should not be merged casually with the 2025 Radar statistics. “Non-human” is broader than AI traffic and can include search engines, monitoring systems, APIs, security scanners and automated browsers.
The same follow-up argues that some heavily crawled categories saw human traffic fall by as much as 40% in less than a year. That is a Cloudflare-reported observation, not a universal result for every publisher. The larger issue is nevertheless clear: the traditional exchange of access for referral traffic is under pressure.
Post-quantum encryption passed a major adoption milestone
Cloudflare says 52% of human-generated Web traffic observed across its network used post-quantum encryption in 2025. This does not mean that 52% of all Internet traffic, websites or data is “quantum-safe.” It is a Cloudflare metric based on its definition of post-quantum protection and the traffic it could observe.
Rank #3
Post-quantum cryptography is designed to protect public-key encryption from future quantum computers that could break some widely used systems. One reason organizations are preparing now is the “harvest now, decrypt later” risk: an attacker can record encrypted data today and attempt to decrypt it when sufficiently capable quantum systems become available.
Post-quantum protection is a significant defensive upgrade, but it addresses a specific cryptographic threat. It does not prevent phishing, stolen credentials, malware, weak passwords, unauthorized access, vulnerable applications, malicious insiders or DDoS attacks. TLS can protect data in transit while an authenticated attacker still abuses the application behind it.
The encryption finding belongs beside the AI and DDoS findings because it shows the defensive side of the same transition. Operators are modernizing infrastructure for a Web increasingly accessed by machines and exposed to machine-scale threats.
DDoS attacks became more numerous and much larger
Cloudflare’s 2025 fourth-quarter DDoS report recorded 47.1 million DDoS attacks during 2025, more than twice the previous year’s total. That averages 5,376 attacks per hour. Network-layer attacks more than tripled, rising from 11.4 million in 2024 to 34.4 million in 2025.
Cloudflare also reported a 31.4 Tbps attack lasting 35 seconds and a maximum rate of 205 million requests per second during the “Night Before Christmas” campaign. It said hyper-volumetric attack sizes grew more than 700% compared with large attacks seen in late 2024.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The units describe different kinds of pressure:
- Tbps means terabits per second and measures bandwidth volume. These attacks can overwhelm network links.
- Bpps means billions of packets per second and measures packet-processing pressure on routers, firewalls and other equipment.
- Mrps means millions of requests per second and measures application-layer request volume. Such attacks can exhaust Web servers, APIs, databases or other application resources without using the greatest bandwidth.
Consequently, the largest number is not always the most operationally important. A moderate-looking HTTP flood can be more damaging to an application than a larger bandwidth event if it targets an expensive database query or an authentication endpoint.
Aisuru-Kimwolf shows the botnet problem
Cloudflare described Aisuru-Kimwolf as a botnet primarily made up of malware-infected Android TVs. It estimated that the botnet contained between 1 million and 4 million infected hosts. During the December 2025 campaign, Cloudflare reported 902 hyper-volumetric attacks, with maximum rates of 24 Tbps, 9 billion packets per second and 205 million requests per second.
The infected-host figure is Cloudflare’s estimate, not an independently audited global census. The practical lesson does not depend on treating the estimate as exact: consumer-connected devices can become attack infrastructure, and a distributed botnet can combine bandwidth, packet and application attacks at machine speed.
A record attack does not mean every organization will receive that exact volume. It does show what attackers can coordinate and why waiting for a human to identify, classify and manually block each event is no longer an adequate primary defense.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →The common thread is automation
The three main findings describe different sides of one structural change:
- AI crawlers automate information gathering, comparison and action.
- Botnets automate disruption using compromised devices.
- Post-quantum cryptography automates protection against a future computational threat.
Cloudflare’s 2026 Threat Report adds a forward-looking concern: attackers are increasingly using stolen session tokens, trusted third-party tools, AI-assisted reconnaissance, deepfakes and other high-trust techniques. This is not part of the 2025 Radar measurement, but it helps explain why security teams must look beyond perimeter defenses.
The most important change may not be one spectacular exploit. It is the industrialization of attacks: cheaper reconnaissance, scalable botnets, automated content generation and compromised identities that can appear legitimate to systems designed mainly to detect obviously hostile traffic.
What website owners should do
- Inventory automated traffic. Measure requests, bytes, origin load, cache hits, referrals and business outcomes separately for humans, search crawlers, AI crawlers, APIs, monitors and suspicious automation.
- Separate crawler purposes. Decide whether training, search, retrieval and user-action agents should receive the same access. Do not assume a user-agent string proves identity or intent.
- Review policy and enforcement. Update
robots.txtand published terms, but use authentication, rate limits, bot controls and access rules where enforcement matters. - Protect expensive paths. Rate-limit login, search, checkout, API and database-heavy endpoints. A legitimate agent can still be operationally harmful if it sends requests too quickly.
- Protect the origin. Use a CDN or reverse proxy where appropriate, restrict direct origin access, protect DNS and ensure administrative interfaces are not exposed unnecessarily.
- Test DDoS response. Define escalation paths, preserve logs, identify critical dependencies and test application behavior under traffic spikes. DDoS mitigation cannot repair an overloaded database or insecure API design.
- Review identity and integrations. Use strong authentication, least privilege and monitoring for session tokens, service accounts and trusted SaaS connections.
- Begin post-quantum planning. Inventory cryptographic dependencies, identify data that must remain confidential for years and track post-quantum support from infrastructure and software vendors.
What this report cannot prove
Cloudflare’s data is strategically useful because of the scale and variety of its vantage point, but it should not be treated as a neutral census. The report cannot prove that 52% of the entire Web is post-quantum encrypted, that 4.2% of all Internet traffic is AI traffic, or that more than half of every Internet metric is non-human.
Nor does “6% of traffic was mitigated” mean Cloudflare blocked 6% of the Internet. Cloudflare says that 6% of traffic across its network was mitigated for potentially malicious or customer-defined reasons. The denominator is Cloudflare-observed traffic, and the category includes customer-configured mitigation.
The strongest conclusion is narrower and more defensible: across Cloudflare’s large but partial view, the Internet in 2025 became more automated, more prepared for a future cryptographic threat and more exposed to high-volume automated attacks. Website operators should respond by measuring machine traffic separately from human traffic, making deliberate crawler-access decisions and building security controls that can act faster than either attackers or bots.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

