Ruishu Information Warns Machine Traffic Now Dominates Internet as AI Agents Surge
Ruishu Information has published the 2026 Automation Threat Report, revealing that non-human traffic now constitutes the majority of internet activity. According to the findings, bots accounted for approximately 68 percent of overall traffic between early 2025 and Q2 2026, with malicious bots representing 55 percent of that share. Human-driven access has dropped to roughly 22 percent, while AI Agent-generated traffic has risen rapidly from less than 1 percent to between 8 and 12 percent.
Requests originating from LLMs and AI Agents have surpassed 450 billion, reflecting more than 400 percent year-over-year growth. Agent browsers alone now represent 9.7 percent of AI Agent traffic and recorded more than an eightfold quarter-over-quarter increase, making them the fastest-growing segment. The report concludes that the internet has entered a new phase in which machines are no longer mere participants but primary users.
From Traditional Bots to Autonomous AI Agents
The report redefines non-human traffic into three categories: traditional bots, AI-enhanced bots, and AI Agents. Traditional bots typically follow pre-set rules for tasks such as scraping or credential stuffing. In contrast, AI Agents can understand objectives, plan actions, invoke tools, and adapt based on environmental feedback. To describe this evolution, Ruishu Information introduces an L1-L5 threat framework ranging from low-autonomy scripted attacks to multi-agent systems capable of independent planning and collaboration.
New Attack Surfaces and Industry Impact
The addition of AI Agents has expanded the list of tracked threat scenarios from nine to thirteen. Four new categories include LLM application attacks, agent supply-chain compromise, agent identity impersonation and hijacking, and autonomous AI-orchestrated attacks. Financial services recorded a 60 percent share of malicious bot traffic, while the internet sector led in AI Agent traffic at 15 percent. Manufacturing showed the fastest growth in automation-related threats.
Shifting from Detection to Trust Governance
Traditional defenses relying on IP addresses, user agents, or static fingerprints are becoming less effective against sophisticated agents that can operate inside legitimate browser environments. The report advocates moving toward a trust-governance model that evaluates identity, behavior, and intent. Under this approach, high-trust traffic receives normal access, medium-risk traffic faces rate limiting or additional verification, and low-trust traffic is subject to stricter controls or blocking.
Ruishu Information recommends five core measures: WAAP full-link defense, full-lifecycle data protection, dynamic environment detection, attack-chain correlation, and dedicated agent trust governance. These controls aim to reduce reliance on static signatures through dynamic obfuscation, tokenization, and fingerprinting techniques while enabling differentiated handling of compliant versus malicious machine traffic.
Related articles
OpenAI GPT-6 Astra Deploys Multi-Agent Parallel Processing, Increasing Local CPU Load and Security Risks
Early users of GPT-6 Astra have observed the model distributing complex tasks across multiple specialized agents that plan, solve, test code, verify results, and iterate after failures. This multi-agent approach enables faster handling of multi-step workflows compared to sequential chatbots. OpenAI states that Astra can control computers, operate browsers and applications, and install or test software, though it has not officially confirmed a native multi-agent architecture. Main computations run in the cloud, but agent tools can execute on user devices or corporate servers, leading to noticeable processor load when multiple agents compile code, launch browsers, run tests, and operate containers simultaneously. Corporate environments face added complexity as each agent requires virtual machines, sandboxes, internal data access, and careful environment cleanup. The increased autonomy has prompted OpenAI to strengthen monitoring of Astra actions and permission boundaries for subscribers of ChatGPT and enterprise clients.
Microsoft Copilot Can Surface Overshared Data Despite Permission Boundaries
Microsoft documentation states that Copilot only accesses data authorized for the signed-in user, yet default SharePoint and OneDrive sharing settings often grant broad access that the AI then respects literally. This creates accidental oversharing risks where Copilot retrieves documents shared too widely years earlier. Administrators can use Content Management Assessment and Data access governance reports, including the EEEU report covering the top 100 sites shared in the past 28 days, to identify problematic content. Two distinct controls exist: Restricted Access Control removes access entirely while Restricted Content Discovery hides items from Copilot and search without altering permissions. Sensitivity labels combined with encryption can exclude programmatic access for agents, though Microsoft does not guarantee outright blocking. Interaction logs stored in Microsoft Purview retain user prompts, Copilot responses, and citations to accessed documents, providing an audit trail for oversharing incidents.
Adaptive LLM Worm Uses Local Models to Craft Per-Target Exploits in Heterogeneous Networks
Researchers from the University of Toronto have published a preprint describing an adaptive computer worm driven by LLM agents that spreads across corporate networks by generating individualized attack strategies for each compromised system. Unlike traditional worms such as WannaCry that rely on fixed exploits, this worm maintains its own infrastructure by running local LLMs on infected GPU-equipped machines to analyze vulnerabilities and synthesize new attack vectors in real time. The system was tested in an isolated FakeCorp environment containing Linux, Windows, and IoT devices, successfully leveraging known real-world vulnerabilities to propagate over 48 hours and seven-day autonomous runs. Two core components power the worm: a GPU-hosted LLM component and a hierarchical agent framework with memory, reasoning graph, and tool modules that manage reconnaissance, exploitation, and payload deployment. The authors note that the approach creates an economic asymmetry favoring attackers because the worm parasitizes victim compute resources, eliminating the need for external C2 or commercial LLM services. They warn that adding adaptive reasoning to historical worms such as SQL Slammer, Conficker, or Stuxnet would significantly increase their resilience while remaining slower and noisier than classic self-propagating malware.
Building Secure On-Prem AI Assistants: How to Keep Corporate Data Inside Closed Contours
Many organizations hesitate to deploy AI assistants due to strict data protection rules that prohibit sending information to external clouds. The article explains how to implement AI models entirely within a company's own infrastructure, ranging from on-premise servers to fully offline laptops. It breaks down four deployment locations from public APIs to local devices and clarifies three distinct access levels: read, write, and execute. The author emphasizes that most business value comes from read-only access combined with human-in-the-loop controls for any irreversible actions. Practical recommendations include RAG over model size, quantization for local hardware, and maintaining immutable audit logs. The piece also warns that preparing clean knowledge bases often consumes more effort than the model itself.