Akamai Reported Surge in AI Bot POST Transactions

Data from August 2026 shows AI crawlers are increasingly performing interactive site actions.

Updated on Sept. 22, 2026 in Artificial Intelligence

Akamai Reported Surge in AI Bot POST Transactions

Live Poll

Do you trust websites to secure your personal data against automated AI shopping bots?

Akamai recently observed that verified AI crawlers are sending high-frequency POST requests to websites, marking a shift toward interactive agent behavior. The company analyzed a 30-day sample of global traffic to document how AI bots are performing actions like logins and cart additions.

Why it matters

The transition of AI crawlers from passive content scraping to active POST requests creates new security considerations for retailers and travel platforms. As agents gain the ability to interact with site workflows, protecting PII and preventing unauthorized service access becomes a priority for web administrators.

In a 30-day sample of verified AI crawler traffic, ecommerce sites accounted for 44.8% of all POST transactions while travel sites made up 30%. The Model Context Protocol, a new standard for connecting AI models to external data, currently represents 4.1% of these transactions.

The players

Akamai

A global content delivery network and cloud security provider that monitors web traffic patterns and bot activity.

Anthropic

An AI research and deployment company focused on building steerable AI systems and testing new model capabilities.

The details

AI bots utilize POST requests to initiate server-side actions, such as adding items to a shopping cart or completing a login, which differ from standard GET requests used for fetching page data. By monitoring the ratio of these request types, retailers can differentiate between legitimate automated agents and malicious traffic. The study also highlighted the emergence of the Model Context Protocol (MCP) — an open standard that allows AI models to communicate with data repositories — as a growing vector for potential PII exposure.

Timeline

  1. August 2026: Akamai conducted a 30-day analysis of global AI bot traffic.

  2. 2026: The Model Context Protocol is projected to grow as an attack surface.

The Tech Race

This analysis extends the understanding of web agent behavior established during the testing of the Mythos model in Anthropic's Project Glasswing. As models transition from static analysis to active interaction, the industry is racing to formalize standards like the Model Context Protocol to manage these new capabilities.

Developers and site administrators should monitor traffic logs for an increase in non-GET requests from known AI crawlers. These patterns suggest that automated agents are beginning to utilize site-specific features that could impact database performance or user account security.

The takeaway

The rise of POST-capable AI bots signals that web infrastructure must move beyond simple request-blocking to session-aware security models. Watch for updates to the Model Context Protocol specifications in 2026 to see how security standards evolve to accommodate agent-driven workflows.

Further reading

For more on how new agent standards are impacting web security, see Artificial Intelligence.

Live Poll

Do you trust websites to secure your personal data against automated AI shopping bots?