← Back to blogToday it does. Integral Ad Science and DoubleVerify both bucket declared AI agents inside general invalid traffic, so those impressions are stripped out and not paid for. That classification has already cost at least one US publisher an entire buyer's budget, and better bot detection will not fix it.

Does AI agent traffic count as invalid traffic (IVT)?

Today it does. Integral Ad Science and DoubleVerify both bucket declared AI agents inside general invalid traffic, so those impressions are stripped out and not paid for. That classification has already cost at least one US publisher an entire buyer's budget, and better bot detection will not fix it.


An AI agent that fetches a page on a real person's behalf falls into a category digital advertising has no billing code for. It is mechanical at the network layer and human at the intent layer, and every verification system in production was built to answer only the first half of that question. The Media Rating Council's invalid traffic framework splits non-human activity into general invalid traffic, which is declared or routinely filterable, and sophisticated invalid traffic, which is fraud laundered to look like a person. Agent traffic lands in the first bucket by default. The impression is removed from the billable count, the publisher earns nothing for the read, and none of that changes just because a paying customer asked for the page.

What counts as invalid traffic?

Invalid traffic is the industry term for ad activity that does not come from a genuine human audience, and it is the metric buyers use to decide what they will and will not pay for. The MRC's Invalid Traffic Detection and Filtration Guidelines divide it in two. General invalid traffic, or GIVT, covers activity that identifies itself or follows known patterns: declared search crawlers, data-centre IP ranges, simple scripts on a timer. Most of it can be filtered at the network edge using published lists. Sophisticated invalid traffic, or SIVT, covers deliberate deception: residential proxies, hijacked browser extensions, mobile emulators spoofing device fingerprints. Catching SIVT is essentially why HUMAN, DoubleVerify and Integral Ad Science exist as standalone accredited businesses.

The commercial stakes are not marginal. Fraudlogix puts invalid traffic at roughly 20 per cent of programmatic impressions, about 37 billion dollars of US advertiser spend, while Juniper Research's global estimate for advertising spend lost to fraud runs above 100 billion dollars. Every one of those detection systems was designed around a single question: is there a person behind this session?

How do verification vendors classify AI agents today?

Four figures on invalid traffic - roughly 20 per cent of programmatic impressions are invalid traffic (Fraudlogix), about 16 per cent of general invalid traffic is tied to legitimate AI tool bots (DoubleVerify, Jan 2025), AI bots generated 15 per cent of clicks in unprotected media (DoubleVerify 2026), and the publisher earns nothing for an agent read booked as GIVT.

Both of the major verification vendors currently place declared AI agents inside the general invalid traffic bucket. Integral Ad Science stated the position plainly to Digiday in November 2025: it detects and blocks AI bots including declared agents used for retrieval-augmented generation, chatbots and sophisticated scrapers, and reports them as GIVT rather than SIVT, "so advertisers do not pay for non-human traffic media". DoubleVerify, per the same reporting, does not split agentic visitors out separately either, counting them within its general invalid traffic parameters.

The volume behind that decision is real. DoubleVerify's data published in January 2025 showed general invalid traffic nearly doubling year on year in the second half of 2024, up 86 per cent, and passing two billion ad requests a month for the first time, with roughly 16 per cent of that tied to bots belonging to legitimate AI tools such as GPTBot, ClaudeBot and Applebot. DoubleVerify's 2026 Global Insights research, distributed on 29 July 2026 and drawing on campaigns monitored through 2025 plus a survey of 22,000 consumers and 2,020 marketing decision-makers, reported fraud and invalid traffic violation rates down 41 per cent year on year in North America and 45 per cent across EMEA, but also found that in unprotected media AI bots generated 15 per cent of clicks.

So the classification is defensible on the vendors' own terms. An agent does not see a display ad, does not form a brand impression, and in most cases does not execute the JavaScript the ad call depends on. Charging an advertiser for that impression would be indefensible. The problem is what happens to the publisher on the other side of the ledger.

Why the classification is already costing publishers money

Flow showing how an agent visit turns into lost revenue - a reader asks an assistant, an agentic browser fetches the article, the verification vendor books the session as GIVT, the buyer sees an invalid traffic alarm and switches the budget off, and the publisher is left with a logged request, a stripped impression and paused spend.

The clearest documented case is Salon. In late October 2025 a mid-sized buyer switched off its entire spend with the publisher after receiving an Integral Ad Science report flagging an invalid traffic alarm, triggered by a spike in agentic visitors. Justin Wohl, vice president of strategy at Adtitude and formerly Salon's chief revenue officer, described the buy-side response as disproportionate: not all of the views were agentic, and plenty of humans were in the mix, but rather than set flags to suppress ads on agent sessions the buyer shut everything off. His warning about the wider risk is the sharpest version of the argument. While AI crawlers were only scraping content, publishers still earned from ads. If buyers stop trusting that impressions are human, they pause spend entirely, and at that point "the publisher is totally dead in the water".

This is not yet a universal experience. Paul Bannister, chief revenue officer of Raptive, told Digiday that after significant investigation his team had not found enough of this traffic to be worth worrying about across its portfolio, though he expects it to vary by vertical and called it "more fear right now than reality, but worth watching". Both things can be true: the aggregate volume is currently small, and the buy-side reaction to it is binary and immediate.

Olivia Joslin, co-founder and chief operating officer of TollBit, framed the structural problem: "Agents and bots mimicking humans is an anti-pattern that has dangerous implications, such as eroding advertiser trust." The erosion does not require the traffic to be large. It requires one verification alert to reach one media buyer.

Three kinds of AI traffic, three different answers

Treating "AI traffic" as one category is what makes this conversation circular. There are three distinct types arriving at a publisher's origin, and they deserve different handling.

Server-side retrieval bots are the declared fetchers dispatched from an AI company's own infrastructure, such as GPTBot, ClaudeBot and PerplexityBot. They announce themselves, they generally do not run JavaScript, and no meaningful ad call fires in the first place. Classifying them as non-human is straightforwardly correct. The commercial question here is not measurement but compensation.

Agentic browsers are the hard case. Perplexity's Comet, OpenAI's Atlas and the Claude Chrome extension run on the user's own machine, in a real rendering engine, carrying that user's cookies and logged-in sessions. HUMAN Security's Satori Threat Intelligence Team reported that in April 2026 browser-based agents accounted for roughly 71 per cent of activity across the top ten agents it observed, with Comet at 48.12 per cent, Atlas at 21.33 per cent, the Claude Chrome extension at 17.33 per cent and ChatGPT Agent at 8.55 per cent. Media took the largest share of that traffic at 45.62 per cent, ahead of ecommerce at 38.20 per cent and travel at 14.12 per cent, and 69.57 per cent of agentic activity touched product, search and article routes. These sessions arrive with user-agent strings, cookies and behavioural patterns that closely resemble human browsing, because in an important sense a human is behind them.

Undeclared scrapers are the third group: headless Chrome spun up on cloud instances, routed through residential proxies, identifying as nothing in particular. Simon Wistow, co-founder of Fastly, described the current landscape as "a much bigger menagerie of bots" spanning old credential-stuffers, the major search and AI crawlers, and a grey zone of firms "spinning up headless Chrome on EC2 instances and just scraping everything", which is why Fastly now runs bot detection on every single request rather than a sampled minority. This group belongs in the fraud bucket and nobody disputes it.

The direction of travel makes the distinction urgent rather than academic. Fastly's analysis of billions of requests across its network found AI-driven traffic growing at 6.5 times the rate of human traffic, with Wistow noting the network is "just about to tick over into 50 per cent of all traffic is bots". TollBit's State of the Bots report for the second half of 2025 estimated one bot visit for every 31 human visits.

Why better bot detection will not fix this

The instinctive response is that the verification vendors have adapted to every previous shift and will adapt to this one. That reasoning misreads what changed.

Every earlier wave of detection solved the same underlying problem: separate sessions behaving like people from sessions behaving like machines. When fraudsters improved their mimicry, detectors found the residual tells, the models were retrained, and the loop continued. It worked because behavioural signals exist in both legitimate and fraudulent traffic, so separation was a solvable classification problem.

A legitimate agent acting for a real customer defeats that loop by design. It trips headless detection, it has no mouse-movement entropy, it fills forms at machine speed, and it does all of that while a paying human waits for the result. Dave Byrne, writing for the Brand Safety Institute in May 2026, calls these sessions intent-bearing non-humans and puts the shift precisely: the question the stack has answered for fifteen years is one of identity, whether there is a human behind this mouse, and the question replacing it is one of provenance, whether there is a human mandate behind this token. Identity is a verification problem. Provenance is a trust problem, and it needs a credential that mostly does not exist yet.

The same tension is being litigated in public. Amazon sued Perplexity in November 2025 over Comet's agents accessing password-protected areas of its site on users' behalf, and in March 2026 a federal judge issued an injunction blocking Comet from the Amazon marketplace. Amazon argued security and unauthorised training data. Perplexity argued Amazon was protecting its ad load. The unresolved question underneath is the same one every publisher faces: what do you do with a machine session that a real customer authorised?

The infrastructure that would fix it, and how far away it is

The standards work is further along than most buyers realise. Cloudflare has shipped Web Bot Auth, cryptographic signing that lets an agent prove which operator it belongs to, and has partnered with GoDaddy on an Agent Name Service; the IETF has a working group on the same primitive. The IAB Tech Lab published an agentic roadmap in January 2026 covering standardised agent profiles, open-source reference implementations for buyer and seller agents, and new trust, provenance, measurement and transaction-integrity signals, mapped onto Model Context Protocol, Agent2Agent and gRPC, with a workstream explicitly covering measurement updates for zero-click search and AI user agents. Anthony Katsur, chief executive of the IAB Tech Lab, has argued that publishers will need ad systems that recognise an AI-driven visit, decline to run a standard ad call that serves no purpose for a language model, and substitute server-side decisioning built for non-human traffic. That thinking sits behind the Tech Lab's Trusted Server framework, which Katsur said in late 2025 had at least half a dozen publishers in the US, UK and Germany waiting to pilot it.

None of it is finished, and the sequence cannot be shortcut. The signing standard has to stabilise, agents have to be issued credentials, verification vendors have to build signed-agent handling into allow-list logic, and that handling has to become the default rather than something a buyer negotiates. That runs on a multi-year timeline in the optimistic case. For the whole of that window, the default setting in the verification stack is exclude, and the cost lands on the publisher.

What publishers should do this quarter

Measure at the edge, not in the tag. Client-side analytics cannot see server-side retrieval bots at all and misfile agentic browser sessions as ordinary visits. Server logs and CDN data are the only place the three traffic types can be separated, and you cannot argue with a buyer about a number you do not have.

Report your agentic share before a verification alert does it for you. The Salon case turned on a buyer learning about the spike from a third-party report rather than from the publisher. A monthly figure supplied proactively, with the breakdown by traffic type, changes the conversation from an alarm into a briefing.

Suppress standard ad calls on identified agent sessions. If the impression will not be billable, serving it contaminates your own numbers and inflates your discrepancy rate. Move that decision server-side where it can be made before the response is assembled.

Put agent handling into your next verification contract. Ask for agentic traffic to be broken out separately in reporting rather than folded into a single GIVT line, and ask what allow-list treatment a signed agent will receive when Web Bot Auth credentials are in circulation. Vendors respond to renewal conversations.

Decide the subscriber case now. Le Monde, which blocks almost all non-human traffic unless a licensing deal exists, is working through what happens when a paying reader arrives through an assistant rather than a browser. Its chief technology officer Paul Laleu is watching Model Context Protocol apps and OAuth-style extensions as the plumbing that would let an agent tell a publisher, in effect, that it is fetching an article for someone who already pays. Every publisher with a paywall faces the same question, and answering it late means blocking your own customers.

Where the revenue actually comes from

Comparison of a human page visit against an AI agent session - the human visit fires an ad call, counts as a billable impression, can form a brand impression and pays the publisher, while the agent session rarely executes the ad call, is stripped from the billable count as GIVT, forms no brand impression and pays the publisher nothing. No accent colour by design - the agent column loses by dimness, per the guide.

If the ad call should not fire for an agent session, the commercial value has to be captured somewhere else in the request. That is the argument for treating the read itself as the monetisable event rather than waiting for a human impression that will not arrive. blankspace operates at that layer, detecting AI and agent traffic at the CDN edge and placing contextual brand facts into the response an agent reads, so a retrieval that is worth nothing in a display auction still carries commercial value. The broader point holds regardless of vendor: as long as monetisation depends on a JavaScript ad call rendering to a human eye, every agent session is a cost with no offsetting revenue, and the verification stack will keep being right to exclude it.

Frequently asked questions

Is AI agent traffic classified as fraud?

Not by the major verification vendors. Integral Ad Science has stated that it reports declared AI agents, including retrieval bots serving chatbots, as general invalid traffic rather than sophisticated invalid traffic, which is the fraud category. The practical effect is the same for a publisher, since the impression is still excluded from billing, but the distinction matters for how a buyer interprets an alert on your domain.

Do AI agents see or click on ads?

Server-side retrieval bots generally do not, because they do not execute the JavaScript most ad calls depend on. Agentic browsers do render pages, so an ad can technically load, but there is no evidence agents form brand impressions and DoubleVerify's 2026 research found AI bots generated 15 per cent of clicks in unprotected media, which is a measurement contamination problem rather than performance.

Can advertisers really pull spend over agentic traffic?

Yes, and at least one has. In October 2025 a mid-sized buyer switched off its entire budget with the US publisher Salon after an Integral Ad Science report raised an invalid traffic alarm caused by a spike in agentic visitors. Raptive, by contrast, investigated its own portfolio and concluded the volumes did not yet justify concern, so exposure varies considerably by vertical.

How do I tell agent traffic from human traffic on my own site?

Declared bots can be identified from user-agent strings and published IP ranges in your server logs. Agentic browsers are far harder, because they arrive with real user agents, cookies and logged-in sessions, and most analytics tools cannot distinguish them at all. Edge-level detection or a specialist agent-visibility product is currently the only reliable route.

Will signed agents solve the invalid traffic problem?

Eventually, but not soon. Cloudflare's Web Bot Auth, the IETF working group on agent signing and the IAB Tech Lab's January 2026 agentic roadmap are all building toward verifiable agent credentials and provenance signals. The standard has to stabilise, credentials have to be issued, and verification vendors have to make signed-agent allow-listing a default rather than an option, which is a multi-year sequence. Until then the default treatment is exclusion.