Next Article in Journal
From Asymmetry to Equilibrium: How Government Regulation Drives Sustainable Digital Asset Management on Media Platforms in China
Next Article in Special Issue
Detecting Health Product Misinformation on Social Media Using Large Language Models Grounded in Biomedical Evidence
Previous Article in Journal
A Hybrid Fuzzy Rough Set, Hierarchical CFA, and Random Forest Approach for Modeling and Validating Voting Intentions: Evidence from the 2023 Thai General Election
Previous Article in Special Issue
Evaluating the Impact of Instagram Engagement Metrics on Corporate Revenue Growth: Introducing the Loyalty Rate
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

The Vanishing User: Web Analytics in an Agent-Dominated Internet

1
School of Business, Alcorn State University, Lorman, MS 39096, USA
2
Bailey College of Engineering & Technology, Indiana State University, Terre Haute, IN 47809, USA
*
Author to whom correspondence should be addressed.
Information 2026, 17(5), 453; https://doi.org/10.3390/info17050453
Submission received: 7 April 2026 / Revised: 1 May 2026 / Accepted: 4 May 2026 / Published: 8 May 2026
(This article belongs to the Special Issue Recent Developments and Implications in Web Analysis, 2nd Edition)

Abstract

Conventional web analytics treats the human user as its fundamental unit of analysis, assuming stable preferences, identifiable intentions, and behavioral patterns that unfold over time. That assumption is under strain. Crawlers and traditional bots already account for a substantial fraction of online interactions, and autonomous AI agents are emerging as a further class of actors layered on top of this automated traffic. Unlike either, these agents do not possess persistent identities or psychologically grounded motivations. They are task-specific, dynamically instantiated processes whose behaviors are contingent and often orchestrated by external systems. Their presence weakens the interpretive value of core metrics, including sessions, engagement, conversion, and retention. A click may reflect an optimization routine, a proxy objective, or a recursive agent-to-agent exchange rather than meaningful human intent, and traditional inference frameworks cannot reliably distinguish among these possibilities. This is a position paper. It synthesizes literature across bot and agent detection, agent architecture, web measurement validity, governance of automated systems in adjacent sectors, and the epistemology of digital trace data, and it argues that web analytics should supplement, and in places replace, its human-centered model with an agent-aware model focused on interaction dynamics within hybrid ecosystems of human and non-human actors. The paper develops a working taxonomy of crawlers, traditional bots, AI agents, LLM-powered agents, and autonomous agents; identifies three properties of LLM agents (identity discontinuity by design, task-based instantiation, agent-to-agent loops) that distinguish the present challenge from prior bot-detection problems; examines opaque agent objectives, synthetic traffic loops, and the indistinguishability between human-originated and agent-mediated signals; and proposes five candidate measurement primitives (task chain, actor class, interaction provenance, objective alignment, signal authenticity) with explicit operational definitions. Governance machinery from energy systems and critical infrastructure offers a partial template, and we delimit which dimensions transfer and which do not. The contribution is conceptual and programmatic, presenting a vocabulary, set of candidate primitives, and research agenda for a field whose foundational unit of analysis is becoming unreliable.

1. Introduction

Web analytics, as a discipline and a commercial practice, was built on a specific bet about what the internet is: a space where humans act and where those actions leave interpretable traces. The entire inferential architecture of the field, from session tracking and funnel analysis to engagement scoring and cohort retention, assumes that the entity generating data is a person whose behavior can be explained, predicted, and influenced through psychological, economic, or social models. A pageview meant someone looked at something. A click meant someone wanted something. A purchase meant someone decided something. These assumptions held for roughly three decades, not because they were theoretically airtight, but because they were close enough to the truth to be useful. However, that margin of adequacy is narrowing.
The emergence of autonomous AI agents capable of browsing, interacting with, and transacting on the web has introduced a category of actors that share few of the properties the analytics framework requires. These agents do not have preferences in any psychologically meaningful sense. They do not persist across sessions the way a returning customer does. They are instantiated to accomplish a task and dissolved when it is done, leaving behind data traces that look identical to human behavior but mean something categorically different. The volume of such traffic is not trivial. Automated entities already constitute a substantial fraction of online interactions: estimates on social media platforms alone have ranged from 9% to 15% of active accounts [1], while Ng and Carley [2], drawing on global social media data, found that approximately 20% of social media chatter about major events is bot-generated. On the open web, honeypot studies have found that bot-generated requests dominate the traffic logs of newly registered domains [3], and Kirdeev et al. [4] estimated that non-human traffic constitutes close to half of all web traffic. These figures predate the current generation of large language model (LLM)-powered agents, which are more capable and harder to distinguish from humans than the bots of five years ago.
The consequence is a measurement problem with epistemic teeth. If a meaningful and growing portion of the data flowing through analytics pipelines originates from entities whose behavior cannot be interpreted using the models the field has built, then the outputs of those models (the dashboards, the attribution reports, the conversion funnels, the engagement scores) become harder to interpret even as their precision improves. The field is measuring more, with better tools, while the relationship between what is measured and what those measurements were designed to mean grows looser.
This paper advances a direct argument: web analytics should supplement, and in places replace, the human user as its default unit of analysis with constructs that can characterize interaction in a hybrid environment where human actors, AI agents, and recursive agent-to-agent exchanges coexist and are often indistinguishable from one another. This calls for rethinking the conceptual foundations of the field, from the definition of a session to the meaning of intent and from the logic of attribution to the epistemological status of behavioral data itself. The challenge is not confined to web analytics. Parallel debates about algorithmic accountability, governance-integrated explainability, and responsible system design have already surfaced in sectors where autonomous AI makes decisions with direct consequences for human welfare [5,6,7]. The energy sector, in particular, has developed governance frameworks for AI-driven systems that face structurally similar problems: black-box decision-making, accountability gaps when automated systems fail, and the difficulty of maintaining human oversight as the ratio of machine-to-human activity shifts. Web analytics has yet to learn systematically from these efforts. We argue that some of that machinery transfers and some of it does not, and we mark the line.

Article Type, Scope, and Contribution

This is a position paper. It does not present new empirical data, and it is not a systematic review in the PRISMA sense. It is a conceptual synthesis built on a structured narrative review of literature across five domains: agent architecture and capabilities, bot and agent detection, web measurement and validity, governance of automated systems in adjacent regulated sectors (notably energy and critical infrastructure), and the epistemology of digital trace data. Sources were selected purposively from peer-reviewed venues, recognized industry research (HUMAN Security, Anthropic Research), and high-citation preprints, with a temporal emphasis on work from 2017 to early 2026. Adjacent sectors enter the analysis where they offer transferable governance machinery, not as direct empirical evidence about web traffic.
Source retrieval combined searches in Scopus, Web of Science, IEEE Xplore, ACM Digital Library, and arXiv with targeted lookups for industry research and policy reports cited in those venues. Inclusion required relevance to one of the five thematic domains, traceable provenance, and either peer-reviewed status or, for industry and preprint sources, demonstrated citation impact or established institutional standing. Several claims, particularly those concerning current LLM-agent traffic volumes and detection trajectories, rest in part on industry reports and preprints: we use cautious verbs (suggests, indicates) for those claims and reserve stronger language for findings supported by peer-reviewed evidence.
The paper’s claims sit at three levels, and we take the trouble to keep them separate. The first is structural diagnosis: the conceptual architecture of conventional web analytics, built on identity persistence, intentional intelligibility of behavior, and a behavioral-to-psychological inference chain, was designed for a population that increasingly does not match the data. We support this through the cited literature. The second is reasoned projection: agent share and agent–human indistinguishability will continue to grow, and the field’s ability to compensate through better detection alone will reach diminishing returns. We argue this from documented trajectories and known dynamics, not from forecasts of our own. The third is programmatic proposal: the five measurement primitives we sketch in Section 7 (task chain, actor class, interaction provenance, objective alignment, signal authenticity) and the layered governance architecture we describe in Section 7.3 are candidate constructs for future development and empirical validation. We present them as testable proposals, not as deployed systems.
The primary domain of application is transactional site analytics: e-commerce, SaaS funnels, content platforms with measurable conversion outcomes, and ad-supported publishing. The secondary domain is broader hybrid digital ecosystems where measurement supports business decisions, including community platforms and search-mediated information services. We are not making claims about archival web crawling, scientific scraping, or non-commercial information retrieval, where similar issues arise but where the incentive structures, stakes, and tooling differ. We flag the boundary because some of our claims about metric corruption depend on commercial decision-making contexts that do not apply elsewhere.
The remainder of the paper proceeds as follows. Section 2 reconstructs the implicit theory of the user that grounds conventional analytics and identifies its core commitments. Section 3 traces the empirical emergence of web agents, fixes a working taxonomy of automated traffic, and isolates the three properties of LLM agents that distinguish the present challenge from prior bot-detection work. Section 4 examines the specific mechanisms through which agent traffic corrupts traditional metrics. Section 5 and Section 6 develop two of the most consequential problems: identity discontinuity and synthetic traffic loops. Section 7 proposes the outlines of an agent-aware analytics paradigm, with operational definitions for each primitive and three worked examples. Section 8 confronts the epistemological limits that any such paradigm must accept. Section 9 and Section 10 turn to discussion and conclusions, with the latter calibrating what the paper demonstrates, what it infers, and what it proposes.

2. The Folk Psychology of Web Analytics

Every measurement system carries implicit ontological commitments. A thermometer assumes the existence of temperature; a scale assumes the existence of mass. Web analytics assumes the existence of users, and it assumes specific things about what users are and how they behave. These assumptions are rarely articulated, which makes them harder to challenge, but they can be reconstructed from the structure of the tools themselves.

2.1. The Intentional Stance in Metric Design

Consider the standard session metric. A session groups a sequence of interactions (pageviews, clicks, scrolls) within a bounded time window and attributes them to a single entity. The design of this metric presupposes that the entity has a coherent purpose unfolding over the session: the user arrived wanting something, pursued it through a sequence of steps, and either achieved it or abandoned the effort. Bounce rate, time on page, pages per session, and exit rate all depend on the assumption that the sequence of actions reflects an underlying intention. A high bounce rate is bad because it suggests the user did not find what they were looking for. Time on page is meaningful because it suggests the user was reading or considering the content.
This is, in philosophical terms, the intentional stance [8]: the practice of treating an entity as a rational agent with beliefs and desires, and interpreting its behavior as the product of those mental states. Web analytics has always adopted the intentional stance toward its data subjects, even though it never framed the practice in those terms. The interpretive apparatus of the field, the reason a marketer looks at a funnel and sees a story about customer decision-making, depends on treating clickstream data as evidence of mental states.

2.2. Identity Persistence and the Longitudinal User

The second major assumption is that users persist over time. Retention analysis, cohort analysis, lifetime value calculations, and personalization systems all require the premise that the entity who visited on Monday is the same entity who visits on Thursday, and that their behavior across these visits can be aggregated into a meaningful profile. Cookie-based tracking, device fingerprinting, and login-based identification all serve this assumption. They are technologies designed to maintain the fact, or in many cases the fiction, of identity continuity across sessions.
Without identity persistence, there is no such thing as a returning user. There is no such thing as a customer journey. These concepts require a stable subject whose behavior at time t can be related to their behavior at time t + 1 in a way that reveals something about their disposition, their satisfaction, or their likelihood of future action.

2.3. The Behavioral–Psychological Bridge

The third assumption is that behavioral signals (clicks, scrolls, purchases, time spent) serve as reliable proxies for psychological states (interest, intent, satisfaction, confusion). This is the inferential bridge that makes analytics actionable. Raw behavioral data is, in isolation, meaningless. A click is a click. It becomes meaningful only when it is interpreted as evidence of something about the person who clicked: they were curious, they were convinced, or they were comparing options.
Stier et al. [9] have documented the methodological assumptions embedded in the use of digital trace data for social science research, noting that computational social science treats these traces as nonintrusive, high-precision records of human behavior. The precision is real, but the interpretive layer, the part where a click becomes evidence of interest, has always been a theoretical commitment rather than an empirical finding. The field has tolerated this gap because, for most of the web’s history, the assumption that data was generated by humans was overwhelmingly correct. When that assumption fails, the inferential bridge weakens.

2.4. The Site-Centric Measurement Trap

Even within the domain of purely human traffic, the measurement architecture carries a deeper fragility that the agent problem now exposes. Jansen, Jung, and Salminen [10], comparing Google Analytics with SimilarWeb across 86 websites over a full year, found significant discrepancies between the two platforms on standard metrics. Their findings underscore a structural limitation: site-centric analytics tools rely on cookies and tags rather than actual people. The user that appears in a Google Analytics dashboard is a composite of cookies, device identifiers, and session heuristics, not a verified person. This was already a problematic abstraction when all traffic was human. When a growing share of that traffic originates from agents that rotate identifiers, emulate browser environments, and clear cookie stores between tasks, the composite user becomes a fiction layered on a fiction. The gap between what the tools report and what is actually happening on the site widens in both directions: the human signal is harder to isolate, and the aggregate numbers are harder to trust.

3. The Agent Incursion

3.1. A Working Taxonomy

The literature on automated web traffic uses several overlapping terms, and the implications of the agent problem differ depending on which category an observer has in mind. We adopt the following distinctions throughout the paper.
A crawler is an automated process that retrieves and indexes web content according to fixed rules. Search engine crawlers, archive bots, and academic scrapers fall in this category. Crawlers typically identify themselves through user-agent strings and respect robots.txt directives, and the analytics industry has long-established conventions for filtering them out of human-traffic reporting.
A traditional bot is an automated process designed to perform a specific function (form submission, content posting, ad clicking, vulnerability scanning) using rule-based or shallow-learning logic. Bots can be benign or adversarial. Most of the bot-detection literature reviewed in Section 3.3 was developed against this category. Their behavior is repetitive, their intent is often inferable from request patterns, and their evasion techniques (rotating IPs, randomized timing) are bounded by the architectures available to their authors.
An AI agent, in the sense relevant here, is a system that perceives a digital environment, reasons about goals, and takes multi-step actions to advance those goals. The agent’s behavior is not fixed in advance; instead, it adapts to what the environment returns. This category includes earlier reinforcement-learning agents but is dominated, at the time of writing, by language model-driven systems.
An LLM-powered agent is an AI agent whose reasoning module is a large language model. These agents read rendered web pages much as humans do, interpret natural-language goals, and select actions through prompts rather than scripts. WebArena [11], commercial browser-automation agents from major model providers, and Claude Code in its agentic configurations exemplify this class for now.
An autonomous agent is an LLM-powered agent that operates with minimal human-in-the-loop intervention between goal specification and outcome. Autonomy is a matter of degree, ranging from supervised copilots that pause for confirmation at consequential steps to fully autonomous shopping or research agents that complete entire transactions without further input.
Synthetic traffic, in this paper, refers to web traffic generated by any of the above non-human actors. We do not treat synthetic traffic as inherently fraudulent. An autonomous shopping agent placing a real order on behalf of a real human generates synthetic traffic that represents genuine commerce; the issue is interpretive, not legal.
These categories shade into one another in practice. A modern e-commerce site sees crawler traffic, traditional bot traffic, LLM-agent traffic, and human traffic in the same pipeline, often without reliable signals to distinguish them. The argument of this paper concerns primarily the third and fourth categories, but it is sharpened by the fact that the field’s tooling cannot cleanly separate any of the four.

3.2. What Is Genuinely New About LLM Agents

Critics and practitioners reasonably ask why the agent problem is not simply the bot problem at a higher difficulty setting. Three properties of LLM-powered agents take the present challenge beyond an extension of bot detection. They are not new themes in isolation, but they compound in ways that break the inferential model of analytics rather than merely stressing it.
The first is identity discontinuity by design. A traditional bot, even an evasive one, is typically a persistent process with consistent objectives across runs: its evasion tactics target the detector while its purpose remains stable. An LLM agent is typically instantiated for a task and dissolved when the task is completed. Two agents from the same framework, instantiated minutes apart, can pursue unrelated goals, present different behavioral signatures, and share no continuity that analytics can recover. This is not a fragmentation problem to be solved with better identity stitching, it is a structural feature of how the agents are built. The very techniques that make analytics platforms good at reconstructing fragmented human identities (probabilistic matching across cookies, devices, and sessions) misfire when applied to entities whose successive instantiations were never the same actor in the first place.
The second is task-based instantiation rather than profile-based operation. Detection systems built around long-running behavioral profiles (return frequency, evolving interaction patterns, accumulated session history) lose their grip when the unit of agency exists only for the duration of a goal. There is no profile to detect because there is no entity with a persistent profile. Bot detection literature has typically assumed that signals accumulate over time; with task-based agents, the relevant signals exist only for the duration of a single task, and the signal volume per task is sometimes too small to support classification.
The third is agent-to-agent interaction loops. When Agent A queries a site whose interface is itself mediated by Agent B, both sides of the interaction are machine-generated. Detection literature has assumed a human is present on at least one side of any session worth measuring. Once both sides can be agents, the event traces being collected describe a machine-to-machine negotiation that the analytics layer interprets as user behavior. This is the structural feature that makes the click-fraud literature, surveyed below, an inadequate template for the present problem: in click fraud, synthetic traffic is adversarial and exceptional; in the agentic web, machine-to-machine traffic is normal and intended.
These three features compound. Each one alone is hard for detection systems built on the prior generation of bots. Together, they are not better-camouflaged bots; they are a different kind of actor whose data trace was not what the analytics tradition was designed to interpret.

3.3. From Bots to Autonomous Agents: The Empirical Picture

Automated traffic on the web is not new. Search engine crawlers, scrapers, vulnerability scanners, and spam bots have operated alongside human users since the earliest days of the commercial internet. The traditional response was to filter: identify known bot signatures, exclude them from analytics, and treat the remaining data as human-generated.
This filtering approach worked tolerably well when bots behaved in distinguishable ways. Conventional bots follow repetitive patterns, send requests at inhuman speeds, ignore JavaScript-rendered content, and leave characteristic signatures in server logs [3]. Xu et al. [12] demonstrated that in e-commerce marketplaces, rule-based and statistical methods could separate automated search traffic from human queries with reasonable accuracy, because the two categories generated distinct behavioral signatures. Fetterly et al. [13], in one of the earliest systematic analyses of query logs, showed that non-human behaviors, including meta-search engines, automated crawlers, and scrapers, systematically distort characterizations of human web search behavior. Their work provided early evidence that the assumption of human-originated web data was empirically fragile well before the current era of agentic AI.
The current generation of AI agents breaks this filtering model. LLM-powered agents do not operate by executing fixed scripts against a website’s structure. They interpret web pages as a human would, by reading rendered content, understanding context, making decisions based on goals specified in natural language, and adapting their behavior to unexpected outcomes. Zhou et al. [11] constructed WebArena, a benchmark environment consisting of functional websites across e-commerce, social forums, collaborative development, and content management domains, and demonstrated that GPT-4-based agents could perform multi-step, goal-directed tasks across these sites. Their best agent achieved a 14.41% end-to-end success rate on complex tasks, compared to 78.24% for humans. The gap is large, but the direction matters more than the magnitude: agents are performing the same tasks as humans, on the same websites, using the same interfaces.

3.4. The Agentic Web as Architectural Shift

Yang et al. [14] introduce the concept of the Agentic Web, a phase of internet evolution defined by autonomous, goal-driven interactions in which agents interact with one another to plan, coordinate, and execute tasks on behalf of users. In this model, the web ceases to function purely as a human-facing information system and becomes, in part, an infrastructure for machine-to-machine coordination. The user delegates intent (book me the cheapest flight to Chicago next Thursday) and an agent, or a chain of agents, carries out the necessary web interactions without human involvement at the interaction level. Browser automation frameworks, API-mediated agent architectures, and commercial agent platforms are already operational. The question is no longer whether agents will generate web traffic at scale, but how fast the ratio of agent-to-human interactions will shift, and whether analytics systems can adapt before their outputs become unreliable for the specific decisions they support.
Bandi et al. [15] provide a comprehensive review of the frameworks and evaluation metrics being developed for agentic AI systems. Their survey reveals a striking disconnect: the metrics used to evaluate agent performance (task completion rate, step efficiency, error recovery) share almost no conceptual overlap with the metrics used in web analytics (engagement, conversion, retention). These two measurement traditions describe the same interactions on the same websites using incommensurable vocabularies. Krupp et al. [16] reinforce this finding, documenting how the field of agent evaluation has developed its own measurement infrastructure with no reference to the analytics frameworks operating on the other side of the same data pipeline.
Anthropic Research [17] has begun to formalize this gap. Their work on measuring AI agent autonomy develops metrics that draw on both agentic API usage data and Claude Code behavior to quantify agent autonomy at scale, grappling with the challenge of defining task completion, interruption rates, and decision scope for agentic systems. These metrics do not map neatly onto traditional human user analytics, and Anthropic’s researchers acknowledge as much. The very primitives they propose (autonomy level, interruption frequency, tool-use scope) constitute an alternative measurement vocabulary that the web analytics field has no framework for absorbing. Two industries are building measurement systems for the same interactions, and neither system can parse the other’s outputs.
Recent survey work reinforces this architectural picture. Ning et al. [18] document how LLM-based agents perceive web pages through DOM parsing or rendered screenshots, reason about next steps, and execute multi-step workflows across sites without human intervention between steps. Sapkota, Roumeliotis, and Karkee [19] draw a useful distinction between individual AI agents and agentic AI systems, where the latter coordinate multiple specialized agents through orchestration layers, shared memory, and tool-use protocols. Ali and Dornaika [20] emphasize that modern agent architectures incorporate governance-aware logging and audit mechanisms as built-in components, generating structured records of every decision and action. These internal logs constitute a data source far richer than anything traditional web analytics collects, and they point toward the governance-integrated measurement approach developed in Section 7.

3.5. Scale, Trajectory, and the Detection Arms Race

Estimating the current proportion of agent-generated web traffic is difficult because the most capable agents are designed to be indistinguishable from humans. The trajectory, however, is clear from less sophisticated proxies. Varol et al. [1] estimated that between 9% and 15% of active Twitter accounts were bots. Li et al. [3], studying web traffic to honeypot domains over seven months, found that bots constituted the vast majority of visitors. In e-commerce, Xu et al. [12] documented that automated traffic represented a substantial portion of search queries, requiring dedicated detection and separation systems. Ng and Carley [2], working with global social media data, found that approximately 20% of chatter about major events is bot-generated, and that bot and human behavioral signatures remain consistently distinguishable across geographies and platforms. That cross-platform baseline is valuable, but it was established against bots far less sophisticated than the LLM-powered agents now entering the web.
The detection side of this equation faces its own compounding difficulty. The HUMAN Security Research Team [21] identifies key detection signals for distinguishing human users from autonomous AI agents, including network context, browser authenticity, and execution environment artifacts. Their report makes a critical concession: modern AI agents often rotate identifiers and emulate real browser environments, making single-indicator detection unreliable. Layered, context-aware behavioral analysis is now the minimum viable approach, and even that faces diminishing returns as agent architectures evolve. Gajewski et al. [22], proposing a dual approach that combines rule-based methods with supervised learning to distinguish human from bot behavior, demonstrate that hybrid recognition systems outperform single-method techniques. They also acknowledge the growing challenge of bots that accurately mimic human interaction patterns. The detection problem has the structure of an arms race, and the arms race favors the agents, because advances in language modeling improve both agent capability and agent camouflage simultaneously.
Additional evidence from the detection literature confirms the difficulty of the classification problem. Hayawi et al. [23] review deep learning approaches to social media bot detection and find that while neural models achieve strong performance against conventional bots, they face a moving target as bot sophistication increases. Aljabri et al. [24] catalog the full range of ML-based detection methods (profile-based, content-based, graph-based, and temporal) and conclude that no single approach will suffice for the current generation of LLM-driven agents. Sayyad et al. [25] demonstrate that behavioral biometrics, particularly mouse movement patterns and interaction timing, can reliably distinguish humans from automated agents, though their work predates the most capable agent architectures now in development. Xu et al. [26], reviewing LLM applications in cybersecurity, show that the same language-modeling advances that power useful web agents also enable more sophisticated evasion of detection systems, confirming the arms-race dynamic described above.
These figures establish a baseline. The agents now entering the web are more capable, more varied in their behavior, and harder to classify. The proportion of web traffic they generate will increase as agent-based interfaces (voice assistants, copilots, autonomous shopping agents) become a more common mode of web interaction for both consumer and enterprise users.
Table 1 classifies the sources reviewed in this paper across five thematic domains. Several sources contribute to more than one domain; the table reflects each source’s primary contribution. The classification reveals that detection and agent architecture research have developed in parallel, with limited cross-pollination, while governance frameworks from adjacent sectors (particularly energy systems) offer transferable models that the analytics literature has not yet absorbed.
Table 1. Classification of Reviewed Literature by Thematic Domain.
Table 1. Classification of Reviewed Literature by Thematic Domain.
Thematic DomainSourcesCore Concern for Analytics
Agent architectures and capabilities[11,14,15,16,17,18,19,20,27]Agents execute goal-directed tasks across web interfaces using perception, reasoning, and action modules, generating traffic structurally unlike human browsing
Bot and agent detection[2,3,12,13,21,22,23,24,25,28,29]Detection faces an arms race; behavioral biometrics, deep learning, and hybrid methods achieve strong results against current bots but face diminishing returns as agents improve
Metric corruption and measurement validity[4,9,10,30,31,32,33]Sessions, conversions, retention, and engagement metrics lose interpretive validity when applied to agent-generated data
Identity, attribution, and epistemology[1,8,33,34]The intentional stance underlying analytics requires a persistent, psychologically legible subject; agents lack these properties, weakening the inferential bridge
Governance, ethics, and institutional design[5,6,7,35,36,37,38,39,40,41,42]Governance frameworks (regulatory sandboxes, responsible design, accountability mapping) provide partial transferable models for analytics governance

4. The Corruption of Core Metrics

If a substantial and growing fraction of the entities generating web interaction data are not human users, then every metric that depends on the human-user assumption is compromised. The corruption is not random; instead, it takes specific forms that trace to structural differences between human and agent behavior.

4.1. Sessions and Engagement

A session, as defined by most analytics platforms, is a group of interactions by a single user within a given time frame, with 30 min of inactivity as the standard boundary. The metric assumes that the user is pursuing a goal and that the session captures the behavioral trace of that pursuit. Session duration, pages per session, and engagement rate are all treated as indicators of user interest and content quality.
An agent does not engage with content in this sense. It processes information to extract what is needed for a task and moves on. An agent might load a page, extract a price, compare it to another price on a different site, and exit, all within milliseconds. Or it might simulate prolonged engagement because its architecture involves rendering and parsing the full page, generating a session profile that looks identical to a human reading and scrolling. In neither case does the session metric measure what it was designed to measure: the quality of the user’s experience with the content.
Moen [29] proposed a session- and IP-level behavioral model to distinguish bot from human HTTP traffic, highlighting how aggregate session patterns (bounce rate, time-on-site, click depth) are systematically corrupted by automated agents. The corruption is not simply additive noise; it is structured distortion. Agents produce session profiles that cluster in ways that pull the distributional statistics of the entire dataset away from the human signal, so that even the clean human sessions are interpreted against a skewed baseline.

4.2. Conversion and Attribution

Conversion metrics track whether a user completed a desired action: a purchase, a signup, a download. Attribution models assign credit for that conversion to touchpoints in the user’s journey, allocating value to ads, emails, search results, and content pages that preceded the conversion event.
When an agent completes a purchase, the conversion is real in a transactional sense (money changed hands, a product was ordered), but the attribution logic falls apart. The agent did not see an ad and feel persuaded. It did not read a blog post and develop brand awareness. It executed an instruction, often from a human who made their decision through channels the analytics system cannot observe: a conversation with a friend, a recommendation from a different AI, or a preference specified months ago and stored in a configuration file. The touchpoints the attribution model credits are artifacts of the agent’s execution path, not evidence of a persuasion process.

4.3. Retention and Lifetime Value

Retention metrics assume that a user who returns is exhibiting loyalty, satisfaction, or habit. Lifetime value calculations project future revenue based on historical behavioral patterns attributed to a persistent user identity.
An agent that returns to a website repeatedly may be doing so because its human principal reuses the same agent configuration, because the agent itself has been configured to monitor prices on a schedule, or because the website appears in the agent’s search results for a class of queries. None of these patterns indicate loyalty or satisfaction in the sense the metrics intend. The concept of lifetime value, in particular, loses coherence when the customer is an ephemeral process rather than a person. The same human might interact with a website through different agents, or multiple humans might interact through the same agent framework, dissolving the one-to-one mapping between identity and behavior that lifetime value requires.

4.4. The Amplification Problem

Click fraud research has documented how automated traffic distorts advertising metrics at scale. Sadeghpour and Vlajic [30] surveyed the deployment of click bots and ad fraud techniques, identifying a range of schemes from simple invalid traffic to sophisticated automated click operations that mimic human browsing patterns. Fulgoni [31] characterized the problem as a multibillion-dollar black hole, documenting how bogus traffic inflates audience metrics and drains advertising budgets. Nagaraja and Shah [32] demonstrated that detecting these patterns requires traffic-level analysis rather than inspection of individual clicks, because individual fraudulent clicks are designed to be statistically indistinguishable from legitimate ones.
The advertising industry’s experience with click fraud is instructive but should function as a cautionary tale, not a template. The ad fraud response was built around the assumption that synthetic traffic is adversarial and can be isolated from legitimate activity. In the agentic web, synthetic traffic is not adversarial, but is normal commerce. An autonomous shopping agent that buys a product on behalf of a human is generating synthetic traffic from the analytics system’s perspective, but it represents a genuine economic transaction. The corruption of metrics does not come from bad actors exploiting the system. It comes from the system’s inability to distinguish among types of legitimate activity that carry different informational content.
Kirdeev et al. [4] framed the detection challenge in terms that sharpen this point. They treat human users as the positive class and apply positive-unlabeled (PU) learning to detect malicious bots without requiring large, labeled datasets. Their finding that filtering bot traffic yields cleaner training data for recommendation and personalization engines reveals a less obvious form of corruption: agent-contaminated signals degrade not only the analytics dashboard but the machine learning models that feed on the same data. Recommendation engines trained on mixed human–agent signals will learn to optimize for a phantom population that does not exist, serving up results calibrated to a behavioral distribution that represents neither human preferences nor any coherent alternative.

4.5. The Observer Effect in Detection

A subtler problem compounds the corruption described above. Any detection system that identifies and filters agent traffic from analytics pipelines creates an evolutionary pressure on agent architectures to evade detection. This is a measurement-theoretic version of the observer effect: the act of measuring changes the thing being measured. As analytics platforms develop behavioral fingerprints for agent traffic, agent developers will tune their systems to avoid those fingerprints, producing a ratchet in which each improvement in detection capability triggers a corresponding improvement in evasion capability. The long-term equilibrium of this dynamic is not better detection; it is permanent uncertainty about the composition of any given traffic stream.
Table 2 consolidates the metric-specific disruptions analyzed in the preceding subsections. For each traditional metric, the table identifies the human-user assumption it depends on, the mechanism through which agent traffic corrupts it, and the supporting evidence from the reviewed literature.
The supporting evidence in Table 2 varies in transferability. Findings cited for sessions, engagement, and traffic composition are direct, drawn from empirical bot studies, and they extend with high confidence to LLM-powered agents only as those agents reproduce bot-like signatures. Findings cited for conversion and attribution are analogical, transposed from click-fraud research where the synthetic traffic was adversarial rather than legitimate. Findings cited for retention, lifetime value, recommendation, and personalization are indirect, based on detection studies and meta-analyses whose original frame did not isolate autonomous LLM agents specifically. Readers should weight each row accordingly.

5. Identity Discontinuity

The problem of identity in web analytics has always been more fragile than practitioners acknowledge. Users clear cookies, switch devices, browse in private mode, and share accounts. Analytics platforms have developed increasingly sophisticated methods (cross-device graphs, probabilistic matching, login-based identification) to stitch together fragmented identity signals into coherent user profiles. These methods work imperfectly, but they rest on a valid underlying premise: there is a real person behind the data and the task is to connect the pieces.
Agents break this premise at a deeper level. The problem is not that agent identity is fragmented and needs stitching. The problem is that agent identity is not the kind of thing that can be stitched, because there is no persistent subject to recover.

5.1. The Ephemeral Actor

A modern AI agent is typically instantiated for a task and dissolved when the task is complete. It does not carry forward preferences, memories, or behavioral history unless those are explicitly persisted in external storage by its orchestrating system. Even when an agent framework does maintain state across sessions, the identity of the agent is a configuration, not a subject. The same agent framework can be instantiated with different goals, different constraints, and different behavioral parameters, producing entities that share code but share nothing that analytics would recognize as behavioral continuity.
This is not analogous to a human who changes preferences over time. Humans change, but they change within a framework of psychological continuity that makes longitudinal analysis meaningful. An agent that is instantiated today with the goal find the cheapest running shoes under $100 and instantiated tomorrow with the goal research enterprise CRM software is not the same actor in any analytically useful sense, even if it operates from the same IP address, uses the same browser fingerprint, and accesses the same cookie store.

5.2. The Principal–Agent Collapse

Web analytics has always assumed a tight coupling between the entity generating data and the entity whose behavior the data reveals. When a person clicks, the click is evidence about that person. Agents introduce a principal–agent gap: the entity generating the data (the agent) is acting on behalf of a different entity (the human principal) whose preferences, intentions, and decision processes are inaccessible through the data the agent generates.
This gap makes the behavioral–psychological bridge described in Section 2.3 structurally unsound. The behavioral data reflects the agent’s execution strategy, not the principal’s mental state. Inferring user preferences from agent-generated data requires a theory of how the agent translates principal intent into web behavior, and that theory does not exist in any form the analytics field can operationalize.
Volkova et al. [5], analyzing accountability challenges in AI-driven smart grid services, identify an analogous structural problem: when decisions leading to system failures are made by black-box models, mapping those failures to responsible actors requires an accountability framework that does not yet exist. The web analytics case is less dramatic (a misattributed conversion is not a power outage), but the structural logic is comparable. When an automated intermediary sits between human intent and system outcome, the causal chain that traditional accountability and measurement frameworks depend on is broken at the same joint.
Chu et al. [28] documented this problem at a smaller scale in their work on automated bot detection, noting that the difficulty of maintaining accurate user classifications increases as actors switch between bot-like and human-like behaviors. In the agentic web, this switching is not an anomaly to be caught by a classifier; it is the normal mode of operation. A human might begin a research task manually, hand it off to an agent, review the agent’s results, and then complete a purchase manually, producing a single user journey that is partly human-generated and partly agent-generated, with no reliable signal marking the transitions.

5.3. Identity as a Spectrum

The clean binary of human or bot that has organized the field’s thinking about traffic quality is dissolving into a spectrum. At one end, a person typing queries into a search engine and clicking results. At the other end, a fully autonomous agent executing a complex task with no human interaction. In between, a proliferating range of hybrid configurations: humans using AI-assisted browsers, copilots that suggest and execute actions with varying degrees of human oversight, agents that pause for human confirmation at critical steps, and multi-agent systems where one agent’s output becomes another agent’s input.
Chandler and Paolacci [33] sharpen this taxonomic challenge by identifying AI agents as an emerging third category of data contamination distinct from both traditional bots and careless human respondents. Their argument, developed in the context of online data collection for behavioral research, applies with equal force to web analytics: the field’s contamination models have been built around a two-category framework (legitimate human traffic versus illegitimate bot traffic), and this framework cannot accommodate an entity that is neither a human nor a traditional bot but something with its own distinct behavioral signature and its own distinct implications for data quality.
Analytics systems built to classify traffic into human and bot categories cannot represent this spectrum. The classification problem is no longer binary but continuous, and the position on the continuum affects the interpretive validity of every metric applied to the resulting data.

6. Synthetic Traffic Loops and Recursive Agent Exchanges

Among the more disorienting developments for web analytics is the emergence of traffic that has no human origin at any point in its causal chain. When Agent A, acting on behalf of a human, queries a website that is managed by Agent B, and Agent B generates a dynamic response based on the query, both the request and the response are machine-generated. If Agent A then takes an action based on Agent B’s response (adding a product to a cart, submitting a form, following a link), the resulting data trace is a record of a machine-to-machine negotiation that analytics will interpret as a user session.

6.1. The Recursive Problem

Yang et al. [14] describe agent-to-agent communication as a core feature of the Agentic Web, not an edge case. In their framework, agents interact with one another to coordinate complex tasks, forming chains where the output of one agent becomes the input of the next. When these chains pass through web interfaces (as they do when agents interact with web-based APIs, e-commerce platforms, or content management systems), they generate interaction data that enters the analytics pipeline.
The recursive problem emerges when agents on both sides of a web interaction optimize their behavior based on signals that include analytics-derived metrics. If an e-commerce site uses engagement data to rank products, and the engagement data includes agent-generated interactions, then the agents are shaping the environment they are navigating, creating a feedback loop with no human in the circuit. The analytics system, designed to measure human preferences, is instead measuring the emergent dynamics of agent-to-agent optimization.
This feedback loop has a partial precedent in energy systems, where Gritsenko and Wood [36] describe how algorithmic governance has become a reality as automated systems manage everything from load balancing to market trading. Their observation that algorithmic decision-making in critical infrastructure can produce emergent behaviors that no individual system was designed to create applies in modified form to web analytics: the aggregate effect of many agents optimizing against analytics-derived signals may produce outcomes that none of their designers intended or foresaw. The energy comparison is not perfect (energy markets have regulators with mandates and physical instrumentation; web analytics has neither), but the structural lesson, that coupled feedback among automated systems generates behaviors that are not explicable from any single component, transfers.

6.2. Synthetic Engagement and the Meaning Vacuum

The click fraud literature documented an earlier version of this problem. Sadeghpour and Vlajic [30] described how click bots inflate engagement metrics, and Fulgoni [31] quantified the financial consequences of treating synthetic traffic as genuine. But click fraud was understood as a pathology, an aberration to be detected and corrected. In the agentic web, synthetic engagement is not a pathology but a structural feature of how the system operates.
When an agent engages with content, the engagement metric registers a data point that is structurally identical to a human engagement event. If the content management system responds by surfacing that content more prominently (as engagement-based algorithms do), it changes the information environment for both human and agent visitors. The metric has ceased to function as a measurement and has become a control signal in a feedback system whose participants include entities for whom engagement has no psychological referent.
This creates what might be called a meaning vacuum: the data exists, the metrics compute, the dashboards update, but the connection between the numbers and any interpretable reality has been weakened. The analytics system is producing outputs that look like knowledge but correspond, in part, to dynamics the system’s designers did not intend to measure.

7. Toward an Agent-Aware Analytics Paradigm

If the arguments of the preceding sections hold, then the field of web analytics faces a choice between two paths. The first is to treat the agent problem as an extension of the bot problem: improve detection, improve filtering, and continue interpreting the remaining data under the traditional framework. The second is to accept that the traditional framework’s assumptions hold less well as agent share rises, and to begin constructing an alternative that accommodates both kinds of actor.
We argue that the first path will reach diminishing returns. It will fail because the most capable agents are designed to be behaviorally similar to humans on every standard signal, because the boundary between human and agent traffic is a spectrum rather than a line, and because filtering out agent traffic will increasingly mean filtering out a large share of the legitimate web interactions (and thus the economic activity) that occur through agent-mediated channels. An analytics framework that excludes agent behavior from its scope will become a framework that measures a shrinking and unrepresentative slice of the web.
The second path requires rethinking several foundational commitments. We sketch the alternative below, with explicit operational definitions for each proposed primitive.

7.1. New Units of Analysis

The user must be supplemented by units of analysis that can accommodate non-human actors. We propose three, ordered from atomic to aggregated.
The interaction event, stripped of its implicit assumption about the generating entity, can serve as a primitive. Rather than grouping events into sessions attributed to users, the system would characterize individual events by their structural properties: timing, sequencing, conditional relationships to other events, and consistency with known agent or human behavioral distributions.
The task chain offers a higher-level alternative. Rather than modeling sessions (implicitly: human goal-pursuit episodes), the system would model the execution of tasks, which may involve human actions, agent actions, or interleaved sequences of both. Task chains would be characterized by their structure (linear, branching, recursive), their origin (human-initiated, agent-initiated, system-triggered), and their outcome (completion, abandonment, error).
The actor class would replace the binary human/bot classification with a multi-dimensional characterization of the entity generating data. Dimensions might include autonomy level (fully human, human-assisted, human-supervised, fully autonomous), persistence (ephemeral, session-scoped, persistent), and objective transparency (stated goal, inferred goal, opaque).

7.2. New Measurement Primitives, Operationally Specified

Krupp et al. [16] and Bandi et al. [15] have documented the measurement frameworks being developed within the agent evaluation community. These frameworks evaluate agents on task completion, step efficiency, error recovery, and resource consumption. Web analytics could draw on these metrics to develop a parallel vocabulary for characterizing the agent-side of web interactions. Anthropic Research [17] has gone further, proposing specific primitives for quantifying agent autonomy, including interruption rates and decision scope, that could serve as building blocks for analytics systems designed to operate in mixed-actor environments.
To make our proposals testable rather than metaphorical, we specify each primitive in terms of inputs, unit of analysis, output, and inferential limits. We do not claim these specifications are final; we offer them as the minimum scaffolding needed to evaluate the constructs as candidate analytical instruments.
Interaction provenance assigns each event a probabilistic label indicating whether it was generated by a human, an agent, or a hybrid actor. Inputs include declared user-agent metadata, network-level signals (IP reputation, ASN, residential-versus-datacenter origin), browser-environment fingerprints, behavioral biometrics where available (cursor dynamics, scroll micro-timing), and any provenance headers transmitted by cooperating agent operators. The unit of analysis is the individual event. The output is a continuous probability distribution over actor classes, with calibrated uncertainty. The inferential limits are substantial: provenance cannot be recovered for events from non-cooperating agents that fully emulate human signatures, and the calibration of the probability distribution depends on the availability of ground-truth labels, which are increasingly hard to obtain.
Actor class characterizes the entity generating a sequence of events along three dimensions: autonomy level (categorical, from fully human to fully autonomous), persistence (categorical, from ephemeral to persistent), and objective transparency (categorical, from stated to inferred to opaque). Inputs are the sequence of events, their provenance probabilities, and any operator-declared metadata about the actor. The unit of analysis is the actor instance, defined as a contiguous behavioral trace plausibly attributable to a single decision-making entity. The output is a structured tuple specifying the actor’s position on each dimension, with confidence intervals. The inferential limit is that the actor instance is itself a constructed object, not a recovered identity; for opaque actors, the construction may not stably correspond to anything in the underlying system.
Task chain characterizes a goal-directed sequence of interactions that may span multiple actors, sessions, and sites. Inputs are timestamped event sequences, provenance labels, and inferred goal markers extracted through structural analysis (form submissions, conversion events, navigation patterns) or natural-language goal declarations from cooperating agents. The unit of analysis is the chain itself, identified by stable opening and closing conditions. The output is a structured representation of the chain’s topology (linear, branching, recursive), its actor composition (the sequence of actor classes involved), and its outcome (completion, abandonment, error). The inferential limit is that chain boundaries are heuristic; chains that interleave human and agent actions across long time horizons may be impossible to bound reliably.
Objective alignment estimates the relationship between an actor’s inferred goal and the goals of the system being interacted with. Inputs are the task chain representation, the site’s stated objectives (sell products, retain users, surface relevant content), and the inferred objective of the actor. The unit of analysis is the task chain. The output is a continuous score representing the degree of goal alignment, ranging from full alignment (a customer browsing for a product they intend to buy) to neutral (a research agent gathering price information without intent to transact) to misaligned (a scraping operation extracting data the site does not intend to provide). The inferential limit is that actor objectives must be inferred from observable behavior; for goals that have no behavioral signature, the score collapses to a default value and ceases to be informative.
Signal authenticity estimates the degree to which a behavioral signal reflects a choice that is interpretable under the traditional framework; that is, the probability that the signal can be read as evidence of preference, intent, or satisfaction in the way conventional analytics assumes. Inputs are the event itself, its provenance probability, the actor class, and the behavioral context (the surrounding event sequence). The unit of analysis is the individual signal type (a click, a dwell, a scroll, a conversion). The output is a continuous confidence score indicating how much weight the analyst should place on the signal as evidence of human preference, with separate scores for separate interpretive uses. The inferential limit is that authenticity is not a property of the signal alone but of the interpretive question being asked: the same agent click may carry low authenticity for inferring preference and high authenticity for measuring task completion.
Concretely, the proposed outputs take five different formal shapes: interaction provenance is a probability distribution over actor classes; actor class is an ordinal-categorical tuple with confidence intervals on each dimension; the task chain is a relational structure encoding topology, actor composition, and outcome; objective alignment and signal authenticity are bounded continuous scores; and the principal–agent graph (introduced in Section 5.2 and listed in Table 3) is a directed graph whose nodes are principals and agents and whose edges are delegation relationships. We treat these as candidate output formats for empirical refinement, not as mathematically stabilized metrics.
Table 3 maps these primitives against the traditional analytics concepts they would supplement or replace. The right column identifies the conceptual shift each new primitive requires.

Three Worked Examples

To make the proposed primitives more concrete, consider how three common analytics situations would change under an agent-aware framework.
Example 1.
A retail site reports a 3.2% conversion rate, up from 2.8% the previous quarter. Under traditional analytics, this is straightforwardly good news. Under a provenance-aware framework, the same data is decomposed: 1.8% conversions from high-confidence human visitors (down from 2.0%), 1.1% from human-assisted agent visitors (autonomous shopping copilots placing orders for stated principals), and 0.3% from fully autonomous agents acting on stored configurations. The aggregate is up; the human channel is down. The provenance decomposition does not invalidate the headline number, but it changes the implications: the marketing team’s attempt to improve the human conversion path is failing, while the rise in agent-mediated orders is being driven by upstream platform changes the team has no visibility into. Without provenance, the team optimizes against the wrong signal.
Example 2.
A content publisher’s most-engaged article, by dwell time and scroll depth, is a long-form piece on industrial supply chain practices. Under signal-authenticity scoring, the article is flagged: dwell-time signals on this piece have low authenticity for inferring human interest, because a substantial share of the dwell minutes come from agents that load and parse the full page as part of monitoring or training tasks. The article may genuinely be interesting to humans; it may also be a magnet for agent traffic because of its keyword density and structured information. The authenticity score does not tell the publisher which is true; it tells them that the engagement signal alone cannot answer the question. They can then either invest in higher-fidelity human-signal collection (surveys, qualitative feedback) for that piece or accept that engagement is noisy here and weight it less in editorial decisions.
Example 3.
A SaaS platform tracks customer journeys across marketing emails, search ads, and the trial signup flow. A particular cohort of trial users converts at unusually high rates after clicking a specific paid search ad. Under task-chain analysis, the cohort’s trajectories are reconstructed across the principal–agent graph. In 60% of cases, the click came from a research agent comparing competing SaaS tools on behalf of an enterprise buyer who had already made a tentative selection; the agent visited multiple competing platforms, but the human principal had pre-committed to the eventual purchase before the agent click occurred. The attribution model credited the paid ad. The task chain reveals that the ad participated in a navigation step but did not cause the conversion in any persuasion-relevant sense. Reallocating budget toward this ad on the basis of the original attribution would be a category error.
These examples are illustrative, not validated. We offer them to show what the proposed primitives would change in practice, and to make their failure modes legible: each example identifies an interpretive question the new framework helps with, and a residual uncertainty the framework does not resolve.

7.3. Governance, Transparency, and Institutional Design

An agent-aware analytics paradigm cannot develop from the analytics side alone. It requires cooperation from the agent ecosystem, and it requires governance structures that the web analytics community has not yet seriously considered. If agents are to be analytically tractable, they must declare themselves, or at least leave detectable traces of their nature and objectives.
Standards for agent identification (analogous to the robots.txt convention for crawlers, but richer and more enforceable) could require agents to transmit metadata about their operator, their objective class, and their autonomy level. Such standards would not solve the measurement problem entirely (agents with adversarial objectives would not comply), but they would create a baseline of transparency that enables the analytics field to calibrate its models against the cooperating subset and reason explicitly about the non-cooperating residual.
Danaher et al. [35] provide a taxonomy directly applicable here. Their work on algorithmic governance identifies four ideal types of governance systems, ranging from autonomy-friendly to out-of-control, based on the interaction between transparency and automation levels. A web analytics ecosystem in which agents operate opaquely, generate unclassifiable traffic, and feed back into the algorithmic systems that govern content visibility and ad pricing sits squarely in the out-of-control quadrant: high automation, low transparency. Moving toward the autonomy-friendly quadrant requires both technical standards (agent self-identification, provenance metadata) and institutional mechanisms (audit requirements, third-party verification) that the analytics industry has not yet begun to build.

7.3.1. The Energy Sector Analogy

We have drawn repeatedly on AI governance experience from energy systems and critical infrastructure. The transfer is not automatic and deserves to be delimited, because the incentive structures, actor configurations, and data regimes of commercial web environments differ in important ways from those of regulated infrastructure.
Three dimensions translate well. The first is the structural problem of accountability when automated decisions sit between human inputs and consequential outputs. Volkova et al.’s [5] accountability mapping framework for grid services treats each automated step as a documented decision point with an identifiable owner; the same logic applies to agent-mediated commerce, where each agent action ought to leave a documented record traceable to its principal. The second is the regulatory sandbox model from Gritsenko and Wood [36]. Sandboxes work in energy because they let operators test how a new automated control system behaves under realistic load before it touches the live grid. The analytics equivalent would be platforms where vendors, agent operators, and large publishers can observe how new measurement primitives behave on traffic that includes a known mix of human and agent activity. The third is the responsible algorithm design framework from Ransan-Cooper et al. [7], which embeds questions about distributional fairness, technical reliability, and community trust into the design phase rather than treating them as compliance overhead. These three mechanisms are largely procedural and can operate in different institutional contexts.
Three dimensions translate poorly. First, the energy sector operates under a regulatory regime that gives state actors clear authority to mandate transparency, audit, and shutdown. Web analytics has no equivalent regulator, and existing data-protection regimes (GDPR, state-level privacy laws) address adjacent problems rather than the agent-traffic problem directly. Second, the energy sector has a small number of large operators whose interests can be coordinated through industry bodies; web analytics involves millions of publishers, dozens of platforms, and an open-ended population of agent developers, which makes industry self-coordination harder. Third, the data in energy systems is largely physical (load, voltage, frequency) and verifiable through independent instruments, while web analytics data is observational and subject to manipulation by the entities being measured. A grid operator can install a meter; a publisher cannot easily install an instrument on an agent operating from elsewhere.
We treat the energy analogy, then, as a source of governance machinery rather than as a complete blueprint. The mechanisms (sandboxes, accountability mapping, responsible design) are transferable but the institutional context is not. Where we draw on energy sector parallels in this paper, we do so to import procedural ideas, not to claim that the regulatory or commercial settings are equivalent.

7.3.2. Other Sources of Governance Machinery

Ferenci et al. [6], surveying AI governance in local energy systems, identify a set of interlocking deployment barriers that apply with equal force to analytics: governance-integrated explainability (can the system explain what its metrics mean when the data comes from mixed sources?), distributional equity (whose economic interests are served when agent traffic inflates engagement?), and data governance (who owns and controls the provenance metadata that makes agent-aware analytics possible?). These are design requirements that the next generation of analytics tools must satisfy, regardless of how the regulatory environment evolves.
Zhang et al. [37] present an ethical assessment framework for AI security and ethics in smart grid operations, providing criteria for utilities and regulators to evaluate whether AI applications align with safety standards and societal values. The web analytics field lacks any equivalent framework. No set of criteria exists for evaluating whether an analytics tool produces reliable outputs in an agent-contaminated data environment, or for assessing the downstream effects of decisions made on the basis of degraded metrics. Building such a framework is among the more pressing institutional tasks the field faces.
Trust research adds a further dimension to this governance challenge. Afroogh et al. [34] survey trust in AI across disciplines and identify competence, safety, robustness, transparency, and ethical alignment as dimensions that shape whether humans accept AI-mediated outcomes. In a web analytics context, an agent-completed purchase involves a trust relationship between the human principal, the agent, and the vendor; traditional conversion metrics capture none of this complexity. Barba et al. [42], examining combined web scraping and AI applications through bibliometric analysis, document rapid growth in this area since 2020, alongside increasing concern about surveillance, consent erosion, and what they call the recoding of the web for algorithmic consumption. Their findings suggest that the data collection practices underlying current analytics (cookies, tracking pixels, behavioral profiling) will face mounting ethical and regulatory pressure as agents become both the collectors and the subjects of data. Blut, Ghiassaleh, and Wang [43], in a meta-analysis of recommendation agent performance, show that these agents already measurably influence purchase decisions, which means that optimizing for agent selection criteria is not a future concern but a present commercial reality.

7.4. A Layered Architecture

Figure 1 presents a proposed layered architecture that integrates the primitives, governance requirements, and detection methods discussed above. The architecture is layered in the sense that each layer transforms the output of the layer below, and information moves upward with progressively richer interpretive context.
Layer 1, traffic classification, takes raw interaction events from web pages and APIs as input and applies behavioral biometrics, deep learning, and anomaly detection to attach probabilistic actor-class labels to each event. Detection methods reviewed in Section 3.5 operate at this layer. The unit of information moving upward is the classified event: a record annotated with its likely origin in human, agent, or hybrid activity rather than a bare timestamp and URL.
Layer 2, identity and attribution, maps classified events onto principal–agent graphs and actor-class profiles. Information moves upward as classified events tied to interpretable actor structures: who, or what, is plausibly acting, and on whose behalf. Where cooperating agents transmit provenance metadata, that metadata enters here.
Layer 3, behavioral telemetry, groups attributed events into task chains and computes signal-authenticity and objective-alignment scores. The interpretive status is now action-level rather than event-level, and the analyst can reason about whether a chain represents goal-aligned commerce, neutral information retrieval, or misaligned extraction.
Layer 4, business intelligence, aggregates task chains into the metrics that decision-makers consume. Information moves upward as decision-ready summaries with explicit confidence intervals reflecting the authenticity scores from below. The interpretive status is now suitable for action, but the action is taken with awareness of the underlying composition of human and agent activity.
Feedback loops connect Layer 4 back to Layer 1: agent behavior responds to analytics-derived signals (visibility on engagement-ranked surfaces, ad pricing on conversion-driven auctions), generating new traffic that re-enters the classification pipeline. Governance requirements (transparency, consent, audit, distributional equity) cross-cut all four layers. Provenance metadata declared by cooperating agents enters at Layer 2; audit logs are produced at every layer for compliance and reconstruction; consent and equity considerations shape which inferences are licensed at Layers 3 and 4.
In a production implementation, this layered architecture would replace the single-pipeline model (collect, attribute, report) that characterizes current analytics platforms. We do not present this architecture as a deployed system. We present it as a candidate design that future research and engineering can test, refine, or replace.
The four-layer stack (traffic classification; identity and attribution; behavioral telemetry; business intelligence) carries information upward with progressively richer interpretive context, while feedback loops from Layer 4 back to Layer 1 capture how agent behavior responds to analytics-derived signals. Governance requirements cross-cut all four layers.

8. Epistemological Limits

Even with improved measurement frameworks, agent-aware analytics will confront hard limits on what web interaction data can reveal. These limits are not technical problems to be solved with better algorithms; they are structural features of a hybrid human–agent web.

8.1. The Opacity of Agent Objectives

When a human visits a website, the analytics system infers their objective from their behavior: they searched for running shoes, so they probably want running shoes. This inference is imperfect, but it is grounded in a shared context of meaning between human actors. Humans and analysts share a conceptual vocabulary for goals, preferences, and decision-making.
Agents operate on objectives specified by their orchestrating systems, and those objectives may be expressed in terms that have no relationship to the categories web analytics uses. An agent might visit a running shoe page because it is testing website response times, because it is building a training dataset, because it is comparing prices for a meta-search engine, or because it is executing a task specified in natural language by a human whose intent is mediated through layers of prompt engineering and agent architecture. The same behavioral trace (the same page load, the same click) maps to different underlying realities depending on the agent’s configuration, and that configuration is, in most cases, invisible to the analytics system.

8.2. The Inference Gap

Stier et al. [9] noted that integrating digital trace data with survey data requires careful attention to the gap between behavioral records and the psychological constructs researchers want to measure. In a human-only web, this gap could be bridged (imperfectly) through calibration: survey studies could validate the relationship between specific behavioral patterns and self-reported attitudes, intentions, and experiences.
In a hybrid web, this calibration breaks down. You cannot survey an agent about its satisfaction with a website. You cannot ask an agent why it bounced. The behavioral data generated by agents is not a noisy signal of a psychological state; it is a signal of a computational process that has no psychological state. No amount of methodological sophistication can extract human meaning from non-human data.
This creates an asymmetry that will compound over time. As agents generate a larger fraction of web interaction data, the proportion of data amenable to psychological interpretation will shrink, and the proportion interpretable only in computational terms (task completion, execution efficiency, error frequency) will grow. The analytics field will need to decide whether its goal is to continue measuring human experience on the web (in which case it needs to isolate and identify the shrinking human signal) or to measure web interaction dynamics regardless of the nature of the actors involved (in which case it needs a new interpretive framework that does not depend on psychological inference). Most likely, the field will need to do both, with explicit acknowledgment of which framework applies to which question.

8.3. The Indistinguishability Horizon

The most challenging epistemological limit is what might be called the indistinguishability horizon: the point at which the behavioral output of AI agents becomes statistically indistinguishable from human behavior across all observable dimensions. Current agents have not reached this point; Zhou et al. [11] found that GPT-4-based agents still underperform humans on complex web tasks, and detection systems can still identify many categories of automated traffic [3,28]. However, the trajectory is clear. Agent capabilities are improving faster than detection capabilities, because agents benefit from the same advances in language modeling that make them harder to detect.
The HUMAN Security Research Team [21] has documented how this convergence plays out in practice: modern AI agents rotate identifiers, emulate real browser environments, and produce execution traces that overlap with human behavioral distributions on every standard metric. Their finding that no single detection signal is reliable reinforces the deeper epistemological point. The indistinguishability horizon is not a distant theoretical possibility; it is an approaching practical reality whose early effects are already visible in the decreasing accuracy of traffic classification systems.
When the indistinguishability horizon is reached for a given context, the analytics field will face a situation in which its data is a mixture of human and agent-generated signals that cannot be separated by any behavioral criterion alone. At that point, the question who is the user becomes unanswerable from the data alone, and every metric that depends on the answer becomes, to a degree proportional to the agent share of traffic, harder to interpret without external information about provenance.
These limits are not equally binding for all decisions. Three operational stances remain viable even where classification is poor. First, decisions about transactional outcomes (orders, signups, contracts) can still be made under low signal authenticity, because the transaction is real regardless of who initiated it. Second, decisions about content quality, audience composition, and channel performance should be reported with explicit uncertainty intervals or confidence labels tied to provenance estimates rather than as point values. Third, inferences that depend on psychological states (loyalty, satisfaction, intent, human preference) should be avoided when the underlying signal is mediated by agents; where such inferences are required, they should be supplemented with higher-fidelity instruments such as targeted surveys or panel-based research designed to recover the human signal directly.

9. Discussion

9.1. Implications for Practice

Organizations that rely on web analytics for decision-making (which is to say, most organizations with a web presence) are operating with instruments whose accuracy is degrading in ways that are difficult to detect from within the analytics framework itself. A dashboard that shows increasing engagement may be measuring a genuine uptick in human interest, an increase in agent traffic, or a feedback loop between agent behavior and engagement-optimizing algorithms. Without the ability to distinguish among these explanations, the dashboard is more likely to mislead than to inform.
The most actionable near-term step is to develop and deploy interaction provenance tracking, even in its most rudimentary form. Understanding the composition of traffic (how much is identifiably human, how much is identifiably automated, and how much is ambiguous) gives organizations a basis for calibrating their confidence in analytics outputs. This is less a technical challenge than an institutional one: analytics teams must acknowledge that their data is contaminated and that the contamination is worsening, rather than treating agent traffic as a nuisance to be filtered and forgotten.
The analytics industry itself faces a structural disincentive to confront this problem. Vendors whose products promise granular insight into user behavior have little motivation to publicize that the concept of a user is fraying. The same dynamic that delayed the advertising industry’s reckoning with click fraud (the parties best positioned to measure the problem were the parties whose revenue depended on ignoring it) threatens to delay the analytics industry’s reckoning with agent traffic. Organizations that rely on analytics outputs should push for transparency about agent-traffic contamination from their vendors, rather than waiting for vendors to volunteer it.

9.2. Implications for Research

For computational social science and digital marketing research, the implications are equally severe. Studies that use web behavioral data as evidence of human attitudes, preferences, or decision-making processes must confront the possibility that their data includes agent-generated observations that violate the human-behavioral assumptions of their models. Stier et al. [9] called for more careful integration of digital trace data and survey data; the agent problem makes this integration not just desirable but necessary, because digital trace data can no longer be assumed to be human-generated without independent verification.
Chandler and Paolacci [33] extend this concern beyond bots to the epistemological status of web-collected behavioral data itself. Their argument that human deception and careless responding now rival automated interference as sources of data contamination, combined with their identification of AI agents as a distinct third category, suggests that the data quality problem is not a single problem but a cluster of related problems, each with different detection signatures and different implications for inference. Researchers who treat bot filtering as a sufficient data-cleaning step are addressing one contamination source while ignoring two others.
More broadly, the agent problem demands new theoretical work at the intersection of human–computer interaction, measurement theory, and the philosophy of social science. The field needs a coherent account of what web interaction data means when the interacting entities are a heterogeneous mixture of humans, human–agent hybrids, and fully autonomous systems. The current framework, inherited from a period when web user and human were near-synonyms, cannot provide this account on its own.

9.3. Implications for Governance

The corruption of web analytics by agent traffic is not solely a measurement problem but also a governance problem. If engagement metrics drive content recommendation algorithms, and agent traffic inflates engagement metrics, then agents are shaping the information environment for human users through a mechanism that is invisible to the systems’ operators. This is a form of inadvertent algorithmic manipulation that falls outside the scope of existing regulatory frameworks, which focus on deliberate fraud (as in the click fraud literature surveyed in [30,31]) rather than on the systemic effects of agent activity on data-driven decision systems.
Governance responses will need to operate at multiple levels. At the technical level: mandatory or incentivized agent identification standards, transparency requirements for agent-mediated interactions, and audit frameworks that test the human-signal integrity of data pipelines used for consequential decisions. At the institutional level: new structures that give affected parties (consumers, content creators, small businesses whose search visibility depends on analytics-driven algorithms) a seat at the table where these standards are set.
Yang [39], writing about power dynamics in frontier AI governance, argues that the epistemic and symbolic power of tech giants over AI infrastructure risks producing a form of governance capture: the entities best positioned to define the rules are the entities whose interests the rules will serve. The web analytics case carries the same risk. If the governance of agent-analytics interactions is left to the major analytics platforms and the largest agent operators, the resulting standards will reflect their priorities (data access, market position, platform lock-in) rather than the priorities of the broader web ecosystem.
Moreno [38] proposes that AI governance in the energy sector must balance three goals: consumer protection, system stability, and competitive market innovation. This tripartite framing translates, with the caveats noted in Section 7.3.1, to web analytics governance, which must balance the protection of human signal integrity, the stability of data-driven decision systems, and the space for agent-mediated commerce and services to develop. Getting this balance wrong in either direction carries real costs: overregulation could stifle the efficiency gains that agent-mediated web activity promises, while underregulation allows the quiet degradation of the data infrastructure on which much of the digital economy depends.
Delina and Tung [40] raise an additional concern that the web analytics field has so far ignored: equity. In their work on AI-assisted energy transitions, they argue that without proper governance, AI optimization may exacerbate existing inequalities rather than reduce them. The same logic applies to the analytics case. If agent traffic disproportionately represents the behavior of well-resourced users (those who can afford AI assistants and autonomous shopping agents), then analytics systems that fail to distinguish between human and agent traffic will overweight the preferences of affluent consumers and underweight everyone else. The metrics will look comprehensive while the picture they paint grows increasingly skewed.
Yang et al. [14] note that the Agentic Web raises governance challenges extending beyond current regulatory paradigms, including questions about accountability, economic impact, and societal risk. The analytics dimension of these challenges (the question of what happens when the data that governs digital systems is increasingly generated by the systems themselves) deserves specific attention from policymakers. It is not sufficient to regulate agents and analytics separately. The feedback loops between them, where agents generate data that shapes algorithmic decisions that in turn shape the environment agents operate in, require governance that addresses the coupled system, not its individual components.

10. Conclusions

This paper demonstrated that the conceptual architecture of conventional web analytics rests on three commitments (identity persistence, intentional intelligibility, behavioral-to-psychological inference) that were sound when human users dominated web traffic and that lose force as agent share increases. The reviewed evidence shows that automated traffic broadly is already a substantial fraction of online interactions, that the share of autonomous LLM-agent traffic specifically is rising on a clear trajectory even where its current magnitude is hard to enumerate directly, that detection has the structure of an arms race rather than a solvable classification problem, and that the inferential bridge connecting clicks to mental states does not extend to entities without mental states. We have also documented, through the cited literature, that the analytics field and the agent-evaluation field are building parallel measurement vocabularies for the same interactions without speaking to one another.
We inferred, reasoning from cited trajectories rather than original measurement, that filtering will not be enough. The most capable agents are designed to be indistinguishable from humans on every behavioral signal in current use, and the same advances in language modeling improve agents and their camouflage in the same step. A field that depends on isolating human signal from a stream that may soon be majority-agent in some contexts will have to reckon with the limits of separation as a strategy. We do not claim a generalized collapse of current analytics. We claim that the domain of validity is shrinking and that the rate of shrinkage is faster than the field has acknowledged.
This paper has proposed certain key programmatic ideas, too. The five primitives we sketch (task chain, actor class, interaction provenance, objective alignment, signal authenticity) are candidate constructs, not deployed systems. We have specified each in terms of inputs, unit of analysis, output, and inferential limits, so that future empirical work can test, refine, or replace them. The layered governance architecture we describe borrows machinery from regulated infrastructure sectors (sandboxes, accountability mapping, responsible design) and translates it into a less regulated commercial environment, with the limits of that transfer made explicit. We offer the architecture as a research and development agenda, not as a settled solution.
Other sectors, particularly energy systems governance, have begun developing the institutional and technical frameworks needed to manage AI-driven systems that operate at scales where human oversight cannot extend to every decision. Web analytics can borrow procedural ideas from their experience: from regulatory sandboxes that test governance models before deployment, from accountability frameworks that map automated decisions to responsible actors, and from responsible design practices that embed ethical considerations into algorithmic systems from the start. We have been careful not to claim that the regulatory or commercial settings transfer; the procedural mechanisms can travel even when the contexts cannot.
The vanishing user of this paper’s title is not a forecast about humans leaving the web. Humans will continue to use the web. But the user as the field’s organizing abstraction, the stable, intentional, psychologically legible subject whose behavior anchors every metric, is becoming a less reliable proxy for the entity that actually generates the data. The interesting question is no longer how to track that subject more precisely. The interesting question is what web measurement can mean in an environment where the subject is, increasingly, a configuration rather than a person, and where the answer will require new theories, new methods, and a measure of humility about the limits of measurement itself.

Author Contributions

Conceptualization, B.G. and D.C.; literature review, B.G. and D.C.; writing (original draft preparation), B.G.; writing (review and editing), B.G. and D.C. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable.

Informed Consent Statement

Not applicable.

Data Availability Statement

No new data were created or analyzed in this study. Data sharing is not applicable to this article.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. Varol, O.; Ferrara, E.; Davis, C.; Menczer, F.; Flammini, A. Online human-bot interactions: Detection, estimation, and characterization. Proc. Int. AAAI Conf. Web Soc. Media 2017, 11, 280–289. [Google Scholar] [CrossRef] [Scilit]
  2. Ng, L.H.; Carley, K.M. A global comparison of social media bot and human characteristics. Sci. Rep. 2025, 15, 10973. [Google Scholar] [CrossRef] [Scilit]
  3. Li, X.; Azad, B.A.; Rahmati, A.; Nikiforakis, N. Good bot, bad bot: Characterizing automated browsing activity. In Proceedings of the 2021 IEEE Symposium on Security and Privacy; IEEE: Piscataway, NJ, USA, 2021; pp. 1589–1605. [Google Scholar] [CrossRef] [Scilit]
  4. Kirdeev, A.; Knoll, M.; Anand, A. Botcha: Detecting malicious non-human traffic in the wild. In Proceedings of the Online Human Aggression Recognition System Workshop (OHARS); CEUR Workshop Proceedings: Aachen, Germany, 2020; Volume 2758, pp. 52–63. [Google Scholar]
  5. Volkova, A.; Patil, A.D.; Javadi, S.A.; De Meer, H. Accountability challenges of AI in smart grid services. In Proceedings of the Thirteenth ACM International Conference on Future Energy Systems; ACM: New York, NY, USA, 2022; pp. 597–600. [Google Scholar] [CrossRef] [Scilit]
  6. Ferenci, S.; Cotet, F.A.; Lakatos, E.S.; Munteanu, R.A.; Szabo, L. Artificial intelligence in local energy systems: A perspective on emerging trends and sustainable innovation. Energies 2026, 19, 476. [Google Scholar] [CrossRef] [Scilit]
  7. Ransan-Cooper, H.; Sturmberg, B.C.; Shaw, M.E.; Blackhall, L. Applying responsible algorithm design to neighborhood-scale batteries in Australia. Nat. Energy 2021, 6, 815–823. [Google Scholar] [CrossRef] [Scilit]
  8. Dennett, D.C. The Intentional Stance; MIT Press: Cambridge, MA, USA, 1987. [Google Scholar]
  9. Stier, S.; Breuer, J.; Siegers, P.; Thorson, K. Integrating survey data and digital trace data: Key issues in developing an emerging field. Soc. Sci. Comput. Rev. 2020, 38, 503–516. [Google Scholar] [CrossRef] [Scilit]
  10. Jansen, B.J.; Jung, S.G.; Salminen, J. Measuring user interactions with websites: A comparison of two industry standard analytics approaches using data of 86 websites. PLoS ONE 2022, 17, e0268212. [Google Scholar] [CrossRef] [Scilit]
  11. Zhou, S.; Xu, F.F.; Zhu, H.; Zhou, X.; Lo, R.; Sridhar, A.; Cheng, X.; Ou, T.; Bisk, Y.; Fried, D.; et al. WebArena: A realistic web environment for building autonomous agents. arXiv 2024, arXiv:2307.13854. [Google Scholar] [CrossRef] [Scilit]
  12. Xu, H.; Li, Z.; Chu, C.; Chen, Y.; Yang, Y.; Lu, H.; Wang, H.; Stavrou, A. Detecting and characterizing web bot traffic in a large e-commerce marketplace. In European Symposium on Research in Computer Security; Springer International Publishing: Cham, Switzerland, 2018; pp. 143–163. [Google Scholar] [CrossRef] [Scilit]
  13. Fetterly, D.; Manasse, M.; Najork, M. Spam, damn spam, and statistics: Using statistical analysis to locate spam web pages. In Proceedings of the 7th International Workshop on the Web and Databases; ACM: New York, NY, USA, 2004; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
  14. Yang, Y.; Ma, M.; Huang, Y.; Chai, H.; Gong, C.; Geng, H.; Zhou, Y.; Wen, Y.; Fang, M.; Chen, M.; et al. Agentic web: Weaving the next web with AI agents. arXiv 2025, arXiv:2507.21206. [Google Scholar] [CrossRef] [Scilit]
  15. Bandi, A.; Kongari, B.; Naguru, R.; Pasnoor, S.; Vilipala, S.V. The rise of agentic AI: A review of definitions, frameworks, architectures, applications, evaluation metrics, and challenges. Future Internet 2025, 17, 404. [Google Scholar] [CrossRef] [Scilit]
  16. Krupp, L.; Geissler, D.; Wozniak, P.W.; Lukowicz, P.; Karolus, J. Quantifying web agents: A survey on web agent performance and efficiency. OSF Prepr. 2025, 1, 36. [Google Scholar] [CrossRef] [Scilit]
  17. Anthropic Research. Measuring AI Agent Autonomy in Practice; Research Report; Anthropic: San Francisco, CA, USA, 2026. [Google Scholar]
  18. Ning, L.; Liang, Z.; Jiang, Z.; Qu, H.; Ding, Y.; Fan, W.; Wei, X.; Lin, S.; Liu, H.; Yu, P.; et al. A survey of WebAgents: Towards next-generation AI agents for web automation with large foundation models. In Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2; ACM: New York, NY, USA, 2025. [Google Scholar] [CrossRef] [Scilit]
  19. Sapkota, R.; Roumeliotis, K.; Karkee, M. AI agents vs. agentic AI: A conceptual taxonomy, applications and challenges. Inf. Fusion 2025, 126, 103599. [Google Scholar] [CrossRef] [Scilit]
  20. Ali, M.; Dornaika, F. Agentic AI: A comprehensive survey of architectures, applications, and future directions. Artif. Intell. Rev. 2025, 59, 11. [Google Scholar] [CrossRef] [Scilit]
  21. HUMAN Security Research Team. AI Agent Detection: Guide to Identifying Autonomous Traffic; Industry Research Report; HUMAN Security: New York, NY, USA, 2026. [Google Scholar]
  22. Gajewski, M.; Hryniewicz, O.; Jastrzebska, A.; Kozakiewicz, M.; Opara, K.; Owsinski, J.W.; Zadrozny, S.; Zwierzchowski, T. Data-driven human and bot recognition from web activity logs based on hybrid learning techniques. Digit. Commun. Netw. 2024, 10, 1178–1188. [Google Scholar] [CrossRef] [Scilit]
  23. Hayawi, K.; Saha, S.; Masud, M.; Mathew, S.; Kaosar, M. Social media bot detection with deep learning methods: A systematic review. Neural Comput. Appl. 2023, 35, 8903–8918. [Google Scholar] [CrossRef] [Scilit]
  24. Aljabri, M.; Zagrouba, R.; Shaahid, A.; Alnasser, F.; Saleh, A.; Alomari, D. Machine learning-based social media bot detection: A comprehensive literature review. Soc. Netw. Anal. Min. 2023, 13, 20. [Google Scholar] [CrossRef] [Scilit]
  25. Sayyad, P.; Kadam, S.; Kadam, K.; Godage, S.; Zagade, R. Assessment of bot detection approaches using behavioral biometrics and mouse dynamics. Int. J. Adv. Comput. Eng. Commun. Technol. 2025, 14, 746–751. [Google Scholar] [CrossRef] [Scilit]
  26. Xu, H.; Wang, S.; Li, N.; Wang, K.; Zhao, Y.; Chen, K.; Yu, T.; Liu, Y.; Wang, H. Large language models for cyber security: A systematic literature review. ACM Trans. Softw. Eng. Methodol. 2024, in press. [Google Scholar] [CrossRef] [Scilit]
  27. Wang, L.; Ma, C.; Feng, X.; Zhang, Z.; Yang, H.; Zhang, J.; Chen, Z.; Tang, J.; Chen, X.; Lin, Y.; et al. A survey on large language model based autonomous agents. Front. Comput. Sci. 2023, 18, 186345. [Google Scholar] [CrossRef] [Scilit]
  28. Chu, Z.; Gianvecchio, S.; Wang, H. Bot or human? A behavior-based online bot detection system. In From Database to Cyber Security: Essays Dedicated to Sushil Jajodia on the Occasion of His 70th Birthday; Springer International Publishing: Cham, Switzerland, 2018; pp. 432–449. [Google Scholar] [CrossRef] [Scilit]
  29. Moen, E. Bot or Not: Modeling HTTP Traffic to Classify Humans and Bots; Technical Report; Moen AI Research: North Olmsted, OH, USA, 2021. [Google Scholar]
  30. Sadeghpour, S.; Vlajic, N. Click fraud in digital advertising: A comprehensive survey. Computers 2021, 10, 164. [Google Scholar] [CrossRef] [Scilit]
  31. Fulgoni, G.M. Fraud in digital advertising: A multibillion-dollar black hole. J. Advert. Res. 2016, 56, 122–125. [Google Scholar] [CrossRef] [Scilit]
  32. Nagaraja, S.; Shah, R. Clicktok: Click fraud detection using traffic analysis. In Proceedings of the 12th Conference on Security and Privacy in Wireless and Mobile Networks; ACM: New York, NY, USA, 2019; pp. 105–116. [Google Scholar] [CrossRef] [Scilit]
  33. Chandler, J.; Paolacci, G. The Biggest Threat to Online Data Collection Is Humans, Not Bots. Observer (Association for Psychological Science), 27 March 2026. Available online: https://www.psychologicalscience.org/publications/observer/humans-not-bots.html (accessed on 30 April 2026).
  34. Afroogh, S.; Akbari, A.; Malone, E.; Kargar, M.; Alambeigi, H. Trust in AI: Progress, challenges, and future directions. Humanit. Soc. Sci. Commun. 2024, 11, 1568. [Google Scholar] [CrossRef] [Scilit]
  35. Danaher, J.; Hogan, M.J.; Noone, C.; Kennedy, R.; Behan, A.; De Paor, A.; Felzmann, H.; Haklay, M.; Khoo, S.M.; Morison, J.; et al. Algorithmic governance: Developing a research agenda through the power of collective intelligence. Big Data Soc. 2017, 4, 2053951717726554. [Google Scholar] [CrossRef] [Scilit]
  36. Gritsenko, D.; Wood, M. Algorithmic governance: A mode of governance approach. Regul. Gov. 2022, 16, 45–62. [Google Scholar] [CrossRef] [Scilit]
  37. Zhang, Y.; Zhao, C.; Meng, Z.; Lai, C.S.; Chen, X. An ethical assessment framework for AI security and ethics in smart grid. Glob. Energy Interconnect. 2025, 9, 298–314. [Google Scholar] [CrossRef] [Scilit]
  38. Moreno, V.K.; Poudineh, R. Reshaping the Consumer-Energy Relationship Through AI: Opportunities, Risks and Regulatory Outlook. OIES Paper: EL. 2026. Available online: https://www.oxfordenergy.org/wpcms/wp-content/uploads/2026/01/EL62-Reshaping-the-Consumer-Energy-Relationship-through-AI.pdf (accessed on 30 April 2026).
  39. Yang, S. Innovation without representation: Epistemic, infrastructural and symbolic power in frontier AI governance. Sci. Cult. 2026, 1–11. [Google Scholar] [CrossRef] [Scilit]
  40. Delina, L.L.; Tung, Y.S. Towards a just AI-assisted energy transitions for vulnerable communities. Energy Res. Soc. Sci. 2024, 118, 103752. [Google Scholar] [CrossRef] [Scilit]
  41. Guasselli, F. AI-driven energy futures: Emerging sociotechnical imaginaries in the tech industry. Energy Res. Soc. Sci. 2025, 129, 104407. [Google Scholar] [CrossRef] [Scilit]
  42. Barba, G.; Lezzi, M.; Lazoi, M.; Corallo, A. Combined use of web scraping and AI-based models for business applications: Research evolution and future trends. Manag. Rev. Q. 2025, in press. [Google Scholar] [CrossRef] [Scilit]
  43. Blut, M.; Ghiassaleh, A.; Wang, C. Testing the performance of online recommendation agents: A meta-analysis. J. Retail. 2023, 99, 440–459. [Google Scholar] [CrossRef] [Scilit]
Figure 1. Conceptual Framework: Layered Architecture for Agent-Era Web Analytics.
Figure 1. Conceptual Framework: Layered Architecture for Agent-Era Web Analytics.
Information 17 00453 g001
Table 2. Summary of Core Metric Corruption Mechanisms.
Table 2. Summary of Core Metric Corruption Mechanisms.
MetricHuman-User AssumptionAgent Corruption MechanismEvidences
Sessions and engagementSessions reflect coherent goal pursuit; dwell time indicates interestAgents process pages in milliseconds or simulate extended engagement; session distributions shift away from human baselines[3,29]
ConversionA completed action reflects persuasion through touchpointsAgents execute instructions from principals whose decisions occurred outside the analytics pipeline; attribution credits artifacts of execution paths[30,31]
AttributionTouchpoints in the journey influenced the outcomeAgent execution paths bear no relationship to persuasion; credited touchpoints are navigational steps, not decision factors[32]
Retention and lifetime valueReturning visitors exhibit loyalty; behavior aggregates into stable profilesAgent returns reflect configuration persistence or scheduled monitoring, not satisfaction; identity mapping dissolves across agent frameworks[4,33]
Traffic compositionData is predominantly human-generatedAgent share is growing and increasingly indistinguishable from human traffic; single-indicator detection is unreliable[1,2,21,22]
Recommendation and personalizationBehavioral signals reflect human preferencesModels trained on mixed human–agent signals optimize for a phantom population representing neither human nor agent interests[4,43]
Table 3. Traditional Measurement Primitives and Their Agent-Era Counterparts.
Table 3. Traditional Measurement Primitives and Their Agent-Era Counterparts.
Traditional PrimitiveProposed PrimitiveConceptual ShiftKey References
Session (user goal pursuit)Task chain (structured execution trace)From inferring intent to observing execution structure; tasks may span sites and involve multiple agents[14,15,18]
User identity (cookie/device-based)Actor class (multi-dimensional characterization)From binary human/bot to a spectrum: autonomy level, persistence, objective transparency[21,33]
Engagement (time, scrolls, clicks)Signal authenticity (confidence score)From treating all behavioral signals as preference indicators to estimating the probability that a signal reflects human choice for a specified interpretive use[9,29]
Conversion attributionInteraction provenanceFrom crediting touchpoints with persuasion to tracking whether each interaction was human-originated, agent-mediated, or hybrid[5,19]
Retention/lifetime valuePrincipal–agent graphFrom tracking returning users to mapping the relationship between human principals and the agents acting on their behalf[17,34]
Bounce rate/exit rateObjective alignment scoreFrom inferring dissatisfaction to assessing whether visitor and site goals were aligned or structurally mismatched[11,16]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

George, B.; Choudhary, D. The Vanishing User: Web Analytics in an Agent-Dominated Internet. Information 2026, 17, 453. https://doi.org/10.3390/info17050453

AMA Style

George B, Choudhary D. The Vanishing User: Web Analytics in an Agent-Dominated Internet. Information. 2026; 17(5):453. https://doi.org/10.3390/info17050453

Chicago/Turabian Style

George, Babu, and Divya Choudhary. 2026. "The Vanishing User: Web Analytics in an Agent-Dominated Internet" Information 17, no. 5: 453. https://doi.org/10.3390/info17050453

APA Style

George, B., & Choudhary, D. (2026). The Vanishing User: Web Analytics in an Agent-Dominated Internet. Information, 17(5), 453. https://doi.org/10.3390/info17050453

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop