IA & Marketing

876 impostors: what your AI traffic really hides

Over thirteen days in August, 1,129 automated visitors showed up on our site as AI assistants fetching a page for a human. We asked for their papers. AI traffic verification means checking that claim against published address ranges and reverse resolution. At Fast Growth Advisors, no AI visibility figure is produced any other way.

876 were lying.

That number changes how you should read everything you think you know about your AI traffic. Including, perhaps, statistics published by the largest players in the market.

A line of text is not an identity

Every automated visitor announces who it is on arrival at a server. That announcement is called the user-agent, and it is a line of text the visitor writes itself.

Nothing, technically, stops it from putting « Googlebot » or « ChatGPT-User » there.

Nearly every measurement tool counts that line and stops there. The headline figures published on AI crawling, scrape ratios, error rates, traffic shares, are computed on it.

Yet there is a way to verify. Google, OpenAI, Microsoft and others publish the address ranges their bots operate from, or a reverse-resolution mechanism that confirms identity both ways. The check is public, documented, free.

We applied it to every request in our server logs, across two sites, from 11 to 23 August.

Each automated visitor received a verdict: authenticated, proven spoof, unverifiable, or undecided.

Seven Googlebots out of sixty-seven

First result, the simplest to tell: 67 distinct addresses claimed to be Googlebot on our main site. Seven belonged to Google.

The other sixty?

Machines rented from consumer hosting providers, duckdns.org and digivps.com among others. Anyone can rent a server and write « Googlebot » in their header. Many do: the disguise opens doors that firewalls close to anonymous visitors.

On our second site, 20 addresses claimed to be Googlebot. The seven authentic ones were the same.

The gap between the two sites is not a matter of method: it measures each site’s exposure to impostors. A control figure that actually controls something.

The error rate belongs to the impostors

The central result of these thirteen days sits in the most sensitive category: requests presenting as an AI fetching a page on a human’s behalf, the traffic everyone wants the curve of.

Of 1,129 declared requests, 154 were authenticated, 876 were proven spoofs, the rest unverifiable or undecided. Three readings of the same traffic:

The authenticated ones find their page 99.4% of the time. None lands on a page that does not exist.

The spoofs land on a page that does not exist 69.1% of the time. They probe, poke, and hunt for weaknesses more than for content.

All verdicts combined, the reading any classic tool would produce: 53.7% errors.

Vercel, in the reference study on AI crawlers, publishes 34.82% of missing pages for ChatGPT and 34.16% for Claude. Figures of the same order as our unfiltered total. Never of the same world as our authenticated requests.

Hence a hypothesis, which we give as a hypothesis: the crawl waste attributed to AI may measure, for a large part, actors passing themselves off as AI. We claim nothing about anyone else’s method. We show that on our servers, the gap between the two readings is 53.7 points.

What does verification change, figure by figure?

The same traffic, read two ways. On one side what a classic tool shows by summing declarations. On the other what identity verification gives, request by request, on the AI fetches of fast-growth.fr during the window.

Behaviour of AI fetches by identity verdict. fast-growth.fr, 1,129 requests, 11 to 23 August 2026.
Verdict Requests Pages found Missing pages
Authenticated 154 99.4% 0.0%
Not verified 99 87.9% 1.0%
Proven impersonation 876 30.7% 69.1%
All verdicts combined 1,129 n.a. 53.7%

Authenticated requests do not knock on the wrong door: not one missing page across 154 requests. Impersonations grope around, with 69.1% of requests aimed at pages that do not exist. And the total, the only reading a non-verifying tool can produce, shows a 53.7% error rate. The gap between the two readings reaches 53.7 points.

The full method, the four verdicts, the breakdown by bot class across two sites and the limits of our own instrument are in the white paper: Counting bots, not lies, freely available, with its PDF version.

What honesty requires us to say

Not everything unverified is fraudulent, and the distinction deserves care.

ClaudeBot, Anthropic’s crawler, cannot be authenticated: its publisher provides neither an address range nor a reverse record. It is an unverifiable bot, not an impostor, and our counts place it in a column separate from the proven spoofs. Same status for DuckDuckGo. The real question, which we leave open, is why some publishers provide the means to verify them and others do not.

Our measurements and our instrument have their limits, and we would rather write them down before someone finds them for us.

On our main site, 12% of AI-agent traffic came in reality from a single bot. For that one, verification did not succeed even though it should have. We have not yet worked out why. Those requests are counted separately.

Neither authenticated, nor accused.

And our volumes are what they are: 154 authenticated requests over thirteen days, two small-business sites. We do not claim to describe the web. We describe a method, and what it changes to the figures when you apply it. A reader who runs the same measurement on their own logs will find different proportions, but the same gap between what bots declare and what verification confirms.

An acquisition channel 88.9% false

Identity verification is not the only place a dashboard lies by construction. Over the same window, the « referral » category, the traffic supposed to come from other sites, weighed 12,087 requests in our logs.

10,740 of them, or 88.9%, were internal navigation: a visitor already on the site clicking through to another of its pages.

The fourth acquisition channel on the measurement screen was not an acquisition channel.

How many authentic AI referrals in the batch? Four.

With the usual caveat, which applies to every tool on the market: the native apps of ChatGPT or Claude send no referrer header, so this traffic is structurally undercounted. A « zero AI referral » shown by a tool is not a fact, it is a blind spot.

The question to ask

You do not need to reproduce our setup to act. A single question to your measurement tool, or to the vendor selling you an AI-visibility report, is enough to place what its figures are worth.

What is the bot identification based on?

If the answer is « the user-agent, » you now know what you are reading. An AI traffic volume that may be mostly false, an error rate that is not yours, and content-budget decisions made for visitors who do not exist.

A counter that does not verify identity is not counting bots. It is counting lines of text anyone can write.

Sources

  1. Vercel and MERJ (web analytics firm). The rise of the AI crawler, 17 December 2024. Reference study on AI crawlers: 34.82% of missing pages for ChatGPT and 34.16% for Claude, against 8.22% for Googlebot. vercel.com
  2. Public bot verification mechanisms: published IP (Internet Protocol) address ranges and two-way reverse DNS (Domain Name System) resolution, documented by Google (verifying Googlebot), OpenAI (GPTBot / OAI-SearchBot / ChatGPT-User user-agents and ranges) and Microsoft. Primary URLs to be set at integration.
  3. Fast Growth Advisors. In-house server-log measurement, two sites, 11 to 23 August 2026: 1,129 requests declaring AI agents (154 authenticated, 876 proven spoofs); 67 and 20 « Googlebot » addresses of which 7 authentic on each side; referral category 12,087 requests of which 10,740 internal navigation and 4 authentic AI referrals. Method and full tables in the companion white paper.

FAQ

How does an AI bot prove its identity, and why isn’t the user-agent enough?

The user-agent is a line of text the visitor writes itself on arrival at a server, and nothing stops it from putting « Googlebot » or « ChatGPT-User » there. Proof of identity comes through another channel: the IP address ranges publishers disclose, or a reverse DNS resolution that confirms origin both ways. In our logs, 67 addresses claimed to be Googlebot and only seven belonged to Google.

Why might my AI crawl error rate be false?

Because a tool that does not verify identity adds real bots and impostors together. On our site, authenticated AI requests found their page 99.4% of the time, while spoofs landed on a missing page 69.1% of the time. All verdicts combined, the reading reached 53.7% errors, a figure driven by the impostors, not the engines. The error rate often attributed to AI may measure, in part, actors passing themselves off as AI.

Is ClaudeBot an impostor since it cannot be authenticated?

No, and the distinction matters. ClaudeBot cannot be authenticated because Anthropic publishes neither an address range nor a reverse record, but an unverifiable bot is not a proven spoof. Our counts place it in a separate column, like DuckDuckGo. The only open question is why some publishers provide the means to verify them and others do not.

How do I know what an AI-visibility report is worth?

Ask your tool or vendor one question: what is the bot identification based on? If the answer is « the user-agent, » the reported AI traffic volume may be mostly false and the error rate is not yours. Also check how the referral category is counted, often inflated by internal navigation, and keep in mind that the native apps of ChatGPT or Claude send no referrer header, which structurally undercounts real AI visits.