AI-powered bots are mimicking human behavior with growing precision, undermining traditional defense mechanisms. Thales argues for a strategic shift: instead of merely blocking attacks, organizations should make them expensive enough that automation stops paying off for attackers.
According to Thales, predator bots will increasingly teach themselves how to hunt through AI feedback loops. Every attack and every countermeasure consumes resources — energy, time, and personnel. According to Tim Chang, VP of Application Security at Thales, effective defense against malicious bots follows exactly this economic logic: security teams should not rely on blocking alone, but should raise the cost and complexity of an attack until automation becomes a poor investment for its operator.
Blocking alone is not success, Chang says. If attackers keep coming back, the model isn’t working. AI-powered bots increasingly convincingly mimic human behavior — typing, browsing, pausing, clicking — to blend into legitimate traffic. The key question has shifted, according to Chang, from “Is this traffic malicious?” to “Who or what is accessing this application, under what conditions, and with what intent?”
Distorted traffic
According to Thales threat intelligence, bots now generate more internet traffic than humans do, and more than a third of that activity is malicious. Alongside established attack techniques such as SQL injection and cross-site scripting, AI-powered “predator bots” have become part of the core threat landscape, the company says. They combine behavioral abuse that imitates legitimate users with volumetric attacks designed to overwhelm infrastructure or obscure intent.
The economic impact is considerable, according to the company: insecure APIs and bot attacks cause significant losses worldwide every year — not only through outages, but also through price scraping, inventory hoarding, manipulated workflows, and a gradual erosion of trust in digital services.
As long as an attack costs less than defending against it, attackers structurally retain the upper hand, Chang argues. People, bots, APIs, agents, and automated systems interact continuously across modern applications, often without unified controls for identity, access, and governance. In this environment, static credentials reach their limits. Security must instead treat identity as a dynamic signal shaped by context and behavior.
Making attacks costlier, not just blocking them
Traditional defenses were built for a different era, Chang explains. Static controls assumed automation was primitive and easy to detect; rate limiting assumed predictable attacker behavior. Even behavioral defenses are under pressure as bots grow better at imitating human nuance. In some cases, defenses inadvertently train attackers by revealing thresholds that make future attacks cheaper.
Instead, the decisive factor is the attacker’s cost-benefit calculation, Chang says: an attack pays off once the value gained exceeds its cost, regardless of the technique used. Merely slowing an attack down without changing that underlying math all but guarantees a persistent threat.
Turning economics against the attacker
Chang draws a parallel to the “poison pill” defense used in corporate finance, which makes hostile takeovers prohibitively expensive. A similar principle applies in application security: rather than absorbing all defense costs internally, organizations can shift them onto the attacker. Techniques such as proof-of-work, advanced fingerprinting, and identity-aware behavioral enforcement make every interaction progressively more expensive for bots and automated tools. Attackers don’t stop when they’re blocked — they stop when continuing no longer makes economic sense. This turns scaling from an advantage into a liability for attackers.
APIs as the central interface
APIs have become the primary point of contact between people, machines, and autonomous agents, Chang says. Agent-based systems introduce new risks, including automated actions without clear identity, API abuse at machine speed, and limited accountability for decisions made without human involvement. Passive detection is no longer sufficient; application security must be enforced actively, with an identity-first approach, and on a continuous basis. Organizations that adopt identity-centric controls, Chang argues, protect not only their systems but also their revenue, customer trust, and long-term growth.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de
