Thu, 23 Jul 2026

Combat AI-powered bot surge with session-level behavioural analysis

Cloudflare has announced the general availability of Precursor, a next-generation behavioural detection and verification system designed to combat the rising tide of automated bot traffic that now accounts for roughly 57% of all web requests.

Built directly on Cloudflare’s edge network, Precursor monitors entire user sessions in real time to detect bot automation, replacing static, point-in-time checks with continuous behavioural validation.

The launch marks a significant evolution in bot management strategy, as modern AI-powered bots have become increasingly adept at faking single actions to bypass traditional security checkpoints.

While legacy defenses rely on disruptive CAPTCHAs or one-time verification challenges, Precursor analyzes ongoing interactions—such as mouse movement, scrolling rhythm, typing cadence and page visibility—to distinguish human users from automated imposters without interrupting legitimate traffic.

“Traditional security checks look at a single moment in time, but modern bots have gotten smart enough to fake their way through the front door,” said Dane Knecht, CTO of Cloudflare.

“Instead of just checking an ID at the gate, we are looking at behavior over the entire visit. This makes life seamless for real users, while making it incredibly difficult and expensive for bad actors to fake human behavior.” Dane Knecht

Precursor’s session-level approach addresses a critical blind spot in current bot defenses. By continuously collecting robust browser signals and evaluating interaction trails across an entire session, the system prevents automated agents from resetting their behavioral signatures through page refreshes.

The solution is enabled with one click, requiring no code modifications, and logs aggregate behavioral patterns rather than recording specific user inputs to protect end-user confidentiality.

Related:  Readying for that AI-led cyberattack

The shift toward session-based behavioral analysis aligns with broader industry trends. AWS WAF’s Bot Control managed rule group similarly emphasizes the need for multi-layered bot detection, combining real-time monitoring, rate-limiting and client-side interaction challenges to identify sophisticated bots involved in credential-stuffing and application-level attacks.

AWS guidance notes that for the most difficult bots, organizations should consider adding dedicated bot management solutions alongside WAF to achieve advanced mitigation capabilities.

Zscaler’s approach to bot mitigation also highlights the importance of continuous behavioral telemetry, with its Zero Trust Exchange platform analysing user and device behavior across sessions to detect anomalies that static checks might miss.

Both AWS and Zscaler underscore that as AI agents become more prevalent, defenses must evolve from reactive, signature-based models to proactive, behavior-driven validation.

“Until now, the space between those moments [like login and checkout] was a black box,” Knecht added. “With Precursor, we’re now eliminating that blindspot.”

Key capabilities include privacy-led defense that records only timing rhythms rather than actual keystrokes, zero-code setup, real-time analysis of browser telemetry, and session-long security measures that compound context to adjust Bot Scores dynamically.

As automated traffic eclipses human activity for the first time, Cloudflare’s Precursor represents a shift from checkpoint security to continuous behavioral intelligence—making it exponentially harder for bots to blend into the crowd.

Related Stories

MORE STORIES