According to security vendor Palo Alto Networks’ 2026 annual survey, the ratio of machine identities (including AI agents) to human identities in enterprises has reached 109 to 1; CyberArk’s 2024 survey in the same series found a ratio of 45 to 1 (the methodology for this continuous series of annual surveys has been adjusted from year to year). In April 2026, Microsoft made corresponding institutional arrangements: with the Microsoft Entra Agent ID platform officially becoming generally available, agents are first-class citizens alongside employees in Microsoft’s enterprise directory; when a sponsor leaves the company, management of the agents under their name is automatically transferred to their manager.
These changes provide evidence across three dimensions, pointing to the same ongoing shift: the extent to which agents occupy software is surpassing humans across three successive stages. The first stage is traffic: more than half of all web requests are now generated by machines. The second stage is workload: agents already account for more new database creation events on Neon than humans, and data from GitHub and Linear also show rapid growth in agent code contributions and issue resolution workloads. The third stage emerged latest and cuts deepest: new products in 2026 are being designed for agents from day one, with human-facing interfaces relegated to afterthoughts—the very question of who a product is designed for has been inverted. After reading this article, you will be able to answer a question that previously could only be answered by speculation: to what extent have agents occupied software, and down to which layer?
All data cited in this article specify the measuring party and methodology; vendor self-reported figures are noted as vendor-reported methodology.
On June 3, 2026, Matthew Prince, CEO of network infrastructure provider Cloudflare, disclosed a set of web monitoring data, followed by a report from NBC News on June 4. According to data from Cloudflare’s traffic monitoring product, Cloudflare Radar, automated programs accounted for 57.5% of HTML requests, while human-initiated requests accounted for 42.5%. The sample scope of this statistic covers roughly one-fifth of websites globally, sourced via third-party reporting. This 57.5% includes not only AI agents, but also all automated programs, such as traditional search crawlers and monitoring scripts.
The rapid expansion of AI programs is the primary driving force. Looking closer at specific categories of scraping requests, data scraping used for LLM training surged from 22% of all crawler requests in spring 2025 to 52% in June 2026. In its one-year anniversary report published on July 1, 2026, Cloudflare stated that over half of internet traffic now originates from non-human entities. According to the Cloudflare Radar 2025 Year in Review, in 2025 all AI visits excluding Googlebot accounted for only 4.2% of global HTML requests; however, within the same year, scraping behavior representing user operational intent skyrocketed by more than 15x year-over-year. Monitoring data from HUMAN Security in May 2026 showed that traffic from autonomous agents in the narrow sense grew at a month-over-month rate of 5.26%, with Comet and Atlas—two autonomous browsing tools—commanding a 70% share, while 8.2% of requests were directly blocked by defensive rules deployed on websites.
When it comes to accessing the web, machines are already sending more requests than humans.
Inside the software development pipeline, the shift is unfolding in the output proportions of specific tasks. Several platforms have already observed significant growth in agent workload; in new database creation events on Neon, the share of machines has surpassed that of humans.
A prime example is Neon, a serverless database provider. On May 14, 2025, Databricks announced its acquisition of Neon for approximately $1 billion (according to media reports). The official acquisition announcement cited internal telemetry data indicating that over 80% of newly created databases on Neon were provisioned automatically by AI agents rather than created by humans. Ali Ghodsi, CEO of Databricks, also confirmed this, noting that four out of every five new databases were spun up by code. However, 80% refers to newly created database events telemetry within the platform, rather than the absolute cumulative number of databases. Looking back to October 2024 when the platform became commercially available, the official blog recorded the proportion at around 30% (the original link to this blog post is now broken; the figure comes from search snippets and industry accounts). Thus, in a little over six months, this proportion rose from 30% to 80%.
Similarly, project management tool Linear reported the same observation. On March 24, 2026, CEO Karri Saarinen revealed via an open letter that more than 75% of enterprise workspaces had installed coding agents; in just three months, the workload completed by machines grew fivefold, and nearly 25% of new issues were authored by agents. On the same day, Linear also launched its own agent product, and added support for automated coding sessions on June 11.
The shift at code hosting platform GitHub is even more striking. According to the Octoverse 2025 State of Open Source report, under GitHub’s vendor-reported methodology, between May and September 2025, more than 1 million pull requests in public repositories were authored by agents. In code review, GitHub officially announced on March 5, 2026, that automated assistants on the platform had completed a cumulative 60 million reviews, accounting for over one-fifth of the platform’s total code reviews. Payment provider Stripe disclosed in its June 11, 2026 technical retrospective that, by its vendor-reported methodology, agent traffic accounted for approximately 40% of documentation traffic, and 70% of API resource requests from new Stripe CLI users originated from agents.
On specific tasks such as provisioning new databases, agent workload on certain platforms has already surpassed human workload; in authoring and reviewing code, existing data demonstrates rapid growth, with proportions varying across platforms.
If traffic growth and workload surges represent merely quantitative shifts, at the leading edge of software design, the entire engineering design order has inverted. On October 1, 2026, Zeno Rocha, founder of email provider Resend, posted on social media announcing Inboxes, an inbox product built for humans and agents alike. Yet anyone attempting to learn more about Inboxes would find no product landing page, no promotional blog post, and no changelog entry on the official website.
Publicly available product information currently comes primarily from
official
API documentation carrying beta warnings, accompanied by an early
access application link. The documentation notes that the feature
remains in private beta, accessible only to limited users, and response
formats may change upon general release. On the package distribution
network, the accompanying preview SDK package version is
[email protected], with documentation code
snippets dating as far back as August 5, 2026.
A deeper look into the specific features provided by Inboxes reveals that every capability leans toward programmatic manipulation rather than human readability. For example, 15 webhook events cover inboxes, email threads, sending and receiving, and draft lifecycles; thread events include creation, folder changes, assignments, and tag updates. When managing email threads, built-in assignment fields cater directly to multi-agent collaboration. Draft reply generation uses idempotent design: repeatedly creating the same reply draft returns a 200 OK status code, preventing duplicate draft creation. When specifying forwarding options, the platform configures receiving addresses on the user’s behalf, eliminating MX record setup. The search endpoint supports only case-insensitive substring matching on subjects and tags. In the reply endpoint, recipients are automatically inherited from the parent message, while cc and bcc can be manually specified, with total recipients capped at 50; webhook event callbacks also provide attachment metadata.
Inboxes is not an isolated case. On September 22, 2026, Resend announced its headless dashboard initiative, built around the premise that everything achievable on the web dashboard should be executable through code. They promised that every future feature would offer headless operational capabilities, granting equal access to humans and agents alike and placing developers firmly in the operator’s seat.
Between September 14 and 21, Resend rapidly launched 9 APIs
previously confined to the web dashboard—including metric queries,
headless callbacks, broadcast cancellation, email sharing, automation
duplication, segment updates, clicked links listing, API key renaming,
and broadcast duplication—and previewed that dynamic key issuance and
event filtering would open in the next phase. On the same day, Resend
also rolled out an integration with Stripe Projects in its official
changelog. Developers no longer need to manually log into a web
interface to link cards and copy keys; an agent simply runs the command
stripe projects add resend/email, and the background
automatically links accounts, generates API keys, writes them into
environment variable files, and installs skill packages; billing for
newly created accounts is managed through Stripe (when connecting an
existing Resend account with an active team, billing remains with
Resend). Resend’s flurry of moves points toward one singular change.
Historically, building software meant drawing mockups, designing UIs, and writing dashboards for humans to click through, only wrapping them into APIs once mature. Today, from day one of a project, teams design around how machines will invoke services: defining standard protocols, structured responses, event streaming, and idempotency first. Web dashboards meant for human eyes are either pushed down the priority queue or reduced to secondary interfaces for debugging.
This inverted design order is becoming a shared convention across next-generation developer infrastructure. Stripe Projects partnered with over 60 service providers to establish a protocol advocating that just as developers once used package managers to install code packages, they can now connect to cloud services with a single command—no dashboards, no config files—with the opening section of official documentation guiding developers to start building directly from coding agents.
E2B, promising a virtual machine for every agent, raised a $21 million Series A; according to its official website, cumulative sandbox starts have exceeded 1 billion, with 94 of the Fortune 100 registered, and the center of its homepage features a terminal command. Firecrawl, promising clean data for agents, secured $75 million in funding, with a dedicated machine-facing portal in its website footer pointing directly to the skill configuration file SKILL.md. Cloudflare also launched an agent-focused email service on April 16, 2026, supporting keyless binding, MCP services, and CLI tools, noting officially that email is becoming a core interaction interface for agents.
These products share another common trait: their primary entry point is not a web interface for humans.
The exemplar of the previous generation of search was Google: a single search box where a human types a few words and results appear neatly arranged; that interface was the product itself. Doing comparable work, Firecrawl and Exa have taken a different path: the entrance is API documentation and a single command; if a human wants to try it out personally, they have to open a terminal and call the API. While the CLI is technically usable by humans, both companies’ public positioning explicitly targets programmatic invocation by AI—the customer sitting at the top of their design priority list is not someone sitting in front of a browser.
The rules of software have changed: products are targeted first at machine invocation from inception, with web pages serving as secondary accessories for human browsing.
Having witnessed traffic surpassing half, output multiplying, and design order inverted, one might think machines are poised to replace humans across all dimensions. But the moment you turn your focus to commercial transactions and security defense, you immediately discover that this is not the case at all.
These real-world limits refer to two very concrete, objective constraints: price limits and trust limits. In these areas, agents have not only failed to surpass humans, but are subjected to restrictions far stricter than those placed on humans at every turn.
First, on pricing, software platforms offer no subsidies for the technical sophistication of agents; any attempt to scale throughput with machines immediately runs into paywalls and quotas. For example, OpenAI’s agent feature introduced on July 17, 2025, is restricted to paid users, with Pro users limited to 400 messages per month and other paid tiers capped at just 40. GitHub bills each machine session as one premium request, and announced that starting June 1, 2026, Copilot code review would consume Actions runner minutes, eating into shared allocations. Model vendors are even stricter: effective April 4, 2026, Anthropic prohibited Claude Pro/Max subscription quotas from connecting to third-party agent frameworks such as OpenClaw, requiring such usage to go through pay-as-you-go billing.
Cost sensitivity is equally evident in email services. Resend’s official pricing terms specify that every inbound email received counts against existing transactional email quotas; data retention periods for the existing email service Free, Pro, and Scale tiers are all 30 days (Enterprise terms are custom negotiable), while separate pricing and long-term storage plans for Inboxes remain unannounced. This is easy to understand: machines can receive and parse email around the clock without pause; without quotas or retention constraints, massive inbound volume would blow through service provider infrastructure costs.
However, the deeper boundary lies in the fact that machines have yet to prove a viable commercial loop. A classic example: on September 29, 2025, Stripe and OpenAI teamed up to launch Instant Checkout, enabling AI to complete purchases inside conversations; in January 2026, media reported that Shopify merchants completing sales through ChatGPT checkout had to pay a 4% transaction fee to OpenAI. Approximately six months after launch, OpenAI announced a retrenchment of the feature on March 24, 2026, reverting to a traditional app model. According to media reports, only 12 merchants ever actually integrated the feature.
Macro forecasts from consulting firms are similarly inflated: McKinsey projected agentic commerce to reach $3 to $5 trillion by 2030, while eMarketer projected just $144 billion; according to third-party compilations of forecasts, the upper bound of McKinsey’s $5 trillion prediction is roughly 35 times eMarketer’s figure. The discrepancy stems from differing definitions of agentic commerce: McKinsey tallies spending influenced or orchestrated by agents, including the associated human purchases. To date, no official data demonstrates how much transaction volume agents have independently completed—this statistical void in itself outlines the real-world limit.
The second real-world limit is the trust constraint. In network security, automated programs have never enjoyed the treatment accorded to normal users; they are routinely viewed as potential malicious attackers and bad actors. Cloudflare has invested substantial effort here: introducing the Web Bot Auth proposal on May 15, 2025, to verify bot identities via cryptographic signatures; launching a pay-per-crawl billing trial on July 1, 2025, while setting blocking unauthorized AI crawlers by default as a standard policy on the same day; adding poisoning capabilities to honeypot systems in August 2026 to serve falsified data to non-compliant bots; and beta-testing an agent paywall gateway product on September 30.
Legal actions are also keeping pace. In November 2025, Amazon filed suit against Perplexity’s shopping agent, alleging that it concealed its bot identity in violation of platform terms of service. The court issued a preliminary injunction, and the case is currently before the Ninth Circuit Court of Appeals under docket number 26-1444. Risk control systems sound continuous alarms: according to vendor-reported figures at Stripe Sessions 2026, one in six signup attempts for AI services on Stripe came from malicious actors; in the month prior to the report, Stripe’s Radar risk engine intercepted over 3.3 million high-risk registrations for eight high-growth AI businesses.
Outside the tech sphere, in the real world where money and trust are negotiated, machines remain suspect entities, and every single cent owed must still be paid in full.
From traffic and workload to design order, the evolutionary arc of technology is unmistakable: traffic surpassing half means machines now occupy the lion’s share of network conduits; workload surpassing half is occurring in specific tasks on select platforms, such as new database creation events on Neon; and an inverted design order means new products target machines by default from day one. Traffic and localized workload figures are backed by platform telemetry; the shift in design order is corroborated by public interfaces and releases from products like Stripe Projects and Resend.
Yet understanding these three stages requires keeping the real-world limits firmly in view. The real-world limits stem from broader societal economic contracts and legal accountability. The entities creating value and bearing risk remain human beings. Programs provision databases and send messages, and cloud vendors charge for resources; programs scrape data, and security perimeters treat them as potential hazards. Amazon’s litigation against Perplexity also demonstrates that platform access disputes involving agents are still adjudicated within existing legal frameworks between the underlying human organizations. This is a landscape simultaneously radical and constrained, offering three foundational criteria for today’s system developers and product builders.
First, assess programmatic usability. If a product’s interaction logic remains trapped inside a dashboard, requiring manual clicks for external calls, it is rapidly losing compatibility with the mainstream ecosystem.
Second, define strongly typed interfaces, event streaming, idempotency controls, and metadata on the very first workday of the project. Relegate the dashboard to a secondary tier, reserved strictly for debugging.
Third, fortify defenses at the real-world limits. Evaluate quotas, billing, and permission risks; systems lacking quota caps, signature verification, and malicious traffic defenses will pay a devastating price under the strain of high-frequency operation.
Recognizing that machines have taken center stage in traffic, output, and system design, while seeing clearly their limits in money and trust—this is the reality of software today.