AsiaTechDaily – Asia's Leading Tech and Startup Media Platform
For more than two decades, digital visibility has largely been defined by search engine optimization. Businesses invested heavily in improving Google rankings, optimizing websites for search algorithms, and driving organic traffic through keywords and backlinks. Today, however, another transformation is underway. As AI-powered search platforms such as OpenAI’s SearchGPT, Perplexity, Google’s AI-powered search experiences, and Microsoft’s Copilot increasingly become gateways to online information, startups are entering an era where discoverability depends not only on traditional search engines but also on artificial intelligence systems that continuously crawl, interpret, and summarize web content.
The shift is occurring alongside an unprecedented rise in automated internet traffic. According to the 2026 Thales Bad Bot Report, bots accounted for 53% of global web traffic in 2025, while in Singapore, automated traffic reached 58%, significantly outnumbering human users. More importantly, AI-powered bot attacks increased 12.5 times compared with the previous year, highlighting how artificial intelligence is fundamentally changing the nature of internet automation. Rather than existing solely as malicious tools, AI agents are emerging as a distinct category of internet traffic, interacting directly with websites, APIs, and enterprise applications.
For startups across Asia, this evolution creates a strategic dilemma. Remaining visible to AI-powered search engines has become increasingly important for customer discovery, yet unrestricted AI crawling can expose proprietary data, pricing information, product documentation, and intellectual property. As businesses embrace AI-driven marketing and digital transformation, the question is no longer whether automation should be allowed, but how it should be governed.
The emergence of generative AI has fundamentally altered how users search for information. Instead of returning pages of hyperlinks, AI-powered search engines increasingly provide synthesized answers generated from information collected across multiple websites.
For startups, this changes the rules of digital visibility. In the traditional SEO model, businesses primarily optimized content to rank highly on search engines. Success depended on technical optimization, backlinks, keywords, and content quality. AI-powered search introduces another layer. Companies must now ensure their content is accessible and understandable to AI systems while simultaneously protecting sensitive business information from automated extraction.
This distinction is becoming increasingly important because not every automated visitor behaves in the same way. Some AI crawlers help improve discoverability by indexing content for legitimate search experiences, while others scrape proprietary information for competitive intelligence, model training, or unauthorized commercial use. The challenge is no longer distinguishing between humans and bots. It is distinguishing between beneficial and harmful automation.
During an exclusive conversation with AsiaTechDaily, Andy Zollo, Senior Vice President, Application and Data Security for Asia Pacific and Japan at Thales, said startups should move away from treating every AI crawler as a security threat.
“The tension is real. AI search engines depend on crawlers to index content, so a blanket block does carry discoverability risk. But the answer is not choosing one or the other, but it is precision over blunt force.
Founders should not treat all AI crawlers as the same. The data shows the problem is already playing out in practice: in 2025, more than 10% of AI fetch agents and nearly 9% of AI crawlers triggered security controls, even when operating as legitimate tools. The line between helpful and harmful automation is thin, and it requires more than a blocklist to manage.
The better approach is understanding what each crawler is actually doing and making access decisions based on that, not simply a blanket block or allow. Done right, you stay visible to legitimate AI search engines while keeping the scrapers out.”
His comments reflect a broader shift taking place across the digital economy. As AI becomes embedded into search, productivity tools, customer support platforms, and enterprise applications, organizations can no longer rely on traditional security approaches that simply block automated traffic. Instead, they must develop policies that distinguish trusted AI services from malicious actors while preserving business visibility.
The latest Thales research suggests that automation is no longer an occasional phenomenon driven by credential stuffing or web scraping campaigns. Instead, machine-driven activity is becoming a permanent feature of the internet.
One of the report’s most significant findings is the emergence of AI agents as a new category of internet traffic. Unlike traditional bots that perform repetitive automated tasks, AI agents increasingly interact directly with applications, APIs, and enterprise systems to retrieve information, complete workflows, and execute increasingly sophisticated tasks.
This evolution blurs the distinction between legitimate and malicious automation. At the same time, APIs have become one of the primary attack surfaces. According to the report, 27% of bot attacks in 2025 targeted APIs, allowing attackers to bypass conventional web interfaces and interact directly with backend systems using authenticated requests that often appear legitimate. For startups building SaaS platforms, fintech applications, marketplaces, developer tools, and AI products, this represents an increasingly important cybersecurity challenge. Rather than attacking websites alone, automated systems are targeting the digital infrastructure that powers modern businesses.
Asia’s startup ecosystem is particularly exposed to this transition. Across the region, startups increasingly rely on APIs, cloud-native applications, AI-powered services, and digital platforms that exchange enormous volumes of machine-generated traffic. Many technology companies also publish extensive technical documentation, developer portals, pricing information, and knowledge bases to support customers and ecosystem partners.
These resources are precisely the types of content AI systems seek to index. For founders, this creates competing priorities. On one hand, limiting AI crawler access too aggressively may reduce visibility within emerging AI search platforms that influence purchasing decisions and product discovery. On the other, allowing unrestricted automated access risks exposing proprietary assets and increasing security vulnerabilities.
The challenge extends beyond marketing. It now influences cybersecurity, intellectual property protection, infrastructure governance, and long-term competitive strategy. As AI-powered search becomes increasingly integrated into consumer and enterprise workflows, managing machine-to-machine interactions may become as important as managing human users.
The rise of AI search requires startups to reconsider long-standing assumptions about website access and digital security. Rather than relying on broad blocking policies, organizations should consider a more nuanced approach that includes:
This shift reflects a broader transition from simply defending digital assets to actively managing how intelligent systems interact with them.
Artificial intelligence is transforming far more than online search. It is reshaping how information is collected, interpreted, and delivered across the internet. As AI agents become increasingly active participants in digital ecosystems, startups will need to rethink how they balance openness with protection.
The challenge is no longer deciding whether to allow bots. It is determining which forms of automation create value and which introduce unacceptable risk. For Asia’s startup ecosystem, that distinction could become a defining competitive advantage. Companies that successfully combine AI discoverability with intelligent governance will be better positioned to reach customers, safeguard proprietary information, and build trust in an internet where machines increasingly interact with one another as often as they do with people.