All Six AI Engines Name the Same Ten Bot Management Vendors. Only ChatGPT Puts DataDome First.

bot management AI search visibility bot mitigation generative engine optimization
Govind Kumar
Govind Kumar

Co-founder/CPO

 
August 25, 2026
15 min read
All Six AI Engines Name the Same Ten Bot Management Vendors. Only ChatGPT Puts DataDome First.

TL;DR

  • We analyzed 240,000 AI engine responses to 10,000 enterprise buyer-intent queries about bot management, bot mitigation and automated-traffic defense, across six engines and four markets. Cloudflare led with 232,000 mentions, ahead of Akamai at 210,000, DataDome at 203,000 and Imperva at 196,000, and those four took 55.8% of all mentions. Cloudflare opened five of the six engines. ChatGPT opened with DataDome, and read it at mean position 1.5 against Cloudflare's 3.1. The engines reached that shortlist from cited domains that overlap by a mean Jaccard coefficient of 0.17, and only 2.0% of the 3,906,000 pages they cited were dead.

When a security team buying automated-traffic defense opens an AI engine before a vendor site, the list that engine returns sets the shortlist before anyone books a call. We wanted to know what the engines actually say in one category, measured at scale rather than inferred from a handful of prompts.

Key Takeaways

  • Cloudflare recorded 232,000 mentions, Akamai 210,000, DataDome 203,000 and Imperva 196,000. Those four took 55.8% of all mentions across the 37 brand strings recorded, and ten brands were named by all six engines.
  • Being mentioned most is not the same as being named first. Cloudflare opens five of six engines, but in ChatGPT its mean ordinal position is 3.1 while DataDome's is 1.5, where 1 means named first.
  • Cited-domain overlap between engines averaged 0.17 as a Jaccard coefficient, where 0 is disjoint and 1 is identical. The highest pair, at 0.32, was Gemini and Perplexity, two engines from different companies.
  • 47.3% of all cited pages sit on a vendor's own site, but that figure rests on ChatGPT alone. For the other five engines, most citations fall outside every source type we track.
  • Only 2.0% of cited pages were dead. Cloudflare led all four markets, and the same four brands held the leading positions in every one of them.

What We Analyzed and How

We issued 10,000 enterprise buyer-intent queries about bot management, bot mitigation and automated-traffic defense to six AI engines: ChatGPT, Perplexity, Gemini, Microsoft Copilot, Google AI Overview, and Google AI Mode. Every query ran in four markets (United States, Canada, India, Germany), producing 40,000 responses per engine and 240,000 in total during August 2026.

For every response we recorded length, cited sources and the type of site each one sits on, whether each cited URL still resolved, each brand named, and the ordinal position of that brand's first appearance. The same counting method, written up as a repeatable process, is in our guide to measuring AI share of voice across engines. The corpus contained 3,906,000 cited sources, 37 brand strings, and 84 distinct product entries once plan, edition and category-noun spellings of one product were merged.

Two limits are worth stating up front. The engines are commercial services without pinned model versions, so a repeat run would not reproduce identical responses. The query set is also purposive rather than randomly sampled. We therefore report descriptive statistics only, and make no claims of statistical significance. Full methodology and validity limits are in the complete benchmark report.

Which Bot Management Vendors Do AI Engines Name Most?

Cloudflare led the category with 232,000 mentions, followed by Akamai at 210,000, DataDome at 203,000 and Imperva at 196,000. Those four sit within 36,000 mentions of each other and take 55.8% of all mentions recorded across the 37 brand strings. The fifth-placed vendor, HUMAN Security, recorded 137,000, and the gap from Imperva down to it, 59,000, is the largest between any two adjacent brands in the leading twelve.

Figure 1. AI engine mentions by bot management brand AI engine mentions by bot management brand. Cloudflare 232,000; Akamai 210,000; DataDome 203,000; Imperva 196,000; HUMAN Security 137,000; Radware 91,000; Arkose Labs 73,000; F5 65,000; Kasada 63,000; Netacea 45,000; Cequence 38,000; Fastly 33,000. 0 50,000 100,000 150,000 200,000 250,000 Cloudflare 232,000 Akamai 210,000 DataDome 203,000 Imperva 196,000 HUMAN Security 137,000 Radware 91,000 Arkose Labs 73,000 F5 65,000 Kasada 63,000 Netacea 45,000 Cequence 38,000 Fastly 33,000 Brand mentions
Figure 1. AI engine mentions by bot management brand. The 12 most-mentioned of 37 brand strings recorded; n = 240,000 responses. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.

Ten of the 37 brand strings were named by all six engines: Cloudflare, Akamai, DataDome, Imperva, HUMAN Security, Radware, Arkose Labs, F5, Kasada and Fastly. That is a category with a settled core, and a larger one than we found in the DSPM category, where the engines picked the same three vendors. The tail is where the engines part company. 18 of the 37 strings were named by exactly one engine, none above 11,000 mentions, and several of them are fraud-prevention vendors, verification services and security consultancies that one engine pulled into the category on its own.

Our finding: The engines recorded 84 distinct product entries, and 43 of them were named by exactly one engine. Akamai and HUMAN Security each held 8 separate entries, and HUMAN Security was written three different ways as a brand.

That fragmentation is a measurement problem before it is a marketing one. Even after we merged plan and edition spellings of the same product, one vendor's name still appeared as "HUMAN Security", "HUMAN" and "Human Security" across 14 entries. A visibility tool counting exact strings reports three weak brands instead of one strong one. Publish one canonical product name and use it consistently, or accept that your share of voice will be split across variants you never chose.

Do the Engines Agree Because They Read the Same Sources?

No. They reach the same shortlist from largely separate evidence.

We measured the overlap between each pair of engines' cited domains using a Jaccard coefficient, where 1 means identical source sets and 0 means no shared domains at all. The mean across all 15 engine pairs was 0.17. Only six pairs reached 0.20. The highest value anywhere was 0.32, between Gemini and Perplexity, which are run by different companies. The three Google-operated engines scored 0.16, 0.30 and 0.24 with each other, so in this category a shared parent did not produce the highest overlap.

The lowest was 0.03, between Microsoft Copilot and Google AI Mode. Microsoft Copilot recorded the lowest overlap with four of the other five engines, and its most-cited domain was a statistics aggregator that appears in no other engine's top three. ChatGPT's most-cited domain was a bot vendor's own site. Google AI Mode's was an analyst firm. Every engine had a different most-cited domain.

Volume makes this worse. ChatGPT supplied 1,950,000 of the 3,906,000 cited sources, 49.9% of the corpus, from the same 40,000 responses every other engine had. Microsoft Copilot supplied 155,000, 4.0%. A source list that earns you ChatGPT citations describes almost half the corpus and almost nothing about what Copilot or Perplexity read. Why the engines diverge this much is a question about how each one selects sources in the first place, which we break down in how the major AI engines choose which sources to cite.

Where the Evidence Actually Comes From

Across the corpus, 47.3% of cited pages sit on a domain belonging to a vendor named in the response. That number is misleading on its own, because it rests on one engine.

Figure 2. Share of each engine's citations that point to a vendor's own site Share of each engine's citations that point to a vendor's own site. ChatGPT 65.2%; Gemini 42.2%; Google AI Overview 42.2%; Google AI Mode 31.9%; Perplexity 13.5%; Microsoft Copilot 7.7%. 0% 20% 40% 60% 80% ChatGPT 65.2% Gemini 42.2% Google AI Overview 42.2% Google AI Mode 31.9% Perplexity 13.5% Microsoft Copilot 7.7% Vendor-site share (% of cited sources)
Figure 2. Share of each engine's citations that point to a vendor's own site. Cited pages on a domain belonging to a vendor named in the response, as a share of that engine's own cited sources; n = 3,906,000 cited sources. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.

ChatGPT drew 65.2% of its citations from vendor sites, and its three most-cited domains were all vendor sites. It is the only engine for which vendor sites are the largest class. For the other five, the largest class is the residual: pages outside every type we track. Gemini and Google AI Overview each drew 42.2% from vendor sites, Google AI Mode 31.9%, Perplexity 13.5% and Microsoft Copilot 7.7%, with 88.4% of Copilot's citations falling in that residual class. Analyst and review sites carried only 6.5% of the corpus, peaking at 13.3% of Gemini's citations.

For a vendor this changes the instruction. Your own documentation, product and integration pages are the primary citation surface for ChatGPT, and ChatGPT alone. The other five engines read comparison sites, statistics aggregators and a long tail of unclassified pages, and your visibility there depends on being described accurately by other people.

Why Being Mentioned Most Does Not Mean Being Named First

Mention volume and ordinal position are different things, and in this category they agree in five engines and disagree in one.

Cloudflare took the first-mention position in five of the six engines and recorded the highest mention total in the study. ChatGPT was the exception: it named DataDome first, and DataDome's mean ordinal position in ChatGPT was 1.5 against 3.1 for Cloudflare, the only engine in which DataDome was read earlier than Cloudflare. In Perplexity the pattern reversed: Cloudflare averaged position 1.0 and DataDome 4.3, the latest position for any of the three leading brands anywhere.

Figure 3. Mean ordinal position of Cloudflare and DataDome by AI engine Mean ordinal position of Cloudflare and DataDome by AI engine. ChatGPT: Cloudflare 3.1, DataDome 1.5; Microsoft Copilot: Cloudflare 1.2, DataDome 3.5; Gemini: Cloudflare 2.5, DataDome 2.9; Google AI Mode: Cloudflare 1.7, DataDome 3.5; Google AI Overview: Cloudflare 1.7, DataDome 2.4; Perplexity: Cloudflare 1.0, DataDome 4.3. Cloudflare DataDome 1 2 3 4 5 ChatGPT 1.5 3.1 Microsoft Copilot 3.5 1.2 Gemini 2.9 2.5 Google AI Mode 3.5 1.7 Google AI Overview 2.4 1.7 Perplexity 4.3 1.0 Mean ordinal position (1 = named first)
Figure 3. Mean ordinal position of Cloudflare and DataDome by AI engine. Lower is earlier in the response; n = 240,000 responses across six engines and four markets. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.

The mention counts inside ChatGPT are almost level, at 38,000 for Cloudflare and 39,000 for DataDome, so the opening slot there is a matter of order rather than volume. And DataDome's lead in ChatGPT does not carry across. It was read earlier than Akamai in only two engines, ChatGPT and Google AI Overview, and sat third or later in four.

Akamai shows the third pattern. Second on mentions at 210,000, it never took a first-mention position in any engine, and Cloudflare was read earlier than it in all six. Its mean position ran from 2.5 to 3.3, a narrower range than either of the other two. It is reliably in the answer and reliably not at the top of it.

Our finding: A vendor can be named in most responses and still be read third, and a vendor named less often can open the answer. Frequency and order are two separate visibility problems that respond to different work.

If you report only mention counts, you will miss the ordering story entirely. If you report only position, you will miss vendors that are present everywhere but never first. Track both.

How Reliable Are the Sources the Engines Cite?

Of the 3,906,000 URLs the engines attached to their responses, 76,560 did not resolve to a reachable page when we tested them. That is 2.0%.

The rate ranged from 0.0% for Microsoft Copilot and Gemini to 3% for Google AI Overview, with ChatGPT at 2.3%. ChatGPT accounted for 44,800 of the dead pages, 58.5% of the total, in proportion to its share of citations.

The definition matters in this category more than most, because the vendors under study sell the bot protection that turns automated requests away. A page that answers a crawler with a 403 is not dead: it exists, and the crawler was refused. We count a page as dead only when it returns not-found, gone or a server error, or its host cannot be reached after a retry. On that definition the evidence base is almost entirely intact. No engine cited its own parent's properties at a measurable rate, and no engine recorded a refusal.

Finding out which of your own URLs an engine is citing still takes a per-engine workflow; ours is in how to track AI citations, mentions and sources. But link rot is not the lever here. Inclusion is.

Does the Answer Change by Country?

Not in who leads, and not in who is in the leading group. Cloudflare was first in the United States, Canada, India and Germany, and the same four brands held the four leading positions in every market.

Market First Second Third
United States Cloudflare DataDome Akamai
Canada Cloudflare DataDome Akamai
India Cloudflare Akamai Imperva
Germany Cloudflare Akamai DataDome

Brands ranked by mentions within each market; n = 60,000 responses per market. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.

What changed was the order below Cloudflare. DataDome was second in the United States and Canada, Akamai second in India and Germany. No market-specific vendor entered the leading positions anywhere. At product level the stability holds: 21 of the 84 product entries were recorded in all four markets, and every one of the ten most-mentioned entries was.

That result is not universal across the categories we have measured. Our analysis of what AI engines recommend in network security found recommendations diverging by engine and by region, but it covered seven engines across ten markets, so the difference may be scope rather than category.

This is a negative result, and it is useful precisely because it is negative. It rules out market localization as an explanation for absence. If your brand is missing from the vendor set in one of these four markets, it is missing in all of them, and a locale-specific landing page will not be what fixes it.

Six Engines, Six Answer Shapes

The engines that agree about vendors do not agree about how to answer.

Mean response length spans a factor of 5.5, from 105.5 words in Perplexity to 584.0 in ChatGPT. Microsoft Copilot anchored 68% of its responses to an explicit calendar date, more than double any other engine, while Gemini anchored none. ChatGPT hedged most, at 13% of responses. Gemini and Google AI Mode hedged in none.

Truncation was recorded in four of the six engines, from 3% in Google AI Overview up to 45% in Gemini, with Perplexity close behind at 42%. We did not measure what truncation removes, but where an engine cuts off mid-sentence the vendors named late in a list are the likeliest to be lost, which would compound the ordering problem above for anyone reliably named third.

The engines also disagree on substance. ChatGPT repeatedly ranked DataDome first for deployment across several delivery networks; Gemini more often led with Cloudflare or Akamai for detection at the network edge. ChatGPT alone stated that DataDome is the only vendor supporting cryptographic authentication of automated agents. Microsoft Copilot alone placed Forter and Kroll in its account-takeover rankings, and alone returned 12 product entries that no other engine named. We record those as observed and do not assess them.

The practical consequence is that one piece of content cannot be shaped for all six. A 105-word answer has room for three vendor names and no qualification; a 584-word answer has room for a comparison table. The claims that survive compression are short, specific and quantitative.

What Should Vendors Do With This?

Decide whether you have an inclusion problem or an ordering problem. They are not the same, and they do not respond to the same work. If you are outside the group of ten brands every engine names, nothing about ordering matters yet.

Measure all six engines separately. With mean cited-source overlap at 0.17, a program tuned to one engine tells you almost nothing about the other five. If you are choosing instrumentation, we compared 15 AI search monitoring tools.

Treat your own site as ChatGPT's evidence, not everyone's. ChatGPT draws 65.2% of its citations from vendor sites and supplies 49.9% of the corpus. The other five engines mostly read pages you do not control.

Publish one canonical product name and repeat it. 43 of 84 product entries came from a single engine each, and one leading vendor's name was written three ways. Naming drift splits your own share of voice.

Write the specifics the engines reuse. Across the corpus the same selection criteria came back: behavioral detection at the edge, device fingerprinting, false-positive rates, real-time scoring, integration with a CDN or WAF, and policy control over verified automated agents. Concrete figures on those give an engine something to extract. A general description of the category does not.

Do not localize yet, and do not budget for link rot. The leading group was identical in all four markets, and 2.0% of cited URLs were dead.

Frequently Asked Questions

How many AI responses did this bot management study analyze?

240,000 responses, from 10,000 enterprise buyer-intent queries issued to six AI engines across four markets in August 2026. The corpus contained 3,906,000 cited sources and 84 distinct product entries.

Which bot management vendor has the highest AI search visibility?

Cloudflare, with 232,000 mentions across the study, ahead of Akamai at 210,000, DataDome at 203,000 and Imperva at 196,000. Cloudflare was also named first by five of the six engines tested.

Do all AI engines cite the same sources for bot management recommendations?

No. Mean cited-domain overlap between engine pairs was 0.17 on a Jaccard scale where 1 is identical. The highest overlap recorded anywhere was 0.32, between Gemini and Perplexity, and the lowest was 0.03, between Microsoft Copilot and Google AI Mode.

What percentage of AI-cited sources are dead links?

2.0% across this study, ranging from 0.0% for Microsoft Copilot and Gemini to 3% for Google AI Overview. A page that refuses an automated request is counted as reachable, because it exists.

Does AI search visibility differ by country for bot management tools?

Not in this study. Cloudflare led the United States, Canada, India and Germany, and Cloudflare, Akamai, DataDome and Imperva held the four leading positions in every market. Only the order below Cloudflare changed: DataDome was second in the United States and Canada, Akamai in India and Germany.

Final Thoughts

The engines agree about vendors and disagree about evidence. Ten of 37 brand strings were named by all six, four of them took 55.8% of all mentions, and the same brand led every market, while the engines behind those answers shared a mean of 0.17 of their cited domains and drew them from very different kinds of site.

For a vendor in this category the shape matters more than any single number. Visibility is concentrated into a small group of names the engines reuse across markets and phrasings, and it is reached through six largely separate evidence bases. Entering that group is a different problem from improving a position inside it, and it has to be solved once per engine.

We ran the identical protocol in a different category and found the same structural pattern: which attack surface management platforms AI engines recommend, also 240,000 responses across six engines and four markets.

The full methodology, the per-engine tables and the validity limits are in the complete benchmark report.

Disclosure: GrackerAI publishes this research and sells AI search visibility measurement for the category it covers. The study measured how AI engines describe vendors. It did not test, evaluate, or rank any vendor's product, and no vendor paid for or requested placement.

Govind Kumar
Govind Kumar

Co-founder/CPO

 

Govind Kumar is a product and technology leader with hands-on experience in identity platforms, secure system design, and enterprise-grade software architecture. His background spans CIAM technologies and modern authentication protocols. At Gracker, he focuses on building AI-driven systems that help technical and security-focused teams work more efficiently, with an emphasis on clarity, correctness, and long-term system reliability.

Related Articles

Which Attack Surface Management Platforms AI Engines Recommend: A 240,000-Response Study
attack surface management

Which Attack Surface Management Platforms AI Engines Recommend: A 240,000-Response Study

Original study of 240,000 AI engine responses on attack surface management: vendor share of voice, cited sources, dead-link rates, and engine variance.

By Deepak Gupta August 27, 2026 14 min read
common.read_full_article
AI Detection in B2B Content: A Practical QA Workflow for Cybersecurity Teams
AI Detection

AI Detection in B2B Content: A Practical QA Workflow for Cybersecurity Teams

Learn a practical QA workflow for detecting AI-generated B2B content in cybersecurity to protect clients, data, and brand reputation.

By Vijay Shekhawat September 4, 2026 5 min read
common.read_full_article
OneTrust Is the Most-Named Third-Party Risk Vendor. No AI Engine Names It First.
third-party risk management

OneTrust Is the Most-Named Third-Party Risk Vendor. No AI Engine Names It First.

OneTrust drew the most mentions across 300,000 AI answers on third-party risk management, yet no engine named it first. Bitsight opened three of six.

By Govind Kumar August 30, 2026 16 min read
common.read_full_article
AI Engines Mention Bitwarden Most for Enterprise Password Managers. Four of Six Name 1Password First.
enterprise password manager

AI Engines Mention Bitwarden Most for Enterprise Password Managers. Four of Six Name 1Password First.

Bitwarden tops 240,000 AI engine responses on enterprise password managers, 1Password opens four of six engines, and Keeper is second on mentions yet never first.

By Deepak Gupta August 22, 2026 15 min read
common.read_full_article