Spur Intelligence, a Lake Mary, Florida cybersecurity startup that separates human users from bots, has raised $200 million in a round led by Insight Partners. The financing arrives at the exact moment enterprises are confronting a new baseline for the open web: as of mid-2026, automated traffic now outnumbers human traffic online, according to Cloudflare's latest report.
Spur was founded in 2017 by two former Defense Department engineers, five years before ChatGPT's public launch turned generative AI into a mass-market product and, downstream, into a mass-market source of automated traffic. The company's platform is designed to identify the infrastructure sitting behind sessions — the VPNs, residential proxy networks, and anonymization services that make modern bots hard to distinguish from legitimate users.
Insight Partners framed the raise around a visibility gap. Enterprise security teams can see the requests hitting their sites and APIs, but not what is actually generating them.
“As sophisticated criminal VPNs, residential proxy networks, and anonymization infrastructure proliferate, organizations are increasingly operating with a critical blind spot: they can see the activity, but not the infrastructure behind it.”— Thomas Krane, Insight Partners
Key facts
- 01Spur Intelligence raised $200 million led by Insight Partners for its bot-detection platform.
- 02The Lake Mary, Florida startup was founded in 2017 by two former Defense Department engineers — five years before ChatGPT launched.
- 03Cloudflare reported that as of mid-2026, bots are now more active on the internet than humans for the first time.
- 04Cloudflare CEO Matthew Prince said agentic traffic crossed the threshold roughly a year ahead of his own forecast.
The scale of the problem has moved faster than most forecasts. Cloudflare, which sits in front of a large slice of internet traffic, said last month that bots have overtaken humans as the dominant source of activity on the web, driven in large part by agentic AI systems making autonomous requests on behalf of users, developers, and other software.
That crossover matters for security economics. Bot detection has been a corporate line-item for two decades, aimed at credential stuffing, scraping, ad fraud, and account takeover. Agentic traffic layers a harder problem on top: some of the automated requests are legitimate — an AI assistant booking a flight for its user, an agent pulling a price for a shopper — and some are hostile, and the two look nearly identical at the packet level.
Cloudflare CEO Matthew Prince has been vocal about how fast the curve moved.
Spur's pitch is that legacy signals — user agents, IP reputation, CAPTCHA friction — are not enough when the adversary is renting residential IPs by the hour and driving a headless browser with an LLM. The startup instead fingerprints the underlying infrastructure, flagging sessions that originate from known proxy networks, criminal VPNs, and anonymization services even when the surface behavior looks routine.
The $200 million round places Spur among the better-funded pure-play bot-detection vendors, a category that has historically been dominated by broader web-security platforms such as Cloudflare, Akamai, and human-verification specialists like hCaptcha. Insight, which typically writes growth-stage checks, is betting that agentic AI turns bot management from a niche control into a core layer of enterprise security spend.
There is a genuine tension in the market Spur is entering. Not every bot is bad — publishers, retailers, and SaaS vendors increasingly want to serve AI agents as first-class customers, because those agents are acting on behalf of real buyers. A detection product that indiscriminately blocks automated traffic risks cutting off future revenue. Spur and its peers will have to prove they can distinguish sanctioned agent traffic from adversarial automation, not just flag both as non-human.
The read for the AI market is that infrastructure built for a web of humans is being repriced for a web of agents. Cloudflare's traffic-mix data is the clearest signal yet that the shift is not a projection but a present-tense operating condition, and Insight's $200 million check is a bet that the enterprises paying for perimeter security have not yet adjusted their stack to match. Expect more capital to move into this layer — identity, provenance, and agent-attestation — over the next several quarters, and expect the frontier labs to eventually meet detection vendors halfway with signed agent identities.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




