# EU AI Readiness Observatory — Threat Note 01 methodology

Published: 2026-09-09

Observation window: 90 days ending 2026-09-08
Host: `verisai.eu`

## Inclusion

Requests were included when the VerisAI bot registry classified the User-Agent as `ai_scored` or `ai_secondary`. Provider identity was evaluated using available Cloudflare bot signals, published provider CIDR ranges, reverse DNS, ASN ownership and Cloudflare Radar evidence.

## Definitions

- **Provider verified:** network evidence matched the claimed provider with medium or high confidence.
- **Unverified:** the claimed provider identity could not be confirmed. This alone is not proof of malicious intent.
- **Sensitive-target attempt:** an unverified request targeted credentials, secrets, environment variables, configuration, source/deployment files or runtime/API inspection paths.
- **Source IP identity:** a unique source IP counted through an irreversible hash. Raw addresses are not published.

## Limitations

- This is a case study of one domain, not an EU-wide prevalence estimate.
- Requests and network identities are not counts of human attackers.
- Shared cloud infrastructure does not identify the operator.
- User-Agent strings identify the claimed crawler name, not the responsible organization.
- The remaining 5,709 unverified public/other-path requests are not automatically classified as malicious.
- HTTP 200 on a requested sensitive path did not prove retrieval. Representative live checks returned the public homepage fallback and found no leak.

## Publication rule

The report describes **AI crawler impersonation and attempted credential discovery**. It does not attribute the activity to the AI companies whose bot names were copied, and it does not claim that credentials were stolen.

## Citation

VerisAI (2026). *EU AI Readiness Observatory, Threat Note 01: Some crawlers are thieves in disguise.* https://verisai.eu/observatory/threat-note-01-ai-crawler-impersonation
