Gartner and bot management: the Magic Quadrant that does not exist
There is no Gartner Magic Quadrant for bot management. There is one for Cloud WAAP, and bot mitigation is a criterion inside it. Where each vendor appears, and how to read the two analyst views together.

The Gartner Magic Quadrant for bot management is one of the most requested documents in this category, and it does not exist. The reason it does not exist is useful for understanding how the market is structured.
What Gartner publishes
Gartner covers this space in two places, neither of which is a bot management Magic Quadrant.
The Magic Quadrant for Cloud Web Application and API Protection is the relevant quadrant. Cloud WAAP is Gartner's category for cloud-delivered services combining a web application firewall, DDoS mitigation, bot management and API protection into one offering. Cloudflare, Akamai, Imperva, F5, AWS, Fastly and Radware are the vendors you find there. Bot mitigation is a criterion inside a broader evaluation.
Gartner Peer Insights runs a separate Bot Management review category, built on customer reviews rather than analyst placement. DataDome, HUMAN, Kasada, Arkose Labs, Netacea, CHEQ, F5, Radware, Imperva and Cloudflare all have profiles there.
So when a vendor cites Gartner on bot management, it is worth asking which of those two they mean, because they carry very different weight.
Why the two analyst views name different vendors
Put the lists next to each other and the difference is stark.
Forrester's Q2 2026 Bot and Agent Trust Management Wave names DataDome, HUMAN and Kasada as Leaders, Arkose Labs, CHEQ and Netacea as Strong Performers, and hCaptcha and Google reCAPTCHA Enterprise as Contenders. Cloudflare and Akamai are absent.
Gartner's Cloud WAAP quadrant is built around Cloudflare, Akamai, Imperva, F5 and AWS. The Forrester specialists are mostly absent.
Neither list is incomplete. They are answers to different questions.
Gartner's question is roughly: which vendor can consolidate my web application security into one cloud service? That question structurally favours the CDN and WAF platforms, because consolidation is what they sell.
Forrester's question is: which vendor is best at establishing trust for bots and agents specifically? That question structurally favours the specialists, because depth is what they sell.
If your procurement process picks one analyst view and treats it as the market, you get a predictable failure. Use only the WAAP quadrant and you buy a bundled product that handles commodity automation well and targeted attacks poorly. Use only the Wave and you may buy a specialist to run alongside a WAF you already pay for, duplicating what you have.
How to read them together
A practical order of work, drawn from watching these evaluations run:
Start with what is already in the contract. If you have Cloudflare Enterprise or an Akamai CDN, you already own bot mitigation. Turn it on properly and measure it before you buy anything. Sometimes that is the whole project.
Then find out what gets through. The bundled layer handles the commodity traffic. What survives is the question. If what survives is stealth-headless frameworks on residential proxies, solver services, or real-device farms, no amount of WAAP consolidation fixes it, and the Wave is your list.
Then decide whether you want to operate it. DataDome, HUMAN, Kasada and Arkose all include a managed service. That is a product decision rather than a pricing one, and it determines who authors the rule during a live incident.
Then look at Peer Insights, not the placement. Vendor placement tells you about vision and revenue. Reviews tell you what daily operation is like. Forrester's own Wave picks up the same themes that appear in reviews: CHEQ's numeric reason codes, Kasada's limited UI customisation, hCaptcha's clunky management interface.
The category naming problem
One more thing worth knowing if you are searching for research.
Forrester renamed this market in late 2025. What was bot management, bot mitigation and bot detection is now bot and agent trust management, on the grounds that AI agents fall between humans and bots and a binary block-or-allow decision loses real customers.
Gartner has not adopted that rename as of Q3 2026. Gartner still says bot management.
So the same market currently has two analyst names, and searching for one will not find research filed under the other. If you are doing a literature review before a purchase, search both.
How Prosopo compares
Prosopo is not currently in either evaluation. The Wave applies a standalone product revenue threshold, and a Gartner Peer Insights presence is on our roadmap.
What we compete on today is the specific capability both analyst houses repeatedly mark vendors down for. Forrester criticised CHEQ for numeric reason codes that are difficult to interpret and reCAPTCHA Enterprise for lack of detail and limited drill-down. Arkose customers asked for more self-service configuration. Kasada customers reported limited UI customisation.
Every Prosopo block comes with a reason you can read. Not a score, not a policy label. Strings your team can grep, like Solver service detected or Inconsistent hardware readings for device, with the underlying event drillable by request ID and exportable to whatever SIEM you already run.
That is a design choice rather than an analyst rating, and you should weigh it accordingly.
Related
Building an analyst-backed shortlist?
If you are reconciling the Forrester Wave against a WAAP Magic Quadrant and working out who belongs on your list, tell us what you are protecting.
Frequently Asked Questions
Is there a Gartner Magic Quadrant for bot management?
No. Gartner does not publish a Magic Quadrant dedicated to bot management. Bot mitigation is evaluated as a capability inside the Magic Quadrant for Cloud Web Application and API Protection, known as Cloud WAAP, and Gartner Peer Insights runs a separate Bot Management review category. If someone shows you a Gartner Magic Quadrant for bot management, check which document they are citing.
What is the Gartner Magic Quadrant for Cloud WAAP?
Cloud Web Application and API Protection is Gartner's category for cloud-delivered services that combine a web application firewall, DDoS mitigation, bot management and API protection in one offering. Cloudflare, Akamai, Imperva, F5, AWS, Fastly and Radware are the vendors typically evaluated. Bot mitigation is one criterion among several rather than the focus.
How does the Gartner WAAP view differ from the Forrester bot and agent trust Wave?
They evaluate different vendors because they are asking different questions. Gartner's WAAP quadrant is about consolidated platforms, so it favours CDN and WAF vendors who bundle bot mitigation. Forrester's Q2 2026 Bot and Agent Trust Management Wave evaluates specialists, so DataDome, HUMAN, Kasada, Arkose Labs, CHEQ and Netacea appear and Cloudflare and Akamai do not. Neither list is wrong. They are answers to different procurement questions.
Which analyst view should I use for a bot protection shortlist?
Use the Forrester Wave if the bot problem is the reason you are buying, because it evaluates the specialists on detection depth and agent trust. Use the Gartner Cloud WAAP quadrant if you are consolidating web security spend and bot mitigation is one requirement among several. Buyers who use only the WAAP view tend to end up with a bundled product that handles commodity automation and misses targeted attacks.
Is Prosopo in any Gartner or Forrester evaluation?
Not currently. The Forrester Q2 2026 Wave applies a standalone product revenue threshold for inclusion, and a Gartner Peer Insights presence is on our roadmap for the coming quarters. What we compete on today is the capability both analyst houses repeatedly mark vendors down for: a block reason a customer team can read and act on.




