I don’t know the details of this setup, but perhaps the reverse proxy could distribute traffic based on the Cookie header? Bots are unlikely to send a string “EEVblogForum=” in it, while I believe that all logged in users will. This way guest (and bot) traffic may go to a smaller subset of backend nodes, while everything else gets a relatively smooth ride.
Using string “PHPSESSID=” instead may work too, but I guess agentic LLMs nowadays will simulate that part pretty well. But if the offending guests are not sending it, it’s one more way to send them to tarpit without affecting normal users beyond the first request.