All resources

Act

August 10, 2026 · 7 min read

By Marcus Bransbury · Founder, Robot Visible

Cloudflare AI crawler defaults explained

From 15 September 2026 Cloudflare blocks training and agent crawlers by default on ad-serving pages. What changes, who it affects, and how to check yours.

Quick answers

Is Cloudflare blocking AI crawlers by default?

Partly, and not the way most coverage implies. From 15 September 2026 Cloudflare's default configuration blocks training and agent crawlers on pages that display ads, while search crawlers remain allowed. The defaults apply to new customers, new sites added by existing customers, and existing free-plan customers who have not changed their settings by that date. Any site owner can change any of the three categories at any time.

Does Cloudflare's 15 September change affect my website?

Only if your site is behind Cloudflare and displays ads. The training and agent blocks are scoped to ad-serving pages, so a site without ads sees no change to what reaches its content. The group affected without taking any action is existing free-plan customers who display ads and have never configured their AI bot settings. Sites on paid plans with an existing configuration keep it.

What is a mixed-use AI crawler?

A crawler that performs more than one job under a single user agent, typically indexing for search while also collecting content for model training, without letting the site owner accept one and decline the other. Cloudflare evaluates these against all of their behaviours rather than the most permissive one, and from 15 September 2026 blocks mixed crawlers that offer no such choice on all pages that display ads.

Will the Cloudflare change stop ChatGPT citing my site?

Not by itself. Search crawling stays allowed under the new defaults, and the training and agent blocks apply only to pages that display ads. If your pages carry ads and you leave the agent category blocked, an assistant fetching your page live during an answer can be refused, which is the part worth checking. A page that was not being cited before the change will not start or stop being cited because of it.

How do I opt out of Cloudflare's new AI crawler defaults?

In your Cloudflare dashboard, open Security Settings and use "Configure AI bot policies". Search, training and agent can each be set independently to block on all pages, block on pages with ads, or allow. Cloudflare has said all customers can opt out of the new defaults at any time before 15 September 2026, and the settings stay editable afterwards. The legacy "Block AI bots" toggle is deprecated on that date.

What is Cloudflare Pay Per Use?

It is the successor Cloudflare announced for Pay Per Crawl, paying publishers when their content is actually used rather than each time it is fetched. Two partners are named: Ceramic.ai, where opted-in publishers can be paid when their content appears in search results, and You.com, where an agent pays on demand for specific premium content. Cloudflare describes it as experimental and has published no general availability date.

What changes on 15 September 2026

On 1 July 2026 Cloudflare announced a new way of classifying automated traffic, and a set of defaults that take effect on 15 September 2026. Instead of treating every non-human request as one category, Cloudflare now separates three behaviours: crawling for search, crawling for model training, and fetching on behalf of a user in real time.

From that date, the default configuration allows search and blocks training and agent traffic on pages that display ads. Search crawlers are not blocked by the new defaults. Site owners can change any of it, in either direction, at any time.

The legacy "Block AI bots" toggle is being deprecated on the same date. If your site uses it, your configuration moves onto the new three-category model, and mixed-purpose crawlers that combine search with training are blocked by it.

Who the new defaults apply to

This is the part most coverage gets wrong in one direction or the other. Cloudflare's press release names three groups, and the distinction matters because only one of them is affected without doing anything.

Which Cloudflare customers receive the new AI crawler defaults on 15 September 2026
Who you areWhat happens on 15 September
A new Cloudflare customerYou onboard onto the new defaults
An existing customer adding a new siteThe new site onboards onto the new defaults
An existing free-plan customer who has not changed their settingsThe new defaults apply to your existing site
An existing customer who has configured their AI bot settingsYour configuration is kept; the legacy toggle moves onto the new model

Search, training and agent are three different crawls

This split is the genuinely useful part of the announcement, and it outlasts the deadline. These three behaviours have always been distinct, and treating them as one category is why so much crawler advice is confused. Blocking "AI bots" as a single class has, for years, also blocked the retrieval that puts a page into an answer.1,2

Cloudflare's three AI traffic categories and the new default for each
CategoryWhat the crawler is doingNew default
SearchIndexing content so it can be retrieved and cited when someone asks a questionAllowed
TrainingCollecting content to train or fine-tune a modelBlocked on pages that display ads
AgentFetching a page in real time on behalf of a user, such as an assistant retrieving a source mid-answerBlocked on pages that display ads

Why mixed-use crawlers are treated separately

Some crawlers do more than one of those jobs under a single user agent, so a site owner cannot allow the search behaviour and decline the training behaviour. Cloudflare's term for these is mixed or multi-purpose crawlers, and it evaluates them against all of their behaviours rather than the most permissive one.

Where a crawler does not give the site owner that choice, it is blocked on all pages that display ads. The effect is a commercial one: a crawler that separates its behaviours keeps its search access, and one that bundles them does not. Whether that pressure works is not something anyone can claim yet.

Whether this actually affects you

Work through these in order. Most sites will stop at the first or second line, and that is the honest result rather than a disappointing one.

  • Not on Cloudflare? Nothing here applies. The change is a Cloudflare default, not an industry standard.
  • No ads on your pages? The training and agent blocks are scoped to pages that display ads, so the new defaults do not change what reaches your content.
  • On a paid plan with settings you have already configured? Your configuration is kept.
  • On a free plan, displaying ads, and never touched your AI bot settings? This is the case that changes on 15 September without any action from you.
  • Using the legacy "Block AI bots" toggle? It is deprecated on 15 September regardless of plan, and it now blocks mixed-purpose crawlers that combine search and training. If you turned it on to stop training, check whether it is also costing you retrieval.

How to check and change your setting

The controls live in your Cloudflare dashboard under Security Settings, in "Configure AI bot policies". Each of the three categories can be set independently, and Cloudflare offers the same three choices for each: block on all pages, block on pages with ads, or allow.

Do this before 15 September if you want a different outcome from the default. Cloudflare has said all customers can opt out of the new defaults at any time before that date, and settings remain editable afterwards.

  • Open Security Settings and read your current AI bot configuration before changing anything, so you know what you are changing from.
  • Decide the three categories separately. Allowing search while declining training is now expressible, and it was not under a single AI-bots toggle.
  • If you rely on assistants retrieving your pages live, look hard at the agent category before leaving it blocked.
  • Re-check that your important pages are still reachable after any change, rather than assuming the setting did what you intended.

Run a free scan to see what a crawler can currently read

Pay Per Use: paid when content is used, not when it is fetched

Alongside the defaults, Cloudflare said it is evolving Pay Per Crawl into Pay Per Use. Its stated reasoning is that crawling is a crude measure of value: a page might be crawled once and cited in thousands of answers, or crawled repeatedly and never used.

Two partners are named. With Ceramic.ai, publishers who opt in can be paid when their content appears in search results, and participating publishers get reporting on the queries their content appeared for, the page and snippet used, and average result position. With You.com, an agent can pay on demand for a specific piece of premium content.

Cloudflare describes this as experimental and has not published a general availability date, so treat it as a direction rather than a revenue line. The reporting is the part worth watching: query-level evidence of which page and snippet an answer used is the measurement most publishers currently lack.

What this does not change about AI visibility

A crawler policy decides whether a request is allowed. It does not decide whether your page is worth citing once it arrives. Sites that were not being cited before 15 September will not be cited afterwards because a default changed, and the reverse is also true.

The useful response to a dated platform change is to know your own position rather than react to a headline: what your current setting is, whether your key pages are reachable and readable, and whether anything is actually citing them today. If a change on 15 September moves your evidence, you can only tell that against a baseline recorded before it.

How to track AI visibility over time

Sources and further reading

  • Your site, your rules: new AI traffic options for all customers Cloudflare. Cloudflare's own announcement of 1 July 2026, the first-party source for the three-category model, the 15 September 2026 date, and the default allowing search while blocking training and agent traffic on pages that display ads.
  • Cloudflare Allows the Agentic Internet to Flourish with a Simple Philosophy: Your Content, Your Rules Cloudflare. First-party source for exactly which customers receive the new defaults, naming new customers, new sites for existing customers, and existing free customers who have not changed their settings by 15 September 2026, and for the treatment of mixed crawlers.
  • New options to manage AI traffic Cloudflare. Cloudflare's product changelog entry, supporting the statement that all customers can opt out of the new defaults at any time before 15 September 2026 through the dashboard.
  • Block AI bots Cloudflare. First-party documentation for the dashboard location under Security Settings, the per-category choices of block on all pages, block on pages with ads, or allow, and the deprecation of the legacy Block AI bots option.
  • Making AI search smarter Cloudflare. First-party source for Pay Per Use, its stated reasoning that crawling is a crude measure of value, the Ceramic.ai and You.com partnerships, and the reporting offered to participating publishers.

Continue learning

See where your website stands

Run a free scan and get your AI readiness score across all six categories, with the gaps to fix first.