Invest1 publisher2 min readPublished
Cloudflare will block AI crawlers by default from Sept. 15 after bots overtook human traffic
Cloudflare CEO Matthew Prince says bots overtook humans on its network in May 2026, ahead of a Sept. 15 switch to blocking AI crawlers by default. AI companies would then need permission, or a per-crawl deal, to read ad-supported pages on the sites it covers.
The Investor · Invest desk

What happened
- Cloudflare CEO Matthew Prince says automated traffic passed human traffic on Cloudflare's network in May 2026, sooner than he had expected.
- From Sept. 15, 2026, Cloudflare will block AI training and agent crawlers by default on ad-supported pages for new domains and many existing sites, unless publishers opt out.
- Prince estimates non-human traffic could reach roughly 1,000 times human traffic by 2031 as AI agents take on more tasks.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision AI companies that want ad-supported pages under Cloudflare's default must now seek permission or payment terms, and publishers who want agents reading them must act to let them in.
- capability Cloudflare sits where the block-or-permit decision is made, so it gains a place to meter and charge for each crawl if a pay-per-crawl market forms.
- exposure Advertisers buying on click-through and session metrics are exposed, since those numbers assume a person at the browser and most traffic on Cloudflare's network is now automated.
For an ad-funded page, Google's crawl ratio says more about revenue than the headcount crossover does. At about six crawls per referred visitor, 600 hits from Google's crawler sent back roughly 100 readers. At 18:1 the same 600 hits send back about 33, a two-thirds fall in readers per crawl [3][1]. Crypto Briefing puts the current figure at "18:1 or worse" [3], so 33 is the generous case. None of those crawls earn ad revenue [9].
Prince's 2031 forecast [2] starts from something close to parity in May 2026 [1]. Getting from one to 1,000 in five years requires the bot-to-human ratio to grow about fourfold every year, since four to the fifth power is 1,024 [2]. The forecast comes from the chief executive of a company that routes and protects a substantial portion of the web's traffic [7]. The May crossover was measured on that network, and the account of it comes from Prince alone [1].
The mix inside AI crawling has changed too. Training crawlers, the ones scraping content to feed language models, account for 40 to 52% of AI crawler activity, according to the report, a change from an earlier wave dominated by search-adjacent indexing [4]. That leaves 48 to 60% doing something other than training [3]. Prince attributes his 1,000-fold forecast to AI agents running tasks far more often than any person browses [2], so the growth he expects sits mostly outside the training share.
The default can go three ways from here. AI companies accept it and pay for access, per crawl or by micropayment, the model Prince has pointed toward [6]. Publishers opt out in large numbers to keep AI agents reading their pages, and the block changes little [5]. Or AI companies work around it, licensing directly from the biggest publishers or crawling the part of the web Cloudflare does not carry [7]. The report does not include a per-crawl price.
I'd expect the block to hold on most small sites, because a default decides for anyone who does nothing. Those are the sites that, according to Crypto Briefing, could not identify and block crawlers on their own [10]. The counter-thesis is about where the money sits. The largest publishers, whose pages AI companies most want, could already block and negotiate for themselves (the report's point about small and mid-sized sites implies as much [10]), so the default adds the least leverage where payments would be largest. If per-crawl fees end up reaching mostly small sites, ad-funded publishers are still serving 18 crawls or more for every reader Google sends [3].
What to watch
- How many existing Cloudflare sites opt out of the block after Sept. 15, and which sites fall inside the 'significant share' the default covers.
- Whether any AI company signs per-crawl terms through Cloudflare, and the price per access if one is published.
- Whether Google's crawl-to-visitor ratio moves past 18:1 on sites under the new default.