Skip to content

Build1 publisher2 min readPublished

AI-agent requests on Cloudflare's network grew more than 1,700% in a year

Cloudflare says AI-agent requests on its network grew more than 1,700% in a year as non-human traffic passed half the total. It now wants sites to identify and price agents as customers, after advising last year that new domains block AI training crawlers.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying AI-agent requests on Cloudflare's network grew more than 1,700% in a year
Generated illustration

What happened

  • Cloudflare's average load rose from 63 million HTTP requests a second at the end of 2024 to 115 million now, with peaks above 150 million.
  • AI training's share of the crawler requests Cloudflare sees rose from 22% in spring 2025 to 52% by June 2026.
  • Agent traffic follows human routines, with a weekly rhythm and a dip over the summer holidays.
  • Under Web Bot Auth, operators including OpenAI, Google and AWS sign their agents' requests so a site can tell a real agent from an impersonator.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • cost Rising request counts stop tracking revenue, so a site sizing its origin for more automated load pays more for requests that bring back no referral or ad impression.
  • decision A block-all rule written for training crawlers now also turns away agents working for a person, so bot policy has to be set by what each bot does.
  • constraint Rules keyed to a crawler's purpose rest on what the operator declares about itself, the same basis Cloudflare used to count the 52% training share.

Cloudflare's average request rate rose by a factor of about 1.8 from the end of 2024 [1]. Daily agent requests rose by a factor of at least 18 over the past year, since an increase of more than 1,700% is 18 times the starting count [2]. The two windows differ, and the slower figure covers the longer period. Agent requests are growing roughly ten times as fast as the traffic around them, and the window mismatch makes that gap an understatement [3].

For an operator, the shape of that load matters as much as its size. A training crawler collects a site's pages to build a model [10]. An agent fetches pages on a person's behalf, often because that person asked a chatbot something [15]. It comes back each time someone asks about the same content [10]. Cloudflare's contrast is that agent traffic grows with how many questions people ask, not with how much a site publishes [10]. I think that puts agent load in the same capacity plan as human load, with its peaks set by demand inside someone else's product.

Cloudflare's own advice has moved with its data. "Our first instinct was to block all automated traffic," the company wrote [8]. The same post argues that a blanket refusal is not nuanced enough for the Internet economy now being built [7].

Each figure here is an aggregate from Cloudflare's network [1][2]. The claim that more than half of Internet traffic was not human this year is Cloudflare generalising from that vantage [3]. For it to describe a particular origin, that origin's visitor mix would have to resemble the traffic Cloudflare handles in aggregate. The 40% fall in human traffic is a ceiling. Cloudflare reports it as "as much as" 40%, in less than a year, for the most heavily crawled categories [4].

The piece of this I would adopt first is Web Bot Auth. "A bot's name is only worth something if you can trust it," Cloudflare wrote [16]. An impersonator can copy a name but not the operator's cryptographic signature on the request [12]. Moving bot identity from a claimed label to a verifiable signature is good engineering. The dashboards for reading all of this, AI Crawl Control, Business Insights and BotBase, are Cloudflare products [13]. The company counting the bots also sells the counter. The post does not include a per-site distribution of the traffic mix.

What to watch

  • A per-site or per-category breakdown from Cloudflare showing how far the half-non-human figure varies between origins.
  • Adoption of Web Bot Auth signing by agent operators beyond OpenAI, Google and AWS.
  • Whether the AI-training share of crawler requests keeps climbing past 52% after June 2026.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories