Cloudflare says the web has a second audience it never counted
For the first time, more than half the traffic crossing Cloudflare's network is not a person, and AI agent requests are up more than 1,700% in a year.

More than half of the traffic crossing Cloudflare's network no longer comes from people. The company put the figure in writing this week as part of its annual Birthday Week announcements, describing the shift as the arrival of a second audience rather than the disappearance of the first.
The numbers behind the claim
Cloudflare says it averaged about 63 million HTTP requests a second at the end of 2024. That figure has nearly doubled to roughly 115 million, with peaks above 150 million. Over the past year, daily requests from AI agents on the network grew by more than 1,700%.
The damage is not evenly spread. Cloudflare names retail, computer software, IT and services, and financial services among the most heavily crawled categories, and says human traffic to them has fallen by as much as 40% in less than a year. Automated requests still consume bandwidth, compute and origin capacity, but an increasing share of them carry no referral, no ad impression and no subscription.
Crawlers turned into agents
The composition of the traffic has shifted as well. In spring 2025, 22% of the crawler requests Cloudflare saw were for AI training, judged by the crawlers' own stated purpose. By June 2026 that share had reached 52%. Agents behave differently from training crawlers: a training bot takes a copy of a page to build a model, while an agent comes back each time somebody asks a question, so its traffic grows with demand rather than with publishing volume.
Telling site owners what they are serving
Cloudflare's response has moved away from a blanket block. It split its single “block AI bots” switch into separate search, agent and training controls in July, and on 15 September shipped Disallow AI Training, a crawler-level instruction that keeps a site indexed for search while telling an operator not to use its data for training. Apple, Google and Microsoft have said they will honour it.
Identity is the other half of the problem. Web Bot Auth lets operators including OpenAI, Google and AWS cryptographically sign their agents' requests, so a site can distinguish a real agent from an impersonator without guessing from an IP address or a user-agent string. Cloudflare says it sees more than 500 billion verified bot requests a week.
Cheaper pages and a price tag
Two further pieces are aimed at cost rather than access. Markdown for Agents serves a page without the styling built for human eyes, and WebMCP lets a site expose actions directly instead of leaving an agent to guess which button to press. Cloudflare is also building payment rails for agent traffic, which it says reaches sites that a bespoke licensing deal never will.
Our opinion
The 40% decline in human traffic to software and retail sites is the number that should worry publishers, because it describes exactly the audience that used to click an advert. Cloudflare is right that blocking everything is the wrong answer: an agent comparing insurance quotes is a customer, and the person who sent it is still a reader. The harder question is whether signed crawlers and metered payments become open standards or a toll road that only large sites can afford to leave. Cloudflare's answer is that the rails run on x402 and Web Bot Auth so anyone can implement them, which is a promise worth holding the company to. The web spent thirty years teaching machines where to find things; it now has to teach them how to pay.