A new Cloudflare domain is offered two presets at onboarding based on whether the site earns money from ads. A site without ads gets Bot Preference Sync enabled and Allow for Search, Training, and Agent. A site with ads keeps Search allowed, sets Training to Disallow AI Training, and sets Agent to Block on pages with ads.
Key facts
- Cloudflare published the two onboarding presets on 2026-09-15. The post's HTML published time is 2026-09-15T13:00:00.000Z.
- On our own non-monetized zone (insidetheloop.dev, added on 2026-09-29), the botmanagement API on 2026-10-06 read aitraining, aisearch, and aiuser as disabled, fight_mode as false, and Browser Integrity Check as on.
- The Block AI Bots docs page, dateModified 2026-07-01, still states in the future tense that on 2026-09-15 Cloudflare will block Training and Agent on ad pages and leave Search allowed.
- The bots changelog entry dated 2026-07-01 repeats that wording, while its page header reads "Last updated Apr 15, 2026".
- Less than 1% of Cloudflare sites choose to block Search bots, while 17% choose some mechanism to block training.
- Browser Integrity Check is enabled by default. Legacy Block AI bots is marked deprecating on 2026-09-15.
- Existing zones that never configured the three controls migrate from legacy Block AI: unselected becomes Allow for all three; either Block value becomes Search Allow, Training Disallow AI Training, and Agent Block on ad pages.
Cloudflare's preset for a new domain
The 2026-09-15 announcement calls the table recommended settings for a new domain. Customers are offered one of two presets during onboarding:
Setting | No ad monetization | Monetized with ads |
|---|---|---|
Preference Sync | Enabled | Enabled |
Search | Allow | Allow |
Training | Allow | Disallow AI Training |
Agent | Allow | Block on pages with ads |
The ad-monetized preset is stricter because ad revenue depends on human impressions. An agent visiting the page fetches the content without displaying the advertisement to a person.
Cloudflare's Search, Agent, and Training controls
Cloudflare separates AI traffic into three distinct behaviors:
Search indexes content for subsequent queries. Agent acts in real time on a person's behalf, including chat fetch bots like ChatGPT-User and automated browsers driven by Gemini or Claude. Training crawls content to train or fine-tune models. Mixed-purpose crawlers that combine Search and Training are classified under Training.
The 2026-07-01 dashboard controls under Security Settings, then Configure AI bot policies, provide three mitigations: Block on all pages, Block on pages with ads, and Allow. Allow adds no blocking. A block applies to Verified bots with that behavior and unverified bots in the same class.
Disallow AI Training, introduced on 2026-09-15, applies only to Training. It writes a no-training directive to robots.txt via Bot Preference Sync. Accountable mixed-use crawlers remain allowed for search, while training-only crawlers from Amazon, Anthropic, Meta, and OpenAI are blocked. Setting Block or Block on pages with ads now blocks mixed-use crawlers including Applebot, Bingbot, and Googlebot. Agent has no Disallow option because there is no established Disallow directive for agents.
The legacy Block AI bots toggle blocked verified training crawlers and similar unverified bots, while excluding mixed-purpose crawlers. Cloudflare deprecated this toggle and managed robots.txt on 2026-09-15 in favor of the granular behavior controls and Bot Preference Sync.
Bot Preference Sync (introduced 2026-08-21) prepends rules to robots.txt bounded by # BEGIN Cloudflare Bot Preference Sync and # END Cloudflare Bot Preference Sync, adding Disallow: / for training user agents tracked in BotBase.
Cloudflare bot_management fields for AI bots
Zone bot configuration is managed via GET and PUT requests to /zones/{zone_id}/bot_management:
ai_search:disabled,block, oronly_on_ad_pages(robots.txt policy for AI search bots).ai_training:disabled,disallow,block, oronly_on_ad_pages(robots.txt policy for AI training bots).ai_user:disabled,block, oronly_on_ad_pages(robots.txt policy for AI assistant and agent bots).ai_bots_protection:disabled,block, oronly_on_ad_pages(rule blocking AI scrapers and crawlers).ai_bots_migration_opt_out: boolean tracking zones opted out of AI bots managed-rule updates.bot_preference_sync_enabled: boolean enabling robots.txt generation from behavior preferences.fight_mode: boolean enabling Bot Fight Mode.
In the API schema, disabled represents the non-blocked (Allow) state. Setting ai_user to disabled allows user agents in the Agent classification. Setting ai_training to disallow enables robots.txt opt-out while preserving search indexing for accountable crawlers. On our own zone (insidetheloop.dev, added 2026-09-29), ai_training, ai_search, and ai_user were all returned as disabled.
Bot Fight Mode and Browser Integrity Check
Two additional security tools operate independently of AI bot policies:
Bot Fight Mode challenges known bot patterns across the entire domain. It runs outside the Ruleset Engine, so WAF custom rules and Page Rules cannot skip or bypass it. Enabling Bot Fight Mode automatically turns on JavaScript Detections, which cannot be disabled. On our own zone (insidetheloop.dev, added 2026-09-29), the API reported fight_mode: false, confirming it starts disabled on a new zone.
Browser Integrity Check (BIC) looks for HTTP headers commonly abused by spammers and denies access. It also challenges requests with missing or non-standard user agents. BIC is enabled by default across all zones, documented under WAF tools, and confirmed active (value: "on") on insidetheloop.dev. You can disable BIC globally under Security Settings, DDoS attacks, Browser integrity check, or selectively bypass it using a WAF custom rule with a skip action.
Setting Agent to Allow does not turn off Bot Fight Mode or Browser Integrity Check. If an agent uses a non-standard user agent or lacks common browser headers, BIC can challenge the request even if AI bot policies allow agents.
How to check that Cloudflare is not blocking agents
To confirm a domain allows AI agents, query the zone configuration with curl:
curl "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/bot_management" \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"Check the following fields in the response:
ai_usermust be"disabled". If set to"block"or"only_on_ad_pages", Cloudflare will block user-directed AI agents.ai_bots_protectionmust be"disabled". A value of"block"activates the legacy scraper-blocking rule.fight_modeshould befalse. When true, headless agent traffic may trigger CPU-intensive challenges.
Next, verify Browser Integrity Check:
curl "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/settings/browser_check" \
-H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"If Browser Integrity Check is "on", ensure AI agent requests send standard HTTP headers and a recognized user agent, or configure a WAF custom rule to skip BIC for agent endpoints.
Sources
- Have it both ways: stay discoverable in search while disallowing AI training: https://blog.cloudflare.com/accountable-mixed-use-ai-crawlers/ (read 2026-10-06)
- Your site, your rules: new AI traffic options for all customers: https://blog.cloudflare.com/content-independence-day-ai-options/ (read 2026-10-06)
- Say it once: introducing Bot Preference Sync: https://blog.cloudflare.com/bot-preference-sync/ (read 2026-10-06)
- Block AI Bots: https://developers.cloudflare.com/bots/additional-configurations/block-ai-bots/ (read 2026-10-06)
- Changelog, Cloudflare bot solutions: https://developers.cloudflare.com/bots/changelog/ (read 2026-10-06)
- Update Zone Bot Management Config: https://developers.cloudflare.com/api/resources/bot_management/methods/update/ (read 2026-10-06)
- Get Zone Bot Management Config: https://developers.cloudflare.com/api/resources/bot_management/methods/get/ (read 2026-10-06)
- Bot Fight Mode: https://developers.cloudflare.com/bots/get-started/bot-fight-mode/ (read 2026-10-06)
- Free plan, bot solutions: https://developers.cloudflare.com/bots/plans/free/ (read 2026-10-06)
- Browser Integrity Check: https://developers.cloudflare.com/waf/tools/browser-integrity-check/ (read 2026-10-06)
Last verified: 2026-10-06.