Cloudflare Blocks AI Crawlers by Default on September 15. What Site Owners Must Do
On September 15, 2026, Cloudflare changes how it treats AI crawlers for every site. Here is what could quietly cut your AI visibility, and the settings to check before then.
On September 15, 2026, Cloudflare changes how it treats AI crawlers by default, and if your site is behind Cloudflare you could lose visibility in AI search without changing a thing. From that date, Cloudflare blocks AI training and agent crawlers on ad-supported pages by default, sorting AI bots into three buckets, search, agent, and training, and any mixed-use crawler that will not declare which job it is doing on a page with ads gets blocked entirely (Cloudflare1). For the millions of sites on Cloudflare’s free tier, and for every new sign-up after that date, the blocking is on by default, so this is not only something that happens if you opt in; it is something that happens unless you check (Help Net Security2). I build edge and protection tooling at RankShield, and the reason this deserves a calm read rather than a panic is that the controls are genuinely useful, but they interact in a way that can cut your AI visibility as a side effect. What this guide does is explain exactly what changes, who is affected, the difference between the three crawler types so you can decide deliberately, and the settings to check before September 15. One honest note first: whether to allow or block AI training on your content is your decision, not ours, and this guide is about making it an informed one, not about talking you into either choice.
What actually changes on September 15?
Cloudflare stops treating AI crawlers as one undifferentiated group and starts sorting them into three jobs, then applies a new default that blocks two of the three on pages that carry advertising. From September 15, 2026, an ad-supported page permits search crawlers but automatically blocks training and agent crawlers, and any crawler that serves more than one purpose and will not declare which job it is doing on a given request gets blocked entirely on those pages (Cloudflare1). The single old "block all AI" toggle is replaced by this purpose-based model.
The part that catches people is who this is on for automatically. For the millions of sites on Cloudflare’s free tier, and for every new sign-up after September 15, the blocking is the default, so you get it whether or not you asked for it, and allowing AI training access becomes a manual opt-in (Help Net Security2). Existing paying customers keep the ability to override the defaults from their dashboard and readmit specific crawlers, but they still have to go and do it.
This is a policy applied at Cloudflare’s edge, which is why it can change your site’s behavior without any change on your side. It will not appear in your CMS, it raises no error, and nothing on your origin server is different. The crawler simply gets a different answer at the edge than it did the day before. That is what makes a dated edge default worth a calendar reminder: the change is real, it is automatic for a huge number of sites, and it is invisible unless you go looking.
Could you lose AI visibility without changing anything?
Yes, and that is the single most important thing to understand about this change. If your site is on Cloudflare’s free tier or you sign up after September 15, the new blocking defaults apply automatically, so AI training and agent crawlers start getting blocked on your ad-supported pages without you touching a setting. For some owners that is exactly what they want; for others it is an unintended loss of reach they never chose, and the only way to know which camp you are in is to check.
There is a subtler trap that can cost you search and AI-answer visibility even if you meant only to block training. Because some crawlers serve more than one purpose, blocking the training function can also block multi-purpose crawlers such as Googlebot, Bingbot, and Applebot, even when you intended to keep search crawlers allowed (Search Engine Journal3). Since Bing’s index is a major input to ChatGPT’s search, and Google’s crawl feeds AI Overviews, a training block that cascades to those crawlers can quietly remove you from the AI answers you were trying to appear in.
So the honest risk is not dramatic, but it is real and easy to miss: a default you did not set, or a training block that reaches further than you expected, can reduce your presence in AI search with no visible symptom. Nothing breaks, no page errors, your analytics look normal, and yet the crawlers that put you in front of AI users are getting turned away at the edge. That is precisely the kind of silent change that is worth ten minutes before the deadline to confirm you are on the right side of.
What is the difference between search, agent, and training crawlers?
They are three different jobs an AI crawler can do, and blocking each one costs you something different, which is why treating them as one decision is the mistake this change is designed to fix. A search crawler indexes your pages so you can appear in search results and in AI answers built on that index; an agent crawler fetches your page live when a user asks an AI assistant about you; and a training crawler collects content to train a model. Same category, "AI bots," but three very different consequences.
The one you almost always want to keep allowed is search. If you block search crawlers, you remove yourself from the indexes that feed AI answers, so you can disappear from ChatGPT’s search, Google’s AI Overviews, and Perplexity even though your site is up and fine. This is the opposite of what most businesses want, and it is the reason the September 15 default keeps search allowed while blocking the other two. Agent access is a judgment call: allowing it lets AI assistants pull your page for a user in the moment, which is increasingly how people reach sites.
Training is the genuinely optional one, and here the honest position is that it is your call. Blocking AI training crawlers so models do not learn from your content, or so you can charge for that access, is a legitimate business decision that many publishers are making deliberately, and it has no direct effect on whether you appear in search. The catch, covered above, is that some crawlers do more than one job, so a training block can unintentionally catch a multi-purpose search crawler. Knowing the three are separate is what lets you block what you mean to and keep what you need.
What should you actually do before September 15?
Spend ten minutes deciding deliberately instead of letting a default decide for you. First, confirm whether your site is behind Cloudflare and on which plan, because free-tier and new sites get the blocking on automatically while existing paid plans keep the current behavior until you change it. Second, in your Cloudflare dashboard, find the AI crawler or bot controls and look at the search, agent, and training settings as three separate switches, not one. Third, make an explicit choice on each, and write down why, so it is a decision you can defend rather than a default you inherited.
For most businesses that want to be found, the safe configuration is to keep search allowed, decide on agent based on whether you want AI assistants fetching your pages live, and treat training as a genuine choice about whether you want models learning from your content. If you do block training, verify afterward that you have not also blocked a multi-purpose search crawler, because that cascade is the most common way this change quietly costs visibility. Check your server logs or robots handling after the deadline to confirm the search crawlers you care about are still getting through.
The one thing not to do is nothing, at least not without confirming that the default is what you want. As we covered in how attackers find your new website, the edge is a powerful layer precisely because it acts before anything reaches your origin, and that power cuts both ways: a good default can protect you, and an unexamined one can quietly work against you. Ten minutes before September 15 turns this from something that happens to you into something you decided.
How do you control this without becoming your own edge engineer?
You either learn the controls and manage them yourself, which this guide is meant to make possible, or you let a managed edge handle deliberate crawler decisions for you so a platform default is never quietly making the choice. For a technical owner who is comfortable in the Cloudflare dashboard, the do-it-yourself path is entirely reasonable: review the three switches, decide each, and check your logs after the deadline. Nothing here requires a vendor.
What a managed edge adds is that keeping these decisions deliberate becomes someone’s job rather than an afterthought, which matters because this will not be the last edge default that changes. Platform policies shift, new crawler types appear, and each change is another silent opportunity to lose visibility you did not mean to give up. Having your edge managed means a change like September 15 is reviewed and decided on purpose instead of landing as a surprise, and it is the same posture we described in running your site from a managed edge.
To be clear and honest about the boundary: no managed service exempts you from a platform’s policies, and the underlying controls here are Cloudflare’s. What a service like RankShield’s managed edge does is make sure the crawler-access decision is made deliberately and kept aligned with your goals, rather than left to a default you never saw. Whether you do that yourself or have it managed, the deadline is the same: decide before September 15 rather than after, because after the deadline a default has already decided for you.
What is the one thing to do before September 15?
Check your Cloudflare AI crawler settings and decide on purpose, because after September 15 a default decides for you. From that date, Cloudflare blocks AI training and agent crawlers on ad-supported pages by default, blocks any mixed-use crawler that will not declare its job, and turns the blocking on automatically for free-tier sites and every new sign-up. The change happens at the edge, so it is invisible: no error, no CMS change, just crawlers getting a different answer than they did the day before. For a huge number of sites, that means AI-crawler access could change without anyone choosing it.
The decision is genuinely yours, and this guide is about making it informed rather than pushing you either way. Keep search crawlers allowed if you want to stay in ChatGPT search, AI Overviews, and Perplexity; decide agent access on whether you want AI assistants fetching your pages live; and treat training as a real choice about your content, while watching that a training block does not cascade to a multi-purpose search crawler. Do it yourself in the dashboard, or have your edge managed so defaults never decide for you, but do it before the deadline. If you would rather not track edge changes like this yourself, see how RankShield manages your edge.
Questions, answered.
What is changing with Cloudflare and AI crawlers on September 15, 2026?
From September 15, 2026, Cloudflare stops treating AI crawlers as one group and sorts them into three jobs, search, agent, and training, then applies a new default on ad-supported pages that allows search crawlers but blocks training and agent crawlers. Any crawler that serves more than one purpose and will not declare which job it is doing on a given request is blocked entirely on those pages. Crucially, for the millions of sites on Cloudflare’s free tier and for every new sign-up after that date, this blocking is on by default, so allowing AI training access becomes a manual opt-in rather than something you have to actively turn off. Existing paying customers keep the ability to override the defaults from their dashboard. Because this is a policy applied at Cloudflare’s edge, it can change your site’s crawler behavior without any change on your side: it will not appear in your CMS, it raises no error, and your origin server is unchanged. The crawler simply gets a different answer at the edge, which is why it is worth checking your settings before the deadline.
Will this change hurt my AI search visibility?
It can, in two ways, which is why it is worth ten minutes to check. First, if your site is on Cloudflare’s free tier or you sign up after September 15, the new blocking defaults apply automatically, so AI agent and training crawlers start getting blocked on your ad-supported pages without you choosing it. Second, and more subtly, blocking the training function can also block multi-purpose crawlers such as Googlebot, Bingbot, and Applebot even when you meant to keep search crawlers allowed, because those crawlers do more than one job. Since Bing’s index is a major input to ChatGPT’s search and Google’s crawl feeds AI Overviews, a training block that cascades to those crawlers can quietly remove you from AI answers. The important thing is that none of this produces a visible symptom: no error, normal analytics, your site up and fine, while the crawlers that put you in front of AI users are turned away at the edge. To avoid an unintended loss, keep search crawlers allowed, and if you block training, verify afterward that you did not also block a search crawler.
What is the difference between search, agent, and training AI crawlers?
They are three different jobs an AI crawler can do, and blocking each costs something different. A search crawler indexes your pages so you appear in search results and in AI answers built on that index, so blocking it can remove you from ChatGPT search, Google AI Overviews, and Perplexity even though your site is up. An agent crawler fetches your page live when a user asks an AI assistant about you, so allowing it lets assistants pull your content in the moment, which is increasingly how people reach sites. A training crawler collects content to train a model, and blocking it, to keep models from learning from your content or to charge for that access, is a legitimate business choice that has no direct effect on whether you appear in search. The reason the distinction matters is that the September 15 default keeps search allowed while blocking agent and training, and that treating them as one decision is the mistake the change is designed to fix. Knowing they are separate lets you block what you intend, usually training, and keep what you need, usually search.
Does this apply to free Cloudflare accounts?
Yes, and free accounts are actually the most affected, which is the opposite of what many owners assume. For the millions of sites on Cloudflare’s free tier, and for every new sign-up after September 15, 2026, the new blocking defaults are on automatically, so AI training and agent crawlers begin getting blocked on ad-supported pages without the owner changing anything, and allowing AI training access becomes a manual opt-in. Existing paying customers are treated differently: they retain the ability to override the defaults through their Cloudflare dashboard and readmit specific crawlers if they choose, but they still have to go and make that change. The practical implication is that if you run a small business site on Cloudflare’s free plan and you have never thought about AI crawler settings, this change will apply to you by default, and the only way to know whether the resulting configuration matches what you actually want is to log in and look. Free-tier does not mean unaffected here; it means affected by default.
Should I block AI training crawlers on my site?
That is a genuine business decision that only you can make, and both choices are defensible. Blocking AI training crawlers means models do not learn from your content, and it opens the door to charging for that access, which is why many publishers are choosing to block deliberately; it also has no direct effect on whether you appear in search results or AI answers, because search and training are separate functions. Allowing training means your content can be used to train models, which some owners are fine with and others are not, on principle or on business grounds. There is no universally correct answer, and anyone who tells you there is one is substituting their preference for your judgment. What matters is that the decision is deliberate and informed: understand that training is separate from search, that blocking training does not remove you from AI answers by itself, and that the one real technical risk is a training block cascading to a multi-purpose crawler that also does search. Decide training on the merits for your business, keep search allowed if you want AI visibility, and verify the result rather than trusting the default.
How do I keep my site visible in AI answers after September 15?
Keep the search crawlers allowed, and confirm it rather than assuming it. The crawlers that put you in AI answers are the search-indexing ones, which feed ChatGPT search, Google’s AI Overviews, and Perplexity, so the single most important setting is to ensure those remain allowed after the September 15 change. Concretely: confirm whether your site is behind Cloudflare and on which plan, open the AI crawler or bot controls in your dashboard, and look at search, agent, and training as three separate switches. Keep search allowed, decide agent based on whether you want AI assistants fetching your pages live for users, and choose training on the merits for your content. If you do block training, verify afterward that you did not also block a multi-purpose search crawler like Googlebot or Bingbot, because that cascade is the most common way sites lose visibility unintentionally. After the deadline, check your server logs or robots handling to confirm the search crawlers you care about are still getting through. If tracking edge changes like this is not something you want to own, a managed edge can keep the decision deliberate and aligned with your goals, but the underlying controls remain Cloudflare’s either way.
References
- Cloudflare. Your site, your rules: new AI traffic options for all customers (from September 15, 2026 Cloudflare blocks AI training and agent crawlers on ad-supported pages by default; three crawler categories search/agent/training; mixed-use undeclared crawlers blocked entirely; free-tier and new sign-ups default to blocking).
- Help Net Security. Cloudflare changes AI crawler access rules (free-tier and new sign-ups get blocking on by default; existing paying customers can override via dashboard).
- Search Engine Journal. Cloudflare’s AI crawler rules can block Googlebot (blocking training can also block multi-purpose crawlers such as Googlebot, Bingbot, and Applebot even when search is allowed).
Jamie Kloncz
Founder & CEO, RankShield
Jamie Kloncz is the founder and CEO of RankShield, the verifiable AI and quantum security platform. He started the company after two attacks landed in a single week: his phone was cloned, and his business was hit by a click-fraud campaign. One targeted him as a person, the other his livelihood, and no single tool defended both. That experience, together with surviving an AI voice-clone scam, shaped RankShield’s core belief: the threats of the AI age are personal first, and trust should be something you can check, not just extend.
Make every AI action provable.
RankShield is the verifiable, quantum-safe AI security platform — protection you can check, not just trust.