Cloudflare’s New AI Crawler Rules: What They Mean for Your Visibility

Google AI

Cloudflare just split AI access into three switches. Flip the wrong one, and you vanish from search.

Jordan Parkes
Cloudflare New AI Crawler Rules

Key Takeaways:

  • Crawl access is now three decisions: Cloudflare splits AI traffic into Search, Agent, and Training, each managed individually.

  • Blocking Training can block Googlebot: under the new “strictest-rule” logic, multi-purpose bots default to the most restrictive setting.

  • The exposure is narrow but real: it centers on legacy “Block AI Bots” adopters and unconfigured free-tier sites.

  • Agent access is a conversational-visibility lever: blocking it means opting out of ChatGPT’s and Perplexity’s live answers, independent of Google.

Executive Summary: Cloudflare reworked how it classifies and gates AI crawlers, fracturing the permission decision between Search, Agent, and Training (bots). Starting September 15, blocking Training can silently block Googlebot, turning a defensive content-protection setting into a search-visibility liability. Crawler access is no longer an IT footnote, but a commercial control that determines whether a brand is even eligible for AI citation.

On July 1, 2026, Cloudflare retired its one-click “block AI bots” toggle, replacing it with behavior-based controls.

Then, it set new defaults that can quietly block crawlers.

If your brand operates on Cloudflare, this is the moment to revise your security settings – and to do so deliberately.

What exactly did Cloudflare change with the July 1, 2026 update?

Cloudflare now sorts AI crawlers into three behaviors: Search, Agent, and Training.

  • Search: Crawlers that index content to answer questions later.
  • Agent: Bots that act in real time on the user’s behalf.
  • Training: Crawlers that pull content to build or fine-tune a model.

The new controls let websites independently manage automated traffic for each behavior, and they are live for all customers, including the free tier.

Why this matters 

Starting September 15, 2026, Cloudflare is introducing a new set of default settings:

  • Default posture change: New customers and new sites of existing customers will have Training and Agent bots blocked by defaulton pages that display ads; Search bots stay allowed.
    • Existing free-tier customers who haven’t changed their settings by September 15 will be automatically migrated to these defaults on the same date.
  • “Strictest-rule” change: Cloudflare will start treating multi-purpose crawlers based on their overall behavior, applying the most restrictive applicable rule.
    • If Training is blocked, Googlebot, Applebot, and Bingbot get blocked too, even if Search is allowed.

Why do new rules threaten Google visibility?

The reason is structural: Google uses a single, mixed-use bot for both search indexing and AI training, so it automatically falls under the “strictest-rule” umbrella – and since they refuse to split its crawler, blocking Training at the edge means blocking Googlebot outright

Even if you disallow Google-Extended in your robots.txt, it makes no practical difference. A Cloudflare block operates at the network level, making it far harder to bypass than a simple robots.txt line, which is an advisory instruction that Google can ignore.

Put bluntly, when it comes to Googlebot, there’s currently no clean way to allow search while opting out of training.

Cloudflare Blocks Googlebot
Robots.txt is a request. Cloudflare’s edge block is a brick wall. [Image credit: ZeroClick Labs via ChatGPT]

Who is actually affected by Cloudflare’s new defaults?

Because Googlebot only drops when a Training block is in effect, the real exposure narrows down to two groups: sites that flipped the legacy “Block AI Bots” toggle back in 2025 and free-tier accounts that never configured their crawler settings.

The first group is most at risk, purely because the legacy block is now folded under the “strictest-rule” regime. The second group is partially protected, since new defaults only block crawlers on pages that display ads, meaning that an ad-free site with no existing block gets to keep Google on the guest list.

So, for most brands, the honest takeaway is reassuring: you’re probably fine – but check anyway.

Subscribe for practical updates on AI discovery, answer engine visibility, and the shifts that matter most for brands trying to stay visible.

What do new Cloudflare rules mean for your website?

Come September 15, “politely declining” the use of your content for AI training may actually escalate into firewalling Googlebot – and that means your site won’t be crawled as effectively, which could eventually impact your visibility in search results. Fortunately, the fix for this one is a simple five-minute Security settings review: open Cloudflare dashbox and confirm, explicitly, that Search is allowed even where Training is blocked

What do the new rules mean for SEO & GEO?

From the optimization perspective, Cloudflare effectively branched crawl access into three separate decisions, each of which maps cleanly onto visibility outcomes:

  • Search protects your eligibility for AI Overviews, AI Mode, and Bing-fed answers. Keep it on, nearly without exception.
  • Agent is your live-retrieval path into Perplexity’s and ChatGPT’s conversational answers. Block it, and you may disappear from both.
  • Training is the lowest-visibility-cost lever in general – but only for cleanly split crawlers. On Google, it’s all-or-nothing.

At its core, this is an eligibility problem before it’s a tactics problem. Put simply, no amount of structure or schema earns a citation if the network layer bounces the crawler away at the door. Therefore, verifying edge-level crawler reachability must become a part of your technical audit checklist – right alongside the crawl-access and indexability checks.

What’s more, there’s a flip side to that coin: Cloudflare is now laying the groundwork to charge AI crawlers rather than simply bar them – and if it takes, crawl access may become a veritable revenue decision.

Allow keep on Your call depends on goals Block OK low visibility cost
Business type SearchIndexes for AI answers AgentLive fetch per user TrainingFeeds model training
B2B SaaS / services AllowCitation eligibility AllowChatGPT / Perplexity reach Your callLow visibility cost
Ad-supported publisher AllowKeep discoverability Your callDefault blocks on ad pages Block OKYour IP leverage
E-commerce / retail AllowProduct visibility AllowAgentic shopping Your callLow stakes
Local / home services AllowLocal AI Overviews AllowAssistant reach Your callMinimal concern

The Google trap: blocking Training also blocks Googlebot. Google uses one bot for search and AI training, so there is no way to keep Google search visibility while blocking Google training at the network level.

Before September 15, 2026: confirm Search is allowed, and check for a legacy “Block AI Bots” toggle — it now maps to a Training block that drops Googlebot.

Your buyers are asking AI assistants for recommendations right now

Your misconfigured settings are turning those assistants away…

…and your buyers with them.

ZeroClick Labs offers a solution to that problem – and more.

We work the full GEO/SEO stack – from crawl-layer access to citation-first content clusters, across every frontier platform, including ChatGPT, AIOs, and Perplexity.

Connect with us today, and let’s make it easy for AI engines to reach you – and far more likely to choose you!

“Our agency had no idea how to approach AI visibility. ZeroClick only does this one thing so they actually know what works. Worth every penny just to not waste time figuring it out ourselves.” – Jay

Discover how ZeroClick Labs can strengthen your AI search presence.

Get More AI Insights