Cloudflare Pay Per Use Turns AI Content Use Into a Billable Event
Cloudflare launched Cloudflare Pay Per Use in beta on September 30, creating a new payment path between AI companies and online publishers. Instead of charging whenever a bot crawls a page, the system records when an AI product actually uses that page. Cloudflare then bills the AI company and pays the publisher.
That distinction sounds small, but it changes the economic unit behind AI content licensing. Crawling measures access. Pay Per Use attempts to measure value after access, such as a citation in an answer or a review influencing an automated recommendation.
The conflict is equally important. AI companies want current, authoritative material without negotiating separate contracts with millions of websites. Publishers want compensation when an AI answer replaces the visit that once supported advertising, subscriptions, or customer acquisition.
Cloudflare is positioning itself between those interests as the identity provider, usage ledger, billing service, and payment processor. The Pay Per Use beta gives publishers another option besides blocking AI bots or accepting uncompensated use.
The model also introduces a difficult trust question. Buyers report their own usage, while publishers depend on those reports to calculate earnings. Cloudflare can validate whether a reported page belongs to an enrolled publisher, but that does not independently reveal every unreported use.
Cloudflare Pay Per Use therefore represents more than another crawler setting. It is an attempt to turn AI content licensing from private dealmaking into repeatable internet infrastructure.
Cloudflare Pay Per Use Changes What Publishers Sell
The beta moves the billable moment from fetching content to using it inside an AI product.
Under the program, an AI company creates an offer for publishers. The buyer identifies its crawler, defines what counts as a paid use, and specifies the compensation attached to that event. It also connects a payment account through Cloudflare.
A publisher can review the offer inside the Cloudflare dashboard. The offer identifies the buyer, the covered use, and the proposed terms. The publisher can accept the program, decline it, or stop participating later.
This is not a universal license covering every possible AI activity. Each program defines the permissions attached to its offer. Those terms can also restrict whether the content may be used for training.
Once a publisher accepts, the AI company can crawl permitted material as an identified, verified bot. Verified bots are automated clients whose operators and purposes Cloudflare has authenticated.
The content can then support several types of AI output. A search service might cite a passage in an answer. A research agent might quote reporting in a generated brief. A shopping assistant might use a review while deciding which product to recommend.
The buyer decides which of these events qualifies for payment. One offer might count a visible excerpt. Another might count a recommendation influenced by an article, even when the user never sees that article directly.
That flexibility recognizes that the same page can create different kinds of value. A citation shown to a reader is not identical to background evidence used by an automated agent. Publishers can accept separate offers for separate uses.
The buyer reports each qualifying event to Cloudflare through an application programming interface, or API. Each record contains the time, source URL, and an event identifier. Cloudflare checks that the URL belongs to a publisher enrolled in that buyer’s program.
Cloudflare aggregates the submitted records, bills the buyer, and pays participating publishers monthly. Publishers can see reported uses and estimated earnings by buyer, domain, and time period.
The arrangement reduces integration work for both parties. An AI company gets one reporting interface instead of building separate payment systems for every publisher. A publisher gets one dashboard instead of maintaining custom integrations with multiple AI services.
Cloudflare also says publishers do not need to alter their origin servers for every buyer. That matters for smaller organizations without the legal and engineering resources required for individual licensing deals.
The beta is limited, however. Cloudflare is working directly with participating buyers and publishers rather than offering automatic enrollment for the entire web. It has not presented the program as a finished marketplace.
That scope makes the current release a commercial test. Cloudflare needs to learn whether buyers receive content worth paying for and whether publishers receive meaningful, reliable compensation.
Why the Crawl-for-Traffic Bargain Stopped Working
AI answer engines can consume a publisher’s reporting while removing the visit that previously financed it.
Traditional web search operated through an imperfect but understandable exchange. Publishers allowed search engines to index pages. Search results then directed some users back to those pages, where publishers could earn revenue or build an audience.
AI search weakens that exchange. An answer engine can read several pages, combine their information, and respond without requiring the user to open any source. Citations can remain visible while the economically valuable visit disappears.
Cloudflare has been documenting this gap through its crawl-to-refer ratio, which compares automated page requests with referral visits. Its 2025 analysis found large differences among AI services.
In one observed period, Anthropic had nearly 50,000 crawler requests for each referral. OpenAI recorded 887 requests per referral, while Perplexity recorded 118. These ratios change over time, but the underlying imbalance remains important.
Cloudflare later reported that AI training represented 52 percent of classified crawler requests in June 2026. That was up from 22 percent in spring 2025, according to its bot traffic review.
Those figures come from Cloudflare’s own network and classification systems. They do not measure every website or prove that each crawl generated commercial value. They do show why publishers no longer treat bot access as a neutral technical issue.
The pressure is strongest for publishers producing current or specialized information. News, research, product reviews, and trade reporting lose value quickly. These categories are also useful to AI products that need answers beyond a model’s training cutoff.
A large media company can negotiate directly with an AI platform. Smaller publishers, independent researchers, and specialized sites usually cannot. The legal work alone can make an individual agreement impractical.
Major publishers have already chosen different responses. Some have signed bilateral licensing agreements. Others have filed copyright lawsuits, blocked crawlers, or adopted combinations of licensing and access controls.
The Associated Press, for example, licensed archive material to OpenAI and later arranged to provide current information for Google’s Gemini product. The financial terms of its Google agreement were not disclosed, according to the AP licensing report.
Those deals validate the idea that credible content has measurable value to AI companies. They do not create a path for the millions of sites lacking direct access to major technology companies.
Cloudflare first addressed that market gap through blocking and Pay Per Crawl. In July 2025, it began blocking AI training crawlers by default for new domains unless site owners chose otherwise.
Its Pay Per Crawl model allowed participating publishers to charge for access. A crawler could pay and receive the page, or face an HTTP 402 response indicating that payment was required.
That approach restored leverage at the website boundary. It also charged buyers before they knew whether a page would contribute to an answer, recommendation, or other product output.
AI systems typically retrieve more material than they ultimately use. A search process might inspect many pages before selecting one passage. Charging for every fetch can make research costly without connecting payment to the final result.
Cloudflare publisher payments now target that mismatch. Pay Per Use asks buyers to compensate publishers only after content contributes to a defined product experience.
The model pressures both sides. Publishers must decide whether an offer fairly values downstream use. AI companies must decide whether better access and fewer custom contracts justify reporting and payment obligations.
Paying for Outcomes Creates a Different Market
Paying for use aligns compensation more closely with value, but it lets each buyer define what value means.
This is the core reversal behind Cloudflare Pay Per Use. The publisher controls whether to accept an offer, yet the AI company initially defines the billable event and proposes its terms.
A buyer could pay whenever its answer includes an excerpt from an enrolled page. That event is visible and relatively easy to explain. A publisher can compare citations, reported events, and surrounding traffic.
A shopping agent creates a more complex example. It might read five reviews, extract several attributes, and recommend one product. The user could see the recommendation without seeing any quotation or source link.
The buyer might define a paid use whenever an enrolled review shapes that recommendation. However, influence inside a multi-source system is harder to observe than a visible citation.
Similar questions apply to research agents. A generated report might incorporate one source directly, use another to confirm a claim, and retrieve several pages that add nothing. Each role carries different potential value.
Cloudflare does not impose one definition across these cases. It supplies the enrollment, reporting, billing, and settlement infrastructure. Buyers design programs, while publishers decide whether those programs are acceptable.
This differs from a fixed royalty system. There is no universal rate for an article, citation, or recommendation. The market begins with individual offers covering specific uses.
That design can support experimentation. Current reporting might command different terms from old archive material. A visible quotation might be valued differently from silent influence on an agent’s decision.
Cloudflare says it wants publishers eventually to counter offers and price content by use. Those features are part of its direction, not evidence that the current beta has already produced a liquid marketplace.
The model also separates access from downstream permission. A publisher can retain crawler controls while joining selected programs. Accepting one offer does not necessarily authorize every buyer or every type of AI use.
Machine-readable licensing is developing beyond Cloudflare. The RSL standard lets publishers express terms covering attribution, crawling, training, and use inside generated outputs.
RSL calls the last category pay per use. It can include content used for inference, grounding, or generation. Grounding means supplying external evidence that helps an AI system produce a current or supported response.
Cloudflare and RSL approach parts of the same problem from different directions. RSL standardizes how rights and payment terms can be expressed. Cloudflare provides a managed commercial system that connects those ideas to identities, reporting, bills, and payouts.
Neither approach eliminates direct licensing. Large publishers and high-value data owners can still prefer negotiated contracts with custom guarantees. Standardized systems become more useful when the number of buyers and sellers makes private negotiation inefficient.
The economic promise resembles payment networks. A card network does not decide what every product is worth. It establishes rules and infrastructure that allow many parties to transact without building a new settlement system each time.
Cloudflare wants to play a comparable role for agentic content use. Its network position gives it visibility into authenticated crawlers and control over access for participating websites.
That position is an advantage, but it also concentrates influence. Publishers must trust Cloudflare’s classifications and settlement records. Buyers must accept Cloudflare as an intermediary in a market that remains commercially unsettled.
Pay Per Use will matter only if enough valuable publishers and credible buyers participate. Infrastructure can reduce friction, but it cannot create demand for interchangeable content or force AI companies to accept unfavorable terms.
Self-Reported Usage Is the Beta’s Hardest Test
The program’s central weakness is that the party owing money also reports the events that create the bill.
Cloudflare states this limitation directly. Usage is self-reported, and program terms require complete reporting. Cloudflare verifies that each submitted use maps to an enrolled publisher.
That check can reject invalid payment records. It cannot independently identify an answer, recommendation, or agent action that a buyer never submits.
For publishers, the missing audit path is more important than dashboard design. A precise chart of reported uses does not reveal whether the underlying reports are complete.
Cloudflare is working toward richer context for each event. Possible details include the query keywords, the topic, or the product that used the content. The company says this reporting would exclude personal data.
More context would help publishers understand which work creates value. It could also help them compare editorial investment with AI-derived revenue.
Yet contextual reporting still depends on definitions. If a buyer pays only for visible quotations, then background retrieval does not qualify. If it pays for influence, the system needs a credible way to determine contribution.
Attribution becomes difficult when models synthesize many sources. A generated sentence can reflect several pages without reproducing any passage. Retrieval logs can show which documents entered a workflow, but they do not automatically measure causal influence.
Buyers also need safeguards. Duplicate events, automated retries, incorrect URLs, and ambiguous attribution could increase charges. A usable system needs stable event identifiers and consistent reporting rules.
The parties therefore need more than a payment API. They need agreed definitions, audit procedures, dispute handling, and evidence that links an output to licensed material.
Cloudflare can compare buyer reports with crawler activity, but these datasets describe different stages. A crawl does not prove later use, and a prior index can power an answer without a new crawl at that moment.
The beta must also distinguish between fresh retrieval and model training. Cloudflare says each program’s terms can limit training rights. Publishers should not assume a paid answer citation automatically authorizes training.
Enforcement presents another uncertainty. Identified buyers can follow the system and pay according to accepted terms. Unauthorized crawlers can disguise themselves, ignore directives, or acquire similar information elsewhere.
Cloudflare has developed blocking tools and AI Labyrinth, which feeds unwanted bots generated pages designed to waste their resources. These controls raise the cost of noncompliance, but no perimeter catches every automated collector.
There is also a competitive risk for publishers. A buyer can favor sources with lower terms, broader permissions, or cleaner machine-readable content. That can turn participation into a race toward cheaper licensing.
The opposite outcome is possible for scarce material. Exclusive reporting, proprietary research, or specialist databases can command stronger terms because substitutes provide less value.
Pay Per Use may therefore expose a harsh distinction between content that is available and content that is commercially differentiated. Publishing alone does not guarantee meaningful AI revenue.
The system also does not resolve copyright law. Courts and regulators continue to examine whether AI training and generated output qualify as fair use or require licenses.
Licensing systems can operate while those disputes continue. Participation shows that a publisher and buyer accepted certain terms. It does not establish that every unlicensed AI use would have been unlawful.
Cloudflare should avoid presenting reported payments as a complete measure of content value. Publishers should also treat early dashboard earnings as experimental data rather than proof of a durable business model.
Trust will depend on reconciliation. If publishers can compare reported uses with citations, referrals, crawler logs, and independent monitoring, discrepancies become easier to investigate.
A mature version will likely require audit rights or technical attestations. Without them, the program asks publishers to trust the buyer, Cloudflare, and an event definition they did not create.
AI Licensing Is Moving From Contracts to Infrastructure
The larger shift is not one payment product, but the conversion of content rights into rules that software can read and execute.
The first generation of AI publishing agreements focused on named companies and negotiated archives. These contracts helped major platforms secure valuable material while giving selected publishers a new revenue source.
That model cannot cover the open web efficiently. Every custom contract adds negotiations, rights reviews, technical integration, reporting requirements, and payment operations.
Cloudflare Pay Per Use turns those repeated tasks into shared infrastructure. The buyer integrates once with Cloudflare. Participating publishers manage offers through the same dashboard.
RSL addresses a related coordination problem through an open specification. A crawler or agent can inspect machine-readable terms rather than searching for licensing language written for humans.
HTTP 402 is appearing as another building block. The web status code means payment is required, although it historically lacked a widely adopted payment workflow. New systems are trying to connect that signal with automated settlement.
Cloudflare’s separate Monetization Gateway applies this idea to APIs, tools, and data services. Those resources can charge per request because the request itself is the consumed product.
Published content behaves differently. Crawling a page and using it are separate actions, which explains why Cloudflare now offers both Pay Per Crawl and Pay Per Use.
These models can coexist. A publisher might charge for access to a specialized archive while accepting outcome-based payment for current articles. Another might allow crawling freely but require payment when material appears in an AI answer.
The emerging stack contains several layers. Identity establishes which bot or agent is acting. Permissions determine what it may access. Licensing specifies allowed uses. Metering records billable events. Settlement transfers payment.
Analytics then shows what happened. Cloudflare already provides crawler data through AI Crawl Control and answer visibility through its optimization tools. Pay Per Use adds reported downstream activity and earnings.
For publishers, this creates a potential decision system. They can compare which bots crawl, which services cite, which uses generate payment, and which content categories perform best.
Those insights also carry editorial risks. If publishers chase only topics that AI services license frequently, coverage can narrow around measurable machine demand. Public-interest work may remain valuable despite generating few billable uses.
Knowledge workers face a similar tension inside organizations. Documents often acquire value when they support a later decision rather than when someone first stores them. A well-managed AI knowledge base preserves provenance so users can trace that value back to its source.
Provenance means retaining information about where material came from and how it entered a result. It becomes essential when automated systems combine public reporting, internal documents, and generated analysis.
AI companies benefit from clearer provenance too. Licensed, attributable sources can improve answer quality and reduce uncertainty about access rights. Reliable fresh content also helps products answer questions that static training data cannot cover.
However, the commercial incentives remain unresolved. AI companies can use public material, licensed feeds, user-provided documents, synthetic data, or alternative sources. Publishers compete against all of them.
Cloudflare’s advantage is scale across websites, not ownership of their content. It must persuade buyers that a broad network of permissioned sources is more useful than fragmented scraping or limited bilateral agreements.
Publishers must make a parallel judgment. They need to decide whether broader AI distribution and new payments compensate for weaker direct traffic and reduced control over presentation.
That balance will differ by business model. A subscription publisher might protect complete articles while licensing selected facts. A product-review site might value attributed recommendations. A research provider might reserve its most current work for direct customers.
There is no single correct setting. The significance of Cloudflare publisher payments lies in making those choices operational instead of purely legal.
Three Signals Will Decide Whether Pay Per Use Works
Adoption, auditability, and negotiating power will determine whether this beta becomes a market or remains a controlled experiment.
The first signal is buyer participation. Cloudflare has described the workflow and its goals, but the market needs identifiable AI products submitting real usage at meaningful scale.
Buyer diversity matters as much as buyer count. If only one type of search product participates, publishers receive a narrow demand signal. Research agents, shopping assistants, and enterprise systems would test different definitions of use.
Broad participation would strengthen Cloudflare’s claim that one integration can replace thousands of individual deals. Limited participation would suggest that major AI companies still prefer private contracts or unrestricted public content.
The second signal is reporting quality. Publishers need evidence that submitted events correspond with observable citations, recommendations, or agent outputs.
Cloudflare plans to add contextual details such as topics and query keywords. The useful test is whether publishers can reconcile those details with independent signals while protecting user privacy.
Formal audit procedures would strengthen the system further. Clear correction rules, dispute windows, and buyer attestations would reduce dependence on goodwill.
Persistent gaps between observed citations and paid events would weaken the model. They would show that defining use is easier than verifying it.
The third signal is publisher control over terms. Cloudflare says it wants publishers eventually to counter offers and price content differently by use.
That feature would move the system closer to a genuine market. Without negotiation, publishers can only accept or reject definitions and terms created by buyers.
The distribution of earnings will matter too. Strong returns for a small group of premium publishers would validate demand for scarce content, but not necessarily a web-wide funding model.
Meaningful participation from smaller specialist sites would support Cloudflare’s broader argument. It would show that standardized infrastructure can extend licensing beyond media companies with large legal teams.
Publishers should track more than total payments. Useful measures include earnings per used page, differences among buyers, reporting delays, cancellation rates, and changes in direct referrals.
AI companies should examine answer quality, access to previously blocked sources, integration costs, and the reliability of publisher permissions. A payment model survives only when both sides receive measurable value.
Cloudflare Pay Per Use offers a credible mechanism for testing that exchange. It links verified buyers, publisher consent, usage records, billing, and payouts in one system.
It does not yet prove that self-reported AI usage can support publishers at scale. The beta must demonstrate that buyers report consistently, payments justify participation, and creators gain meaningful negotiating power.
The next few months should reveal whether the market moves beyond access fees toward outcome-based licensing. Watch which AI companies join, what audit controls appear, and whether publishers can negotiate.
If you publish original work, start by comparing crawler activity, AI referrals, citations, and any reported usage. Then ask the decisive question: does the value returned by Cloudflare Pay Per Use match the value your work creates inside someone else’s product?



