Cloudflare’s 2026 Annual Founders’ Letter Says Agents Won, but the Web’s Bargain Did Not
Cloudflare’s 2026 Annual Founders’ Letter marks a first that arrived much earlier than expected: automated web traffic passed human traffic in May 2026. Cloudflare had forecast that crossing for late 2027. The company now argues that AI agents have broken more than a traffic record. They are testing the economic bargain that funded the open web.
Cloudflare co-founders Matthew Prince and Michelle Zatlyn published the letter on September 27, the company’s 16th birthday. Their message is optimistic about what people can create with AI. It is far more cautious about how agents discover, consume, and reward that work.
The central conflict is not humans against machines. It is agent efficiency against creator economics. An agent can inspect hundreds of businesses before recommending one, while every unchosen business absorbs infrastructure costs and receives no customer.
That dynamic places Cloudflare between two groups that need each other. AI companies need timely, trustworthy web content. Publishers, developers, merchants, and independent creators need discovery, compensation, or both.
Cloudflare wants to become the coordination layer between them. Its proposed model combines verified bot identities, purpose-based controls, freshness signals, and payments tied to content use. Whether enough AI companies accept those rules remains the decisive question.
Cloudflare’s 2026 Annual Founders’ Letter Redefines the Web’s Traffic Problem
The letter turns automated traffic from a technical measurement into an economic warning.
Cloudflare says agents and AI crawlers pushed automated traffic above human traffic in May 2026. That was more than a year ahead of its previous forecast. The company attributes the change to rapidly expanding agent activity, not declining human use.
Cloudflare also predicts that automated traffic will reach 1,000 times human traffic within five years if current trends continue. That projection is a company forecast, not an independently established outcome. Still, the earlier crossover makes the direction difficult to dismiss.
The important change is what automated software now does. Traditional bots indexed pages, checked availability, filtered spam, or gathered information for search engines. AI agents increasingly research, compare, decide, and transact for users.
Cloudflare offers a simple scenario. An agent asked to recommend lunch might inspect 1,000 restaurant menus before choosing one. The selected restaurant might earn a customer, but 999 others still served requests without receiving business.
The agent saves one person significant time. It also transfers the research cost onto websites that did not request the work. Cloudflare describes this as a tragedy of the commons, where beneficiaries do not bear the full cost of their consumption.
That framing expands the debate beyond news publishers and model training. Restaurants, contractors, retailers, travel services, and software providers can all face the same imbalance. Their pages become machine-readable inputs, even when the resulting transaction happens elsewhere.
This matters because agents do more than replace individual page visits. They can compress an entire customer journey into one answer. Discovery, comparison, selection, and purchasing can occur without the user seeing most contributing websites.
The founders’ letter argues that this shift threatens small businesses most. Agents tend to choose using available data, measurable attributes, and prior signals. Those inputs often favor established companies with larger digital footprints.
Human choices contain factors that ranking systems struggle to capture. A customer might visit a deli because the staff remembers a name. Someone might prefer a local store because it sits along a familiar route.
An agent has no personal memory of that interaction. It also does not pass the storefront while driving home. Unless those advantages become structured signals, they can disappear from an automated comparison.
Cloudflare therefore presents the traffic milestone as a market-design problem. The question is no longer whether bots can reach a website. It is whether the resulting market preserves opportunities for new creators and smaller businesses.
The letter also gives Cloudflare a clear strategic role. A company positioned between websites and automated clients can classify requests, enforce access rules, reduce waste, and help route payments. Cloudflare wants that intermediary position to become central to the agentic web.
AI Agents Are Expanding Creation and Concentrating Discovery
AI is lowering the cost of building online while raising the risk that new projects remain invisible.
The optimistic half of Cloudflare’s argument concerns creation. The company says the web’s long plateau ended around mid-2025, when the number of new sites began growing again. Cloudflare disputes the idea that most of this growth is disposable AI-generated material.
Instead, Prince and Zatlyn credit AI-assisted development with bringing more people onto the web. Vibe coding tools let users create software through natural-language instructions, even when they lack conventional programming experience.
Cloudflare says more than seven million developers now build on its developer platform. It also says many AI coding services prefer Cloudflare as a deployment target. Those are company-reported figures and claims, but they show why Cloudflare views AI creation as an opportunity.
Students can turn an idea into a working application. Small teams can test products without first assembling a large engineering organization. Startups can publish experiments faster than earlier generations of founders.
Yet the same technology that expands supply can narrow distribution. More people can create websites and applications, while a smaller number of agent interfaces mediate how users find them.
This is the central reversal in Cloudflare’s 2026 Annual Founders’ Letter. AI expands who can build, but agents can concentrate who gets discovered. The web gains more creators while its recommendation layer becomes less diverse.
An agent often optimizes for measurable outcomes. It can compare availability, price, review counts, delivery time, compatibility, or specifications. It has less access to relationships, local context, emerging reputation, and the appeal of taking a chance.
Established companies usually possess more reviews, references, structured data, and historical interactions. Their information appears in more indexes and model outputs. Each recommendation can then produce additional signals that strengthen the next recommendation.
That feedback loop creates an incumbent advantage. Large businesses become easier for agents to evaluate, so agents select them more frequently. Increased selection generates more data, which makes them even easier to select.
The pressure does not fall only on merchants. Independent websites also depend on readers encountering their work. If an answer engine summarizes their reporting, the reader might never reach the original page.
A Pew Research study found that users clicked traditional results in 8 percent of visits containing a Google AI summary. The rate was 15 percent when no summary appeared. Links inside AI summaries received clicks during only 1 percent of visits.
Those findings do not prove that every publisher loses the same amount of revenue. They do show that answer interfaces can weaken the connection between being cited and receiving a visitor.
Cloudflare CEO Matthew Prince extended the argument during a June 2026 event. He warned that agents can compare thousands of products without brand loyalty or emotional attachment. That process can place lesser-known businesses at a structural disadvantage.
Cloudflare’s concern is partly principled and partly commercial. The company benefits when more websites, applications, and agents use its infrastructure. A diverse web creates more customers and more traffic across its network.
That incentive does not invalidate its diagnosis. It does mean readers should treat the letter as both a policy argument and a platform strategy. Cloudflare is describing a problem while proposing itself as essential infrastructure for solving it.
The Old Crawl-for-Traffic Bargain No Longer Balances
The primary conflict is between agents that demand more web access and creators receiving less value from that access.
For roughly three decades, public web discovery followed an understandable exchange. A search engine crawled a page, indexed it, and displayed a link. The website accepted the crawling cost because search sent people back.
Those visitors could subscribe, view advertising, make purchases, or join a community. Crawling and monetization operated within the same basic path. The exchange was imperfect, but both sides could receive value.
AI answer engines interrupt that path. They can retrieve information, synthesize it, and satisfy the user without requiring a visit. An accurate citation still has reputational value, but it does not automatically produce attention or revenue.
Agents increase the imbalance because one request can trigger a large research process. A user asks one question, but the agent might fetch hundreds of pages. The interface captures the user relationship while websites serve the underlying work.
This does not mean every automated visit is harmful. Some agents complete transactions that directly benefit a merchant. Others help users reach services they would not have discovered independently.
The difficulty is distinguishing beneficial delegation from extraction. A real-time shopping agent behaves differently from a crawler collecting material for model training. A search index also has a different purpose from either activity.
Cloudflare introduced a purpose-based taxonomy in July 2026. It separates automated behavior into search, agent, and training categories.
Search automation gathers content for later responses. Cloudflare says site owners should receive referrals or equitable compensation from that use.
Agent traffic acts on a person’s behalf to complete an immediate task. Examples include a browser agent comparing products or a chat service fetching a requested page.
Training crawlers collect material for model development or fine-tuning. That use can permanently absorb information into a model, rather than supporting one current user request.
The AI traffic controls let site owners manage those categories separately. Cloudflare argues that bot operators should also use distinct crawlers when their automation serves several purposes.
The distinction is necessary because a single allow-or-block choice is too crude. Blocking every automated visitor can reduce misuse, but it can also remove a site from new discovery channels. Allowing everything preserves reach while surrendering control.
Small sites experience this tradeoff most sharply. They need discovery because few users already know their names. Yet they have limited leverage when a large platform extracts content without returning meaningful traffic.
Large publishers can negotiate licensing agreements directly with AI companies. Independent writers, niche databases, local merchants, and small software teams usually cannot. Any workable system must scale beyond individually negotiated contracts.
Cloudflare’s strategy is to transform access into a programmable choice. A site should be able to permit search, reject training, welcome customer-directed agents, or request compensation for particular uses.
That vision also requires trustworthy identification. A crawler’s user-agent string is only a declaration, and a malicious operator can misrepresent it. Cloudflare has therefore promoted Web Bot Auth, which uses cryptographic credentials to verify automated clients.
Verified identity still does not solve every enforcement problem. A crawler can use proxies, browser automation, or outsourced collection to resemble human traffic. Content can also be obtained from mirrors, archives, or previously assembled datasets.
Cloudflare can impose rules on traffic passing through its network. It cannot establish universal legal rights or prevent every indirect copy. Its influence comes from reach, coordination, and the cost it can impose on noncompliant access.
The company says more than 20 percent of the web sits behind its network. That position gives Cloudflare unusual visibility into changing pages and traffic patterns. It also raises a governance question about one infrastructure provider shaping agent access.
The old bargain was decentralized but largely controlled by search engines. Cloudflare’s replacement might distribute more control to site owners. It could simultaneously grant Cloudflare a larger role in identifying bots, setting categories, and facilitating payments.
Cloudflare Wants to Meter Value, Not Just Block Crawlers
Cloudflare’s proposed mechanism combines less wasteful crawling with payments linked to actual content use.
The company’s first response focused on defense. In July 2025, Cloudflare announced Content Independence Day and introduced controls for blocking AI crawlers. It also began testing Pay Per Crawl, which lets publishers charge automated clients for access.
That approach gave creators a stronger default position. However, payment for every request creates its own problems. A crawl does not always generate useful information, and repeated access does not necessarily create proportionate value.
Cloudflare now wants to move from Pay Per Crawl toward Pay Per Use. Under that concept, compensation follows a valuable outcome, such as content appearing in an AI answer.
The change acknowledges that access and value are different. One page might be fetched repeatedly without affecting an answer. Another might provide the decisive fact behind a recommendation.
Cloudflare says participating publishers can receive information about queries, citations, and ranking through its work with Ceramic.ai. You.com is testing another approach where an agent can pay for specific premium content when needed.
These partnerships remain experiments. They do not yet establish a universal market, a standard valuation method, or broad participation among leading AI platforms.
Cloudflare is also working on the cost side. Its data suggests that more than half of good-bot crawl traffic revisits pages that have not changed. Every unnecessary request consumes bandwidth, server capacity, and AI-company compute.
Freshness signals could tell an answer engine whether a page has changed since its last visit. A crawler could then skip unchanged material while still finding current information.
The AI search program aims to measure whether those signals improve freshness and reduce unnecessary crawling. Cloudflare says it plans to publish results and broaden availability.
This mechanism offers a benefit even without payments. Publishers serve fewer wasteful requests. AI companies reduce retrieval and processing costs. Users can receive information from pages that are more likely to be current.
The model becomes more complicated when compensation enters. A payment system must determine which content influenced an answer and how much that contribution was worth.
Simple citation counting can be misleading. An answer might cite one page while relying on facts learned elsewhere. Several sources might provide the same information, and an agent could combine their contributions.
Pricing also varies by context. A restaurant menu, medical reference, financial filing, investigative report, product catalog, and software documentation page offer different forms of value.
A fixed crawl fee ignores those differences. Outcome-based compensation addresses part of the problem, but it requires attribution that creators and AI services both trust.
The system also needs transaction costs low enough for machine-scale use. Agents can make many retrieval decisions during one task. Manual negotiations or conventional subscription flows would make most interactions impractical.
Cloudflare’s position in the network could reduce those costs. It can recognize participating sites, identify authorized agents, apply access rules, and record usage through common infrastructure.
That role resembles a clearing layer more than a publisher marketplace. Cloudflare does not need to decide every price itself. It can provide the identity, policy, measurement, and payment rails that let others transact.
The approach fits the growth of agentic commerce, where software acts for a user across several businesses. Verified agents need authorization to access accounts, compare offers, and complete purchases without exposing raw credentials.
However, efficient payments do not guarantee a fair market. Large AI companies can still possess greater bargaining power. They can favor free sources, use existing datasets, or direct agents toward partners offering favorable terms.
Creators also face collective-action pressure. One publisher might demand payment, while a competitor remains freely accessible. Unless the paid material is distinct, an answer engine can substitute another source.
Cloudflare must therefore demonstrate more than technical feasibility. It must show that high-quality content improves agent outcomes enough to justify payment. Better attribution must also create revenue that exceeds participation costs.
What Cloudflare’s Numbers Still Do Not Prove
The traffic crossover is significant, but Cloudflare’s proposed economy still depends on adoption, attribution, and enforceable identity.
The headline measurement deserves careful interpretation. “Automated traffic” includes more than autonomous AI agents. Depending on classification, it can include crawlers, monitoring services, security tools, feeds, and other non-human requests.
Cloudflare specifically attributes the accelerated crossover to agents and AI crawlers. Yet a majority-automated web does not mean agents already control most purchases, decisions, or human attention.
Request volume is not economic influence. One agent can generate many requests during a single task, while one human page view can lead directly to a purchase. Comparing raw traffic shares can therefore exaggerate or understate practical impact.
The five-year prediction is even less certain. Cloudflare expects automated traffic to become 1,000 times human traffic if current patterns continue. Infrastructure limits, crawler optimization, regulation, or changing AI architectures could alter that trajectory.
Cloudflare’s own freshness project is designed to reduce repeated requests. If it succeeds, agents might perform more useful work while generating less traffic. That outcome would weaken request volume as the main measure of agent adoption.
The creator argument also varies across business models. A subscription publisher loses something measurable when an answer replaces a visit. A restaurant may benefit if an agent sends a confirmed reservation, even after inspecting many menus.
Some website operators want licensing revenue. Others value distribution, citations, completed transactions, or lower support costs. A single compensation framework cannot treat those outcomes as identical.
Critics also question whether crawler fees can stop evasive collection. AI companies acting in good faith can authenticate, respect policies, and participate in payments. Less cooperative operators can disguise traffic or acquire data elsewhere.
A critical pay-per-crawl analysis argued that generic material remains widely available through existing datasets. It also noted that abusive crawlers have little reason to identify themselves honestly.
That objection becomes less damaging if Cloudflare focuses on current, scarce, or premium information. Old commodity data is easy to substitute. Real-time inventory, specialized analysis, and frequently updated databases are harder to replace.
Cloudflare must also show that its attribution methods are auditable. Publishers need evidence that reported uses reflect actual agent behavior. AI companies need confidence that charges correspond to content that influenced an answer.
There is another tension around openness. The web grew partly because pages were broadly accessible without transaction negotiations. Introducing payment checks across ordinary retrieval could raise barriers for researchers, archives, accessibility services, and new search providers.
Cloudflare’s purpose categories help, but classifications involve judgment. A search product can also train models. An agent can create an index during a task. A service can change how stored material is used after collection.
Mixed-use crawlers create especially difficult policy choices. Site owners need controls that distinguish current user-directed retrieval from unrelated training. Bot operators must provide identities and purposes that remain accurate over time.
Cloudflare’s proposal therefore depends on governance as much as engineering. Someone must define categories, resolve disputes, update classifications, and respond when an operator violates declared terms.
The company should also publish evidence about false positives and false negatives. Blocking legitimate automation can damage discovery and accessibility. Failing to identify disguised automation weakens creator protections.
Concentration remains the largest structural concern. Cloudflare warns that agents could favor incumbents and leave fewer openings for new businesses. Yet a compensation market dominated by major infrastructure and AI providers could create another concentrated layer.
The strongest version of Cloudflare’s argument is not that its system has solved these issues. It is that the current model no longer aligns costs and rewards.
Cloudflare openly describes its newer programs as experiments. That restraint matters. The company has presented a credible mechanism, but adoption and independent measurement must determine whether it produces a fairer market.
Three Signals Will Show Whether the Agentic Web Can Pay Its Contributors
The next test is whether Cloudflare can convert a persuasive diagnosis into measurable creator revenue and broader market participation.
The first signal is documented performance from Cloudflare’s freshness program. The company says over 50 percent of good-bot crawling revisits unchanged pages. Published trial results should show how much that traffic declines.
Useful reporting would separate bandwidth savings, crawler compute reductions, information freshness, and answer quality. A lower crawl count alone is insufficient if agents miss important updates or favor established sources.
Strong results would support Cloudflare’s infrastructure thesis. They would show that a network intermediary can reduce costs for both sides without simply restricting access. Weak or opaque results would leave the efficiency claim unproven.
The second signal is meaningful participation in Pay Per Use. Ceramic.ai and You.com provide initial models, but the market needs more answer engines, publishers, merchants, and independent creators.
The critical metric is not the number of announced partners. It is whether content contributors receive material payments and useful attribution data. Cloudflare should also show whether smaller publishers can participate without specialized technical work.
Adoption by larger AI platforms would strengthen the model considerably. Refusal would indicate that Cloudflare lacks enough leverage or that AI companies see limited value in paid access.
The third signal is whether purpose-based bot identity survives real-world pressure. Cloudflare needs evidence that search, agent, and training traffic can be classified reliably across mixed-use services.
Watch for crawler operators adopting separate identities, publishers using granular controls, and enforcement against misrepresented traffic. Regulatory decisions could also make machine-readable consent more consequential.
Success would mean agents remain broadly useful while creators gain choices beyond unrestricted access or total blocking. Failure would leave websites serving growing machine demand without a dependable path to compensation.
Cloudflare’s 2026 Annual Founders’ Letter is ultimately a bid to define the rules before a few agent platforms define them alone. The company wants an Internet with many creators, many AI providers, and room for unfamiliar businesses to earn attention.
That outcome is not guaranteed by faster deployment tools or better crawlers. It requires discovery systems that recognize novelty, payment systems that value contribution, and identities that make automated actors accountable.
Developers and enterprise buyers should now inspect how their agents acquire information. Do those systems identify themselves, respect declared purposes, avoid unchanged pages, and preserve source attribution?
Creators should watch whether compensation becomes repeatable revenue rather than a limited pilot. AI users should ask whether convenient answers are weakening the sources that make those answers possible.
The decisive question is no longer whether automated traffic will dominate. Cloudflare says that threshold has already passed. The question is whether the next web rewards the people and businesses that give its agents something worth finding.



