Cloudflare Says Machines Passed Human Traffic in May

Agent Web
Matthew Prince and Michelle Zatlyn wrote Cloudflare's 16th birthday letter on September 27. They say automated traffic passed human traffic on their network in May 2026. They had first put that date in the second half of 2027.
By Shashi Bellamkonda · September 29, 2026
May 2026
date they now give for the crossing
2H 2027
their earlier forecast
1,000x
their five-year projection
7M+
developers they say build on the platform
I first knew Cloudflare as the company that sat in front of a website and stopped a flood of junk requests so people could still open the page. The letter describes a new kind of load. Software agents now read thousands of pages to pick one lunch or one vendor. Most of those sites still pay to serve the request.

Prince and Zatlyn posted the letter on the day Cloudflare launched in 2010. They say the public web started growing again in mid-2025 after years of little change. They say most of that growth is new software from people who can now ship with artificial intelligence tools. They put more than 7 million developers on Cloudflare's platform (Cloudflare, 2026).

They also changed who they say is reading those sites. Cloudflare first forecast that automated traffic would pass human traffic in the second half of 2027. The letter now says that happened in May 2026. If the trend on their network continues, they say automated traffic will be 1,000 times human traffic in five years. They expect people to stay online. They expect agents to keep multiplying (Cloudflare, 2026).

Use the May date as the number they published from their own network. Treat the 1,000 times figure as a forecast. Outside companies cannot count that multiple from public data.

An agent can read 1,000 menus and send one customer

Their example is lunch. An agent can open 1,000 restaurant menus and recommend one place. One restaurant may get the customer. The other 999 still had to serve the page. The person who asked the agent does not see that cost. Last year's letter was about publishers. This year's letter uses restaurants and delis. They are saying the same load now hits ordinary businesses (Cloudflare, 2026).

They say an agent chooses the company it already has the most information about. That is usually the firm that has been online the longest. A clerk who remembers a name or a shop on the drive home does not enter that choice. New companies can launch faster than before and still stay invisible to the agent. Prince and Zatlyn write that an agent trained on today's web would have skipped Cloudflare in 2010. They launched at TechCrunch Disrupt with five data centers while engineers in the audience fixed the last bugs. People took a chance on them anyway (Cloudflare, 2026).

Put two items on a board slide: the May 2026 date, and the cost of serving machines that never buy. If you use the 1,000 times figure, label it as Cloudflare's forecast.

Cloudflare keeps shipping ways to cut that load

That pace is what I see from the outside. Cloudflare began by stopping distributed denial-of-service attacks so a person could still reach a site. It now adds products as the threat changes, and it publishes work that saves compute and network on the machines customers already run.

In July I wrote that half the traffic Cloudflare sees is machines, and that a September default would block training and agent crawlers on new ad pages while leaving search open. In August they added a Markdown view of a page and a score for whether Claude or GPT cites it. In mid-September they split search, training, and agent access so a site can refuse a training copy and still appear in Google. Earlier this month they published how five changes in the 1.1.1.1 cache freed about 100 terabytes of memory without adding servers (July 6; August 29; September 18; September 3).

The letter adds two more claims. Agents fetch pages over and over even when the page has not changed. Cloudflare says more than half of what good bots fetch is unchanged since the last visit. The company says it is teaching crawlers to fetch only what is new, which lowers the load on the site. It also says it will give site owners a way to get paid when an agent uses their work. Those items are announced in the letter. This post does not score the products (Cloudflare, 2026).

Treat search, training, and live agents as three visits

A search crawler indexes a page so a person can find it later. A training crawler copies the page into a model. A live agent reads the page now to answer a buyer. Keep search and live-agent access open on the pages you want a buyer's assistant to use. Turn training off if you do not want the model to keep a copy. Then test the result. Ask an assistant the question a buyer would ask. If your page is missing from the answer, you served the crawl and missed the sale.

If agents do the first round of research, older companies with more pages online will show up first. That is a findability problem for a new product. Cloudflare says it wants hundreds of thousands of AI companies, and it wants creators paid when an agent uses their work. Watch whether that payment appears on an invoice.

If you own a public site this quarter

Sit security and marketing in the same meeting and list which crawlers they allow on the pages a buyer would ask about. Then have someone ask an assistant that buyer question this week. If the answer names a competitor or an old article, fix the access and the page. Save the 1,000 times forecast for later.

Sources: Matthew Prince and Michelle Zatlyn. "Cloudflare's 2026 Annual Founders' Letter." Cloudflare Blog, 27 Sept. 2026, https://blog.cloudflare.com/cloudflares-2026-annual-founders-letter/. Prior shashi.co notes: "Half Your Website Traffic Is Now Bots. Cloudflare Just Gave You a Deadline to Deal With It," 6 July 2026; "Cloudflare Converts Pages to Markdown and Scores Whether Claude and GPT Cite You," 29 Aug. 2026; "Cloudflare Frees 100 Terabytes From the 1.1.1.1 Cache," 3 Sept. 2026; "Cloudflare Lets Sites Refuse Training Without Leaving Google," 18 Sept. 2026.

Disclaimer: This blog reflects my personal views only. Content does not represent the views of my employer, Info-Tech Research Group. AI tools may have been used for brevity, structure, or research support. Please independently verify any information before relying on it.