Cloudflare Is Changing How AI Can Access Your Website on September 15. Before You Block Everything, Here Is What It Actually Means.
On September 15, Cloudflare is changing the default settings that control how AI companies can access websites on its network. If you have a free Cloudflare account and you have not touched your bot settings, the new defaults get applied to your site automatically.
Most coverage of this has landed somewhere between “Cloudflare blocks AI” and “Cloudflare protects publishers.” Both are close enough to be useless if you are trying to decide what to do about your own website.
So here is the accurate version, followed by the part nobody is covering, which is whether any of it should change what you do.
## What Cloudflare actually announced
Cloudflare announced the change on July 1. The details matter more than the headline.
Starting September 15, for new customers and for new sites added by existing customers, the default will be to allow crawling for search while blocking training and agent use, and that default applies to pages with ads. Crawlers that mix all three purposes together, meaning they do not let a site owner distinguish between search, agent use, and training, will be blocked on pages with ads.
The same change will be applied to existing free accounts that have not adjusted their settings in the dashboard by that date.
Settings can be changed at any time, before or after.
Read that carefully and you will notice the qualifier most summaries dropped: pages with ads.
## So who is actually affected
If your website runs advertising, this is a real change and you should look at your settings.
If your website does not run ads, and most small business websites do not, the September 15 default change is considerably narrower than the headlines suggest. A law firm site, a contractor site, a SaaS marketing site, a restaurant site: none of these are the target of this particular default.
That is worth saying plainly, because the reflex when a deadline appears is to open the dashboard and turn everything off. Turning everything off is a decision with consequences, and it is a different decision than the one Cloudflare is making on your behalf.
## The question underneath the deadline
The deadline is a news event. The actual question has been sitting there for two years:
Do you want AI systems to be able to read your website?
Not “should AI companies pay publishers,” which is a fair question and not yours to solve. The narrower one: when somebody asks an AI assistant about the thing your business does, do you want your content to be part of the answer?
For a publisher whose revenue depends on people arriving on the page and seeing ads, that is complicated. An AI answer that uses your work and sends nobody is a straight loss. That is the case Cloudflare is responding to.
For most small businesses the economics run the other way, and this is where the standard advice goes wrong.
## The tradeoff, honestly
**The case for allowing access.**
Your website is usually not the product. It is the thing that causes people to contact you. If someone asks an AI assistant to recommend a commercial plumber in your county and your site is not in the index, you are not in the answer. Discovery is moving to these surfaces whether anyone likes it or not, and being absent from a channel is rarely a strategy.
There is also a practical limit worth understanding. Blocking crawlers at the network level stops well behaved bots that identify themselves. It does not stop everything, and it does not retroactively remove anything already ingested.
**The case for blocking.**
If your content is the product, meaning people pay for access to it or you monetize attention on the page, then a system that consumes your work and answers the question without sending anyone to you is taking value and returning nothing. That is a legitimate business objection and it requires no philosophical position about AI at all.
There is a competitive version too. If you have published genuinely proprietary technical documentation or original research, you may reasonably not want it summarized for free into a competitor’s prospect’s chat window.
**The part that is genuinely unresolved.**
Nobody has good data yet on how much traffic AI surfaces actually send back. Cloudflare’s own announcement includes a new dashboard built specifically so site owners can see how much human traffic individual AI companies return, which tells you something about how poorly understood that number currently is.
Anyone confidently telling you the answer right now is guessing.
## How to decide
Three questions, in order.
**Does your site run ads or sell access to content?** If no, the September 15 default is mostly not about you, and your decision is about the broader setting rather than the deadline.
**Is your content the product, or does your content sell the product?** Documentation, research, and paywalled work is the product. Service pages, case studies, and educational marketing sells the product. The first has a reason to restrict. The second usually does not.
**Can you measure what you would be giving up?** Before blocking anything, look at whether AI surfaces currently send you any traffic at all. If they send some, blocking has a visible cost. If they send none, blocking costs less but also accomplishes less.
## A sensible way to handle it
Log into Cloudflare at some point and look at your current bot and AI crawler settings, so that whatever the defaults become, your configuration is something you chose rather than something you inherited.
If you run ads or sell content access, the decision is worth making deliberately.
If you do not, the action is smaller: know where the setting lives, check what it says today, and revisit it when you have data.
Either way, the useful outcome of this news is not a configuration change. It is knowing that a decision exists.
## The larger pattern
This is the third development in a month pointing the same direction. Zero click searches to the open web have continued to fall. Google confirmed in July that smaller core updates now roll continuously without announcement. And now the largest network layer sitting in front of the web is setting defaults about who gets to read your content.
The common thread is that the relationship between a website and the traffic it receives is being renegotiated right now, largely by parties who are not you, and increasingly through defaults rather than announcements.
The practical response is not to form an opinion about AI. It is to know which of your settings were chosen and which were inherited.
*Source: [Cloudflare’s announcement](https://www.cloudflare.com/press/press-releases/2026/cloudflare-allows-the-agentic-internet-to-flourish-with-a-simple-philosophy-your-content-your-rules/), July 1, 2026.*
—
**About Blue Arctic** — Blue Arctic has provided managed hosting since 2002, on infrastructure we own in Tampa, Florida. Questions about how a change like this applies to your own setup are always welcome.