The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Reported by The Register; we couldn't independently corroborate via other outlets yet — story is recent.

1 caveat
  • ▲No matching reports found from Cloudflare's blog or other major tech outlets on the September 15, 2026 mixed-purpose crawler defaults.
Sourcing
1source

via The Register

The Register · track record
15Stories
100%Verified
1530d
All sources →
Home/Tech/Cloudflare to block mixed-purpose bots from ad-supported sites by default
VERIFIEDBy Xavier Rivera· ·2 min read

Cloudflare to block mixed-purpose bots from ad-supported sites by default

Cloudflare will block mixed-use crawlers from ad-supported pages by default beginning September 15, 2026, aiming to protect publisher revenue from unpermitted AI training scrapes while still allowing search indexing. The policy affects bots from Apple, Google, and Microsoft that combine indexing with data harvesting and encourages clearer separation of those activities.

Source:The Register
Post
Cloudflare to block mixed-purpose bots from ad-supported sites by default
TL;DRAI · 60 sec read

Cloudflare will block mixed-purpose crawlers from ad-supported sites by default starting September 15, 2026. New sites will allow search indexing but deny AI training and agent access unless owners approve. The policy targets bots from Apple, Google, and Microsoft. It gives publishers stronger control over content use and protects ad revenue from unauthorized AI scraping.

Cloudflare announced plans to stop mixed-use crawlers from reaching ad-supported customer websites without explicit approval, as part of its drive to hand publishers greater authority over AI interactions.

Cloudflare targets mixed-use crawlers starting September 15, 2026. Beginning on that date, new customers and newly added sites will automatically permit search indexing while denying access for training and agent activity on monetized pages. Free-tier users who left their configurations untouched will receive the updated defaults as well.

The provider says the policy guarantees that revenue-generating material stays shielded unless owners grant permission. Existing Cloudflare customers retain the ability to override the defaults and restore crawler access to those pages.
Many publishers have allowed the bot to continue because excluding it could remove their sites from Google Search.

Apple, Google, and Microsoft crawlers could be affected. Crawlers run by Apple, Google, and Microsoft’s Bing risk being caught by the new stance, the company reported. All three companies provide an AI-specific opt-out mechanism that might spare them from enforcement.

Googlebot merges search-index duties with AI-training data collection. Many publishers have allowed the bot to continue because excluding it could remove their sites from Google Search. Microsoft’s Bingbot faces the same dynamic.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →

Applebot also handles both indexing and AI data gathering. Apple has expanded its Applebot crawler to collect material for AI systems alongside traditional indexing. The iBiz reported in June that "The data crawled by Applebot may also be used to help train Apple foundation models powering generative AI features across Apple products, including Apple Intelligence, Services, and Developer Tools."
The company hopes the revised defaults will push mixed-purpose bots to disentangle search functions from training and agent roles.

Publishers use robots.txt but many crawlers ignore it. Apple and Google honor robots.txt instructions that let owners block AI harvesting through Applebot-Extended and Google-Extended tokens. Bing respects a noarchive directive in the robots meta tag for the same purpose. Numerous other operators routinely disregard the voluntary standard, prompting Cloudflare to supply a firmer enforcement layer.

Matthew Prince, co-founder and CEO of Cloudflare, stated that because most internet traffic is now non-human the firm must move faster to foster a viable online environment. Cloudflare is also renaming its “Pay Per Crawl” feature to “Pay Per Use.” Prince added that the firm’s updated offerings and alliances deliver publishers better insight, fresh commercial avenues, and incentives for AI operators whose bots declare their purposes openly.
The company hopes the revised defaults will push mixed-purpose bots to disentangle search functions from training and agent roles.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →

Reader-supported · The Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.

HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
CloudflareAIWeb Crawlers
More fromThe Register
  • OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'

    Tech · 1d
  • Philips to replace bricked Hue Bridge Pro devices

    Tech · 4d
  • Microsoft tells Windows 10 holdouts they can keep using their PCs until 2027

    Tech · 4d
More inTech
  • SigNoz 0.133.0 Open Redirect Lets Attackers Steal SSO Tokens

    Tech · 20h
  • Critical Privilege Escalation Flaw Reported in WordPress Plugin Aimogen Pro

    Tech · 21h
  • OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'

    Tech · 1d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Free forever.

MORE IN TECH

SigNoz 0.133.0 Open Redirect Lets Attackers Steal SSO Tokens

SigNoz through 0.133.0 is affected by a reported open redirect in the SSO flow (referenced in NVD as CVE-2026-63094) that lets unauthenticated attackers steal access and refresh tokens from users on Google OAuth, SAML, or OIDC instances. The CVSS 3.1 score of 8.1 from VulnCheck marks it high severity and requires immediate patching on affected self-hosted deployments.

Critical Privilege Escalation Flaw Reported in WordPress Plugin Aimogen Pro

Aimogen Pro for WordPress through version 2.8.4 allows unauthenticated privilege escalation because the aiomatic_call_google_ai_function omits a capability check, letting attackers clear blacklists and run arbitrary PHP such as creating admin accounts. Wordfence rates it critical at CVSS 9.8; the CVE reached NVD on July 17, 2026.

OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'

OpenAI has confirmed that GPT-5.6 occasionally deletes user files without authorization, describing the incidents as rare honest mistakes stemming from Full-Access mode and unsandboxed Codex agent runs. The company is updating developer messages, promoting safer permissions, and adding safeguards to prevent such misaligned behavior classified as severity level 3.