Cloudflare Details Strategy for Navigating the 'Agentic Internet'
Cloudflare's Web Integrity & Trust team is developing new methods to distinguish between beneficial and malicious automated internet traffic, focusing on continuous behavioral analysis.

The internet is no longer a simple dichotomy of human users versus malicious bots. Cloudflare's Web Integrity & Trust team is addressing the increasingly complex landscape of automated traffic, often referred to as the 'agentic internet,' where the lines between human and machine behavior are blurring.
Historically, bots were broadly categorized as 'bad,' while humans were considered 'good.' However, this generalization has become outdated. Humans can engage in fraudulent activities, and many automated agents perform essential functions, from search engine indexing to legitimate automated services. The emergence of hybrid sessions, where a single user session transitions between human interaction and automated assistance, further complicates traditional security models.
Cloudflare's strategy pivots from static, point-in-time security checks to a dynamic approach centered on assessing continuous user behaviors. The core of this strategy involves evaluating the 'Trust' and 'Risk' associated with internet traffic. Risk is defined as the likelihood of a request or action being harmful, often being transient. In contrast, Trust is built over time through a reputation system, informed by the cumulative actions of a user or agent.
To illustrate this, Cloudflare uses an analogy of a doorbell. While a single doorbell ring might be innocuous, repeated rings late at night could signal an issue. However, if the visitor is a known and trusted neighbor, the context changes entirely. Similarly, on the internet, isolated suspicious actions might be less concerning if the overall behavior history of the user or agent builds a strong foundation of Trust.
This framework aims to incentivize safer internet interactions. At the lower end, it focuses on blocking malicious activity. At the higher end, it encourages participation in a safer internet ecosystem by recognizing and rewarding transparent and responsible automated agents. This includes classifying 'Verified' bots based on their honesty in self-declaration and their adherence to earned trust.
Cloudflare's BotBase system is evolving to track not only known good bots but also less-than-good agents. By monitoring and validating the behavior of known good actors, Cloudflare can identify when these expectations are not met, leading to a bot being 'unverified' if it abuses trust within the network.
To combat sophisticated automated threats, Cloudflare has introduced Precursor, a client-side system designed to detect subtle, inhuman bot traffic that might evade network-level analysis. Precursor continuously evaluates user behavior throughout a session, making it more difficult for bot developers to mimic human actions over extended periods and across multiple pages. This continuous, Trust-based detection drives up the cost and complexity for bot developers, helping to win the adversarial game.
The team is also looking ahead to future developments, including enhanced tools for site owners to manage emerging challenges in the agentic internet and updates to their bot detection capabilities.