Cloudflare CEO Says AI Bots Now Outnumber Humans on the Web, With 1,000x Growth Projected by 2031
Key Takeaways
- •Cloudflare CEO Matthew Prince confirmed that automated traffic exceeded human traffic on the company's network in May 2026, arriving earlier than he had expected.
- •Prince projects that non-human traffic could reach roughly 1,000 times human volume by 2031 as AI agents operate at frequencies no human browsing session could approach.
- •Google's crawl-to-visitor ratio has deteriorated from approximately 6:1 to 18:1 or worse, weakening advertising models built on human attention.
- •Training-related scraping now accounts for 40 to 52% of all AI crawler activity, a shift from the earlier era when search-adjacent indexing dominated.
- •Beginning September 15, 2026, Cloudflare will block AI training and agent crawlers by default on ad-supported pages, shifting negotiating leverage toward content creators and pointing toward a possible pay-per-crawl model.

The internet has always had bots. What it has never had—until now—is a web where bots outnumber people. Matthew Prince, chief executive of Cloudflare, confirmed that automated traffic surpassed human traffic on the company's network in May 2026, a milestone he said arrived significantly earlier than he had anticipated.
The claim carries unusual weight. Cloudflare routes and protects traffic for a substantial portion of the global web, giving the company a real-time view of what is actually moving across the internet that few organizations can match. That vantage point matters because the non-human traffic in question is not a single phenomenon: it spans search-adjacent indexing, crawlers scraping content for training data, and AI agents—software that retrieves information or completes tasks on a user's behalf rather than a person opening a browser directly.
The math is getting uncomfortable for publishers
If May 2026 sounds bad, Prince's five-year projection is considerably more unsettling. He estimates that non-human traffic could reach roughly 1,000 times the volume of human traffic by 2031, as AI agents execute tasks at frequencies no human browsing session could approach.
The data already points in that direction. Google's crawl-to-visitor ratio—a measure of how often a crawler hits a site relative to the humans it sends back—has deteriorated from approximately 6:1 to 18:1 or worse. For publishers operating on advertising models built around human attention, that ratio matters enormously. A crawler reading an article generates no ad revenue; a crawler reading it three times as often as before, while sending proportionally fewer readers, is actively corrosive to the business.
The composition of AI traffic is also shifting in ways that complicate the picture. Training traffic—crawlers scraping content to feed large language models—currently accounts for 40 to 52% of all AI crawler activity, a meaningful departure from the earlier wave of AI traffic, which was dominated by search-adjacent indexing. That earlier wave at least held out the possibility of a human following a link back to the source; scraping for training data offers no comparable return path, which is why the shift compounds the pressure on ad-funded publishers.
Cloudflare's response: default to block, then negotiate
Prince and Cloudflare are not treating this as a passive observation. Starting September 15, 2026, the company will default to blocking AI training and agent crawlers on ad-supported pages for new domains and a significant share of existing sites. Publishers who want to allow that access will need to actively opt out of the block—meaning that, in practice, covered sites that take no action will have those crawlers excluded automatically.
The architecture of that decision is significant. Flipping the default from "allow unless blocked" to "blocked unless permitted" shifts negotiating leverage decisively toward content creators. now, the burden falls on publishers to identify and block specific crawlers—a technical and operational lift most small and mid-sized publishers cannot manage effectively. Under the new default, AI companies become the party that must come to the table.
Prince has pointed toward a pay-per-crawl or micropayment model as the logical destination, in which AI companies compensate content owners directly for each access rather than through the indirect, traffic-based advertising chain that currently underpins most of the web's economics. How many publishers keep the default block in place, and how AI companies respond to having to request access, are the immediate questions heading into the September 15 rollout.
What it means for the broader digital economy
The advertising-supported web as it exists today was engineered for human attention. Display ads, programmatic auctions, click-through rates, session duration—every metric in the stack assumes a person on the other end of the browser. When the majority of traffic is non-human, that entire measurement infrastructure starts measuring the wrong thing.
For Cloudflare itself, the strategic positioning is considerable. By inserting itself as the infrastructure layer where the block-or-permit decision is made, the company becomes a natural intermediary in any micropayment or licensing architecture that develops.