Skip to content

CLOUDFLARE

Read original ↗

Unveiling good and bad behaviors on the Agentic Internet

Summary

Cloudflare's Web Integrity & Trust team (bots + fraud) lays out its strategy for the Agentic Internet, where the human/bot line blurs into hybrid sessions that shift from human to agentic and back mid-session. The organizing frame is Risk vs Trust — treated as independent but reciprocal values rather than opposite ends of one axis: Risk is how likely a single request/action is to be harmful and is ephemeral; Trust is reputation built up over time. The strategy is to move from static, point-in-time checks (CAPTCHAs, one-time hurdles — Risk-based, context-free) to continuous behavioral evaluation over the whole session (Trust-based, context-rich). The post shares production data from Precursor (the continuous client-side behavioral detection system launched a few weeks earlier), previews Adaptive Intelligence (a self-adjusting ML detection engine that replaces versioned model launches), introduces a set of bot-specific advanced mitigations designed to raise attacker cost without being deterministically reverse-engineerable (the "Bot Antibiotic Problem"), and launches an interactive Precursor Trace demo.

Key Takeaways

  1. Risk vs Trust as independent, reciprocal values. "Risk is how likely something like a request or action is to be harmful, and it's often ephemeral. Trust, however, is built up over time, and it's based on reputation." The doorbell analogy: "Reject anyone who rings my doorbell more than 10 times" fails because Trust — recognizing your best friend on the door camera — is the essential ingredient, not a static rule on the action.

  2. A spectrum of trust, not a binary. Cloudflare builds an ecosystem from blocking malicious activity at the bottom to encouraging participation in a safer Internet at the top — good behavior is rooted in transparency: 1) declare yourself honestly, 2) don't abuse the trust you've earned (the two-part Verified definition). Transparency is symbiotic: declaring who you are reduces friction for bots that site owners want to allow.

  3. BotBase tracks bad actors too, not just good ones. Unlike the older Bots Directory (known-good only), BotBase is a directory of all known bots and agents. Because Cloudflare tracks and validates behavior for known-good actors, it can detect when those expectations aren't met — abuse of trust leads to being unverified.

  4. Hybrid traffic is real and mid-session. "Behavior often shifts from human to agentic and back over a session" (e.g. a user browsing a store then handing checkout to a shopping assistant). Point-in-time detection misses suspicious behavior that happens mid-session; understanding intent matters so site owners don't block flows they actually want.

  5. Precursor: continuous client-side behavioral detection. A JS detection injected via the CDN (no server-side setup), evaluating user behavior continuously throughout the session rather than once. Two load-bearing properties: (a) Trust-based detection over the entire session; (b) it drives up the cost for bot developers to replicate human behavior across a multi-page timeline — making it economically disadvantageous to outrun the detection is how Cloudflare "wins the adversarial game."

  6. Precursor production numbers. In a 24-hour window: 206 million Precursor evaluation events across 73,438 zones. Validated hypotheses: suspicious behavior often happens mid-session (point-in-time can't catch it); behavior shifts human↔agentic within a session (motivating the behavior-based taxonomy).

  7. Risk-based vs Trust-based detections. CAPTCHAs and one-time hurdles are Risk-based — they lack context. Verification via behavioral tells is Trust-based — it captures context clues from the full user session. Precursor is the tool that analyzes this behavior.

  8. Adaptive Intelligence: a self-adjusting model. Historically Bots ML shipped as versioned model launches — "This pacing doesn't work when bots adapt on the scale of hours or even minutes." Adaptive Intelligence is a new detection engine where the model itself is adaptive — it continues to learn and self-adjust from observed traffic (good to bad), so customers no longer upgrade to a new model version to get the latest predictive detection. Coming to all Bot Management customers.

  9. Determinism is the attacker's friend — the "Bot Antibiotic Problem." "Always sending bots a deterministic response (like a 403 block) makes it easy for a malicious developer bot to probe, observe, and reverse-engineer your defenses." Three advanced, bot-specific mitigations answer this:

  10. Unpredictability / random actions — randomly pick between block / challenge / allow for suspected automated traffic, breaking a bot's automated retry logic and fingerprinting.
  11. AI Labyrinth — trap unauthorized bots in a maze of AI-generated pages to waste compute and crawl budget via misdirection. Three modes: Maze (endless web of linked pages), Summary (LLM-generated real-looking-but-useless summary as training data), Poison (fake content — fake prices/inventory — to pollute collected training data).
  12. Queuing for good bots — not all agentic traffic is bad; queue legitimate automated traffic (e.g. user-directed shopping agents) to manage throughput without denying service.

  13. Disposable / dynamic rulesets. A great defense is predictive and self-correcting — "a system of 'disposable' rules, in which the ruleset is dynamic in nature. This is by design: if attacks constantly evolve, the defenses should, too." Both detections and mitigations aim to stay a step ahead without a security expert reactively hand-setting a fix.

  14. Precursor Trace interactive demo. precursor-trace.cloudflare.app is live and traces your cursor movements using (part of) Precursor's detection mechanism — acceleration, self-correction, rhythm and texture of movement — the tells that separate human from bot.

Architectural Design Decisions

  • Risk and Trust as orthogonal axes. Modeling them as independent-but- reciprocal (rather than a single continuum) lets a high-Risk action from a high-Trust actor be allowed, and a low-Risk-looking action from a zero-Trust actor be scrutinized — the doorbell friend vs the frantic stranger.

  • Continuous session evaluation over point-in-time gates. Trust is accumulated across the session; abuse is caught mid-session. This is the operational counterpart to the 2026-04-21 "behavior, not species" framing and the 2026-07-01 behavior-based taxonomy.

  • CDN-injected client-side JS. Precursor's detection runs client-side, injected at the edge — no per-origin instrumentation, and no "free hall pass" for traffic that passes a single client/browser check once.

  • Economic-disadvantage design goal. The detection is deliberately designed to make replicating human behavior over a multi-page timeline expensive, shifting the adversarial game onto attacker economics rather than a single beatable check.

  • Adaptive model over versioned model. Removing the human-in-the-loop version-bump cadence to match bot adaptation on the scale of hours/minutes.

  • Non-deterministic mitigation by design. Random block/challenge/allow + misdirection (AI Labyrinth) + disposable dynamic rulesets deliberately deny attackers a stable signal to reverse-engineer.

Operational numbers

  • 206 million Precursor evaluation events in a 24-hour window.
  • 73,438 zones on the Cloudflare network running Precursor evaluations in that window.
  • Advanced bot-specific mitigations (unpredictability, AI Labyrinth modes, queuing) slated to roll out closer to the end of the year, with site-owner-selectable strictness.
  • Adaptive Intelligence: launch announcement "coming soon" to all Bot Management customers at the time of writing.

Caveats

  • Roadmap-heavy. Adaptive Intelligence and the three advanced mitigations are previewed, not GA; no accuracy, false-positive, or latency numbers are disclosed for them. Precursor's 206M/73,438 figures are volume, not detection-quality, metrics.
  • AI Labyrinth's Poison mode (serving deliberately fake content to suspected bots) is a misdirection tactic; the post does not discuss collateral risk to mis-classified legitimate agents.
  • Precursor Trace exposes only part of the detection mechanism.
  • The Risk/Trust framing is a strategy narrative; the post gives the conceptual model and production volume, not the scoring internals.

Source

Last updated · 766 distilled / 2,225 read