Unveiling good and bad behaviors on the Agentic Internet¶
Summary¶
Cloudflare's Web Integrity & Trust team (bots + fraud) lays out its strategy for the Agentic Internet, where the human/bot line blurs into hybrid sessions that shift from human to agentic and back mid-session. The organizing frame is Risk vs Trust — treated as independent but reciprocal values rather than opposite ends of one axis: Risk is how likely a single request/action is to be harmful and is ephemeral; Trust is reputation built up over time. The strategy is to move from static, point-in-time checks (CAPTCHAs, one-time hurdles — Risk-based, context-free) to continuous behavioral evaluation over the whole session (Trust-based, context-rich). The post shares production data from Precursor (the continuous client-side behavioral detection system launched a few weeks earlier), previews Adaptive Intelligence (a self-adjusting ML detection engine that replaces versioned model launches), introduces a set of bot-specific advanced mitigations designed to raise attacker cost without being deterministically reverse-engineerable (the "Bot Antibiotic Problem"), and launches an interactive Precursor Trace demo.
Key Takeaways¶
-
Risk vs Trust as independent, reciprocal values. "Risk is how likely something like a request or action is to be harmful, and it's often ephemeral. Trust, however, is built up over time, and it's based on reputation." The doorbell analogy: "Reject anyone who rings my doorbell more than 10 times" fails because Trust — recognizing your best friend on the door camera — is the essential ingredient, not a static rule on the action.
-
A spectrum of trust, not a binary. Cloudflare builds an ecosystem from blocking malicious activity at the bottom to encouraging participation in a safer Internet at the top — good behavior is rooted in transparency: 1) declare yourself honestly, 2) don't abuse the trust you've earned (the two-part Verified definition). Transparency is symbiotic: declaring who you are reduces friction for bots that site owners want to allow.
-
BotBase tracks bad actors too, not just good ones. Unlike the older Bots Directory (known-good only), BotBase is a directory of all known bots and agents. Because Cloudflare tracks and validates behavior for known-good actors, it can detect when those expectations aren't met — abuse of trust leads to being unverified.
-
Hybrid traffic is real and mid-session. "Behavior often shifts from human to agentic and back over a session" (e.g. a user browsing a store then handing checkout to a shopping assistant). Point-in-time detection misses suspicious behavior that happens mid-session; understanding intent matters so site owners don't block flows they actually want.
-
Precursor: continuous client-side behavioral detection. A JS detection injected via the CDN (no server-side setup), evaluating user behavior continuously throughout the session rather than once. Two load-bearing properties: (a) Trust-based detection over the entire session; (b) it drives up the cost for bot developers to replicate human behavior across a multi-page timeline — making it economically disadvantageous to outrun the detection is how Cloudflare "wins the adversarial game."
-
Precursor production numbers. In a 24-hour window: 206 million Precursor evaluation events across 73,438 zones. Validated hypotheses: suspicious behavior often happens mid-session (point-in-time can't catch it); behavior shifts human↔agentic within a session (motivating the behavior-based taxonomy).
-
Risk-based vs Trust-based detections. CAPTCHAs and one-time hurdles are Risk-based — they lack context. Verification via behavioral tells is Trust-based — it captures context clues from the full user session. Precursor is the tool that analyzes this behavior.
-
Adaptive Intelligence: a self-adjusting model. Historically Bots ML shipped as versioned model launches — "This pacing doesn't work when bots adapt on the scale of hours or even minutes." Adaptive Intelligence is a new detection engine where the model itself is adaptive — it continues to learn and self-adjust from observed traffic (good to bad), so customers no longer upgrade to a new model version to get the latest predictive detection. Coming to all Bot Management customers.
-
Determinism is the attacker's friend — the "Bot Antibiotic Problem." "Always sending bots a deterministic response (like a 403 block) makes it easy for a malicious developer bot to probe, observe, and reverse-engineer your defenses." Three advanced, bot-specific mitigations answer this:
- Unpredictability / random actions — randomly pick between block / challenge / allow for suspected automated traffic, breaking a bot's automated retry logic and fingerprinting.
- AI Labyrinth — trap unauthorized bots in a maze of AI-generated pages to waste compute and crawl budget via misdirection. Three modes: Maze (endless web of linked pages), Summary (LLM-generated real-looking-but-useless summary as training data), Poison (fake content — fake prices/inventory — to pollute collected training data).
-
Queuing for good bots — not all agentic traffic is bad; queue legitimate automated traffic (e.g. user-directed shopping agents) to manage throughput without denying service.
-
Disposable / dynamic rulesets. A great defense is predictive and self-correcting — "a system of 'disposable' rules, in which the ruleset is dynamic in nature. This is by design: if attacks constantly evolve, the defenses should, too." Both detections and mitigations aim to stay a step ahead without a security expert reactively hand-setting a fix.
-
Precursor Trace interactive demo. precursor-trace.cloudflare.app is live and traces your cursor movements using (part of) Precursor's detection mechanism — acceleration, self-correction, rhythm and texture of movement — the tells that separate human from bot.
Architectural Design Decisions¶
-
Risk and Trust as orthogonal axes. Modeling them as independent-but- reciprocal (rather than a single continuum) lets a high-Risk action from a high-Trust actor be allowed, and a low-Risk-looking action from a zero-Trust actor be scrutinized — the doorbell friend vs the frantic stranger.
-
Continuous session evaluation over point-in-time gates. Trust is accumulated across the session; abuse is caught mid-session. This is the operational counterpart to the 2026-04-21 "behavior, not species" framing and the 2026-07-01 behavior-based taxonomy.
-
CDN-injected client-side JS. Precursor's detection runs client-side, injected at the edge — no per-origin instrumentation, and no "free hall pass" for traffic that passes a single client/browser check once.
-
Economic-disadvantage design goal. The detection is deliberately designed to make replicating human behavior over a multi-page timeline expensive, shifting the adversarial game onto attacker economics rather than a single beatable check.
-
Adaptive model over versioned model. Removing the human-in-the-loop version-bump cadence to match bot adaptation on the scale of hours/minutes.
-
Non-deterministic mitigation by design. Random block/challenge/allow + misdirection (AI Labyrinth) + disposable dynamic rulesets deliberately deny attackers a stable signal to reverse-engineer.
Operational numbers¶
- 206 million Precursor evaluation events in a 24-hour window.
- 73,438 zones on the Cloudflare network running Precursor evaluations in that window.
- Advanced bot-specific mitigations (unpredictability, AI Labyrinth modes, queuing) slated to roll out closer to the end of the year, with site-owner-selectable strictness.
- Adaptive Intelligence: launch announcement "coming soon" to all Bot Management customers at the time of writing.
Caveats¶
- Roadmap-heavy. Adaptive Intelligence and the three advanced mitigations are previewed, not GA; no accuracy, false-positive, or latency numbers are disclosed for them. Precursor's 206M/73,438 figures are volume, not detection-quality, metrics.
- AI Labyrinth's Poison mode (serving deliberately fake content to suspected bots) is a misdirection tactic; the post does not discuss collateral risk to mis-classified legitimate agents.
- Precursor Trace exposes only part of the detection mechanism.
- The Risk/Trust framing is a strategy narrative; the post gives the conceptual model and production volume, not the scoring internals.
Source¶
- Original: https://blog.cloudflare.com/good-and-bad-agentic-behaviors/
- Raw markdown:
raw/cloudflare/2026-08-07-unveiling-good-and-bad-behaviors-on-the-agentic-internet-dec9e83f.md
Related¶
- sources/2026-07-01-cloudflare-ai-traffic-options — the behavior-based 10-category taxonomy + BotBase visibility plane this post operationalizes. Sibling: taxonomy defines what a bot is; this post defines how continuous behavior over a session is assessed against Trust.
- sources/2026-04-21-cloudflare-moving-past-bots-vs-humans — the framing post ("wanted bots, unwanted humans"); this 2026-08-07 post is its detection-layer companion, replacing the binary with continuous Risk/Trust behavioral evaluation.
- sources/2025-08-04-cloudflare-perplexity-stealth-undeclared-crawlers — the enforcement-precedent post; verified-bot-delisting as the "abuse the trust you earned → unverified" lever this post articulates.
- systems/cloudflare-bot-management — the enforcement plane hosting Precursor, Adaptive Intelligence, and the advanced mitigations.
- risk-vs-trust / continuous-behavioral-detection / hybrid-human-agentic-session / bot-antibiotic-problem / adaptive-ml-detection.
- systems/precursor / systems/adaptive-intelligence / systems/ai-labyrinth / systems/precursor-trace.
- companies/cloudflare.