Skip to content

SYSTEM Cited by 1 source

AI Labyrinth

AI Labyrinth is a Cloudflare defensive mitigation that traps unauthorized bots in an endless maze of AI-generated web pages, wasting their compute and crawl budgets through misdirection rather than a deterministic block. It is one of three advanced, bot-specific mitigations Cloudflare designed as an answer to the Bot Antibiotic Problem — always returning a deterministic response (like a 403) lets a malicious developer probe, observe, and reverse-engineer the defense.

Three modes

Site owners choose the strictness of misdirection:

  • Maze — generates an endless web of linked pages for bots to follow, burning crawl budget on content that goes nowhere.
  • Summary — feeds crawlers an LLM-generated summary of a page that looks real but is entirely useless as AI training data.
  • Poison — serves deliberately fake content (e.g. fake prices or inventory) to a bot, polluting the data it collects for AI training.

Design posture

AI Labyrinth is the canonical wiki instance of ai-labyrinth-misdirection — a waste-attacker-resources mitigation that denies the attacker a stable, reverse-engineerable signal. It sits alongside two sibling mitigations in the same 2026-08-07 posture:

  • Unpredictability / random actions — randomly choosing block / challenge / allow for suspected automated traffic (unpredictable-response-mitigation).
  • Queuing for good bots — throttling legitimate agentic traffic (e.g. user-directed shopping agents) instead of denying it (queue-good-bots).

All three are slated to roll out closer to the end of the year with site-owner-selectable strictness.

Relationship to other systems

Seen in

  • bot-antibiotic-problem — the determinism failure mode AI Labyrinth answers.
  • ai-labyrinth-misdirection — the pattern it instantiates.
  • companies/cloudflare.
Last updated · 766 distilled / 2,225 read