SYSTEM Cited by 2 sources
Precursor¶
Precursor is Cloudflare's continuous client-side behavioral detection system for identifying subtly-inhuman bot traffic that network-signal analysis alone misses. Launched a few weeks before the 2026-08-07 post, it is the tooling embodiment of Cloudflare's Trust-based detection posture: rather than a one-time gate, it evaluates user behavior continuously throughout the session.
Architecture¶
- CDN-injected JavaScript. When a customer enables Precursor, the JS detection is injected at the edge — "it doesn't require sitting at the computer and figuring out where or how to rerun these detections." No per-origin instrumentation.
- Continuous session evaluation. Precursor scores behavior across the entire session — "no more free hall passes for abusive traffic that found a way to pass client and browser-side checks just once." This is the canonical wiki instance of continuous-session-behavioral-detection.
- Behavioral tells. It analyzes signals like cursor acceleration, self-correction, and the rhythm/texture of movement — the involuntary micro-behaviors of a real human interacting with a computer (exposed partially through the Precursor Trace demo).
Why it works (the two load-bearing properties)¶
- Trust-based detection over the whole session — captures context clues a point-in-time Risk-based check (CAPTCHA, one-time hurdle) structurally cannot.
- Drives up bot-developer cost — replicating human behavior over a multi-page timeline is expensive. By making evasion economically disadvantageous, Cloudflare frames this as how it "wins the adversarial game" — the design goal is attacker economics, not a single beatable check.
Production data (2026-08-07, 24-hour window)¶
- 206 million Precursor evaluation events.
- 73,438 zones running Precursor evaluations.
Patterns validated at that scale:
- Suspicious behavior often happens mid-session — point-in-time detection wouldn't catch it.
- Behavior often shifts human → agentic → human within a session (see hybrid-human-agentic-session), reinforcing the need for a behavior-based taxonomy so site owners handle traffic by use case rather than blocking wanted flows.
Relationship to other systems¶
- systems/cloudflare-bot-management — Precursor is the client-side behavioral-detection engine feeding the enforcement plane; complements the network-signal / ML fingerprinting detections with client-observed behavior.
- systems/adaptive-intelligence — sibling detection engine on the server/ML side; Precursor supplies the session-behavior signal, Adaptive Intelligence is the self-adjusting predictive model.
- systems/precursor-trace — public interactive demo exposing part of Precursor's cursor-analysis mechanism.
Seen in¶
- sources/2026-08-07-cloudflare-unveiling-good-and-bad-behaviors-on-the-agentic-internet — canonical wiki instance; first production-data disclosure (206M events / 73,438 zones in 24h).
- sources/2026-09-29-cloudflare-adaptive-application-security-for-the-ai-era-how-cloudflare — the "govern access and agent behavior" stage: Precursor supplies the client-side and session-level signals (typing cadence, mouse movement, navigation patterns, action sequences — e.g. an agent that navigates a checkout in two seconds, skipping browsing/comparison) that distinguish human from automated behavior across a whole session.
Related¶
- continuous-behavioral-detection — the concept Precursor is the canonical instance of.
- risk-vs-trust — the Trust-based-vs-Risk-based framing.
- hybrid-human-agentic-session — the traffic shape Precursor is built to handle.
- companies/cloudflare.