You are only affected by Cloudflare's September 15, 2026 default block if two things are both true: your site is a new Cloudflare property or on the free plan, and it serves ads on pages an AI crawler would reach. From that date, Cloudflare blocks Training and Agent bots by default on any page that displays ads, and treats "mixed-use" crawlers — ones that combine search with training — by all of their behaviors at once. Existing paid customers keep their current settings untouched, and a store with no ads on any page falls outside the trigger entirely.
We have been tracing this change from the crawler side while building Contexta, because the same default that protects a publisher's ad revenue can quietly cut a store out of AI answers when it catches a bot you actually wanted. Here is the exact test for whether it touches your site, the failure mode to watch, and what to verify once the date passes.
What exactly changes on September 15, 2026?
From September 15, 2026, Cloudflare's default settings block "mixed-use" AI crawlers on any page that displays ads, so that human attention — the thing an ad page is monetizing — is protected from bots that would substitute for it. Cloudflare sorts crawler behavior into three jobs: Search, which indexes your content to answer questions about it later; Agent, which acts in real time on a person's behalf; and Training, which absorbs your content permanently into a model.
The key mechanic is how it treats a bot that does more than one job. Cloudflare's own wording is that multi-purpose crawlers — specifically those that combine Search with Training — "will be allowed/blocked according to all of their behaviors," so a bot that both indexes and trains gets blocked on ad pages because of the training half. This is a default flip, not a new capability: Cloudflare has let sites block AI bots since July 2025, as covered in how Cloudflare's default AI-crawler block works. What is new is the ad-page trigger and a fixed calendar date.
Are you affected? The two conditions to check
You are hit by the default block only where both conditions hold: your site is a new Cloudflare customer, a new domain added by an existing customer, or on the free plan — and it serves ads on the pages a mixed-use crawler reaches. Existing paid Cloudflare customers keep their current configuration; nothing flips automatically, and Cloudflare has said it will keep notifying customers before the date.
That second condition rules out a large share of stores immediately. Most WooCommerce shops sell products rather than run display ad units (AdSense, an ad network, sponsored placements), so the ad-page trigger never fires for them regardless of plan. The sites genuinely in scope are ad-monetized: content blogs, recipe and news sites, and stores whose blog section carries ads — on free-tier or newly onboarded Cloudflare.
Will this cut your store out of AI answers?
Only on pages that both serve ads and sit on an affected Cloudflare configuration — but where it does bite, the risk is real, because a mixed-use block judges a bot by all its behaviors and can shut out a crawler you wanted for search or AI visibility. A bot that indexes your pages for search but also trains on them gets blocked on your ad pages for the training half, and it takes its search visit with it.
This over-blocking is the failure mode we watch for. Cloudflare's taxonomy tries to keep Search separate from Training, but a crawler that will not cleanly split its purposes is handled by its most invasive behavior, so an ad-monetized page can lose the exact bot that was putting it into AI answers — the same disappearance behind why AI assistants stop citing a site. The only reliable way to know which bots still reach a given page is to fetch it as each one. Contexta's AI Visibility check does this directly: it requests your pages as GPTBot, OAI-SearchBot and PerplexityBot, flags where Cloudflare is blocking them, and confirms whether the content is readable without JavaScript.
Is this the same as Cloudflare's Pay Per Crawl?
No — the September 15 block is a default setting that decides whether a bot is stopped, while Pay Per Crawl is Cloudflare's marketplace for charging bots to access content, now evolving into "Pay Per Use." The block governs access on your ad pages; Pay Per Use governs payment, letting publishers earn when their content is actually used rather than only when it is fetched, starting with partners Ceramic.ai and You.com.
The two work in opposite directions and it helps to keep them straight. One is a wall you can raise or lower per bot category; the other is a toll you can charge once a bot is through. If the money side is where your interest sits, the mechanics are in Cloudflare's pay-per-crawl model for AI crawlers.
What should you check once September 15 passes?
Confirm three things: which Cloudflare plan and AI-traffic settings your site runs, whether any of your pages serve ads, and whether the bots you care about can still fetch those pages after the date. If you are an existing paid customer, verify your zone has not been switched to the new defaults; if you are on the free plan or adding a new domain, open the AI-traffic controls in your Cloudflare zone settings before the 15th and set them deliberately rather than inheriting the block.
Then decide which crawlers you actually want through, because the answer is not "all" or "none." A search-and-answer bot like OAI-SearchBot earns its access differently from a pure training crawler, and which AI crawlers to allow and which to block walks through the trade-off bot by bot. Set the policy on purpose, then re-test after the date to confirm the pages you rely on are still reachable by the bots that cite you.
FAQ
Does Cloudflare's Sept 15 2026 block apply to existing paid customers?
No — existing paid Cloudflare customers keep their current settings, and nothing changes automatically on September 15. The new default applies to new Cloudflare customers, new domains added by existing customers, and all existing free-plan sites. Paid customers can confirm they want no changes in their zone settings before the date.
What counts as a "mixed-use" crawler under the new policy?
A mixed-use crawler is a bot that combines more than one behavior — specifically Search plus Training — and it is judged by all of its behaviors at once. Cloudflare defines three jobs: Search indexes content to answer questions later, Agent acts in real time for a person, and Training absorbs content into a model. A bot that searches and trains gets blocked on ad pages for the training half.
My WooCommerce store has no ads — am I affected?
No — the block only applies to pages that display ads, so an ad-free storefront falls outside the trigger regardless of your Cloudflare plan. Most WooCommerce shops sell products rather than run ad units, so they are not in scope. The sites genuinely affected are ad-monetized blogs, news and recipe sites, or stores whose blog section carries ads on free-tier or new Cloudflare properties.
How do I check whether AI bots can still reach my pages after Sept 15?
Fetch each page as the specific bot you care about — GPTBot, OAI-SearchBot or PerplexityBot — and confirm it is not being blocked at the Cloudflare edge. A live per-bot fetch test is the only reliable way to see what each crawler actually receives, since a robots.txt allowance does not guarantee the edge lets the bot through. Re-run the test after the date to catch any default that flipped.
