Skip to main content
LLMgram · AI News · 2026-09-15

Cloudflare lets sites block AI training while staying search-visible

Cloudflare lets sites block AI training while staying search-visible

Cloudflare is giving site owners a way to remain discoverable while disallowing AI training, introducing new controls and an Accountable designation that establish a shared model with Apple, Google, and Microsoft for mixed-use AI crawlers. Publishers can now signal training refusal without sacrificing search visibility through Cloudflare's controls. Anthropic's separate threat intelligence report documents eight months of Claude abuse, illustrating why training-data boundaries matter. Chinese AI labs including Alibaba's Qwen team, DeepSeek, and Moonshot AI relayed requests en masse or extracted training data, with Qwen alone accounting for more than 151 million exchanges. Actors also used Claude for missile software and autonomous kamikaze drones. Site operators gain a vendor-backed split between discovery and training, while model providers confront API-scale distillation attempts.

Sources

Cloudflare lets sites block AI training while staying search-visible

Cloudflare lets sites block AI training while staying search-visible

Cloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountable designation establish a shared model with Apple, Google, and Microsoft.

Key takeaway

Cloudflare's Accountable designation lets publishers block AI training crawlers while keeping content visible in search through a shared Apple-Google-Microsoft model.

What happened

Cloudflare announced new controls and an Accountable designation that let site owners stay discoverable in search while disallowing AI training, establishing a shared approach with Apple, Google, and Microsoft for mixed-use AI crawlers.

Anthropic's new threat intelligence report documents eight months of Claude abuse, with Chinese AI labs including Alibaba's Qwen team, DeepSeek, and Moonshot AI relaying requests en masse or extracting training data; Qwen alone accounted for more than 151 million exchanges, and actors also used Claude for missile software and autonomous kamikaze drones.

Evidence

  • Cloudflare introduced controls and an Accountable designation with Apple, Google, and Microsoft for mixed-use AI crawlers.

    Cloudflare AI · attributed

    New controls and an Accountable designation establish a shared model with Apple, Google, and Microsoft.

  • Site owners can stay discoverable while disallowing AI training.

    Cloudflare AI · attributed

    Cloudflare is giving site owners a way to stay discoverable while disallowing AI training.

  • Anthropic documented eight months of Claude abuse in a threat intelligence report.

    The Decoder · attributed

    Anthropic's new threat intelligence report documents eight months of Claude abuse.

  • Qwen alone accounted for more than 151 million exchanges tied to training-data extraction.

    The Decoder · attributed

    with Qwen alone accounting for more than 151 million exchanges

  • Actors used Claude for missile software and autonomous kamikaze drones.

    The Decoder · attributed

    Actors also used Claude for missile software, autonomous kamikaze drones

Why it matters

Publishers and API operators now face parallel defenses against industrial-scale training extraction, spanning web crawling policy at the edge and API abuse documented against frontier models.

Limits and uncertainties

The Decoder analysis notes Anthropic's report lacks verification of whether extracted data was successfully used to improve competitor models.

Practical implications

Builders and researchers should treat frontier model APIs as targets for data distillation and enforce rate limiting, anomaly detection, and strict usage policies.

Site operators on Cloudflare can adopt Accountable controls to separate search discoverability from AI training permission without a binary opt-out.

What to watch

Whether Apple, Google, and Microsoft crawlers consistently honor Cloudflare's Accountable designation in production traffic.

Whether Anthropic's countermeasures reduce ongoing large-scale extraction attempts such as the 151 million Qwen-linked exchanges.

Sources

LLMgram editorial selection and synthesis · @llmgram. LLMgram is not the original publisher of this information.
Continue on LLMgram: Open in AI Signal →
Original reporting: Have it both ways: stay discoverable in search while disallowing AI training