Automated traffic overtook human traffic on the web in May 2026, according to Cloudflare's 2026 annual founders' letter, published September 27 to open the company's sixteenth birthday week. The company had previously forecast that crossover for the second half of 2027. Agents and AI crawlers pulled it forward by more than a year, and Cloudflare now projects automated traffic reaching roughly 1,000 times human traffic within five years — a figure it calls conservative if current trends hold.
Key takeaways
- Cloudflare says the automated-versus-human traffic crossover happened in May 2026, ahead of its own second-half-2027 forecast, and projects 1,000x human traffic in five years.
- More than half of what well-behaved bots fetch has not changed since their previous visit, making a large share of crawl load pure waste.
- The company frames agent traffic as a tragedy of the commons: an agent may read 1,000 restaurant menus to recommend one, leaving 999 sites with the serving costs and nothing in return.
Why the crossover arrived early
The shift is not a story about people using the web less. Cloudflare is explicit that the crossover is not a matter of human traffic falling away; the curve moved because agent traffic is expanding far faster than the company modelled. An AI agent asked to find a flight or a cheaper phone plan will read more pages in a minute than a person manages in an afternoon, and it does so on every request.
That is a different load profile from the one CDNs were built around. Human sessions are bounded by attention. Agent sessions are bounded only by the task, and the task is often exhaustive by design.
The 999 restaurants problem
Cloudflare's central argument is economic rather than technical. If an agent surveys a thousand nearby menus to recommend one lunch spot, one restaurant wins the business and the other 999 absorbed the cost of serving a visitor who was never going to buy anything.
The people benefiting from that legwork are not the ones paying for it, so nothing in the loop encourages restraint — the textbook setup for a tragedy of the commons. The letter also raises a second-order risk: because agents tend to favour whoever they have the most information about, and that is usually whoever has been around longest, agent-mediated commerce may quietly raise the barrier for new entrants and push markets toward consolidation.
Wasted fetches are the tractable part
One number in the letter points at an unusually fixable problem. Cloudflare's data suggests more than half of what good bots fetch has not changed since their last visit, because crawlers still crawl the way search engines always did: everything, repeatedly, changed or not.
The company says it has been working to let crawlers see more of the web while fetching only what is new, which cuts load without cutting coverage, and separately to give anyone publishing content or applications a way to get paid when agents use their work. That builds on the crawler-declaration scheme Apple, Google and Microsoft signed on to earlier this month. More partnerships are promised during birthday week.
The web is growing again
A quieter finding cuts against the prevailing gloom. By some measures the web plateaued or shrank between 2012 and 2025, then saw an explosion of new sites from mid-2025 onward. Cloudflare says AI slop accounts for some of that but not most of it; the bigger driver is people with ideas and no coding background shipping real things with vibe-coding tools. It counts more than 7 million developers on its developer platform.
What to watch next
The letter is a position paper as much as a measurement, and the position is self-interested: Cloudflare measures this traffic on its own network and sells the products that would meter it. The figures are its own and have not been independently audited. Still, the 1,000x projection sets a concrete test. If automated traffic scales anywhere near that while per-fetch compensation stays theoretical, the cost of being crawled becomes a line item every small site has to reckon with.
FAQ
Does automated traffic passing human traffic mean the web is mostly bots now?
By Cloudflare's measurement of its own network, more automated requests than human requests now cross it, which happened in May 2026. That is a statement about request volume, not about people abandoning the web — Cloudflare attributes the crossover to exploding agent traffic rather than to any expected decline in human traffic.
What is Cloudflare proposing to fix the crawl-cost imbalance?
Two things: conditional crawling so bots retrieve only content that has changed since their last visit, and a mechanism for site owners to be paid when agents use what they publish. Neither fully removes the cost of serving agents; they reduce waste and create a route to compensation.
Are these numbers verified by anyone outside Cloudflare?
No. The crossover date, the 1,000x five-year projection and the share of unchanged bot fetches all come from Cloudflare's own network telemetry as presented in the founders' letter, and should be read as vendor-reported.






