Industry Pulse

Cloudflare's AI Training Opt-Out: What to Change This Week

A new network-level setting splits search crawling from AI-training crawling for the first time

Laptop screen showing analytics and performance graphs on a desk, warm natural light
Search visibility and AI training are now separate switches, not one tradeoff.Photo via Unsplash

The short answer

Cloudflare launched a 'Disallow AI Training' setting on 15 September 2026 that separates search crawling from AI-training crawling at the network level for the first time. Site owners can block crawlers that train AI models while Googlebot, Bingbot, and Applebot keep indexing them for search. It's a domain-level toggle in Security Settings, not a code change, and it doesn't affect search rankings.

Cloudflare shipped something on 15 September that fixes a genuine annoyance: until now, you could block AI companies from training on your content, or you could stay visible in Google. Not both — most robots.txt setups couldn't tell the difference between a crawler indexing you for search and the same company's crawler hoovering up text to train a model. The new Cloudflare AI training opt-out setting separates the two at the network level. If you publish anything you don't want regurgitated by a chatbot with the serial numbers filed off, this is a five-minute fix worth making today, not next quarter.

What is Cloudflare's AI training opt-out, exactly?#

It's a new domain-level control in Cloudflare's Security Settings, live as of 15 September 2026. Instead of one blanket allow/block for a crawler, Cloudflare now classifies bot traffic by intent — Search, Training, or Agent — and lets you block Training specifically, even from companies that used to send one crawler for everything.

Cloudflare calls Googlebot, Bingbot, and Applebot "Accountable" mixed-use crawlers, because Google, Microsoft, and Apple have committed to respecting the training opt-out without touching search indexing. Amazon, Anthropic, Meta, and OpenAI already run separate crawlers for search versus training, so blocking their training bots doesn't touch search at all. Cloudflare's own writeup has the full breakdown, including a public Radar dashboard tracking which operators actually comply.

Does this hurt my Google rankings?#

No. That's the entire point of the announcement. Googlebot is on Cloudflare's Accountable list, so switching your setting to "Disallow AI Training" leaves search indexing untouched — you're only cutting off the separate pipeline that feeds model training data.

I'll admit I read the first three summaries of this and assumed it was another "protect your content" gesture with no teeth. It isn't. The enforcement happens at Cloudflare's network layer, not by trusting a crawler to read your robots.txt and behave.

Who should actually turn this on#

If your site is a five-page brochure with a contact form, this changes almost nothing for you, and you can move on with your day.

If you run a blog people read for the writing, a pricing page competitors screenshot, original research, or documented case studies — the stuff that makes your AEO work worth doing in the first place — this is exactly the content training crawlers are pulling. GCC and European service businesses publishing compliance guides, US and Canadian SaaS teams with docs sites, Indian D2C brands with product education content: all of you have something in that second bucket, even if it's smaller than you think.

A five-minute checklist if your domain sits behind Cloudflare:

  • Open Security Settings for the domain
  • Set AI Training to "Disallow AI Training"
  • Leave Search on Allow — this is what keeps Googlebot indexing you
  • Leave or set Agent to "Block on pages with ads" if the site runs ads
  • Check Cloudflare's Radar dashboard occasionally to see which operators actually comply

The honest trade-offs#

Turning training off costs you nothing measurable today — no ranking hit, no traffic hit. The catch is on the upside: nobody has shown that opting out of training gets your brand mentioned more often when someone asks ChatGPT or Gemini a buying question. It might do nothing for citation volume. My honest read is that it's a defensive move, not a growth lever, and I'd frame it to a client that way rather than oversell it.

The other gap: this setting doesn't touch the crawlers powering live AI answers and citations, like the ones behind AI Overviews or a Search Console AI report. Cloudflare says granular per-operator controls for those are coming "early next year," which in practice means you're waiting on it, not deciding it.

How we're handling it at WebEpex#

We went through Security Settings on every client domain we run behind Cloudflare this week and set Training to "Disallow AI Training" while leaving Search on Allow — a five-minute change per domain, done before we touched anything else on the list. For ad-supported client sites we also left Agent traffic blocked on ad pages, which was Cloudflare's own recommended default and matched what we'd have configured by hand anyway.

At WebEpex we build content strategy and AEO work for GCC, European, US, Canadian, and Indian clients, and the honest reason we moved fast on this one is that it's free. There's no build, no migration, no code review. We didn't bother waiting for a "should we" conversation with anyone — we just flipped the switch and told clients after, in their weekly update.

What I'd tell a client asking about this#

Check whether you're on Cloudflare first — this setting doesn't exist if you're not. If you are, go to Security Settings this week and set AI Training to "Disallow AI Training." It's free, it's reversible, and it costs you zero search visibility. If you're not on Cloudflare and you publish content worth protecting, this is a reasonable nudge to move your DNS. If neither applies to you, doing nothing is also a fine answer this week — just don't confuse this setting with actually getting cited by AI answer engines, which is a separate, harder job.

If you want a second pair of eyes on whether your setup even has this lever to pull, send me your domain and I'll tell you straight — takes two minutes, no pitch attached. cal.com/webepex/growth-review

Sources

  1. Have it both ways: stay discoverable in search while disallowing AI training — Cloudflare Blog

Frequently asked questions

Straight answers to what people ask about Cloudflare AI training opt-out.

Does the Cloudflare AI training opt-out hurt my Google ranking?
No. Googlebot, Bingbot, and Applebot are Cloudflare's 'Accountable' mixed-use crawlers, meaning they keep indexing your pages for search results even when you block their AI-training data collection. Blocking training and losing search visibility are no longer the same switch.
How do I turn on the Cloudflare AI training opt-out?
If your domain sits behind Cloudflare, go to Security Settings and set the AI Training control to 'Disallow AI Training.' Existing customers' prior robots.txt-based preferences migrate automatically; new domains need to pick a setting themselves.
Should a small business even bother with this?
If your site is mostly a lead-gen brochure with no original writing, it changes little. If you publish original research, pricing pages, or a blog people read for the writing rather than just the facts, it's worth the five minutes — that's exactly the content training crawlers pull.
Does this affect AI Overviews or ChatGPT citing my content?
Not directly yet. This setting controls model-training crawlers, not the separate retrieval crawlers that power live AI answers and citations. Cloudflare says granular controls for those are coming 'early next year.'
Prakhar Vohra
Written by

Prakhar Vohra

Founder & Growth Lead

Founder & CEO - WebEpex & DevAegis, Co-Founder - Tattva Aura Events, I work 1:1 with founders & to build profitable & scalable revenue models

Want this run for you?

We build the system, run the ads and hold the number. Book a call and we will map it in 30 minutes.

Book a call