AgentReady at agentready.market, operated by Villepinte Studio β€” the e-commerce transaction audit. Unaffiliated with other AgentReady-named products.

On September 15, 2026 Cloudflare changes its default rules for AI traffic: the Agent and Training classes are blocked by default on ad-carrying pages of newly onboarded domains, and the legacy “Block AI Bots” setting starts catching Googlebot. We took the announcement apart in Cloudflare’s September 15 AI defaults: what merchants must check. This page is the other half: what actually happened to real stores, measured before and after, with the protocol written down before the data exists.

The protocol, fixed on September 4

We are writing this on September 4, eleven days before the switch, so the method cannot bend to the result.

  • Population. Every store in our audit corpus whose most recent pre-flip scan recorded a Cloudflare response header (cf-ray or Server: cloudflare). That flag is a header fact the engine stores on every scan; it is not inferred.
  • Baseline. That most recent pre-flip scan, taken any day before September 15.
  • Measurement. From the morning of September 16, each store is re-audited once, in batches of forty per day until the population is exhausted. One pair per store: a before/after comparison, not a time series.
  • Outcome. The change in the audit’s Access pillar β€” the share of the access checks a shopping agent passes (robots policy for the agent class, WAF posture, crawlability, parity between what bots and humans receive). We also record whether the store became unbuyable (the audit’s “capped” state: an agent is stopped before it sees a single product).
  • What we will report. The count of stores measured, how many lost access points, how many became unbuyable, how many gained, how many were unchanged, and the ten largest losses by name. The table below is generated from the database at every page load. No number on this page is typed by a person.
  • What would falsify the worry. If fewer than one store in ten loses access points, the September 15 defaults are a non-event for existing stores and we will say so in this same paragraph’s live block. Newly onboarded domains, which the announcement targets first, are outside this population by construction: our corpus only holds stores that existed before the flip.

The measurement, live

Measurement scheduled. The post-flip rescan starts on September 16, 2026 and this table fills itself as the pairs come in β€” nothing here is written by hand.

The pairs come from cloudflare_flip, a scheduled job in the same audit engine that produces every score on this site. The Access pillar is one of four; the full method is on the methodology page.

What a merchant behind Cloudflare should do this week

The settings, not a rebuild. Two minutes in the Cloudflare dashboard decide which side of the default a store is on:

  1. Security β†’ Bots β†’ AI traffic. Check the per-class rules. If the Agent class reads “block”, shopping agents cannot load the store, whatever the product data says.
  2. Retire the single “Block AI Bots” toggle where it is still on. Since September 15 it also catches Googlebot on some configurations, which is a different problem with the same switch.
  3. Re-run the free scan afterwards. The Access pillar on the report shows whether the agent class gets through, and the report page keeps the before/after for you.

For the wider comparison between Cloudflare’s own agent-readiness score and a transaction audit, see Cloudflare’s agent readiness score vs AgentReady.

FAQ

Does Cloudflare block AI shopping agents by default?

From September 15, 2026, on ad-carrying pages of newly onboarded domains, yes: the Agent traffic class is blocked unless the operator changes the setting. Existing domains keep their configuration, which is exactly why this study measures existing stores rather than repeating the announcement.

How do I know whether my store is behind Cloudflare?

The audit records it from the response headers. Run the free scan; the Access pillar of the report says whether Cloudflare fronts the site and whether the agent class gets through.

Why publish the protocol before the numbers?

So the method cannot be adjusted to fit a result. The count, the pillar and the cutoff dates were fixed on September 4; the table above fills itself from the database from September 16 and is never edited by hand.

Sources