What happened
On its latest quarterly (Q2) earnings call, Cloudflare said the most quotable thing of the season: this quarter, more than half the traffic crossing its network was not human.
The crossover itself happened in June. On 3 June, CEO Matthew Prince posted his own dashboard on X: bot traffic averaging 57.4% over seven days against roughly 42.5% human, swinging between 52% and 62% within a single day. In the same post he admitted his forecast had been overtaken — he had expected late 2027, then revised to early 2027, and agentic traffic grew fast enough to arrive by mid-2026. The earnings line simply turned June’s live number into an official quarterly record.
One clarification before the headline misleads you: this counts requests, not reading. Humans are still the ones reading the articles and watching the videos. Machines win on request volume because a single agent answering one person’s question may sweep dozens of sites at once. So the correct reading isn’t “nobody is on the internet anymore.” It’s that more than half of what your server serves every day has no eyes.
Why it matters to you
Start with something you can verify today: open your GA and the line has probably barely moved.
Not because it broke — because it was never designed to count these visitors. Tools like GA depend on a page loading and running a snippet of JavaScript to report back, and most crawlers and agents never execute JS; the few that do get swept up by built-in bot filtering. Your traffic report has always covered only the half that arrives with a browser and a person behind it. The other half used to be small enough to ignore. It is now bigger than you.
Which means that when your agency walks through that report in the monthly review, every number on the table comes from the 42%. What is actually shifting — who reads your content, and whether they write you into the answer afterwards — sits entirely outside the table. (One client’s daily request count halved while unique visitors barely moved; we had to pull the raw server logs to find out who had disappeared. That story is here.)
Prince put the harsher, more useful version this way: AI agents don’t click ads. They don’t fill in forms, don’t watch the brand film on your homepage, and don’t stop for a promotional banner. They do one thing — read your content, then decide whether to mention you in the answer a human actually sees. On that half of your traffic, the only unit of value you have is being cited: no dwell time, no bounce rate, no clicks.
And the clock is running. 15 September is Cloudflare’s deadline for AI companies to separate search crawlers from training crawlers by identity, with anything still mixed getting blocked. We covered that line last month. Five weeks left.
Do you need to act now
One thing can wait: don’t go researching how to charge agents for access. Prince is building that machine-to-machine settlement layer himself, and he has publicly said he needs ten million transactions per second on day one — infrastructure that doesn’t exist yet. That’s his problem this year, not a line in your budget.
Here’s what does deserve a decision: stop letting “what a person can see” be the only thing that shapes your site. On the same page, a human sees layout, images, and flow; a machine reads whether it can establish in one pass who you are, what you do, why you’re credible, and which sentence it can lift whole. Those two jobs compete inside the same HTML, and twenty years of web production habits have optimised only the first.
Prince also offered a longer projection: on this slope, the machine-to-human ratio reaches 1:1000 within five years, and human presence online becomes a rounding error. Discount that one. His company sells the service that blocks these bots for you and bills AI companies for the crawl — the steeper the slope, the more that product is worth. He has also missed his own timeline twice already. Anyone promising you a timeline is selling something, and that applies to him too.
What holds up is the half that has already happened: more than fifty percent, across a full quarter, stated on an earnings call. And you don’t need the five-year date to start, because none of the preparation is wasted either way: a site a machine can read, fetch, and safely quote is not a worse site for people.
The hard part isn’t knowing to do it. It’s that the work never finishes. Crawler policy changes every quarter, every engine update reshuffles who gets cited, and your dashboard still won’t tell you what you lost. That’s a job somebody has to watch continuously.
If you want to know what you look like on the machine side of that split, we can take a look first.