The full letter didn’t load, so I’m searching for the key claims and using the provided summary as the source of truth.TITLE: Well, the Humans Lost the Traffic Vote

Cloudflare picked its sixteenth birthday to say the quiet part with a nicer font. The company launched on September 27, 2010 in front of people using browsers. Sixteen years later, to the day, the 2026 founders’ letter says automated traffic has surpassed human activity. Your cybersecurity program still treats a login as something a person does with a keyboard. Most of what hits your edge this week will do nothing of the sort.

The letter wants a fair web for AI agents and new creators. You inherit the part where those agents share a request shape with credential stuffing.

Your Logs Called This Years Ago

If you’ve been reading 401s and 429s for a living, none of this is a surprise. Your access logs have been majority non-browser for a long time: uptime probes, partner APIs, CI runners, SEO crawlers, scrapers that ignore robots.txt, and a growing set of assistants that fetch ten endpoints before a human even opens a tab. Cloudflare writing it into an anniversary letter just means the traffic mix is now a sentence a board can repeat.

Graphic from Cloudflare's 2026 annual founders' letter on automated traffic and the changing web
The anniversary note makes the traffic census official. Your SIEM already had the numbers.

Agents don’t browse. They retrieve, retry, fan out, and chain tools. That cadence used to be how you spotted a brute-force run against SSH, RDP, or the customer portal. It’s also how a legitimate integration behaves on a Monday when a model decides to reconcile invoices. If your threat-protection logic is many requests, short interval, cloud ASN, you’ll page on your own vendors and miss the stuffing campaign that throttled itself on purpose.

The founders talk about creators and sustainability. Cute. Your problem is authorization for machines that never agreed to your cookie banner. A polite user-agent and a delegated OAuth token can look identical at a firewall that only sees verbs, paths, and status codes. One of those is a product. The other is how a tenant walks out.

You already paid for defense in depth that assumed the outer layer could tell people from scripts. That layer is now guessing in a population where scripts are the median visitor. The humans are still there. They’re no longer the denominator you sized the platform around.

Cybersecurity Still Expects Someone at the Keyboard

CAPTCHA theater, bot scores, and impossible-travel alerts were built when automation was the suspicious minority. Flip the base rate and those signals get noisy fast. A cloud IP is where your payroll app lives and where a rented proxy farm lives. A headless client is your synthetic monitor and the first hop of an account-takeover kit.

Rate limits trip internal jobs. IP reputation lags by hours while serverless egress rotates in minutes. Allowlists from a 2022 vendor onboarding become permanent holes because nobody wants to be the person who breaks billing. Your SIEM still labels non-browser as noteworthy. Non-browser is the job.

Threat detection that waits for a human-shaped session will stay quiet while an agent with a stolen refresh token empties an API. Cookies, consent banners, a slowly typed password: none of that shows up when the caller is a tool loop. Cyber security teams keep buying more scoring. The gap is simpler. You never issued a first-class identity to the machines you actually wanted on the network.

Brute-force still works. It hides in the same histogram as a helpful agent doing retries. If you only graph request volume, you’ll tune the threshold until both the attack and the business survive. That’s how you get a dashboard that’s green and a helpdesk that isn’t.

Admin planes are a different animal. SSH, RDP, WinRM, and the VPN concentrator still see classic password spraying. Mixing those logs with your public API is how a real stuffing burst gets averaged into agent noise. Split the planes or you’ll tune for the wrong population.

Stop Banning Subnets and Start Binding Identities

You need a split you can defend on a bridge call, not a vibe that says this feels like a bot. Do the next four things this week. They work without a new platform purchase.

  • Inventory every non-human caller: CI, monitors, partners, RPA, AI agents, backup jobs. Name an owner and a token expiry. If you can’t name it, it doesn’t belong on the allowlist.
  • Bind those callers to workload identity or short-lived tokens scoped to the API they need. Static keys in serverless environment variables are how the agent becomes whoever phished the intern.
  • Move autoban off raw source IP as the only signal on public APIs. Controls in the ipban family still earn their keep on Windows jump hosts and SSH; commercial builds such as IPBan Pro fit that admin-plane job. They shouldn’t hold a veto over every cloud ASN that talks to your customer API.
  • Give agents a separate front door: dedicated hostnames, separate rate-limit classes, separate logs. The human login path shouldn’t share fate with a model that retries two hundred times.

Keep going after that. Review allowlists on the same calendar as firewall changes. Stale vendor IPs are standing access. Log user-agent, token ID, and workload identity together so analysts can ask which principal did this instead of which country. Tabletop a night where an approved agent starts calling unapproved methods. Security hardening here is least privilege on tokens, mTLS or signed requests for partners, and a kill switch that revokes a client ID without taking the website down.

If you can’t revoke an agent without a maintenance window, you don’t have incident response. You have a hope.

Incident Response When the Caller Has No Pulse

When automated traffic is the majority, a runbook that starts with disable the user account misses the common case. The caller may be a service principal, a partner client, or a browser-automation box in a contractor’s cloud. Containment is token revocation, client-id blocks, and a route-level shutdown of the agent hostname. You can disable the human later if a human was involved.

Preserve evidence that still exists when the other side is ephemeral compute. Signed request headers, token jti values, and the mapping from client ID to owner will outlive a hyperscaler source IP. That IP will be gone before you finish the bridge.

Practice two plays until they are boring. One is block this botnet. The other is this approved agent exceeded its contract. The first is threat-protection. The second is a business conversation with a kill switch already wired. Confusing them is how you DDoS yourself during a real event.

The founders’ letter will get quoted as a vision for the web. Quote it internally as capacity planning for both abuse and access. The majority population out there no longer types. Your controls have to authenticate work, not faces.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.