Cloudflare launches bot engine it says retrains continuously on live traffic

Cloudflare says Adaptive Intelligence continuously retrains the model behind Bot Score on live traffic. Pricing, performance data and release dates for two planned components remain undisclosed.

By · Published

Primary source: The Cloudflare Blog

Why it matters

Cloudflare says it analyzes more than one trillion requests each day for automated abuse and that the machine-learning model behind Bot Score now retrains continuously on live traffic. Buyers still lack benchmarks showing whether that loop improves detection without increasing false positives, while the disposable rules central to Cloudflare's attack-economics pitch have yet to launch.

Cloudflare starts continuously retraining bot defenses, with disposable rules still ahead — The launch revives Project Honey Pot's founding thesis, but the short-lived rules meant to raise attackers' costs have yet to ship.

Cloudflare, founded by Matthew Prince, Michelle Zatlyn and Lee Holloway, launched Adaptive Intelligence on August 31, 2026. Cloudflare says its first component gives Bot Score a machine-learning model that retrains continuously on live traffic instead of waiting for fixed model releases.

Prince and Holloway began Project Honey Pot in 2004 to track how spammers harvested email addresses. Zatlyn had held roles at Google and Toshiba and helped launch two startups, according to Cloudflare's leadership biography.

Adaptive Intelligence carries that founding premise into a market where attack tooling changes faster. Bot operators can distribute login attempts, scraping or checkout abuse across residential proxies, rotate browser fingerprints and keep request volumes from any single address low. Cloudflare says AI has reduced the effort required to configure and revise those attacks, widening the gap between attackers that adapt continuously and defenses shipped through managed releases.

Cloudflare describes its response as an automated cycle that analyzes traffic, retrains the detection model and tests candidate versions against live requests before deployment. Cloudflare argues that more frequent updates can keep its bot scores closer to current attack behavior than models issued on a fixed release schedule. Cloudflare has not provided comparative performance data to establish that result.

Continuous retraining ships first

The August 31 release puts continuous retraining behind Cloudflare's existing Bot Score, which combines machine learning with behavioral validation, JavaScript fingerprinting, heuristics and checks for verified bots such as search crawlers. Enterprise customers can continue using that score in existing policies while the underlying machine-learning model changes more frequently, according to Cloudflare's launch post.

Cloudflare's bot-detection documentation says its systems evaluate network signals and browser-session behavior. Adaptive Intelligence also draws on browser-session behavior from Precursor, Cloudflare's behavioral detection system for measuring activity across a browser session.

Cloudflare says its engine runs candidate defenses against live traffic before deployment, with the stated goal of limiting false positives.

Cloudflare has not disclosed the model architecture, training-set size or retraining cadence. "Continuously" describes the replacement of scheduled model releases, but Cloudflare has not said whether updates reach production within minutes, hours or days of a new attack pattern appearing.

Disposable rules are still to come

Cloudflare's blog says Adaptive Intelligence will have three components: continuous model improvement, disposable rule generation and learning from protected traffic. Only continuous retraining launched on August 31. Cloudflare describes the other two components as "soon to follow."

The planned disposable-rule system is designed to generate narrow defenses for a specific attack, deploy them and retire them at varying intervals. Cloudflare's theory is that changing rules would contaminate the feedback attackers use to reverse-engineer a defense. A rule could disappear before an operator recovered enough consistent test results to identify the signal being blocked.

Disposable rules carry much of Cloudflare's economic argument. Continuous retraining can help the model follow changing traffic, while the planned rules are intended to make adaptation less predictable and more expensive. Cloudflare has not published measurements showing how long such rules would remain active, how frequently they would rotate or how much additional infrastructure and labor they would require from an attacker.

For the third component, Cloudflare says Adaptive Intelligence will learn from patterns observed across millions of sites. Customer corrections and misses identified through Cloudflare's own measurements could become training signals. A legitimate visitor incorrectly classified as automated traffic, for example, could inform a later model update. The launch post does not provide a release date for this component.

Dane Knecht carries the product thesis

Dane Knecht, Cloudflare's chief technology officer, joined Cloudflare when it had fewer than 30 employees. Before Cloudflare, Knecht founded an acquired e-commerce software company and held product roles at MessageOne and Dell. Cloudflare's account of his tenure identifies later roles including head of product strategy and senior vice president of Emerging Technology and Incubation before he became CTO.

Cloudflare has unusual distribution for testing that thesis. According to Cloudflare's press kit, its network spans at least 335 cities in more than 125 countries. Cloudflare says in its Adaptive Intelligence launch post that it analyzes more than one trillion requests per day for automated abuse. The press kit says Cloudflare protects 20% of all websites and counts 42% of the Fortune 500 as customers.

Cloudflare's 2025 annual report reported $2.168 billion in revenue, up 30% year over year, and approximately 332,000 paying customers in more than 190 countries as of December 31, 2025. Cloudflare also had approximately 5,156 employees at the end of the year, according to the annual report. Those figures cover the full product portfolio. Cloudflare has not disclosed how many customers use Bot Management or Adaptive Intelligence.

Cloudflare entered the public markets in 2019 after raising more than $330 million privately. Its final private round raised $150 million led by Franklin Templeton, with prior backing from investors including New Enterprise Associates, Union Square Ventures, Venrock, Pelion Venture Partners, Greenspring Associates, CapitalG, Microsoft, Baidu, Qualcomm and Fidelity. Adaptive Intelligence is a product launch with no new financing attached.

Pricing and terms remain unpublished

Cloudflare has not disclosed Adaptive Intelligence pricing or contract terms.

Those omissions make the release difficult to compare on operating cost. Buyers also lack data showing how quickly the product responds to a new bypass or how its results compare with the fixed model it replaces.

The economics pitch has competition

Cloudflare says it believes no other bot-detection product works this way. Cloudflare has not published evidence establishing that market-wide claim. Competitors already market adaptive detection or economic deterrence. DataDome describes continuous learning and real-time adaptation, while Arkose Labs markets adaptive challenges designed to make attacks unprofitable.

DataDome separately says it analyzes 5 trillion signals per day and returns detection decisions in under two milliseconds. Akamai Bot Manager, another competitor, says its scoring system learns over time, uses defenses intended to conceal detection signals and can impose computational costs on suspected bots. Kasada, a managed bot-mitigation provider, raised $20 million in February 2026, showing continued investor interest in the category.

Cloudflare's potential distinction is the planned combination of global network telemetry, browser-session behavior and automatically changing disposable detections. Cloudflare's installed base could supply a large and varied stream of attack data. Scale alone does not establish better detection, particularly when false positives can lock legitimate users out of logins, checkouts and account-recovery flows.

Cloudflare has not published changes in detection rates, false-positive rates, challenge rates or attacker costs. Cloudflare has not identified the architecture or size of the model, the release timing for learning across protected sites, or production results from early customers. According to Cloudflare's launch post, disposable rules and cross-site learning remain forthcoming. Its claim that Adaptive Intelligence can reverse attack economics still lacks public performance evidence.

Reader comments

Conversation for this story loads after sign-in.