On September 15, 2026, Cloudflare will change its defaults. New domains and existing free customers who haven't adjusted their settings will automatically block AI agent traffic on pages displaying ads. Training crawlers get blocked too. Search crawlers pass through. Site operators can override any of this in a dashboard, category by category.
The architecture behind that dashboard deserves attention. Cloudflare hasn't just built a toggle. It has built a classification system that distinguishes AI traffic by purpose: Search (crawlers indexing content), Agent (automated real-time activity on a person's behalf), and Training (crawlers collecting data to train models). The default posture for agents, come September, is closed. You want access? The site operator decides, on the site operator's terms.
Cloudflare proxies a large fraction of the web. When it ships a default, that default becomes the web's posture until someone actively changes it. Most people never change defaults. This is how infrastructure shapes behavior at scale: not through mandates, but through what happens when no one makes a choice. The architecture of inaction becomes the architecture of policy.
The reflex extends well beyond traffic classification. Really Simple Licensing, or RSL 1.0, published in December 2025, defines a machine-readable vocabulary for usage rights, licensing terms, and payment requirements that automated systems can discover and interpret. Over 1,500 media organizations, brands, and technology companies have announced support for the standard, including The Associated Press, The Guardian, Stack Overflow, and Vox Media. How widely RSL is actually deployed on live sites today remains unclear. But the specification exists, the endorsements are real, and the direction is legible: the web is constructing infrastructure to express permission in terms machines can parse, so that the absence of permission becomes equally parseable.
Payment networks are doing something structurally parallel. Visa's partnership with OpenAI and Mastercard's Agent Pay both build agent-specific credentialing, spending caps, and merchant-category restrictions into the transaction rails. An agent doesn't just pay. It pays within boundaries the cardholder and the network define together. The authorization side is taking shape quickly. The dispute side, notably, remains thin. Public materials describe fraud monitoring and consumer protections but do not yet identify a distinct dispute category for the specific failure that agent-mediated commerce introduces: the user consented, the merchant processed correctly, and the agent in the middle translated intent badly. When the first wave of these disputes arrives, the existing chargeback categories won't have a name for what went wrong. Someone will need to build one.
Payment networks have built the rails for agent commerce. They have not yet built the dispute categories for when the agent translates intent badly.
What connects Cloudflare's traffic classification, RSL's licensing vocabulary, and the payment networks' credentialing rails is that none of them waited for agents to demonstrate trustworthiness. Each counterparty looked at the acceleration heading toward it and built its own architecture of recognition and control. The web is deciding what agent access looks like. Payment networks are defining what agent spending looks like. Content owners are specifying what agent licensing looks like. In every case, the entity on the receiving end is asserting terms, not accepting them.
The practical boundaries of what agents can do will be set less by what they accomplish in a demo and more by what the receiving world has decided to permit, verify, and price. The web learned, over two decades of bots and scrapers and ad fraud, what happens when you extend trust by default and build defenses later. It is building the defenses first this time. The interesting question is whether the organizations deploying agents have noticed that the counterparties already have.

