Cloudflare removed its promise not to bill for bad bot requests

Stani Mihov
Founder & CEO
·

TL;DR
What changed:
Cloudflare's Service-Specific Terms are now dated September 28, 2026, replacing the version dated June 2, 2026.
The Bot Management section is gone, and with it the sentence "Customer will not be billed for any requests that Cloudflare reasonably determines were generated by bad bots."
Nothing replaced it, so the terms do not say that bad bot requests are now billed, and they no longer say that they are not.
AI models and search services offered through Workers AI and AI Gateway are now provided "AS IS" and "AS AVAILABLE."
New terms for a service called Monetization Gateway make you "solely responsible" for any transactions, disputes, or payments liability.
Cloudflare's promise not to train generative AI on customer content, unless otherwise agreed, did not change.
What to do: Check how your Cloudflare plan counts requests, and ask for written confirmation of whether requests from bad bots are billed.
The change
Cloudflare sits in front of a large share of the web: it speeds up sites, blocks attacks, and filters automated traffic. Its Service-Specific Terms add product-by-product rules to the main customer agreement and are published as six pages. All six now show "Last updated: September 28, 2026." The previous version was dated June 2, 2026.
Most of the edits are housekeeping. Three are not. One removes a billing promise from the Application Services page, one rewrites the rules for third-party AI models on the Developer Platform page, and one adds terms for a new payments service on the Other Terms page. The billing change is the one most customers will care about, and it is a single deleted sentence.
What changed
Bot Management. The whole section was deleted. It had one sentence, which said customers would not be billed for requests from bad bots.
Third-party AI models and search. Models and search services offered through Workers AI and AI Gateway are now made available on an "AS IS" and "AS AVAILABLE" basis, and they count as third-party products "whether or not you have entered an agreement with the third-party provider."
Monetization Gateway. A new section covers a service "designed to help you configure and exchange HTTPS headers in connection with x402, peer-to-peer payments."
AI code review. A new paragraph in the Security Operations Center section covers Vulnerability Discovery and Remediation, in which Cloudflare uses AI tools to review customer code and propose patches.
Housekeeping. The introduction no longer mentions Professional Services or a Statement of Work, and several references to the "Subscription Terms" now say "Agreement."
The sentence that was removed
Until September, the Application Services page had a section headed "Bot Management." It read, in full: "Customer will not be billed for any requests that Cloudflare reasonably determines were generated by bad bots (e.g., requests with a low cf.bot_management.score that are not included in Cloudflare's or Customer's list of allowed bots)."
The score in that sentence is Cloudflare's own measure. Its documentation describes a bot score as "a score from 1 to 99 that indicates how likely that request came from a bot," where "a score of 1 means Cloudflare is quite certain the request was automated." So the promise was specific. If Cloudflare itself judged a request to be a bad bot, and the bot was not on an allow list, the customer would not pay for that request.
The new page has no Bot Management section. The heading and the sentence are both gone, and the sentence does not appear on any of the other five pages or in Cloudflare's other public terms that Venpo tracks.
What the terms say now
With the section removed, what remains is the general definition on the Other Terms page, in the part on units of measurement: "'Request' is a single HTTP/S request that is received by Cloudflare's edge." That definition did not change, and it makes no exception for bots.
It is important to be exact about what this does and does not show. The terms do not say that Cloudflare now bills for bad bot requests. They no longer say that it does not. The page gives no reason for the removal, and the public terms cannot show what an individual customer's order form says. A customer with its own negotiated wording may be unaffected. A customer who relied on the public sentence no longer has it.
AI models and search services are now "as is"
Workers AI and AI Gateway let developers call AI models through Cloudflare. The old terms already said that by using those models, "you agree to the applicable third-party terms, including any acceptable use policies or other restrictions on use of such model." The new wording goes further in three ways.
It now covers "machine learning models and search services," not only models.
It applies "whether or not you have entered an agreement with the third-party provider." If you have no agreement of your own, "you agree to comply with all restrictions, including any acceptable use policies, in the standard terms of the model or search service provider."
Cloudflare now provides the models and search services on an "AS IS" and "AS AVAILABLE" basis. The old text already said Cloudflare had no obligation to indemnify customers for claims arising from the models.
In practice, a team that calls a model through Cloudflare is also bound by that model provider's usage rules, even if nobody on the team ever opened them. We saw a similar shift of responsibility when HubSpot made customers answer for what its AI agents do.
New terms for Monetization Gateway and AI code review
Monetization Gateway is new, so these terms do not take anything away from existing customers. They do set the ground rules for anyone who turns it on. Cloudflare says it "is not a party to or in the flow of funds for any payment," and the customer is "solely responsible for any transactions, disputes, or payments liability arising from or related to your use of Monetization Gateway." Cloudflare may suspend or limit the service "with or without notice." By using it, "you authorize Cloudflare to test and automatically apply service and configuration improvements to enrolled zones." Wallet addresses that a customer provides are sent to Coinbase to verify transactions, and the customer agrees to Coinbase's terms.
The new paragraph on Vulnerability Discovery and Remediation says that "any code patches proposed by Cloudflare are generated by artificial intelligence software, provided as is, and that Customer is solely responsible for reviewing and adopting them."
What did not change
The sentence "Unless otherwise agreed, Cloudflare does not use any Customer Content to train generative AI tools" is the same as before.
The definition of a Request is unchanged.
The other sections of the Application Services page kept their substance, including the rules for the content delivery network on Free, Pro, and Business plans.
Customers still keep the intellectual property rights in what they send to and receive from Workers AI. The new text adds the words "As between Cloudflare and you."
Why this matters
Automated traffic is a growing part of what every website receives, and much of it is unwanted. For a customer whose bill depends on request volume, whether those requests count is a money question, and until September the public terms answered it in one plain sentence. Now they are silent. Silence in a contract is not the same as a new charge, but it moves the answer from a public page to whatever each customer has in writing.
It is also a reminder of where billing rules live. This one was not in the pricing page or the main agreement. It was a single line in a product annex. Limits and billing rules often move this way, as when Box added the right to throttle customers before they hit their limit and when Google Cloud added new billing triggers.
Potential impact
If you use Cloudflare, the update raises five practical questions:
Does your plan or order form count requests, and does it say how bad bot requests are treated?
If you relied on the public sentence, do you have the same commitment anywhere in writing?
Do you watch how much of your traffic Cloudflare scores as automated, so you can spot a change on an invoice?
Do your developers call third-party models or search through Workers AI or AI Gateway, and has anyone read those providers' standard terms?
If you plan to try Monetization Gateway, who is responsible for the wallet, the transactions, and the automatic configuration changes?
How Venpo detected it
Venpo monitors Cloudflare's legal pages as part of continuous vendor risk monitoring. It recorded the new date on the Service-Specific Terms and then the changes to the text, and marked the Bot Management section as removed. Every quote in this article was checked against the old and new versions and against the live pages. The redlines are on the change pages for Application Services, the Developer Platform, and Other Terms, and every monitored Cloudflare document is listed on the Cloudflare vendor profile.
Business outcome
Teams that track Cloudflare saw the deleted sentence as a marked change, with the old wording in front of them. That is enough to check the order form, put the question to an account manager, and get an answer in writing before the next invoice or renewal. A team that only looks at the terms when something goes wrong would find a page with no Bot Management section and no way to know that one used to be there. This is the gap that vendor contract monitoring closes.
Key takeaway
Cloudflare deleted the sentence in its Service-Specific Terms that said customers would not be billed for requests from bad bots, and put nothing in its place. The same update made third-party AI models and search services "as is" and added terms for a new payments service. A removed sentence leaves no trace on the page, so the only way to notice it is to monitor vendor terms of service and compare versions.
The change
Cloudflare sits in front of a large share of the web: it speeds up sites, blocks attacks, and filters automated traffic. Its Service-Specific Terms add product-by-product rules to the main customer agreement and are published as six pages. All six now show "Last updated: September 28, 2026." The previous version was dated June 2, 2026.
Most of the edits are housekeeping. Three are not. One removes a billing promise from the Application Services page, one rewrites the rules for third-party AI models on the Developer Platform page, and one adds terms for a new payments service on the Other Terms page. The billing change is the one most customers will care about, and it is a single deleted sentence.
What changed
Bot Management. The whole section was deleted. It had one sentence, which said customers would not be billed for requests from bad bots.
Third-party AI models and search. Models and search services offered through Workers AI and AI Gateway are now made available on an "AS IS" and "AS AVAILABLE" basis, and they count as third-party products "whether or not you have entered an agreement with the third-party provider."
Monetization Gateway. A new section covers a service "designed to help you configure and exchange HTTPS headers in connection with x402, peer-to-peer payments."
AI code review. A new paragraph in the Security Operations Center section covers Vulnerability Discovery and Remediation, in which Cloudflare uses AI tools to review customer code and propose patches.
Housekeeping. The introduction no longer mentions Professional Services or a Statement of Work, and several references to the "Subscription Terms" now say "Agreement."
The sentence that was removed
Until September, the Application Services page had a section headed "Bot Management." It read, in full: "Customer will not be billed for any requests that Cloudflare reasonably determines were generated by bad bots (e.g., requests with a low cf.bot_management.score that are not included in Cloudflare's or Customer's list of allowed bots)."
The score in that sentence is Cloudflare's own measure. Its documentation describes a bot score as "a score from 1 to 99 that indicates how likely that request came from a bot," where "a score of 1 means Cloudflare is quite certain the request was automated." So the promise was specific. If Cloudflare itself judged a request to be a bad bot, and the bot was not on an allow list, the customer would not pay for that request.
The new page has no Bot Management section. The heading and the sentence are both gone, and the sentence does not appear on any of the other five pages or in Cloudflare's other public terms that Venpo tracks.
What the terms say now
With the section removed, what remains is the general definition on the Other Terms page, in the part on units of measurement: "'Request' is a single HTTP/S request that is received by Cloudflare's edge." That definition did not change, and it makes no exception for bots.
It is important to be exact about what this does and does not show. The terms do not say that Cloudflare now bills for bad bot requests. They no longer say that it does not. The page gives no reason for the removal, and the public terms cannot show what an individual customer's order form says. A customer with its own negotiated wording may be unaffected. A customer who relied on the public sentence no longer has it.
AI models and search services are now "as is"
Workers AI and AI Gateway let developers call AI models through Cloudflare. The old terms already said that by using those models, "you agree to the applicable third-party terms, including any acceptable use policies or other restrictions on use of such model." The new wording goes further in three ways.
It now covers "machine learning models and search services," not only models.
It applies "whether or not you have entered an agreement with the third-party provider." If you have no agreement of your own, "you agree to comply with all restrictions, including any acceptable use policies, in the standard terms of the model or search service provider."
Cloudflare now provides the models and search services on an "AS IS" and "AS AVAILABLE" basis. The old text already said Cloudflare had no obligation to indemnify customers for claims arising from the models.
In practice, a team that calls a model through Cloudflare is also bound by that model provider's usage rules, even if nobody on the team ever opened them. We saw a similar shift of responsibility when HubSpot made customers answer for what its AI agents do.
New terms for Monetization Gateway and AI code review
Monetization Gateway is new, so these terms do not take anything away from existing customers. They do set the ground rules for anyone who turns it on. Cloudflare says it "is not a party to or in the flow of funds for any payment," and the customer is "solely responsible for any transactions, disputes, or payments liability arising from or related to your use of Monetization Gateway." Cloudflare may suspend or limit the service "with or without notice." By using it, "you authorize Cloudflare to test and automatically apply service and configuration improvements to enrolled zones." Wallet addresses that a customer provides are sent to Coinbase to verify transactions, and the customer agrees to Coinbase's terms.
The new paragraph on Vulnerability Discovery and Remediation says that "any code patches proposed by Cloudflare are generated by artificial intelligence software, provided as is, and that Customer is solely responsible for reviewing and adopting them."
What did not change
The sentence "Unless otherwise agreed, Cloudflare does not use any Customer Content to train generative AI tools" is the same as before.
The definition of a Request is unchanged.
The other sections of the Application Services page kept their substance, including the rules for the content delivery network on Free, Pro, and Business plans.
Customers still keep the intellectual property rights in what they send to and receive from Workers AI. The new text adds the words "As between Cloudflare and you."
Why this matters
Automated traffic is a growing part of what every website receives, and much of it is unwanted. For a customer whose bill depends on request volume, whether those requests count is a money question, and until September the public terms answered it in one plain sentence. Now they are silent. Silence in a contract is not the same as a new charge, but it moves the answer from a public page to whatever each customer has in writing.
It is also a reminder of where billing rules live. This one was not in the pricing page or the main agreement. It was a single line in a product annex. Limits and billing rules often move this way, as when Box added the right to throttle customers before they hit their limit and when Google Cloud added new billing triggers.
Potential impact
If you use Cloudflare, the update raises five practical questions:
Does your plan or order form count requests, and does it say how bad bot requests are treated?
If you relied on the public sentence, do you have the same commitment anywhere in writing?
Do you watch how much of your traffic Cloudflare scores as automated, so you can spot a change on an invoice?
Do your developers call third-party models or search through Workers AI or AI Gateway, and has anyone read those providers' standard terms?
If you plan to try Monetization Gateway, who is responsible for the wallet, the transactions, and the automatic configuration changes?
How Venpo detected it
Venpo monitors Cloudflare's legal pages as part of continuous vendor risk monitoring. It recorded the new date on the Service-Specific Terms and then the changes to the text, and marked the Bot Management section as removed. Every quote in this article was checked against the old and new versions and against the live pages. The redlines are on the change pages for Application Services, the Developer Platform, and Other Terms, and every monitored Cloudflare document is listed on the Cloudflare vendor profile.
Business outcome
Teams that track Cloudflare saw the deleted sentence as a marked change, with the old wording in front of them. That is enough to check the order form, put the question to an account manager, and get an answer in writing before the next invoice or renewal. A team that only looks at the terms when something goes wrong would find a page with no Bot Management section and no way to know that one used to be there. This is the gap that vendor contract monitoring closes.
Key takeaway
Cloudflare deleted the sentence in its Service-Specific Terms that said customers would not be billed for requests from bad bots, and put nothing in its place. The same update made third-party AI models and search services "as is" and added terms for a new payments service. A removed sentence leaves no trace on the page, so the only way to notice it is to monitor vendor terms of service and compare versions.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
