Cloudflare launches adaptive bot defence tool

Cloudflare

By Dylan Bushell-Embling
Wednesday, 02 September, 2026

Cloudflare launches adaptive bot defence tool

Cloudflare has launched a bot defence tool that continuously learns from live internet traffic and adapts itself in real time to emerging threats. Adaptive Intelligence uses insights gathered from the vast amount of requests across Cloudflare’s global network to autonomously learn from the meta-signals of live traffic and generate short-lived rules for foiling automated attacks.

The tool uses a machine learning model capable of integrating new bot frameworks and bypass techniques into its detection engine in real time rather than waiting for manual updates or scheduled releases. By continuously changing rules, the solution aims to make it impossible for attackers to study a system, map defences or make lasting progress, and by combining browser-level session behaviour signals with global edge telemetry, the solution can evaluate automation and abuse in detail.

Announcing the tool, Cloudflare senior product manager for Adaptive Intelligence Chris Pope said advancing AI capabilities has made it expensive and difficult to respond and adapt to new attacks, and with conventional defences the question is not whether a determined attacker can get through, but what happens when they do.

“Adaptive Intelligence ... starts from the opposite idea. Rather than betting on a wall that keeps every attacker out, Adaptive Intelligence makes getting through so slow and costly that the attack stops being worth running,” he said.

Pope said the solution has been built on the principle of making it cost less for organisations to defend against attacks than it does for attackers to mount them.

“Part of that is giving an attacker less to learn from,” he said. “Adaptive Intelligence can recognise a bot from a signal without visibly reacting to it, so the attacker keeps relying on a tell they do not realise we can see. And it treats detection as a statistical judgement rather than a fixed rule. That makes it non-deterministic. It weighs many signals at once, so there is no single piece of logic for an attacker to isolate and beat.”

The platform uses a continuously operating detection loop involving observing every signal, retraining on live traffic, deploying across the network, validating the defence and repeating this process based on outcomes and user feedback. The engine remembers previous attacks to prevent attackers simply swapping between profiles, and new detections are built automatically.

“Adaptive Intelligence evaluates traffic over several time windows at once. A short window catches a sudden burst as it develops,” Pope said. “A longer window reveals the behaviour that repeats across thousands of addresses, clients and sessions that have no reason to behave alike, and ties those scattered requests back to a single source. The same engine that spots an obvious scraping spike also surfaces a slow, distributed credential-stuffing attack sending only a handful of requests from each address.”

Image credit: iStock.com/Sundry Photography

Related News

LevelBlue launches local SOC in Sydney

Managed security service provider has launched an SOC in Sydney to help critical infrastructure...

Semperis researchers discover Active Directory flaws

Security researchers from Semperis have uncovered two Active Directory vulnerabilities that they...

Fortinet buys Virtue AI to bolster AI security portfolio

Fortinet has acquired AI runtime protection and automated AI validation company Virtue AI to...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd