Is Cloudflare Blocking ChatGPT and Claude?

Check whether Cloudflare blocks ChatGPT or Claude, understand the default changes, and verify actual crawler outcomes.
The announcement date doesn't tell you your setting
Cloudflare can observe AI crawler requests, block named crawlers, enforce policy with firewall rules, and manage robots.txt. Those are separate controls.
For the domain you care about:
- Open AI Crawl Control and review crawler activity.
- Open Security Settings and inspect the AI bot policies.
- Check Search, Agent, and Training separately.
- Review firewall events for 403 responses or managed-rule matches.
- Fetch the public robots.txt file served by the domain.
If robots.txt allows OAI-SearchBot but Cloudflare still returns a 403, the firewall rule is overriding the policy file. Robots.txt is a request to cooperating crawlers, not an instruction that Cloudflare enforcement must obey.
When Cloudflare changed the defaults
Several Cloudflare announcements are easy to mix up:
- On 23 September 2024, AI Audit became available to every Cloudflare site. This added observation and controls.
- On 1 July 2025, Cloudflare announced AI-crawler blocking as the default for new domains.
- On 24 September 2025, Cloudflare began serving Content Signals Policy comments for free zones without an existing robots.txt file. Comments alone did not block a crawler or state an actual preference.
- On 1 July 2026, Cloudflare introduced separate policy controls for Search, Agent, and Training behavior.
- Cloudflare says another default change for new domains takes effect on 15 September 2026. Training and Agent traffic will be blocked on pages with ads, while Search remains allowed.
This page was reviewed on 4 August 2026. The September 2026 default is scheduled, not yet active at the time of review.
Search, training, and user actions are different
Blocking every crawler from a provider is a blunt policy.
OpenAI uses OAI-SearchBot for ChatGPT Search and GPTBot for content that may be used in training. Anthropic documents Claude-SearchBot, ClaudeBot, and Claude-User. Cloudflare now groups traffic by behavior so site owners can choose a different policy for each job.
Decide what you want before changing the setting:
- Allow Search when discoverability in AI search matters.
- Set a separate Training preference.
- Treat user-initiated Agent traffic as its own access decision.
Verify what happened after a change
After publishing a policy, watch new requests. Record the crawler identity, path, status, and rule that acted on it.
A 200 shows that the request was served. A 403 shows that Cloudflare or another layer refused it. A 429 shows rate limiting. No observed request means only that the connected source saw no matching request during that period.
SearchSeal connects to Cloudflare for crawler evidence and keeps those requests separate from human analytics. This is useful when you operate more than one zone or also run sites outside Cloudflare.
Frequently asked questions
Does Cloudflare block all ChatGPT crawlers by default?
Not as a universal rule for every zone. Check the current policy on the exact domain because defaults depend on when the zone was added and which behavior controls are active.
Does robots.txt override Cloudflare blocking?
A robots.txt allow cannot override a firewall or AI Crawl Control block.
When did Cloudflare start blocking AI crawlers by default?
Cloudflare announced the blocking default for new domains on 1 July 2025. It has since introduced more specific Search, Agent, and Training controls.
Do Cloudflare Content Signals comments block AI crawlers?
Comments alone do not enforce a block. Check the served robots.txt file and the active AI Crawl Control or firewall policy separately.
Verified sources
Related posts
Simple website analytics with AI visibility built in
See visitors, sources, goals, revenue, and AI referrals, plus separate crawler evidence.
Free under 1,000 pageviews a month on a single site. No credit card.