Skip to content

September 15, 2026 · Issue 30 · 4 min read

An infrastructure company decided what your agents may read, and a model vendor ranked your policies second

Cloudflare's new AI traffic defaults take effect today. Under the policy it published in July(opens in a new tab), crawlers get sorted into three categories, Search, Agent, and Training. On pages that display ads, Agent and Training are blocked by default, while Search stays allowed. The new defaults apply to domains newly onboarding to Cloudflare rather than to existing paid configurations, so nothing in your stack breaks this morning. The classification is the part to read. Agent traffic, meaning a bot fetching a page in real time on a person's behalf, is now sorted separately from search, and on ad-supported pages its default answer is no.

Almost every enterprise agent business case written in the last two years assumes the open web is free to read. The agent checks a supplier's published prices, pulls a regulator's guidance page, reads a competitor's spec sheet. Nobody priced that access, because it was never a line item. It is becoming one. Read access for agents is turning into a permission that a third party grants, and the party granting it works for customers who sell ads.

The second decision came from a vendor. On Monday Microsoft AI published a draft Code of Conduct for its MAI models and opened six weeks of public comment. Read past the safety language to the structure. SecurityWeek's account(opens in a new tab) describes a defined Chain of Command: the code of conduct first, then the policies of the companies deploying the model, which the document calls operators, then individual user preferences. Your enterprise policy is the second rank. Absolute constraints, including a ban on producing exploit code or attack tooling, sit above both and cannot be overridden by an operator or a user. The draft also holds that tool outputs, file contents, webpages, and messages from other AI systems carry no authority on their own. That is a sound answer to prompt injection. It is also a statement that the model will disregard instructions your own systems place in front of it unless authority was delegated down that chain.

Be precise about what this is. Current MAI models have not been trained on the document, a revised version is due later this year, and it is meant to guide models slated for 2027. Nothing you can buy today behaves this way. What it is, is the clearest published statement so far of how a major vendor intends to rank its own rules against the rules of the company deploying its model. That belongs in a contract conversation rather than a reading list.

The function that would normally price either change has not started. Gartner data reported by Help Net Security(opens in a new tab) puts 54 percent of 142 chief audit executives as not yet measuring the value of audit's own AI use, with 7 percent connecting it to concrete savings such as reduced external spend or avoided hiring. A OneTrust survey reported the same day(opens in a new tab) found 87 percent of organizations encourage employees to use AI agents, while 47 percent do so with defined governance, oversight, and controls in place. The distance between those two numbers is the population running agents whose permissions are now being set by other people.

Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.

One inventory question comes out of the Cloudflare change, and it is answerable this week. Does anything in your agent stack fetch public web pages at run time, and under whose crawler identity? Real-time retrieval is easy to add and easy to forget. If a workflow depends on reading a page you do not own, that dependency now has a counterparty who can revoke it, and the revocation will not look like an outage. It will look like an agent quietly returning worse answers, on a schedule nobody is watching.

The Microsoft draft raises a different question, and it is one for whoever owns the vendor relationship. If a model's own code of conduct outranks operator policy by design, then the only place your policy acquires standing is the agreement. Three things worth asking a model vendor before the next renewal. What behavior does the vendor commit to that a policy document cannot change unilaterally? What notice do you get when that policy is revised? And when the vendor's rules and your rules conflict in production, who is liable for the output?

Both stories describe the same shift. The interesting constraints on an agent program are arriving from parties outside the company, in documents written without reference to your use case. Neither shows up in a model evaluation, and neither is what vendors compete on.

Also worth knowing