Cloudflare teams up with Chrome, Firefox, and Edge on a privacy-first anti-bot protocol



TL;DR

Cloudflare, Mozilla, Google, Microsoft, and Shopify are building PACT, a privacy-first protocol to verify web traffic legitimacy.

Cloudflare has announced a joint initiative with Mozilla Firefox, Google Chrome, and Microsoft Edge to develop a new internet protocol that verifies whether web traffic is legitimate without tracking users. The protocol, called Private Access Control Tokens, is designed to replace CAPTCHAs and forced logins with anonymous tokens that prove a visitor is human or an authorised bot. Shopify co-developed the technology and the group plans to submit it for formal standardisation.

The announcement comes as bot traffic has officially overtaken human activity online. Cloudflare Radar data shows automated systems now account for roughly 58 percent of HTTP requests to web content worldwide, against 42 percent from people. Cloudflare CEO Matthew Prince shared the milestone on June 3, noting that agentic AI programs browsing on behalf of assistants like ChatGPT and Gemini had accelerated the crossover by about 18 months ahead of his earlier predictions.

PACT works by allowing websites with strong knowledge of a visitor’s identity to issue anonymous tokens. A user’s browser stores the token and can present it to other websites as proof that a real person is behind the session, reducing the need for repeated identity checks. The protocol is designed so that the token cannot be used to track users or reconstruct their browsing history.

The way we interact with the Internet is facing a fundamental shift,” Cloudflare CTO Dane Knecht said in the announcement. “As AI-powered traffic becomes widespread, existing tools to support its use are too generic and coarse.” He said the collaboration would eliminate the friction caused by security protocols for every visitor, whether human or agent, without sacrificing privacy.

The initiative does not aim to block all automated traffic. Cloudflare has itself embraced agentic AI, cutting 1,100 jobs earlier this year after declaring that AI agents now perform work previously done by humans. For many AI agents there is still a human somewhere in the loop with a legitimate reason to access a website.

PACT is meant to distinguish those authorised agents from malicious scrapers and abuse bots, not to shut down automation entirely.

The browser makers framed the effort as essential to the open web. Bobby Holley, CTO for Firefox at Mozilla, said an “avalanche of automated traffic” was pushing sites toward blunt defences like paywalls, identity checks, and invasive tracking. Erik Anderson, director of engineering for the web platform at Microsoft Edge, called effective privacy-preserving tools critical to combating abuse without unnecessary user friction.

Shopify’s involvement reflects the commercial stakes. Ilya Grigorik, a distinguished engineer at the company, said every extra challenge or false positive in ecommerce can turn a purchase into an abandoned cart. Covert browser fingerprinting and extension scanning have emerged as the default tools for platforms trying to identify users, a practice that privacy advocates and regulators have pushed back against.

PACT would offer a standardised alternative that does not require harvesting device characteristics or tracking browsing behaviour.

The protocol builds on earlier work in the same space. Apple already uses a related system called Privacy Pass, which works with a device’s secure enclave to attest to a user’s identity, and Cloudflare uses Privacy Pass as a signal in its bot management products. The IETF published the Privacy Pass Architecture as RFC 9576, and PACT extends that foundation with broader browser support and a focus on the agentic AI traffic that has reshaped the composition of the web in the past year.

No deployment timeline has been announced. The partners have committed to developing the protocol and submitting it for standardisation, but turning a specification into something that works across billions of browser sessions will take time. Users are already migrating away from platforms that impose AI features without consent, and the question of how to manage automated traffic without alienating human visitors is becoming more urgent by the quarter.

Whether PACT arrives fast enough to matter depends on how quickly the standards process moves and how willing websites are to adopt a system that, by design, gives them less data about their visitors rather than more.



Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


gettyimages-647882122

S847/iStock / Getty Images Plus

Follow ZDNET: Add us as a preferred source on Google.


ZDNET’s key takeaways

  • Staff who use AI can end up with more to do, not less.
  • Think carefully about the tools you’re using and why.
  • Adopt a set of standards and refine your outputs.

The promise of productivity boosts from AI can come with an unwelcome side order of stress. Harvard Business Review found that AI doesn’t reduce work; it intensifies it, leading to cognitive fatigue and unsustainable hours.

While the common perception is that AI can help reduce workloads, allowing employees to focus more on higher-value and more engaging tasks, HBR’s research found that staff using AI worked more quickly and often ended up with more to do, not less.

Also: Forget productivity: Here are 5 strategic shifts that drive real AI value

While we’ve written about how some professionals are finding ways to turn AI’s time-saving magic into a productivity superpower, we’ve also recognized that some employees have started to become tired with the low quality of AI outputs.

Ankur Anand, group CIO at tech recruiter Harvey Nash, said professionals who want to avoid cognitive fatigue must understand how to use AI effectively and its potential risks.

“That focus will help to reduce the noise around the workload that AI creates,” he told ZDNET, suggesting that many people have unrealistic expectations about the productivity boost that AI will provide.

Also: Why I ditched Copilot for Claude in Word, Excel, and PowerPoint – and how you can, too

“Many organizations are telling their people, ‘We want to understand how you’re making an impact with AI,'” he said. “But these professionals are not empowered, which means that using AI adds a lot of pressure, because they need to prove themselves on their own terms.”

If you’re going to make the most of AI at work, then you’re going to have to find an effective balance between completing tasks quickly and producing high-quality work. 

Here’s how the experts believe professionals can ensure they reap the benefits, not the problems, of AI — and they suggest that you’ll need to focus on three core areas: tools, guidelines, and outputs.

Limit your toolset

Alex Read, senior enterprise product manager for data at energy provider EDF UK, told ZDNET that the best way for professionals to reap the benefits, not the challenges, of AI is to be uber-focused on tools that help you produce value in your roles.

While there are thousands of potential AI-enabled services on the market, Read said sensible professionals limit their horizons.

Also: How this travel company’s AI rollout drove a 73% satisfaction boost: A 5-step playbook for your business

In his own role, for example, Read focuses on how AI can help him build a data platform and update information accurately, efficiently, and productively: “Anything outside of that scope is noise for me.”

That sentiment resonated with Nick Pearson, CIO at technology specialist Ricoh Europe, who told ZDNET it’s important to take a step back and think carefully about how an AI tool can help you produce value in your role.

“If you think about the phrase ‘gen AI,’ the tech is very good, by definition, at generating outputs,” he said. “I could go to bed in the evening, set the model to work, and we could have four new IT strategies produced overnight.”

Also: Worried AI agents will replace you? 5 ways you can turn anxiety into action at work

However, quantity doesn’t necessarily mean quality. Pearson suggested it’s important to focus on AI’s blind spots, particularly as most models are trained on preexisting content.

“AI can’t inspire people, per se; it can’t naturally create something new, because it’s actually quite recursive,” he said.

“And the judgment you have to put in sometimes, on top of everything else, whether it be an ethical or a capability judgment, is not there automatically in the technology.”

It’s in this gap, said Pearson, that human experts play a critical role: “We’re toying with that concern as an organization and saying, ‘Where does AI really play an important role, versus where are we upskilling people in areas that AI probably won’t play for a long time?'”

Work to the guidelines

HBR’s research found that an initial productivity surge when AI is adopted can lead to lower-quality work, turnover, and other problems as people work harder rather than smarter.

To correct this issue, HBR said companies need to adopt an “AI practice,” or a set of norms and standards around AI use that help professionals ensure they use AI in a constrained but productive manner.

Also: 90% of AI projects fail – here are 3 ways to ensure yours doesn’t

At EDF UK, Read is part of an internal AI Center of Excellence in enterprise IT, which enables policy for the effective use of AI across the wider organization. 

In addition to Read, who contributes input from a data-use perspective, the group includes other tech representatives, such as the firm’s senior manager of AI, principal software engineer, and principal solution architect.

“The remit of this center is to make sure that, when the federated business units are looking to build, develop, and deploy AI services, they have platforms, guidance, best practices, architectural assets, and materials to guide them on how to safely and efficiently adopt AI and operationalize it at scale,” he said.

Some of the key themes the center considers when assessing AI tools are scalability and reusability, ensuring a proposed service doesn’t replicate one already in use.

Also: 5 ways to use AI when your budget is tight

“All new tools and services related to AI will go through that hopper and funnel to understand scope and ensure the security, regulatory, and ethical side of things are understood,” he said, suggesting that all professionals should use their organization’s pre-existing guidelines to foster an appropriate exploitation of emerging tech.

“The benefit that guided approach brings is that it allows us to be clear in our messaging around what AI services can be used, how they’re used from a use-case perspective, and ultimately, what personas are allowed to use them.”

Refine your outputs

Even when tools are assessed and considered acceptable, there can still be an overreliance on AI outputs. Worse, some professionals can drown in the insights they receive, leading to higher stress and fewer benefits.

Louise Newbury-Smith, head of UK&I at technology specialist Zoom, told ZDNET that one way to ensure your outputs are constrained is to focus on prompting.

“Use simple amendments to be specific, such as ‘Give me the top three things with the biggest impact.’ That approach should guide your prompt, rather than saying, ‘Give me everything you know about this topic.'”

Also: 5 ways to fortify your network against the new speed of AI attacks

Newbury-Smith said the successful use of AI is all about being smart about how it’s exploited, and that effectiveness comes down to enablement and engagement. If a prompt yields too much information, refine it until you get what you need. She said this should still be faster than trying to get answers without AI.

The basic message for professionals is that effective applications of AI are all about you staying in the loop, said Bernhard Seiser, vice president of digital, data, and IT at AOP Health.

Think before you use AI, and think again before you push your outputs around the organization.

“It doesn’t help the business if you get AI-generated emails that are many pages long, and then you need ChatGPT to summarize the text,” he told ZDNET.

Seiser said that while there are certain tasks generative AI is good at and worth using for, in the end, “you need to use your brain.”





Source link