Cloudflare teams with Chrome, Firefox, and Edge on privacy-first protocol as bots overtake humans

Reviewed byNidhi Govil

3 Sources

Share

Cloudflare has joined forces with Mozilla Firefox, Google Chrome, and Microsoft Edge to develop Private Access Control Tokens (PACT), a new internet protocol designed to verify legitimate web traffic without tracking users. The initiative comes as bot traffic officially surpassed human activity online, reaching 58 percent of global HTTP requests. PACT aims to replace CAPTCHAs with anonymous tokens that prove visitor authenticity while preserving privacy.

Cloudflare Launches Privacy-First Anti-Bot Protocol With Major Browsers

Cloudflare has announced a collaborative initiative with Mozilla Firefox, Google Chrome, and Microsoft Edge to develop Private Access Control Tokens (PACT), a new internet protocol designed to authenticate human traffic and combat malicious bots without compromising user privacy

1

. Shopify co-developed the technology, and the group plans to submit it for formal standardization

1

. The announcement arrives at a critical juncture: automated traffic now accounts for roughly 58 percent of HTTP requests to web content worldwide, officially overtaking the 42 percent generated by human users

1

.

Source: TechRadar

Source: TechRadar

Cloudflare CEO Matthew Prince shared the milestone on June 3, noting that agentic AI programs browsing on behalf of assistants like ChatGPT and Gemini had accelerated the crossover by about 18 months ahead of his earlier predictions

1

. With StatCounter placing the combined market share of Chrome, Firefox, and Edge at around 77 percent, the PACT protocol will likely roll out to the majority of internet users

2

.

How Web Traffic Verification Works Through Anonymized Tokens

Private Access Control Tokens are designed to allow websites with strong knowledge of a visitor's identity to issue anonymized tokens

3

. A user's browser stores the token and can present it to other websites as proof that a real person is behind the session, reducing the need for repeated identity checks

1

. The protocol is engineered so that the token cannot be used to track users or reconstruct their browsing history

1

.

This privacy-preserving solution addresses a growing problem: when websites attempt to verify legitimate web traffic, traditional solutions like forced logins and invasive tracking compromise user trust

3

. PACT leverages trusted information from contexts that have authentic relationships with people while keeping that information private

3

.

AI-Driven Automation Reshapes the Internet's Traffic Landscape

"The way we interact with the Internet is facing a fundamental shift," said Dane Knecht, CTO of Cloudflare

3

. "As AI-powered traffic becomes widespread, existing tools to support its use are too generic and coarse." The initiative does not aim to block all automated traffic entirely. For many agentic AI programs, there is still a human somewhere in the loop with a legitimate reason to access a website

1

.

PACT is meant to distinguish those authorized agents from malicious scrapers and abuse bots, not to shut down automation completely

1

. Cloudflare itself has embraced agentic AI, cutting 1,100 jobs earlier this year after declaring that AI agents now perform work previously done by humans

1

.

Industry Stakes: Why Privacy-Preserving Solutions Matter for Commerce

Shopify's involvement reflects the commercial urgency behind this effort. Ilya Grigorik, a distinguished engineer at Shopify, explained that every extra challenge or false positive in ecommerce can turn a purchase into an abandoned cart

1

. Covert browser fingerprinting and extension scanning have emerged as the default tools for platforms trying to identify users, a practice that privacy advocates and regulators have pushed back against

1

.

PACT would offer a standardized alternative to replace CAPTCHAs and other friction-causing mechanisms that do not require harvesting device characteristics or tracking browsing behaviour

1

. "Merchants need effective protections against automated abuse, but buyers shouldn't have to pay for them with unnecessary friction or invasive tracking," Grigorik said

2

.

Building on Privacy Pass and the Path to Standardization

The protocol builds on earlier work in web security. Apple already uses a related system called Privacy Pass, which works with a device's secure enclave to attest to a user's identity, and Cloudflare uses Privacy Pass as a signal in its bot management products

1

. The IETF published the Privacy Pass Architecture as RFC 9576, and PACT extends that foundation with broader browser support and a focus on the agentic AI traffic that has reshaped the composition of the web in the past year

1

.

Bobby Holley, CTO for Firefox at Mozilla, said an "avalanche of automated traffic" was pushing sites toward blunt defences like paywalls, identity checks, and invasive tracking

1

. Erik Anderson, director of engineering for the web platform at Microsoft Edge, called effective privacy-preserving tools critical to combating abuse without unnecessary user friction

1

. No deployment timeline has been announced, but the partners have committed to developing the protocol and submitting it for standardization

1

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved