Cloudflare turns AI against itself with endless maze of irrelevant facts

You May Be Interested In:‘We got stuck in puddles’: skiers upset by lack of snow on Swedish slopes



On Wednesday, web infrastructure provider Cloudflare announced a new feature called “AI Labyrinth” that aims to combat unauthorized AI data scraping by serving fake AI-generated content to bots. The tool will attempt to thwart AI companies that crawl websites without permission to collect training data for large language models that power AI assistants like ChatGPT.

Cloudflare, founded in 2009, is probably best known as a company that provides infrastructure and security services for websites, particularly protection against distributed denial-of-service (DDoS) attacks and other malicious traffic.

Instead of simply blocking bots, Cloudflare’s new system lures them into a “maze” of realistic-looking but irrelevant pages, wasting the crawler’s computing resources. The approach is a notable shift from the standard block-and-defend strategy used by most website protection services. Cloudflare says blocking bots sometimes backfires because it alerts the crawler’s operators that they’ve been detected.

“When we detect unauthorized crawling, rather than blocking the request, we will link to a series of AI-generated pages that are convincing enough to entice a crawler to traverse them,” writes Cloudflare. “But while real looking, this content is not actually the content of the site we are protecting, so the crawler wastes time and resources.”

The company says the content served to bots is deliberately irrelevant to the website being crawled, but it is carefully sourced or generated using real scientific facts—such as neutral information about biology, physics, or mathematics—to avoid spreading misinformation (whether this approach effectively prevents misinformation, however, remains unproven). Cloudflare creates this content using its Workers AI service, a commercial platform that runs AI tasks.

Cloudflare designed the trap pages and links to remain invisible and inaccessible to regular visitors, so people browsing the web don’t run into them by accident.

A smarter honeypot

AI Labyrinth functions as what Cloudflare calls a “next-generation honeypot.” Traditional honeypots are invisible links that human visitors can’t see but bots parsing HTML code might follow. But Cloudflare says modern bots have become adept at spotting these simple traps, necessitating more sophisticated deception. The false links contain appropriate meta directives to prevent search engine indexing while remaining attractive to data-scraping bots.

share Paylaş facebook pinterest whatsapp x print

Similar Content

TSMC will stop making 7 nm chips for Chinese customers
TSMC’s $100 billion pledge won’t resurrect US chipmaking, says Intel’s ex-CEO
What are the mystery drones flying over the US?
What are the mystery drones flying over the US?
$1 phone scanner finds seven Pegasus spyware infections
$1 phone scanner finds seven Pegasus spyware infections
New Scientist. Science news and long reads from expert journalists, covering developments in science, technology, health and the environment on the website and the magazine.
Risk algorithm used widely in US courts is harsher than human judges
A man plays Pokemon Go game on a smartphone on July 22, 2016 in Tokyo, Japan.
Niantic uses Pokémon Go player data to build AI navigation system
Data breach hitting PowerSchool looks very, very bad
Data breach hitting PowerSchool looks very, very bad
The News Spectrum | © 2025 | News