A marketing leader wants the company's expertise to be easy to find. A content director wants to protect the value of its original work. The web team receives a request to block AI. Before anyone changes a setting, those leaders need to agree on what they are trying to achieve.
Cloudflare's September 15 announcement makes that conversation timely. The company introduced Disallow AI Training, designed to communicate training restrictions while preserving search access for qualifying crawlers that serve both purposes. The alternative Block setting can stop those crawlers entirely, including their search activity. [1]
Search Engine Journal's same-day coverage identifies a change from Cloudflare's earlier plan and reports how existing settings will migrate. That is useful reporting on the announcement, not an independent test of compliance or business results. [2]
For executives, the decision begins with the role of the website: what value should its content create, for whom, and under what conditions?
Start with the business purpose of the content
Consider two hypothetical businesses. A specialist publisher earns revenue when readers visit its articles or subscribe. A manufacturer publishes product information to help prospective customers evaluate equipment. Both invest in content, but they may place different values on reach, reuse, and a direct customer visit.
Ask the publisher which material attracts subscribers and which material people pay to receive. Ask the manufacturer which information helps a buyer shortlist a product and which information should lead to a consultation. The answers establish the business objectives against which an access policy should be judged.
Cloudflare's release proposes different presets for new domains depending on whether they carry advertising. It also describes separate controls for search, training, and agents. Those are vendor recommendations, not an assessment of an individual company's economics. [3]
A leadership team should write its own short policy before adopting a preset. Name the intended audience, the permitted uses, the business benefit sought, and the concern that would justify a restriction. Record unresolved tradeoffs so they can be revisited with evidence.
Separate the decisions hidden inside 'block AI'
Use separate questions in the review. Should a service be able to find this content for search? May the content be used to train a model? Should an assistant retrieve it for a user? How should the business approach summaries that may satisfy the user's question before a visit?
These questions need separate answers even when the available controls do not map neatly to them. Cloudflare says its new setting publishes a training preference for qualifying mixed-use crawlers and blocks other training crawlers. That combines a communicated preference with access enforcement, depending on the crawler. [1]
Cloudflare's Bot Preference Sync explanation describes aligning published crawler preferences with configured bot policies. [4] Ask the web owner to demonstrate that alignment and explain operator coverage and exceptions. The approval record should show what remains uncertain.
Google's own documentation illustrates why scope matters. It says Google-Extended governs both future Gemini model training and specified grounding uses, which supply content to a model when answering a prompt. Google says the control does not affect inclusion or ranking in Google Search. A training-related choice can therefore reach beyond training; ask which products and uses a restriction covers. [5]
Be equally precise about scope. Cloudflare describes these controls at the domain level. A content inventory can expose different needs within a site, but it does not mean each proposed distinction is available as a separate switch. Have the technical team assess feasibility before making promises. [1]
Distinguish current support from future commitments
Cloudflare's Accountable designation includes both existing capabilities and commitments. Its announcement says Bing support for a robots.txt training preference is targeted for early 2027; until then, selecting Disallow AI Training does not automatically convey that preference to Bing through robots.txt. [1]
That limitation belongs in the management discussion. A policy can be reasonable while its implementation remains incomplete. Assign an owner to each gap, document any interim approach, and set a review date tied to evidence that support has actually arrived.
The press release also describes centralized control over how much content appears in AI summaries as a goal for early 2027. It should be evaluated as a roadmap commitment. It is not evidence that such granular control is available today. [3]
The sources reviewed do not establish universal crawler compliance, preserved rankings, or a financial benefit from selecting a particular policy. The business case should leave room for that uncertainty.
Give the policy an owner and a review process
Put a commercial leader in charge of the intended outcome, with the content owner and web operations lead responsible for the policy and implementation. Bring in other specialists where the content or intended use requires their judgment. Someone should have authority to resolve a disagreement between protecting material and making it discoverable.
For an initial review, choose one domain with a clear business purpose. Capture its current settings and the reason for them. Ask the team to show how the proposed configuration supports the agreed purpose, including operator exceptions and dependencies on future features.
Before a change, record a baseline for relevant search visibility, qualified inquiries, subscriptions, or sales. Choose measures that correspond to the site's purpose. A publisher and a manufacturer need not use the same definition of success.
After implementation, review both access behavior and commercial outcomes. A change in visits alone will not establish what caused it. Compare relevant periods and account for campaigns, content changes, and other plausible explanations before attributing a result to the crawler policy.
Agree who can reverse an unintended restriction and what evidence would trigger that action. Keep the decision record short enough that the next person responsible for the site can understand why it was configured that way.
Make the next investment decision explicit
Budget for policy ownership, technical verification, and measurement alongside any service fees. More detailed controls have limited management value if no one can explain whether they are working or whether they support the business.
At the next review, ask whether the evidence supports keeping the policy, changing it, or collecting more information. Avoid promising a revenue improvement before the organization has observed its own results.
These are proposed management practices, not a validated framework or a reported customer deployment. Their purpose is to give executives a practical way to make an explicit decision about the company's public knowledge. The next web configuration review should begin with an agreed business objective.
Questions for executives
- What business result should access to our public content support?
- Which restrictions are enforced, which depend on operator behavior, and which capabilities are still promised?
- Who owns the decision, and what evidence would cause us to change the policy?
Sources and further reading
- Have it both ways: stay discoverable in search while disallowing AI trainingBryan Becker, Cloudflare Blog · Published 2026-09-15
- Cloudflare Lets Sites Disallow AI Training Without Blocking GooglebotMatt G. Southern, Search Engine Journal · Published 2026-09-15
- Cloudflare Helps End the Search-or-AI-Training TradeoffCloudflare · Published 2026-09-15
- Say it once: introducing Bot Preference SyncJin-Hee Lee, Cloudflare Blog · Published 2026-08-21
- Google's common crawlersGoogle for Developers · Updated 2026-07-14

