Mon, 7 Sep 2026

Cloudflare launches Adaptive Intelligence to reverse bot attack economics

Cloudflare has introduced Adaptive Intelligence, a new continuous detection engine built directly into Cloudflare Bot Management that is designed to reverse the economics of automated cyber attacks.

Powered by insights from trillions of requests across Cloudflare’s global network, the engine autonomously learns from the meta-signals of live traffic, generating short-lived rules that make automated attacks far too expensive and time-consuming to sustain.

A moving target for modern bot threats

Launching an automated cyberattack no longer requires advanced engineering skills. Modern AI and cheap online tools have made it simple and inexpensive to rent networks of compromised devices, mask locations behind real home Internet addresses, and use free software that mimics basic human behavior.

Traditional security tools, which rely on slow, scheduled updates that can take weeks or months to deploy, leave businesses exposed to threat actors who change tactics in hours or minutes.

“Building taller walls fails when the cost of scaling an attack is effectively zero. To stop modern bot threats, you have to flip the economics on the attackers. Traditional defenses offer a static target that threat actors can systematically solvesaid Dane Knecht, CTO at Cloudflare.

He asserts that Cloudflare’s Adaptive Intelligence creates a moving target—rendering an attacker’s engineering efforts obsolete before their operation can ever achieve scale.

Always-on, continuously learning defense

Unlike conventional bot mitigation products that rely on fixed updates, Adaptive Intelligence acts like a single, constantly learning brain. The engine retrains continuously on live traffic, integrating new bot frameworks and bypass techniques into the detection model in real time instead of waiting for manual updates or scheduled releases.

Related:  Visibility gaps worsen as AI expands APIs

Customers benefit from always-on defense that stays close to what attackers are actually doing, rather than drifting further from reality between updates.

Adaptive Intelligence automatically generates short-lived, hyper-targeted rules to block specific threats. These disposable rules rotate at random intervals, preventing attackers from studying the system, mapping defenses, or making lasting progress.

By the time an attacker has reverse-engineered a specific pattern, the engine has already moved on, rendering their engineering effort worthless.

The engine also catches stealthy, low-and-slow threats—such as slow credential stuffing and scraping campaigns—by analyzing multi-timeframe behavior patterns simultaneously.

By combining browser-level session behavior signals from Cloudflare Precursor with global edge telemetry, the multi-layered architecture evaluates automation and abuse beyond basic binary tests, spotting malicious intent without blocking real humans.

Safe, autonomous upgrades

Security updates in Adaptive Intelligence automatically test themselves against live traffic behind the scenes, verifying accuracy and deterring false positives before deployment with zero downtime.

New model weights roll out across the network autonomously, with no version to choose and no upgrade to schedule. Before a new version becomes the primary defense, it runs in shadow mode alongside the current one, scoring live traffic without affecting a single visitor.

For chief information security officers, Adaptive Intelligence shifts the balance of power back to defenders by making each attack attempt short-lived while costing the attacker more than it will ever return. The attacker who never quits now faces a defense that is different each time they return, so their persistence stops paying off.

Enterprise customers can enable Adaptive Intelligence by turning on “Auto Update Machine Learning” in the Bot Management dashboard.

Related:  SG Faces a growing gap between AI risk and readiness

Related Stories

MORE STORIES