Dave Kiss
Good Bot, Bad Bot: Why the Internet Needs a New Handshake
The web was built to keep bots out. Now we need them in. Here's how businesses can prepare for the age of AI agents, and what the emerging solutions look like.
ai-agents · security · web-infrastructure · business-strategy
Every time you've squinted at a distorted image trying to prove you're not a robot, you've participated in one of the internet's longest-running wars. For two decades, websites have built increasingly elaborate defenses against automated traffic. CAPTCHAs, rate limiting, IP blocking, behavioral analysis, the whole arsenal.
And it worked. Mostly.
But now we have a problem. The bots we actually want can't get through either.
The bouncer problem
Picture a nightclub with a strict door policy. The bouncer's job is simple: keep the troublemakers out. Over the years, troublemakers got creative, fake IDs, disguises, social engineering, so the bouncer got stricter. More questions. More verification. Eventually, anyone who looks even slightly suspicious gets turned away.
Now imagine the club owner's business partner shows up. Legitimate business. Good intentions. But he's wearing sunglasses at night and carrying a briefcase, so the bouncer blocks him at the door.
That's where we are with AI agents in 2026.
The Wall Goes Up
CAPTCHAs, rate limiting, and IP blocking become standard. The goal: keep all bots out.
Bots Get Smarter
Scrapers evolve. Headless browsers appear. The arms race intensifies.
AI Agents Arrive
ChatGPT, Claude, and AI assistants need web access. But they look like bots.
The Handshake Era
Web Bot Auth, Macaroons, Wafers. A new model: verify, then trust.
The tools your business might use, Claude helping with research, an AI assistant booking meetings, an agent monitoring competitor pricing, they all look like bots to website defenses. Because technically, they are bots. Good bots, but bots nonetheless.
What makes a bot "good" anyway?
Here's the uncomfortable truth: from a server's perspective, a helpful AI agent and a malicious scraper make the same kinds of requests. Both hit endpoints. Both consume resources. Both don't click cookie consent banners or watch video ads.
The difference is intent, and intent is invisible to a firewall.
A "good" bot might be:
- Your AI assistant researching competitors
- A search engine indexing your site for visibility
- An accessibility tool reading content for visually impaired users
- An AI agent completing a task on your behalf
A "bad" bot might be:
- A scraper stealing your content
- A credential stuffer trying stolen passwords
- A DDoS participant overwhelming your servers
- A price monitor undercutting you in real-time
Same traffic patterns. Opposite purposes. And until recently, no good way to tell them apart.
The old playbook is breaking
The traditional approach was scorched earth: block everything suspicious, ask questions never. robots.txt files, CAPTCHAs, aggressive rate limiting.
But this approach has costs:
For users, it means friction. How many times have you abandoned a form because the CAPTCHA was too annoying? Multiply that frustration by every AI-powered tool your team might use.
For businesses, it means lost opportunities. If an AI agent can't access your product information, it can't recommend your product to potential customers. If it can't read your pricing page, it can't include you in comparisons.
For the ecosystem, it means legitimate automation becomes impossible. The very tools that could make businesses more efficient get blocked at the door.
New approaches for a new era
The tech world is waking up to this problem, and several interesting solutions are emerging.
Web Bot Auth: the cryptographic handshake
The most promising development is Web Bot Auth, an emerging standard backed by Cloudflare, Akamai, AWS, and others. The concept is straightforward: instead of guessing whether a bot is legitimate, make it prove its identity.
Here's how it works:
- A legitimate bot operator generates a cryptographic key pair
- They publish their public key in a well-known location
- When their bot makes requests, it signs them with the private key
- Servers can verify the signature against the public key
It's like giving trusted bots a digital passport. They can prove who they are without revealing sensitive information. Websites can verify their identity without maintaining massive blocklists.
Macaroons: tokens with built-in limits
Another approach comes from distributed systems: macaroons. Think of them as authorization tokens that carry their own restrictions.
A macaroon might say "this agent can access product pages, but not checkout flows, only between 9 AM and 5 PM EST, and only up to 100 requests per hour." The clever part? Anyone holding the macaroon can add more restrictions, but nobody can remove them.
For businesses, this means granular control. You could issue a macaroon that lets a partner's AI agent access your API, with automatic limits baked right into the credential.
Wafers: layered permissions for AI
The newest entry is Wafers, specifically designed for AI agents. Each "layer" adds constraints, creating a chain of accountability. If an agent misbehaves, you can trace exactly who issued its credentials and revoke them.
Cloudflare's Markdown play
Just this week, Cloudflare announced something practical: any website using their service can now serve markdown versions of pages to AI agents. When an AI requests content with the right headers, Cloudflare automatically strips the HTML cruft and returns clean, token-efficient text.
This isn't just about being nice to bots. A markdown response uses roughly 80% fewer tokens than the equivalent HTML. That's real cost savings for AI operations, and it signals that the website wants AI agents to access the content.
The key is consent. Sites opt in by enabling the feature. They can set Content-Signal headers indicating what uses they allow: AI training, search indexing, agentic use. It's a handshake, not a wall.
What this means for your business
If you're running a business in Northeast Ohio, or anywhere else, this shift matters. Here's how to think about it:
If you're using AI tools
The agents you deploy will increasingly need to access the web. Make sure you're using providers that implement proper bot authentication. Ask vendors: "Do you support Web Bot Auth?" If they don't, they'll face more blocks as authentication becomes standard.
If you have a website
Consider how AI agents interact with your site. Are you blocking them entirely? That might hurt discoverability. Are you letting everything through? That's a security risk.
The middle ground is emerging: authenticate, then trust. Look into Cloudflare's bot management options, or similar tools from Akamai or AWS. Configure what AI agents can access, and what they can't.
Practical steps you can take today
Audit your current bot policy. Most businesses have never explicitly decided what bots should access their site. Check your firewall rules, your robots.txt, your CDN settings.
Separate concerns. Mission-critical services like checkout, authentication, and payment flows should stay locked down. Informational content like product pages, blog posts, and pricing can often be more open.
Monitor before blocking. If you're seeing bot traffic, understand it before blocking it. Some of those requests might be from tools your own customers use.
Watch the standards. Web Bot Auth is still emerging, but adoption is growing fast. When major AI providers start requiring verified bot status, you'll want infrastructure that can participate.
The bigger picture
We're at an inflection point. For twenty years, the default was suspicion: if it moves like a bot, block it. That made sense when bots were predominantly malicious.
But now we're building a world where AI agents do useful work, booking appointments, researching options, completing tasks, serving customers. These agents need web access to function. And the websites they access need ways to distinguish them from bad actors.
The solution isn't to tear down all the walls. It's to install doors, doors that open for those who can prove they belong.
The businesses that figure this out early will have an advantage. Their AI tools will work better. Their sites will be discoverable by AI systems. They'll be ready for a world where the question isn't "is this a bot?" but "is this a trusted bot?"
The handshake is coming. Time to learn the greeting.
Navigating AI infrastructure decisions? That's exactly what we help Cleveland businesses with. Reach out at hello@ailaunchpartner.com