Cloudflare, Inc., the leading connectivity cloud company, announced a new initiative with major Web browsers, Mozilla Firefox, Google Chrome, and Microsoft Edge, committing to developing and submitting for standardization a privacy-preserving protocol to help humans and bots prove that their traffic is not malicious.
As the Internet shifts from human-driven clicks to agent activity, website operators must now figure out how to stop aggressive automated traffic, without resorting to invasive tracking. This initiative will lay the foundation for a more frictionless, secure, and private experience for every Internet user and website owner alike.
For decades, website operators have relied on a patchwork of imperfect defense mechanisms to manage automated abuse, but these imperfect techniques are increasingly failing to keep pace with modern threats. Now, with the explosion of Generative AI, the battlefield has shifted yet again. Malicious automation is more widespread, sophisticated, and economically damaging to site owners. As we move toward an era of agentic AI, the line between human behavior and bot activity is blurring, leaving the digital world with an unprecedented privacy problem. When websites attempt to verify that a request originates from a legitimate human or authorized bot, the traditional solutions – forced logins and invasive tracking – compromise user trust.
Private Access Control Tokens (PACT) are designed to allow sites with strong knowledge of “personhood” to issue anonymous tokens. A user’s browser can then provide these tokens to other sites to prove that a human is in the loop, reducing the need for annoying and clunky captchas or invasive tracking. PACT allows all of this to happen without any tracking or ability for sites to identify the user or the user’s browsing history.
PACT will further empower businesses to identify genuine visitors, ensuring they can focus their resources on the traffic that matters to them. PACT leverages trusted information from contexts that have authentic relationships with people while keeping that information private. This provides businesses with high-integrity assurances about their audiences with minimal friction. Using PACT on Cloudflare’s network raises the bar for trustworthiness and integrity online without the traditional costs.







