The AI search startup Perplexity is allegedly skirting restrictions meant to stop its AI web crawlers from accessing certain websites, according to a report from Cloudflare. In the report, Cloudflare claims that when Perplexity encounters a block, the startup will conceal its crawling identity “in an attempt to circumvent the website’s preferences.”
Cloudflare says Perplexity’s AI bots are ‘stealth crawling’ blocked sites
Perplexity disguised its AI crawlers and rotated its IPs to get around restrictions, according to Cloudflare.
Perplexity disguised its AI crawlers and rotated its IPs to get around restrictions, according to Cloudflare.


The report only adds to concerns about Perplexity vacuuming up content without permission, as the company got caught barging past paywalls and ignoring sites’ robots.txt files last year. At the time, Perplexity CEO Aravind Srinivas blamed the activity on third-party crawlers used by the site.
Now, Cloudflare, one of the world’s biggest internet architecture providers, says it received complaints from customers who claimed that Perplexity’s bots still had access to their websites even after putting their preference in their websites’ robots.txt file and by creating Web Application Firewall (WAF) rules to restrict access to the startup’s AI bots.
To test this, Cloudflare says it created new domains with similar restrictions against Perplexity’s AI scrapers. It found that the startup will first attempt to access the sites by identifying itself as the names of its crawlers: “PerplexityBot” or “Perplexity-User.”
But if the website has restrictions against AI scraping, Cloudflare claims Perplexity will change its user agent — the bit of information that tells a website what kind of browser and device you’re using, or if the visitor is a bot — to “impersonate Google Chrome on macOS.” Cloudflare says this “undeclared crawler” uses “rotating” IP addresses that the company doesn’t include on the list of IP addresses used by its bots.
Additionally, Cloudflare claims that Perplexity changes its autonomous system networks (ASN), a number used to identify groups of IP networks controlled by a single operator, to get around blocks as well. “This activity was observed across tens of thousands of domains and millions of requests per day,” Cloudflare writes.
In a statement to The Verge, Perplexity spokesperson Jesse Dwyer called Cloudflare’s report a “publicity stunt,” adding that “there are a lot of misunderstandings in the blog post.”
Perplexity has published a response on its website, claiming Cloudflare conflated 20 to 25 million user agent requests with AI scrapers. “User-driven agents only act when users make specific requests, and they only fetch the content needed to fulfill those requests,” Perplexity says. The startup adds that Cloudflare “confused” Perplexity with “3-6M daily requests of unrelated traffic from BrowserBase,” a cloud browser for AI agents that Perplexity says it only “occasionally” uses.
Cloudflare has since delisted Perplexity as a verified bot and has rolled out methods to block Perplexity’s “stealth crawling.”
Cloudflare CEO Matthew Prince has been outspoken about AI’s “existential threat” to publishers. Last month, the company started letting websites ask AI companies to pay to crawl their content, and began blocking AI crawlers by default.
Update, August 5th: Added Perplexity’s response.
Most Popular
- European retailers yank popular headphones after study reports trace amounts of hormone-disrupting chemicals
- Meta is reportedly laying off up to 20 percent of its staff
- MacBook Air M5 review: a small update for the ‘just right’ Mac
- Gemini’s task automation is here and it’s wild
- PC makers are not ready for the MacBook Neo









