Cloudflare's PACT Isn't Live Yet—But You Need to Know Which Path Your Traffic Takes

2026-07-31 — management consulting India

I watched a client last week ask the same question three times in slightly different ways. "So this PACT thing—does it block bots or not?" The answer is neither comforting nor simple.

On June 22, Cloudflare announced PACT—Private Access Control Tokens—alongside Firefox, Chrome, Edge, and Shopify. It's a privacy-preserving protocol designed to separate "is this a person or an authorized agent" from "is this malicious." The clever part is it does this without tracking anyone. The hard part is that PACT doesn't answer the question that keeps most of us awake.

The Problem PACT Actually Solves

Here's what sites face right now: bots now comprise roughly 58% of web traffic worldwide. That figure alone should reshape how you think about your audience. Most of that traffic is legitimate—AI agents ordering food, processing payments, doing work on behalf of users. But the old infrastructure can't tell the difference between an authorized agent and a malicious scraper.

So sites layer on friction.

CAPTCHAs. Forced logins. Behavioral tracking that treats every visitor like a suspect. Actually, that's not quite right—they treat every visitor like a valuable data point they can squeeze for information. The friction damages conversion, the tracking damages privacy, and nothing really works anyway.

PACT tries to do one thing cleanly: allow sites to issue anonymous tokens that a user's browser can present to other sites as proof of human involvement. A trusted site that already knows you—your email provider, your bank, your regular shopping site—issues a token. Your browser carries it. You show up somewhere else, present it, and you're in.

No CAPTCHA. No login. No fingerprinting.

Here's the Catch That Matters

The protocol doesn't block malicious bots. It just... doesn't apply to them. PACT answers the question "Is someone with permission here?" It doesn't touch "Is someone malicious here?" Those are two different lanes of traffic, and most of us have been treating them as one.

The agentic shift is real. As the web shifts from human-driven clicks to agent activity, you're going to have two types of automated traffic hitting your infrastructure. One type—AI agents acting on behalf of real users—is what PACT handles. The other type, the ones trying to drain your inventory or scrape your content, just isn't on the table.

That's the conversation I wish more people were having. Not "Is PACT good or bad?" but "What do you actually want to know about the traffic arriving at your door?"

Why Three Browsers Agreeing Matters

Getting Chrome, Firefox, and Edge in the same room on any technical standard is rare. Add Cloudflare and Shopify and you've got coverage across browsers, the network edge, and commerce platforms. When a coalition like that commits to a shared protocol, it tends to materialize. Privacy Pass did. Passkeys did.

PACT will probably become real eventually. The standardization process is underway. But "real" doesn't mean deployed. Most of the web still uses CAPTCHA. Most merchants still don't distinguish between a human visitor and an authorized AI agent. The infrastructure exists. The psychology doesn't.

We get this wrong sometimes, actually—we think a standard becomes real when the spec is finished. It becomes real when it's easier to use the new thing than the old thing. That moment hasn't arrived yet. Sites will keep CAPTCHAs around for years after PACT is technically available, just because it's easier to stick with what they know.

What You Actually Need to Think About Now

PACT tokens contain no personal information, and sites cannot use them to track users or their browsing history. That's the privacy part. But here's what actually matters for your business: you need to decide whether you care more about friction reduction or abuse prevention.

Not both. One.

If your priority is reducing friction—getting more customers to checkout, letting AI tools interact with your site—PACT is a path forward. If your priority is stopping scraping and malicious automation, PACT doesn't solve that problem. You'll still need different tools. You'll still need to choose between fingerprinting and friction.

Most consultants get this wrong, including us sometimes. They talk about PACT as if it's a unified solution when it's really just moving one question out of the way so you can focus on the other.

The protocol isn't live. The conversation about what you actually want to measure—human behavior, authorized agent behavior, or malicious behavior—that's what matters now.