Behind the 1,000x forecast, the question is whether the networks that handle internet traffic can absorb the growth cheaply enough, or whether publishers and small retailers end up paying for it.
The internet's traffic mix has not been a 50/50 split between people and machines for years. Cloudflare, which sits in front of roughly a fifth of the web, has been saying so out loud, and on a recent earnings call the company's chief financial officer, Thomas Seifert, made the version of the claim that actually matters for infrastructure planning: non-human traffic could outpace human traffic by a factor of 1,000 within five years (TechRadar reports on the call).
The number is a forecast, and Seifert hedged it himself. "I have called it wrong at every point along the way," he said on the call, referring to Cloudflare's earlier predictions that machines would outnumber humans online by 2027. That earlier call, he noted, was already a year off. Forecasting traffic mix is hard, and the inflection keeps moving as agentic AI, scraping bots, and credential-stuffing tools replace the simpler crawlers of a decade ago. The honesty of the caveat is the part worth keeping, because the version of the story that runs without it is just anxiety.
Every bot request costs Cloudflare money in compute, bandwidth, and the engineering time spent separating it from a real user. Traditional bot traffic was relatively cheap to absorb: dumb scrapers fetched a few pages and left. The new traffic mix is different. Agentic AI browsers and tools that read the web on a user's behalf tend to fetch more pages per session, hold connections open longer, and retry on rate limits. The per-request cost of serving a bot has gone up, not down, even as the volume grows.
Cloudflare is not promising to block the bot traffic. A meaningful share of it comes from partners and customers who want it through, including the search crawlers, AI training pipelines, and price-aggregation services that publishers depend on for distribution. The posture, as Seifert laid it out, is to make the infrastructure cheap enough per request that the growth in machine traffic does not break the parts humans actually use: page load times, checkout flows, search results, paywall integrity. Page speed and checkout completion are the surfaces where the cost shows up first, because both depend on consistent response time under load, and bot traffic is what consumes that headroom.
If the bet does not hold, the cost gets passed along, and the parts of the web that cannot pay more, like independent publishers and small retailers, are the ones that get squeezed first. If it does, the savings accrue to the platform and to the customers who negotiate volume deals, and the parts of the web humans actually use stay usable. The arithmetic is the same at any CDN that promises to absorb a 1,000x traffic mix shift on existing economics: someone is paying for the difference.
The next few earnings calls will tell. One signal is whether average cost per request at the edge falls faster than non-human request volume rises; Cloudflare publishes enough operational data for analysts to track that. Another is whether the user-facing services downstream of Cloudflare, like major retailers and publishers, start reporting measurable improvements in scraper pressure, fraud, and search-gaming, or whether the gains stay invisible to the people paying for them. The third signal is the one Seifert already volunteered: how badly the next round of traffic-share predictions misses, and whether the inflection is closer than a year out or further.
For a non-beat reader, the practical test is whether the next bot-traffic headline is talking about a forecast or a constraint. The forecast is a public-company statement with a self-aware track record. The constraint is real, concrete, and already visible in the engineering work Cloudflare is paying for. Both can be true. The next test is whether the 1,000x figure ages like the 2027 call, or whether the inflection finally shows up in the operational data Cloudflare itself publishes.