Cloudflare has introduced Adaptive Intelligence, a continuous detection engine for its Bot Management suite. By generating short-lived, hyper-targeted rules that rotate before attackers can map them, the system aims to make automated attacks economically unviable. The engine retrains on live traffic, leveraging global telemetry to identify sophisticated threats like credential stuffing and scraping while minimising false positives.
The pitch rests on an argument about cost asymmetry that has been building for several years. Launching an automated attack once required engineering skill. Cloudflare’s account is that cheap tooling and generative models have collapsed that requirement, to the point where someone with a modest budget can rent networks of compromised devices, route traffic through residential IP addresses so it appears to originate from ordinary homes, and run free software that imitates basic human interaction well enough to pass superficial checks.
The attacker can fail repeatedly at negligible cost. The security team has to be correct on every request, in real time, without turning away a paying customer. Cloudflare’s criticism of the incumbent model, including its own earlier generations of tooling, is that detection updates ship on a schedule. The company says conventional bot mitigation can take weeks or months to deploy new signatures while threat actors rotate tactics within hours. That gap is where the product is aimed.
Rotating rules are a bet that attacker reconnaissance is the real bottleneck
The mechanism Cloudflare describes has two parts. The machine learning model retrains continuously on traffic rather than on periodic manual updates, so new bot frameworks and bypass techniques enter the detection engine as they appear. On top of that, the system generates hyper-targeted rules with deliberately short lifespans, which rotate out and are replaced.
The second part is the more interesting claim. Static defences can be reverse-engineered by anyone patient enough to probe them, which is what large-scale credential stuffing and scraping operations do before they scale up. If the rule an attacker mapped on Monday no longer exists on Tuesday, the reconnaissance investment is wasted, and the operation never reaches the volume that makes it profitable.
“Building taller walls fails when the cost of scaling an attack is effectively zero. To stop modern bot threats, you have to flip the economics on the attackers,” said Dane Knecht, CTO at Cloudflare. He described traditional defences as a static target that threat actors can systematically solve, and said Adaptive Intelligence creates a moving target that renders an attacker’s engineering work obsolete before the operation achieves scale.
Cloudflare says the engine draws on more than a trillion web visits a day across its network, a figure the company has not independently verified for this announcement. The scale claim is load-bearing for the product logic, since continuous retraining on a narrow traffic sample would produce a noisier model than one drawing on a large share of global web requests.
The harder problem is low-and-slow traffic that looks entirely legitimate
Cloudflare says the system analyses behaviour across multiple timeframes simultaneously, targeting slow credential stuffing and scraping campaigns that deliberately stay under volumetric thresholds. It also says it combines browser-level session behaviour signals from Cloudflare Precursor with global edge telemetry, evaluating automation and abuse beyond binary bot-or-human tests.
False positives are the commercial risk in any aggressive bot posture, and Cloudflare has addressed it in the launch material. Security updates are tested against live traffic in the background before deployment, the company says, with accuracy verified and false positives checked ahead of rollout, with no downtime.




