A Reddit post, not a confirmed defect, is the entire evidentiary basis for a new warning about Cloudflare’s AI bot controls. A publisher in the r/SEO community reported that switching on Cloudflare’s Block AI Training setting caused both Googlebot and Bingbot to receive HTTP 403 responses when fetching the site’s sitemap. Search Engine Journal first wrote up the thread on August 4, 2026, in a report by Roger Montti. Google’s John Mueller replied and asked the poster to message him directly, a request for more detail, not a confirmation. Google has not verified a bug, and Cloudflare has not commented on the report.

The poster described the trigger plainly: “When I set AI Training = Block, both Googlebot and Bingbot start receiving HTTP 403 responses when trying to fetch my sitemap.” Disabling the setting restored access immediately, according to the same account. The poster also said enabling Bot Fight Mode produced a 403 on sitemap uploads, and that Cloudflare’s own dashboard, in the AI Crawlers panel, listed Googlebot and Bingbot as automatically blocked.

The reported mechanism traces to how Cloudflare classifies crawlers. The poster wrote that Cloudflare now groups Googlebot and Bingbot as bots that serve both search and AI training, so toggling the training block, on this account, catches the search half of that classification along with the training half. Neither Google nor Cloudflare has verified that description of the classification behavior.

The timing is what makes an unconfirmed report worth flagging. Cloudflare’s policy for blocking these dual-purpose crawlers is not scheduled to take effect until September 15, 2026, weeks after this report surfaced. That leaves two open possibilities: either the classification is already being enforced ahead of the announced schedule, or the Block AI Training toggle behaves differently than its label implies. Neither has been confirmed. Both are worth knowing before the change goes live for every Cloudflare customer.

Cloudflare’s own documentation describes what is coming regardless of this report. Starting September 15, the company will set updated defaults so that bots classified as Training or Agent are blocked on pages that carry ads, while bots classified purely as Search remain allowed. Bots that serve both purposes, described in Cloudflare’s documentation as combining Search and Training, are set to be blocked under any configuration that blocks AI training, including the older “Block AI Bots” toggle, unless a site owner opts out before the deadline.

The practical instruction holds regardless of whether this specific report turns out to be a bug or user error. Any site running Cloudflare’s AI bot controls should audit its crawler classification settings now rather than after September 15, check server logs for 403 responses served to Googlebot, and confirm the sitemap is actually fetchable using URL Inspection in Search Console. It is a five minute check against a risk that can cost a site its index coverage.

This is the second time in as many weeks that a site has been hurt by two protective settings interacting in a way nobody intended. We covered a robots.txt disallow paired with a noindex tag producing that same kind of unintended harm on July 29. A blanket AI blocking toggle that also catches the crawler feeding a site’s organic traffic is the same species of problem: the control does exactly what its label says, just not only what the site owner wanted.

Reported by Roger Montti for Search Engine Journal, published August 4, 2026.