AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

Introducing Precursor: detecting agentic behavior with continuous client-side signals

15:00 · July 13, 2026 · Cloudflare AI Blog

Introducing Precursor: detecting agentic behavior with continuous client-side signals

Precursor, our new continuous behavioral validation engine for bot management, offers visibility into how humans and bots actually interact across the full user journey. By turning session-level behavior into bot detection signals, it identifies advanced automation with higher precision — while reducing friction for legitimate users.

Summary

Cloudflare has introduced Precursor, a client-side verification system that extends bot detection across an entire user session rather than relying on isolated checkpoints such as login or checkout pages. The service injects a compact, dynamically assembled JavaScript bundle into HTML responses to gather lightweight behavioral signals—pointer trajectories, keyboard timing and rhythm, focus shifts, and page visibility—without capturing raw keystrokes or linking data to user identities. These signals are buffered locally and forwarded at intervals to Cloudflare’s edge for real-time evaluation.

Precursor addresses the limitation of earlier tools like Turnstile, which already handles billions of managed challenges daily but leaves most of an application’s interaction surface unmonitored. Modern automation can execute JavaScript in real browsers and pass single challenges convincingly; consistent human-like behavior sustained over minutes proves far harder to replicate. Evaluators examine correlations such as pointer activity matching visible page time or keyboard events occurring only while a field is focused, then feed consolidated signals into the existing bot-scoring pipeline.

Because Precursor maintains a session-scoped view, a bot cannot reset its behavioral profile by reloading a page. The system also surfaces session-level analytics that let operators inspect typical journeys, identify divergence from expected patterns, and observe automation indicators that appear only across multiple requests. It is offered as an optional Enterprise Bot Management feature and runs initially without additional friction while the operator tunes enforcement thresholds.

Why it matters

This article is highly relevant for security and privacy professionals in the Netherlands as it addresses the growing threat of AI agents bypassing traditional security measures. Its 'privacy by design' approach aligns well with strict EU/GDPR requirements, offering a compliant way to secure applications against advanced automation.

More in this beat
agent-safetyai-agentsbot-detectioncloudflareobservability-updatesPrecursorTurnstile
Announcing Cloudflare Wallets: The programmable wallet for the agentic Internet

15:00 · August 4, 2026

Announcing Cloudflare Wallets: The programmable wallet for the agentic Internet

This article is relevant for security and privacy professionals as it introduces new paradigms for AI agent identity verification and financial guardrails. Understanding these mechanisms is crucial for securing enterprise APIs against unauthorized agent access and ensuring compliance with automated spending policies.

Relevance 75 · Audience 80

Content Independence Day, one year on: building the business model for the agentic Internet

15:00 · July 1, 2026

Content Independence Day, one year on: building the business model for the agentic Internet

This article is highly relevant for security and privacy professionals as it addresses the growing challenge of unauthorized AI data scraping and provides actionable network-level strategies for bot management. It aligns with EU regulatory priorities regarding data sovereignty, transparency, and the protection of proprietary information from indiscriminate AI training.

Relevance 85 · Audience 90

Unmasking the crawls with Attribution Business Insights

08:00 · July 1, 2026

Unmasking the crawls with Attribution Business Insights

This article is highly relevant for Dutch security and privacy professionals as it provides actionable tools to manage AI data scraping, a critical issue under EU copyright and data protection frameworks. It empowers organizations to protect proprietary content, manage infrastructure costs, and enforce data privacy against aggressive AI crawlers.

Relevance 85 · Audience 90

Phishing 3.0: The Fight Moves to Agent Versus Agent

13:30 · August 19, 2026

Phishing 3.0: The Fight Moves to Agent Versus Agent

This article is highly relevant for security professionals as it highlights the emerging threat of AI-driven phishing agents. Dutch enterprises must adapt their cybersecurity strategies to counter AI-generated attacks, making this crucial for maintaining robust organizational security.

Relevance 85 · Audience 95

Agentao: A Governed Local-First Runtime for Tool-Using LLM Agents

06:00 · August 17, 2026

Agentao: A Governed Local-First Runtime for Tool-Using LLM Agents

Agentao's focus on runtime governance, auditability, and permission-mediated execution aligns strongly with the transparency and human-oversight requirements of the EU AI Act. Dutch AI researchers and engineers can leverage this open-source architecture to build compliant, secure, and inspectable local-first AI agents.

Relevance 85 · Audience 90

How Cloudflare detects MCP traffic and helps secure it

15:12 · August 14, 2026

How Cloudflare detects MCP traffic and helps secure it

Directly addresses AI security risks from agent-driven tool calls via MCP, with actionable network controls usable by Dutch enterprises on managed paths. Strong EU relevance through privacy controls, logging, and compliance with data protection needs. Targets security professionals managing AI deployments.

Relevance 85 · Audience 90

Building an open Agentic Internet: readable, discoverable, callable, and payable

15:00 · August 6, 2026

Building an open Agentic Internet: readable, discoverable, callable, and payable

This article is highly relevant for security and privacy professionals as it introduces new cryptographic standards (Web Bot Auth, PACT) for authenticating and managing AI bot traffic. It provides actionable solutions for Dutch enterprises to protect their domains from unauthorized scraping while aligning with EU data protection and copyright directives.

Relevance 85 · Audience 90

Introducing Kitesurf: The agent-first browser that runs in V8 isolates on Cloudflare Workers

15:00 · August 6, 2026

Introducing Kitesurf: The agent-first browser that runs in V8 isolates on Cloudflare Workers

Kitesurf introduces a secure-by-design, isolated browsing environment for AI agents, addressing the critical security risks of autonomous web interaction. For Dutch security professionals, it offers a scalable, stateless architecture that aligns with strict EU data protection and security standards for enterprise AI deployments.

Relevance 85 · Audience 80

The next generation of MCP

15:00 · August 6, 2026

The next generation of MCP

Security and privacy professionals in the Netherlands can apply the updated authorization and stateless design patterns to secure AI agent deployments, aligning with EU data protection expectations. The protocol changes reduce session management risks and improve auditability for Dutch enterprises adopting MCP.

Relevance 65 · Audience 70