Cloudflare Delays PACT Launch – Decide Traffic Track

Cloudflare's PACT protocol, backed by major browsers, aims to verify humans without tracking, but the authorization track remains.

By Central
The PACT announcement from Cloudflare and major browsers signals a new era of privacy-preserving traffic verification.
Highlights
  • PACT replaces CAPTCHAs with anonymous, unlinkable tokens that prove human presence without tracking.
  • The coalition includes Cloudflare, Chrome, Firefox, Edge, and Shopify.
  • The authorization track for agentic web traffic remains unresolved with no unified protocol yet.

The internet is being reshaped by a fundamental shift: the entity knocking at your server’s door is increasingly likely to be an autonomous agent, not a human with a mouse and keyboard. On June 22, 2026, Cloudflare, in an unprecedented alliance with Google Chrome, Mozilla Firefox, and Microsoft Edge, announced PACT (Private Access Control Tokens) to solve one side of this new equation—proving a human is actually driving the action. However, as the coalition formalizes this privacy-first protocol for traffic verification, it highlights a critical fork in the road that every website operator must now navigate: the personhood track versus the authorization track.

The PACT Announcement: An Unusual Coalition at the Access Layer

The announcement from Cloudflare, backed by the three dominant browser vendors and commerce platform Shopify, represents a rare moment of consensus among competitors who typically guard their access-layer strategies jealously. The stated goal is to replace CAPTCHAs and forced logins with anonymous, unlinkable tokens. A website that has “strong knowledge of personhood” issues a token. Your browser carries that token to other websites to prove a human is present, or that a bot is an authorized agent, without revealing your identity or tracking your movements.

This is the same architectural approach behind Privacy Pass, the privacy-preserving token system that already substitutes for CAPTCHAs across much of the web. The issuing website cannot see where you spend the token. The receiving website cannot trace it back to you. Two separate token uses cannot be linked. The entire mechanism is designed to prove human presence without the invasive friction of logins, CAPTCHAs, and device fingerprinting that define the current web experience.

Getting Chrome, Firefox, and Edge to agree on anything at the access layer has historically been a slog measured in years, if it happens at all. That this coalition includes both the network edge (Cloudflare) and a major commerce platform (Shopify) signals a level of infrastructure alignment that typically precedes a standardized reality. Like Privacy Pass and passkeys before it, PACT is a proposal today, but it is a proposal backed by enough market power to make its eventual deployment likely.

What PACT Is Designed to Solve: The Human-in-the-Loop Problem

PACT is explicitly designed for the case where a person is in the loop. A human clicks a button. A human directs an agent to perform a task. A human is present to vouch for the action. This is the world the web was built on, and proving it cleanly without tracking or friction would represent a genuine improvement over current methods.

As bots and AI-driven agents flood the web, the value of a clean human signal only increases. Fraud detection, fake account prevention, and manipulation of reviews and content all depend on distinguishing human activity from automated noise. The rarer real people become in the traffic mix, the more valuable a reliable personhood signal becomes. PACT promises to deliver that signal without the baggage of invasive verification systems.

But here is the crucial limitation: PACT answers only one of the two questions the agentic web is splitting along. It verifies that a human is present. It does not tell you anything about the autonomous agent acting without a human driver. The web is moving toward a state where agents act on their own, performing tasks on behalf of users without the user being in the loop for every individual decision. That case, PACT does not touch.

The Second Question: Identifying and Authorizing the Agent Itself

Once no human is driving the interaction, you still need to know whether the autonomous agent is allowed to be here, acting for whom, and permitted to do what. This is the authorization track, and it is being built separately by different players with different infrastructure.

Google has already registered its web agent under a verifiable identity, giving it a known face in the traffic stream. The Web Bot Auth standard lets identifiable crawlers sign their requests cryptographically, creating a chain of provenance. Estonia has gone further, moving to issue state-backed ID codes for AI agents with scoped permissions—view only, edit, or pay—limited to specific amounts and purposes. These are all attempts to answer the question PACT deliberately leaves open: what to do with an agent when there is no human behind it.

The access layer is splitting into two distinct tracks. They are not interchangeable. They solve different problems with different infrastructure requirements. PACT is the personhood track. The authorization track is being built elsewhere, and it requires a fundamentally different approach to identity, consent, and permission.

How PACT Protects Privacy While Proving Personhood

For the personhood track, privacy is the paramount design constraint. The tokens must be anonymous and unlinkable to prevent the tracking nightmare that would arise if a person’s vouched-for human status followed them around the web. The cryptographic mechanism ensures that the issuer cannot see where the token is spent. The receiver cannot tie the token back to its origin. Two tokens from the same issuer cannot be linked to the same user.

This is the same privacy-preserving approach that underpins the anonymous token systems already deployed for CAPTCHA replacement. The difference with PACT is the scope: it aims to replace not just CAPTCHAs but also forced logins and device fingerprinting across websites. The ambition is to make personhood verification ubiquitous, invisible, and privacy-safe.

Who Gets to Be a Trusted Issuer: The Power Question PACT Does Not Answer

The harder question the announcement raises is who gets to be a trusted issuer of personhood. That is real power over who counts as human online. The ability to issue tokens that prove human presence effectively becomes a gatekeeping function with significant economic and social consequences. A website that cannot get tokens from a trusted issuer effectively becomes invisible to the human-only parts of the web.

Cloudflare and the browser makers are the obvious candidates for trusted issuer status, and the announcement concentrates that power with the same few infrastructure companies that already control large portions of the web’s plumbing. Whether the standardization process will open issuer status to a wider set of actors, or whether it will remain concentrated in the hands of the coalition members, is a question that will determine whether PACT becomes an open protocol or a closed system governed by a small number of gatekeepers.

Deciding Which Track Your Traffic Actually Needs

There is nothing to implement today. PACT is a proposal, not a released protocol. No origin trial is available. No version exists that your website can check against this quarter. The timeline from a serious coalition to a usable protocol is typically measured in years. The useful move while the proposal is under development is to figure out which track your traffic actually needs, because they are different problems requiring different infrastructure investments.

The decision framework is clear:

  • If your risk is fraud and abuse from traffic pretending to be people, you need the personhood track. PACT is the protocol to follow, and when it becomes available, it will allow you to verify human presence without the friction of CAPTCHAs or the privacy cost of fingerprinting.
  • If your future involves agents transacting on your website on a customer’s behalf, you need the authorization track. PACT will not help you. You need to be looking at verifiable agent identities, signed request standards like Web Bot Auth, and scoped permission models that allow agents to act within defined boundaries.

Most websites have never had to separate these two questions because until 2025, a visitor was a person by default.

That default is breaking down. The traffic mix is changing. Agents acting autonomously are becoming a significant share of web requests, and the old binary of block-or-allow no longer works. A website that blocks all automated traffic will lose legitimate agent interactions. A website that allows all automated traffic will be flooded with fraud and abuse. The split between personhood and authorization is the new framework for managing this reality.

What the Browser Coalition Signals About the Future of Access Control

The coalition behind PACT is signaling something larger than any single protocol. When Chrome, Firefox, and Edge agree on an access-layer standard, it carries the weight of billions of users and the infrastructure that serves them. The addition of Shopify means the commercial web is being designed into the protocol from the start. This is not an academic exercise; it is a practical infrastructure play backed by the companies that operate the web’s core gateways.

The model of Privacy Pass and passkeys provides a useful precedent. Both started as proposals from coalitions that included browser vendors and infrastructure providers. Both went through standardization processes. Both are now deployed at scale. PACT is following the same trajectory. The gap between announcement and availability is real, but the coalition’s commitment to standardization and deployment suggests that PACT will eventually become part of the web’s access layer.

The Mistake to Avoid: Reading PACT as an Answer to the Wrong Question

PACT is a real answer to a real question: Is there a human present? It will, when deployed, provide a clean, privacy-preserving signal that replaces invasive verification methods. That is a genuine improvement for the human-directed web.

The mistake will be reading PACT as an answer to the question the agentic web actually turns on: What do you do with an agent when there is no person behind it? That question remains open. No equivalent protocol exists at the same level of coalition support. The authorization track is still being built in fragments across Google’s identity efforts, the Web Bot Auth standard, and state-level experiments like Estonia’s agent ID codes. There is no unified solution yet.

The practical consequence for website operators is strategic patience on the personhood track and active monitoring on the authorization track. PACT is worth following because the coalition behind it has the power to make it real. But the deeper strategic bet is on the authorization track, because that is where the agentic web’s most disruptive questions are concentrated. A visitor may be a person by default for now, but that default is fading, and the protocols that replace it will define the next era of the internet.

Share This Article