180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-163
Consumer software · United States · 2025 · Undeclared crawling and fabricated attribution

Cloudflare said undeclared crawlers reached brand new domains after Perplexity's declared crawler was blocked, de-listed it as a verified bot, and Perplexity disputed the attribution

By Ellie Harris · Filed Wired reporting June 2024; Cloudflare research published 4 August 2025

Alleged: Perplexity AI developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

Cloudflare said undeclared crawlers reached brand new domains after Perplexity's declared crawler was blocked, de-listed it as a verified bot, and Perplexity disputed the attribution

What happened

Cloudflare reported on 4 August 2025 that it had observed Perplexity crawling sites that had blocked its declared crawler. When the declared crawler was blocked, Cloudflare reported seeing a generic browser intended to impersonate Google Chrome on macOS, making requests from addresses outside Perplexity’s official ranges, with the user agent and source networks repeatedly changed to hide the activity. The test used brand new domains that, in Cloudflare’s words, had not yet been indexed by any search engine nor made publicly accessible in any discoverable way. Cloudflare stated that it had de-listed Perplexity as a verified bot and added heuristics to its managed rules to block the crawling.

Perplexity published a reply the same day, dismissing the research as a publicity exercise and a traffic analysis failure. Its substantive answer was one of misattribution: it stated that Cloudflare had misattributed three to six million daily requests from BrowserBase’s automated browser service to Perplexity. That dispute is not resolved in the sources reviewed for this entry.

The original Wired report could not be retrieved for this entry, and the account that follows rests on outlets reproducing the Wired text. It was reported by Wired in June 2024 that a machine hosted on Amazon infrastructure, and not on Perplexity’s published crawler list, had hit properties belonging to Condé Nast, the publisher of Wired, at least 822 times in three months despite robots.txt blocks. It was reported that Wired built a test page containing a single sentence, and that the product returned an invented story about a girl following glowing mushrooms in a forest, while Wired’s server logs recorded that it never attempted to visit the page. It was also reported that the product told users Wired had reported that a California police officer had stolen bicycles from a garage, and that Wired had published no such report.

What an auditable version would have shown

It cannot be established from outside which sources any particular answer was built from. An auditable version answers that from the agent’s side. A record written for each retrieval says what was requested, from which address and under what declared identity, and whether the request honoured or bypassed an exclusion. A record written for each answer says which retrieved documents were before the model when the response was generated. With those two records, whether an answer rests on a source it names can be checked by reading a log rather than by a publisher testing for it. The identity a crawler presents and the provenance of an answer can instead be checked from records rather than inferred from traffic.

Where the gap was

Cloudflare’s research states that requests continued under a browser identity after the declared crawler was blocked, and Perplexity disputes that the traffic was its own. A ConstraintGate is designed to test a publisher’s exclusion before a fetch is made. A request to an excluded host is refused, and any authorised override is recorded as an explicit decision. The identity a request carries is then a matter of record on the agent’s side. It was reported that the product produced text attributed to a publication that had published nothing of the kind. A CitationVerifier tests each citation against the source it names before an answer is delivered to a user, so an attribution that no retrieved document supports is caught at the point of generation. A ConductRecord preserves the request, the declared identity, the documents retrieved and the output. That allows a disputed answer to be traced afterwards rather than reproduced by a party trying to trigger it again. None of these controls resolves who was responsible for the traffic Cloudflare measured. They mean the record needed to answer that question exists on the agent’s side.

What governance should have looked like

Cloudflare’s findings are contested by Perplexity, whose position is that a substantial share of the traffic belonged to a third party service, and this entry does not resolve that. The 2024 findings rest on Wired’s reporting as carried by other outlets rather than on the original, which could not be retrieved. Where an organisation operates a retrieval agent across the open web, best practice would be for every outbound request to carry a declared and stable identity. Publisher exclusions would be enforced as a check before the request rather than as a policy statement afterwards, and third party retrieval performed on the organisation’s behalf would be identified as such. Each answer would also carry a record of the documents it was actually built from, so an attribution can be tested against them. Several of the copyright claims listed in the sources below are live and untested, and this entry will need revisiting as they are decided.

Failure Pattern: a network operator said undeclared crawler traffic reached material a publisher had excluded, which the company disputed, and a publication separately reported that the product produced text attributed to it that it says it did not publish, with no agent side record tying a given output to the sources actually retrieved.

Governance Principle: an organisation operating a retrieval agent should be able to show, for any answer it produced, which sources were actually fetched and under what identity the request was made, and to establish that a source it names supports the claim attributed to it.

The reference implementation of ConstraintGate, CitationVerifier and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Perplexity AI could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →