cd /news/ai-agents/prove-you-re-human-the-site-wasn-t-c… · home › topics › ai-agents › article
[ARTICLE · art-141825] src=blog.ppb1701.com ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

Prove You're Human. The Site Wasn't Checking Anyway.

Cloudflare published a post announcing Turnstile Spin, a tool that lets an AI coding agent configure Turnstile, and disclosed that it monitors Siteverify calls for every widget and flags any widget serving traffic without server-side validation with a "Fix with Spin" dashboard banner. The disclosure indicates Cloudflare knew per widget that some sites ran the human challenge but never verified the resulting token, and the post omits how many widgets or what share of Turnstile's roughly three billion weekday verifications were affected.

read10 min views1 publishedSep 29, 2026

Back in May I wrote about the whole "prove you're human" racket. reCAPTCHA going from digitizing books to labeling Google's image data, the phone number push, the research showing bots beat humans at the image challenges anyway. Near the end I gave Cloudflare's

Turnstile some partial credit. No traffic lights, no Google, genuinely better. But still a checkpoint you didn't agree to, run by a middleman you didn't pick.

Last Friday Cloudflare published

their own post announcing Turnstile Spin, a tool that lets your AI coding agent set up Turnstile for you. On the surface it's a product launch. Read it a second time and it's something else: an admission that some of those "verify you are human" checkboxes weren't verifying anything.

How It's Supposed to Work #

Turnstile has two halves. The widget sits on the page and runs its challenges in your browser. If you pass, it hands the page a token. Then the site's backend is supposed to send that token to Cloudflare's Siteverify API and ask, "Is this legit?" Only then does the login, signup, or comment actually go through.

Skip the second half and the widget is decoration. The human visitor still gets challenged. The bot just posts straight to the form and the server waves it through, because nobody on the server side ever asked about the token.

"Fix with Spin" #

Here's the part that jumped out at me. Cloudflare says, in their own announcement, that they monitor Siteverify calls for every widget. Any widget that's been serving traffic with no server-side validation now gets a "Fix with Spin" banner in the dashboard.

So Cloudflare knew. Not in the abstract — per widget. They could see which sites were putting you through the challenge and then never checking the result. Enough of those existed that it was worth building a product and a dashboard nag around it. The post even mentions that this flow heads off the support tickets people used to send about broken setups.

What the post doesn't give you is the number. How many widgets? What share of the roughly three billion verifications Turnstile handles on a typical weekday were going to sites that threw the answer away? That's the figure I'd actually want, and it's the one that isn't there.

Think about what that means from your side of the screen. You hit the checkbox. Maybe it spun a while because your DNS filtering blocked something, like I described in May. Maybe you disabled your VPN to get through. And the site on the other end never looked. Your browser did the work, Cloudflare's challenge ran, and the one party that sailed through untouched was the one it was supposed to catch.

AI Builds the Wall Against AI #

The pitch for Spin is that AI coding agents have made it possible for anyone to spin up a site fast, and the security setup didn't keep up with that. Fair enough. Cloudflare also says AI is giving attackers more ways to automate abuse. Their answer is to have the AI install the anti-AI checkpoint.

I'm not even mad at that one, honestly. It's just funny. In May I linked the

ETH Zurich paper where a modified image model solved 100% of reCAPTCHAv2 challenges. Turnstile doesn't use image puzzles, but the solver economy moved right along with it — there are

developer guides for 2026 walking through paying a service to hand you valid Turnstile tokens. So now we have agents building the test, agents taking the test, and a human in the middle clicking a checkbox that may or may not be wired to anything.

And yes, last week I wrote about

Meta's Muse agent lying about what it could read . Different company, different agent, but it's the same question: how much of your security are you comfortable handing to something that confidently tells you what it did? To Cloudflare's credit,

Spin shows a plan and waits for approval before it changes anything, and the code stays on your machine. That's the right design. It's also going to get clicked through by exactly the people it's built for — the ones who don't know what Siteverify is.

The

skill file it hands your agent is careful, too. It tells the agent to treat anything it reads from your repo or from the API as untrusted data that can't change the procedure. That's smart when you're publishing instructions for anyone to paste into any agent, pointed at whatever codebase they happen to have. It even lists "Do not skip validation" as a hard rule.

Which is great, right up until it isn't.

Back in April I wrote about Summer Yue, Meta's director of alignment, who told her OpenClaw agent to confirm before acting. Her real inbox was big enough to trigger context compaction, the instruction got dropped in the squeeze, and the agent bulk-deleted hundreds of emails while ignoring her stop commands. She had to run to her Mac mini and kill it by hand. That's the person whose job is making AI follow instructions.

A rule in a Markdown file is a request, not a guarantee. So the fix for sites that skipped validation is an agent that's been asked nicely not to skip validation.

Credit Where It's Due #

I want to be fair here, same as I was with reCAPTCHA's origin story.

Spin does fix the actual problem. Sites that go through it end up with the backend check in place, which means the challenge people are sitting through finally does something. It also automates migrating off reCAPTCHA and hCaptcha, and every site that moves off Google's checkpoint is one fewer place Google gets to push its phone-verification anchoring on you. Of the two middlemen, Cloudflare is the one that isn't asking for your phone number (yet).

But that's still the trade I called out in May. Moving from Google's tollbooth to Cloudflare's is better. It's not opting out. You still didn't get a vote on either one, and Spin is designed to make Cloudflare's tollbooth easier to put on even more doorsteps — 65,000-plus widgets created through it since July, by their count.

But Wait, There's More #

This post was supposed to go up the other day. It got delayed, and in the meantime Cloudflare kicked off Birthday Week with

another announcement : they're applying to become a certificate authority.

If you're not deep in this stuff, a certificate authority is one of the companies your browser trusts to vouch that a site is who it says it is. It's the padlock. Cloudflare has applied to the Chrome, Apple, Microsoft, and Mozilla root programs, and they've signed a deal to buy an existing GlobalSign root that's been trusted since 2012. A brand-new root takes years to show up on everyone's devices and never reaches the old ones that stopped getting updates. Buying one skips the wait. The trust gets acquired on day one instead of earned. Their pitch is resilience. Let's Encrypt handles a huge share of the web's free certificates, and Cloudflare's post points out that if the dominant free CA "had a bad week, much of the web would have no comparable free, automated alternative ready to take the load." That's a fair point. Single points of failure are bad.

Which is a funny thing to hear from Cloudflare.

Their own post says they sit in front of more than 20% of global Internet request traffic and terminate TLS for millions of domains. Terminating TLS means your encrypted connection actually ends at Cloudflare's edge. Your traffic gets decrypted there, then sent on to the site. Usually re-encrypted. On the Flexible setting, not at all. That's how

Universal SSL worked when they turned it on in 2014, and it's how it works now. So they already see the traffic, they already run the "prove you're human" checkpoint in front of it, and now they want to be one of the companies vouching for the padlock too.

And "a bad week"? Cloudflare has had a few. Just in the last year:

November 18, 2025: A database permissions change caused a config file for Cloudflare's Bot Management system to double in size. That's the part of Cloudflare that decides whether you look like a bot. The file blew past a hard limit, the proxy started throwing errors, and a big chunk of the web went down with it. ChatGPT, X, Shopify, and a long list of others. Core traffic was mostly back after about three hours, and everything was back to normal around six hours after it started. The bot-checking layer didn't just annoy people that day. It took the sites down. #

December 5, 2025: Seventeen days later. A config change meant to patch a React vulnerability tripped a latent bug in their older proxy, and roughly 28% of Cloudflare's HTTP traffic got error pages for about 25 minutes. Shorter, but the same root problem: a config change pushed everywhere at once. #

February 20, 2026: A buggy cleanup task misread a query parameter and started deleting customers' IP routes. About a quarter of the prefixes customers bring to Cloudflare got withdrawn from the Internet. The worst of it lasted about an hour. The full cleanup took just over six hours.

After the first two, Cloudflare declared

"Code Orange: Fail Small" , with the stated goal of making sure "the cause of our last two global outages never happens again." Their words.

Two global outages. In three weeks. They say the work

wrapped up in May , and to be fair, I haven't seen another one on that scale since. But when the CA announcement promises to "fail small," that's the language from the plan they wrote after failing big. Twice.

Worth being clear about what a CA does and doesn't do: issuing certificates doesn't give Cloudflare anyone's traffic. A site could get a Cloudflare certificate and never route through Cloudflare at all. And some of what they're promising is genuinely good. Reproducible builds of the signing software. Attested hardware for the keys. A public dashboard for issuance health and incidents, because as they put it, audits tell you a CA passed, not how it runs on an ordinary Tuesday. It's ACME-first, so switching to them or away from them is a directory URL change. They're also pushing early on post-quantum certificates. If any company other than Cloudflare were announcing this, I'd mostly be nodding along.

But that's the thing. It's the same trade as Turnstile, one layer down. The answer to "too much of the web depends on one free certificate provider" is a company that already sits in front of a fifth of the web's traffic becoming a second one. The fix for concentration is more Cloudflare.

My Take #

The quiet admission in this post is that for enough sites to justify building a product around it, "prove you're human" was pure theater. It wasn't protecting the site. It was friction for real people and a speed bump bots didn't even have to slow down for. The checkpoint only worked on the people it was supposed to let through. All it reliably did was run a challenge in your browser on behalf of a company you never chose to deal with.

Cloudflare fixing that is good. But Cloudflare knowing about it per widget, and the fix being "let an AI agent wire it up," tells you how this whole system actually runs: nobody on the site's side was paying attention, and the checkpoint went up anyway.

Four days later the same company announced it wants to vouch for the padlock too. Each piece has a reasonable pitch on its own. The checkpoint, the proxy, the decryption, now the certificates. Put together, more and more of what happens between you and the website you actually wanted runs through one company you never picked.

Next time a checkbox spins at you, remember it might not be guarding anything. You might just be the only one who got checked.

── more in #ai-agents 4 stories · sorted by recency
── more on @cloudflare 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/prove-you-re-human-t…] indexed:0 read:10min 2026-09-29 · —