Why does my AI agent get blocked on sites it reached fine last month? An AI agent blocked in 2026 usually falls into one of three cases: the site decided it does not want agents, the site's bot detection decided your agent is a bot, or something is rate limiting it. Each case has a different fix, and the most common mistake is buying proxies for a problem a proxy cannot touch. Work out which case you are in first, then apply the matching fix.
2026 added two new layers on top of the old anti-bot stack: Cloudflare now blocks the "Agent" category by default on ad pages of new domains, and a federal court briefly ordered one AI shopping agent off Amazon before an appeals court vacated the order.
Key takeaways
- Agent blocks come in three kinds: policy blocks (the site or its CDN refuses agents), bot flags (your agent looks automated), and rate limits (from the site or from your model API).
- Since September 15, 2026, Cloudflare blocks bots it classifies as Agent by default on ad-displaying pages of newly onboarded domains. Owners can change that setting.
- Most self-built agents are not blocked by policy. They are flagged as bots because they run from a cloud IP, in headless Chromium, with a fresh profile and machine-speed actions.
- The durable fix is one stable identity per agent: a real browser, a kept profile, one clean mobile IP held for the whole task, and human pacing. Rotating IPs makes it worse.
- A proxy does not fix a declared agent a site has chosen to block, a served CAPTCHA, or a 429 from your model provider.
Why Your AI Agent Gets Blocked: Policy, Bot Flags or Rate Limits
An AI agent getting blocked by websites usually traces back to how it arrives. Sites see an agent in one of two ways. Either it announces itself (a declared user agent, a signed request, a known operator's infrastructure), or it arrives looking like a browser and gets scored like any other visitor. That split decides which fix applies.
| Block type | What you see | Who decided | What fixes it | What doesn't |
|---|---|---|---|---|
| Policy block | 403 Access denied where your agent identifies itself, or a legal letter | The site owner or its CDN settings | Permission, a signed agent, the site's API, or a personal browser agent | A new IP |
| Bot flag | Challenges, 403s and silent login failures | Bot scoring on IP, fingerprint and behavior | One stable identity per agent | Rotating IPs faster |
| Rate limit | 429 Too Many Requests | The site, or your model provider | Pacing, backoff, a higher API tier | A proxy, for model API limits |
Most failures land in the middle row.
Before reading an AI agent access denied error as an IP ban, open the same URL in a normal browser on the same connection. If your browser passes and the agent fails, the site is reacting to the agent itself. If both fail, the IP or region is the problem. If only pages that carry ads fail, suspect the new Cloudflare default.
AI Agent Blocked by Cloudflare: The September 15 Default
On July 1, 2026, Cloudflare split AI traffic into three categories that site owners control separately: Search, Agent and Training. Its changelog defines Agent as automated activity acting in real time on a person's behalf, naming chat fetch bots and browser-use agents as examples.
Read the scope carefully, because most coverage exaggerates it. Only domains that join Cloudflare after September 15 get the new default. It applies only to pages that display ads, and site owners can opt out or block on all pages instead. A site that moved onto Cloudflare after September 15 and now refuses your agent on article pages, but not on checkout, fits this pattern. A long-standing Cloudflare site that started refusing agents earlier was changed by its owner, not by the default.
What to Do When Cloudflare Blocks the Agent Category
Cloudflare's category controls act on traffic it can attribute to an agent: declared user agents, signed requests, and operators in its bot directory. There are three ways to work with that, starting with the most sanctioned.
Method 1: Ask, or use another door. Site owners can set Agent to allowed in one click, so for partners and vendors the fastest fix is an email. Many sites with agent-hostile defaults still offer an API or data feed. And the default only covers pages with ads, so an agent that reads ad-free endpoints (account pages, checkout, documentation) may never trigger it.
Method 2: Become a signed agent. Cloudflare verifies agents through Web Bot Auth, which attaches a cryptographic signature to each request. Its signed agents policy sets the bar: honest identification (a Web Bot Auth signature, a published IP list with a stable user-agent, or reverse DNS) and non-abusive behavior: obey robots.txt and crawl directives, keep request rates reasonable, and never evade site owner preferences. That route fits a product like an AI browser, not a scraper aimed at one target.
Method 3: Drive your own browser yourself. An agent operating your own browser profile on your own connection is, in the Ninth Circuit's framing below, the user accessing the site, so category controls aimed at declared agent traffic do not apply to it. Ordinary bot scoring still does, and a site's terms still apply. Whether it passes comes down to the stable identity setup below.
None of the three covers spoofing another bot's identity (claiming to be Googlebot or a signed agent), forging signatures, or continuing into password-protected accounts after a platform has explicitly refused you. That last one is where the Amazon v. Perplexity fight below centers.
When the Block Is Legal, Not Technical: Amazon v. Perplexity
In March 2026, Amazon won a court order blocking Perplexity's AI shopping agent: Judge Maxine Chesney granted a preliminary injunction barring Comet from shopping on Amazon. As GeekWire reported, the court found Amazon likely to win its federal and California computer fraud claims, and Amazon had argued that Comet disguised its agent as an ordinary Chrome session. Perplexity appealed, and on August 4, 2026 the Ninth Circuit vacated the injunction. It held that the user, not Perplexity, "accesses" Amazon's computers, so the agent is a tool, not a person, for computer fraud purposes. The court called its holding narrow and tied to the record, and the case returned to the district court.
“with the Amazon user's permission, but without authorization by Amazon”
For builders, the takeaway is mixed. The appeals court rejected the computer fraud theory, but it tied its reasoning to an agent running on the user's own device. Password-protected accounts, repeated demands to stop, and an agent built to avoid identification all came together in that case, and continued access after an explicit refusal is the fact pattern that supported the original injunction. No proxy or browser setting changes that.
Flagged as a Bot: What Sites See When Your Agent Arrives
Most "my agent stopped working" reports are not policy blocks at all. An AI agent flagged as a bot usually never declared itself. Bot detection caught it anyway, for four reasons stacked together.
Start with the IP. Agents tend to run on cloud VMs, and datacenter ranges are often scored as higher risk regardless of how polite the traffic is (Cloudflare's bot score documentation lists IP and ASN among its inputs), which is why our guide to AI agents on mobile infrastructure starts at the network layer. Next comes the browser: stock headless Chromium leaks automation signals, and a User-Agent claiming Chrome on Windows over a TLS handshake or client hints that disagree is a contradiction detectors look for, as Fingerprint's bot detection overview explains. Then state: a fresh profile on every run has no cookies, no history and no site engagement, which is the exact shape of a throwaway. Last, behavior. Agents tend to click the moment elements render, rarely scroll without purpose, and go straight to the endpoint. When a flag escalates to a challenge page, our Cloudflare Turnstile guide covers how those challenges work.
- IPDatacenter ASNDedicated mobile carrier IP
- BrowserHeadless, fresh profilePatched or headed, kept profile
- SessionNew identity each runSame IP for the whole task
- PaceMachine speedHuman-paced steps
To see which side of that table your agent is on, open this page inside the agent's own browser profile. The check below shows the IP type, carrier or hosting ASN, and location that every site it visits sees too.
What does your IP reveal right now?
How to Fix AI Agent Blocked Errors: One Stable Identity per Agent
The fix that holds is not more anonymity. It is consistency: each agent looks like one ordinary person on one ordinary device, every time it shows up.
Use a real browser engine, not an HTTP client, and swap stock Playwright Chromium for a headed or patched build whose reported fingerprint matches its real environment. Persist the profile directory between runs so cookies and history accumulate. Derive timezone, locale and language from the exit IP, not from the server the agent runs on. Add uneven delays between steps.
Then give each agent one IP and keep it.
Rotating per request is the instinct carried over from scraping, and it backfires here: the cookies an agent earns are tied to its session, and one profile hopping across addresses reads as automation rather than as a new visitor. Rotate between tasks, never inside one.
A dedicated mobile proxy fits that model directly. Each one is a 1:1 physical 4G/5G device with clean IP history (Premium adds dedicated DNS), so the agent's address sits behind carrier CGNAT alongside ordinary phone users instead of in a hosting range, and it changes only when you rotate it.
Let the Agent Provision Its Own Mobile IP Over MCP
Wiring proxy strings into agent configs by hand breaks the moment you run more than a few agents. The VoidMob MCP server lets the agent handle it as a tool call: it searches plans by country, quotes the price, is told to wait for your yes, buys with that price as a hard ceiling, and reads back ready-to-paste connection details.
1# Claude Code; the /mcp page has configs for Codex, Cursor, Gemini CLI and others2claude mcp add voidmob -s user \3-e VOIDMOB_API_KEY=vmk_live_... \4-e VOIDMOB_MAX_ORDER_CENTS=2500 \5-e VOIDMOB_BUDGET_CENTS=5000 \6-- npx -y @voidmob/mcp7 8# Then ask the agent:9# "Find a dedicated US mobile proxy, quote it, wait for my yes,10# then give me the connection details and keep it for this task."11#12# Tools it calls: search_proxies -> purchase_proxy (max_price_cents)13# -> get_proxy_status, and rotate_proxy_ip only between tasksYou create the API key in the dashboard and top up the prepaid balance there with crypto. Both caps live in your MCP server, so one looping agent session cannot spend past them, and every purchase also checks the price you approved against that balance, which is the account-wide limit. Rotation through the tool is limited to once a minute, and the same server also covers carrier numbers for agents that hit phone verification.
Rate Limits: When the 429 Comes From the Site or From Your Model API
A 429 Too Many Requests means something is counting. When the site sends it, slow down, honor the Retry-After header if one is present, and spread work across agents with their own identities instead of pushing one harder.
When the 429 comes from your model provider, no network change will help. The limit sits on your API key and usage tier, so back off exponentially, cut parallel calls, cache repeated prompts, or request a higher tier. Routing model API calls through proxies to dodge those limits breaks provider terms and does nothing for the underlying quota.
FAQ
Why is my AI assistant suddenly unable to access certain websites?
Either the site changed its policy toward agents, or its bot detection started flagging your agent. Since September 15, 2026, Cloudflare blocks bots it classifies as Agent by default on ad-displaying pages of newly onboarded domains. If the agent never identifies itself, the cause is usually a datacenter IP, a headless browser, a fresh profile on every run, or machine-speed behavior.
Does Cloudflare block AI agents by default?
Partly. From September 15, 2026, domains that newly join Cloudflare block the Agent and Training categories by default on pages that display ads, while Search stays allowed. It applies to traffic Cloudflare can classify as an agent, and site owners can allow agents, block them everywhere, or keep the ad-page default.
How do I prevent my AI agent from being flagged as a bot?
Give each agent one stable identity: a real browser engine instead of an HTTP client, a persisted profile with cookies and history, timezone and language matched to the exit IP, human-paced actions, and one clean mobile IP held for the whole task. Rotating IPs inside a task makes flags more likely, not less.
How can I prevent my AI agent from being blocked by API rate limits?
If the 429 comes from your model provider, the limit is tied to your API key and tier. Back off exponentially, reduce parallel requests, cache repeated prompts, and request a higher tier. A proxy does not help with model API limits. If the 429 comes from a website, slow down and honor its Retry-After header.
How do I check if my AI agent is blocked?
Log the HTTP status and page title for every step the agent takes. Then load the same URL in a normal browser on the same connection. If the browser passes and the agent fails, the site is reacting to the agent itself. If both fail, the IP or region is blocked. A 429 points to rate limiting.
Did Amazon win a court order blocking Perplexity's AI shopping agent?
At first, yes. In March 2026, Judge Maxine Chesney of the Northern District of California granted Amazon a preliminary injunction barring Perplexity's Comet agent from accessing Amazon accounts, finding Amazon likely to succeed on its computer fraud claims. On August 4, 2026, the Ninth Circuit vacated that injunction, holding that the user, not Perplexity, accesses Amazon's systems, and sent the case back to the district court.
Identify the Block, Then Fix the Identity
An AI agent blocked in 2026 is rarely a mystery once you sort the cause. Policy blocks need permission, a signed identity, another door, or a personal agent that operates like any other browser. Bot flags need one consistent identity per agent, built on a real browser, a kept profile and a clean carrier IP that stays put for the whole task. Rate limits need patience, not addresses. Next step: open the IP check in your agent's own browser profile, close the gaps in the table above, and only then consider a dedicated IP. If the agent still fails after that, you are in the policy-block row, not the bot-flag row.
Give each agent one stable mobile IP
A dedicated mobile proxy is one real 4G/5G device on a carrier connection, held for the whole task and rotated only when you decide.
