New Private Access Control Tokens (PACT) initiative aims to eliminate CAPTCHAs and invasive tracking while enabling secure verification of human and AI-driven traffic.
Cloudflare has announced a strategic collaboration with Mozilla Firefox, Google Chrome, Microsoft Edge, and Shopify to develop and standardize Private Access Control Tokens (PACT), a privacy-preserving protocol designed to help websites distinguish legitimate users and authorized AI agents from malicious automated traffic.
As AI-powered agents increasingly interact with online services on behalf of users, traditional verification methods such as CAPTCHAs, forced logins, and browser fingerprinting are becoming less effective and often compromise user privacy. PACT introduces a new approach that enables trusted platforms to issue anonymous tokens that can be used to verify legitimacy without exposing personal identity or browsing history.
“The rise of AI-driven traffic demands a new approach to online trust. PACT is designed to help websites verify legitimate users and agents without compromising privacy or user experience.”
— Dane Knecht, CTO, Cloudflare
The initiative aims to create an open standard that balances security, privacy, and user experience while helping businesses defend against sophisticated automated threats. By reducing reliance on intrusive verification methods, PACT is expected to provide a more seamless experience for both human users and AI agents operating across the Internet.
Cloudflare said the protocol will support the emerging era of agentic AI by providing websites with stronger trust signals while maintaining user privacy. The collaboration represents a significant step toward building a more secure, frictionless, and privacy-focused Internet ecosystem.
