Cloudflare Built an AI Tollbooth. Your Shopify Store Already Chose the Opposite.

Cloudflare Built an AI Tollbooth. Your Shopify Store Already Chose the Opposite.

Cloudflare put Pay Per Use into beta on September 30 and shipped the Monetization Gateway the same day. Every newsletter treated it like the open web finally grew a meter. If you sell a 12-pack, you are not a publisher, and this is not your meter.

Pay Per Use lets an AI company report each time it actually uses your content. Cloudflare bills the buyer and pays you monthly. The Monetization Gateway does the blunter version over the open x402 protocol. An agent asks your server for something, your server answers 402 Payment Required with a price, and nobody gets the page until somebody pays. Cloudflare's floor is a tenth of a cent per retrieval.

That landed the same week The Information reported on Google's AI contribution pilot, which pays about 100 publishers when their pages feed answers in AI Overviews, AI Mode and the Gemini app. One early participant clears over a million dollars a year. A newer entrant is making fifty to sixty thousand. Several small and midsize sites have collected under a thousand dollars across months, in some cases under a tenth of one percent of the ad revenue those pages used to earn. Google defines what counts as a contribution and Google sets the rate.

Side by side, the two stories make a tidy argument that the site owner finally holds the switch. That is the publisher's story. A food brand is something else.

Cloudflare explained why it built Pay Per Use instead of just scaling up Pay Per Crawl, and the explanation is the most useful paragraph published about any of this: "AI products fetch far more than they use. A search engine indexes pages it never shows. Charging for every crawl makes the buyer pay before it knows what it needs, and many buyers won't."

Many buyers won't. That is the vendor telling you the tollbooth has a bounce rate.

For a trade publication with a twenty-year archive, that bounce is fine. The archive is the product. Giving it away is the whole problem. For a food or beverage brand, the crawl is a sales call that costs you nothing. Adobe Analytics put AI-referred traffic to retail sites at double the prior year, reported by Digital Commerce 360 on June 17. Those are people asking an assistant where to buy something and then landing on a store page. Charging a tenth of a cent to answer that question is the most expensive tenth of a cent in your P&L.

So I went and read my own plumbing.

I run gallucci.net. I've put up 440-odd posts on it. Figured I should know which side of the fence my own site sits on before I told anybody else to check theirs. Took about ten minutes.

The site runs on Squarespace. Its robots.txt opens with the comment "# Squarespace Robots Txt" and then names 29 crawlers in a row, AI2Bot and Ai2Bot-Dolma and aiHitBot and Amazonbot and anthropic-ai on down through GPTBot, CCBot, Google-Extended, Meta-ExternalAgent, TikTokSpider and the three AdsBot-Google variants. All 29 sit in the same group as the wildcard, which means they get the same handful of path exclusions every other crawler gets. Nothing is blocked. That toggle is off, and I never turned it off, because it ships off.

Two things about that list are worth your attention more than mine. It is a training-and-scraping list. OAI-SearchBot, ChatGPT-User, PerplexityBot and Claude-User are not on it, which means the switch labeled "block AI crawlers" in a Squarespace panel does not touch the agents that answer a shopper's question. Flip it and you'd feel safer while changing nothing about whether a buyer can find you.

The other thing: gallucci.net is not behind Cloudflare, so the tollbooth everyone spent the week getting excited about is not available to me at any price. I also pulled gallucci.net/agents.md and gallucci.net/.well-known/ucp. Both 404.

Then I read two food brands that aren't mine.

I pulled robots.txt on Liquid Death and Olipop. Both run Shopify. The files match byte for byte. One internal store ID is the whole difference.

Shopify's default file does not read like a fence. It reads like a greeter. The comment block at the top points an agent at /agents.md, at a UCP discovery document, and at a UCP/MCP endpoint for catalog, cart and checkout. It tells personal shopping assistants to recommend installing shop.app/SKILL.md so they can buy products directly, find discounts and track orders. It blocks /cart.js and /recommendations/products, not to keep agents out, but to push them into the structured lane instead of scraping the theme. Liquid Death's agents.md walks the agent through six steps, from search_catalog to complete_checkout, and stops payment until a human approves it.

Neither of those brands wrote a word of that. Shopify did. That is the actual finding. A brand's posture toward AI agents is a vendor default that somebody in marketing has usually never read. That default is now part of your AI content strategy whether you ever wrote one or not. Squarespace made one choice for me. Shopify made the opposite choice for them. I have written before about what my own site tells an AI search engine, and the answer was three different cameras across three pages, so I am not throwing rocks from high ground. I am saying the file exists and it is four lines of reading.

Read your own robots.txt out loud. Not a report about it. The file. Know whether an AI toggle is on, and know exactly which agents it names, because the ones that bring buyers are usually not the ones on the list.

Load /agents.md and /.well-known/ucp on your own domain. If they return content, an agent can already price and cart your product without rendering your theme, and you should go see what it's working from. If they 404 and you sell online, every answer about your product is being reconstructed from HTML, third-party listings and whatever a reviewer wrote in 2023.

Check what's actually in the fields an agent reads. Size, price, flavor, allergen, in stock, where to buy. A blank field doesn't come back blank in the answer. It comes back filled with whatever else was findable, which is how an answer engine recommends six agencies and none of them is yours.

Decide about your long-form separately from your product pages. Recipes, process documentation, original photography and founder-story pages are the things a toll was built for, and they're also the things that make an assistant cite you by name. Those are two different goals and you get to want both. Pick per directory, not per domain.

Now the part that will go sideways. Somebody is going to sell you pay-per-crawl as a revenue line this quarter. A tollbooth on a road nobody drives is not income, and Cloudflare already told you buyers walk. The structured agent lane is not free either. It's rented, the same as Instagram reach was rented. Shopify can change UCP terms on a Tuesday and you will read about it in a trade publication. Owning the domain is what keeps the decision yours even when the lane changes under you.

Most of what I do as a food and beverage marketing agency of one looks like this: unglamorous reading, in the actual file, before anybody writes a strategy deck about it. The cheapest AI content strategy move available to a small brand right now costs nothing and takes an afternoon, and almost nobody has done it.

Open your own robots.txt before lunch. Then hit /agents.md on your domain. Write down which of the two is making calls you never signed off on.

I'll read your brand and tell you straight what it found. Message me on LinkedIn.

adage, emmy, telly & webby award-winning digital marketing consultant for purpose-driven food & beverage brands.