Last week I ran a check across 140 healthcare membership organisations — royal colleges, European federations, patient advocacy groups, professional societies. Yours may well have been one of them.
I was looking at something else entirely. What I found instead has a date on it, and the date is five weeks away.
Thirty-three of those 140 organisations are configured in a way that may stop Googlebot reaching their website on 15 September. Not their AI visibility. Their Google listing.
Nobody has done anything wrong. That is rather the point.
What is actually changing
Most of these organisations sit behind Cloudflare — a service that handles web traffic before it reaches the website itself. Roughly a third of the organisations I checked use it, often without anyone in the office knowing, because a previous developer or the hosting company set it up.
At some point over the last two years, Cloudflare offered a button labelled “Block AI bots”. A great many organisations pressed it. It felt sensible. Members’ guidance, clinical standards, years of committee work — why should that be hoovered up to train someone’s chatbot for free?
That was a reasonable decision, and I am not going to tell you it was wrong.
Here is the difficulty. On 15 September 2026, Cloudflare changes how it treats crawlers that do more than one job. From that date, if a crawler does several things and you have blocked any one of them, the block wins.
Googlebot does more than one job. It crawls to build Google Search results — the thing your entire findability depends on. It also crawls for AI training.
So from 15 September, an instruction that meant “don’t train on our content” may start meaning “don’t index us either”. Cloudflare names Googlebot, Bingbot and Applebot explicitly.
Why this lands hardest on membership organisations
Three reasons, and they compound.
Nobody owns the setting. In a commercial business, someone owns the website budget and logs into the infrastructure. In a membership organisation the website is frequently looked after by a communications lead who inherited it, alongside the newsletter, the congress and the members’ handbook. The Cloudflare account was opened by an agency in 2021.
The notification will go to the wrong person. Cloudflare is emailing account holders ahead of the date — to whichever address opened the account. In several organisations I looked at, that will be someone who left years ago.
Nothing looks wrong, and nothing will until it is. This is the bit that worries me most. Of those 33 organisations, most currently have no visible problem at all. Google reaches them fine today. Their site is up, their uptime monitoring is green, their analytics look normal. There is no symptom to notice, right up until traffic falls off a cliff in late September and everyone starts asking whether it was the algorithm.
Three checks, about ten minutes
You do not need a developer for the first two.
1. Are you behind Cloudflare at all?
Ask whoever maintains your site, or look at your DNS settings for nameservers ending in cloudflare.com. If you have no idea who to ask, that is itself worth knowing this month.
If you are not behind Cloudflare, none of this applies to you. Stop here with my apologies for the alarm.
2. Has anyone ever blocked AI bots?
Log into the Cloudflare dashboard, choose your domain, and look under Security → Settings for the AI traffic controls and the older “Block AI bots” toggle.
If Training is blocked, or that toggle is on, Googlebot is in scope from 15 September.
3. Decide what you actually want
This is the only one that needs a conversation rather than a click, and it is worth having properly.
There are two separate questions that the old single button confused:
- Should AI companies train their models on our content? A genuine decision, with a defensible answer either way. If your guidance is your product, blocking training is reasonable.
- Should AI assistants be able to find, read and cite us when a member asks a question? For almost every membership organisation I have worked with, the answer is an emphatic yes. Being the source that gets quoted is the entire point of publishing clinical guidance.
The old button treated those as one question. Cloudflare’s new controls separate them, which is a real improvement — but only if somebody goes in and sets them deliberately.
If you do want to keep blocking training, Cloudflare provides an opt-out so the change does not take Googlebot with it. Use it, and write down why, so that whoever looks next does not quietly undo it.
What I would do this month
If you are behind Cloudflare, get someone into that dashboard before the 15th. It is a settings change, not a project — the hard part is almost always working out who still has the login.
If you are not behind Cloudflare, the underlying question still deserves an answer, but you have no deadline.
And whatever you find, write down what your organisation’s position actually is. The thing that caused this problem was not a bad decision. It was a reasonable decision, made quickly, by someone who has since moved on, that nobody revisited when the ground shifted underneath it.
That will keep happening. The organisations that cope will not be the ones with the cleverest AI strategy. They will be the ones who know what their own settings currently say.
If you would like me to check
I can tell you in about ten minutes whether 15 September is your problem or not — send me your domain and I will look. There is no charge for that and no pitch attached.
If you would like the fuller picture, our Website Check-Up is £400 and covers the technical condition of your site, accessibility and compliance, sustainability, usability, and what AI assistants currently say about your organisation. You will have the report within 48 hours of giving us access, usually within 24, and if you go on to work with us we deduct the £400 from that work.
If the AI question is the one that matters most to you — because accurate guidance is central to what you do — the AI Visibility Check examines it properly on its own, or you can have both together for £750.
Or simply book a call and we will talk it through.
A note on the research
The figures here come from my own check of 140 healthcare membership organisations carried out at the end of July and start of August 2026. I requested each organisation’s homepage as each of twenty documented crawlers and compared the response with what an ordinary browser receives. The “33 at risk” figure counts organisations that are behind Cloudflare, currently refuse training crawlers, and currently serve Googlebot normally — the combination Cloudflare’s change acts on.
I cannot tell from outside whether a given block comes from Cloudflare’s setting or from something else on the site, which is exactly why the checks above are worth running rather than taking my word for it.
Sources
- Cloudflare, Your site, your rules: new AI traffic options for all customers, 1 July 2026
- Cloudflare Bot Management documentation on blocking AI bots
- Content Signals