AI Labyrinth is available on an opt-in basis to all customers, including the Free plan.
It's opt-in for now anyway so if it is causing pain people should find a way to contact the website operators in question and have them open tickets assuming they are not on the free plan and get the AI tuned. When all else fails they can create Tell HN threads here and provide details. Sometimes those threads get the attention of Cloudflare executives here. I would bookmark these [1][2]. Excluding non-executives that are also here.
I am personally not against the idea of having squirrel wheel traps for bots as I have created very simplistic ones in the past that worked well against poorly coded bots and sometimes even crashed them to the point where bot operators would block my domains from being crawled. I do not have the skills of CF to make something more advanced like they did or I would and since I do not use CDN's I am on my own unless someone makes an open source version that can be plumbed into HAProxy or Nginx. I guess that makes me a skiddie.
[1] - https://news.ycombinator.com/user?id=jgrahamc CTO of Cloudflare
[2] - https://news.ycombinator.com/user?id=eastdakota CEO of Cloudflare
I do not see it in the free plan. Per the screenshot in the article, on the bots section I see two toggles - Bot Fight Mode and Block Bots. Below these toggles I see
1. A call to action Upgrade Plan for a Super Bot Fight Mode (pro or business)
2. The link to https://developers.cloudflare.com/bots/plans/ which does not mention (yet) of this new security setting.
Yeah, no. That's silly and no normie knows how to contact website operators, or are likely to even understand they should. Also how would they find the contact of they can't access the website. This is exactly the same situation as their captcha giving you an infinite loop.
With so much hate towards LLMs right now (which isn't unjustified) being vented on the internet there's no doubt sysadmins will do the same here and niche user agents will again suffer.
If this works, then legitimate users won't get fake responses. One concern I have is the experience of people using screen readers.
In the spirit of not pitchforking, it does make it sound like they put some non-trivial energy into making the injections hidden, but I'm with you that monkeying with responses is the road to ruin