Some crawlers may disregard robots.txt, but AI crawlers do not all ignore it. The file tells compliant bots which paths a publisher prefers they avoid; it does not stop a bot from requesting those paths. Signed content permissions could help verify a crawler’s identity or stated purpose, but only a server or edge system that enforces access can actually refuse a request.
What robots.txt does—and what it cannot do
RFC 9309, the IETF’s 2022 standard for the Robots Exclusion Protocol, says a crawler that successfully fetches a site’s robots.txt must follow its parseable rules. That requirement applies to crawlers implementing the protocol; it is not a technical barrier against a bot that chooses not to comply. The RFC is explicit: “The Robots Exclusion Protocol is not a substitute for valid content security measures.”
A robots.txt file is public, so listing a path can reveal that the path exists. It also has a limited scope: Google’s documentation says it applies only to the host, protocol, and port where the file is hosted. A file at one host or protocol does not automatically govern another.
Google says its automated crawlers support the protocol and download and parse robots.txt before crawling. That is one reason the blanket claim that AI crawlers ignore the file is too broad. At the same time, an empirical study analyzing 130 self-declared bots over 40 days reported uneven compliance: bots were less likely to follow stricter directives, and some categories, including AI search crawlers, rarely checked robots.txt. Those findings describe the bots and study period observed, not every AI crawler or future behavior.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Choose the control that matches the outcome you want
“Keep this out of search,” “ask bots not to crawl this path,” and “deny access to this content” are different instructions. A policy file or signal can communicate a preference; technical exclusion requires a control that handles the request.
| Mechanism | What it is for | What it does not guarantee |
|---|---|---|
| robots.txt | Expresses crawl preferences for paths to crawlers that honor the protocol. | It does not authenticate a bot or prevent a noncompliant client from requesting a URL. |
| Page-level robots meta tag or X-Robots-Tag header | Provides page- or resource-level instructions about indexing and presentation. | A crawler must fetch the URL to see the instruction. Google’s explanation notes that a robots.txt block prevents Google from taking those page-level directives into account. |
| Content-use signals | Declare preferences about uses such as search, AI input, or model training. | A declaration is not an access-control rule. Cloudflare describes its optional content-use signal as under test in its documentation. |
| Authentication, server rules, or edge controls | Enforce access decisions by refusing or requiring credentials for requests. | They need to be configured and maintained by the site operator; they do not make an unrestricted public page private merely by publishing a policy. |
For actual prevention, restrict the content at the origin or edge: for example, require HTTP authentication, deny selected paths in server or edge rules, or serve sensitive material only to authorized users. Cloudflare distinguishes policy signals from enforcement through its AI Crawl Control product; availability and behavior should be checked against its current documentation. If a page must remain public to people and ordinary search crawlers, but not to selected automated clients, the decision must happen where requests are evaluated, not only in a file describing preferences.
Rank #2
Where signed permissions might fit
A signed request or credential can provide stronger evidence than a User-Agent string, which a client can simply claim to be. In a workable design, the site operator would verify a signature against an agreed trust arrangement and make an access decision based on the verified identity, requested path, and any declared purpose. The signature could support authorization or an audit record; it cannot force a crawler operator to obey policy outside the system that checks it.
Signing is not a complete design by itself. Operators still need rules for who issues trusted keys, how keys are rotated or revoked, whether an agent may delegate to another client, how to handle replayed requests, and what happens when a request has no valid credential. A signed statement of purpose is only as useful as the trust and enforcement rules behind it. It also does not, by itself, settle licensing, contractual, or legal questions about content use.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
- 【Tired of constantly searching for or resetting your passwords?】 MOSA BEAR password keeper book is the perfect solution for you! This password book provides a dedicated place to securely store all your important website addresses, emails, usernames and passwords, ensuring your information is protected and easy to find. The well-designed log pages help you manage multiple accounts in a systematic way, saying goodbye to password confusion.
- 【Premium Design & Password Security】 The password book with alphabetical tabs features an anonymous cover design with no title on the cover, effectively avoiding information exposure. The password keeper design is specifically designed with password security in mind, providing space to record password hints instead of writing directly on the password itself, further protecting your important information.
- 【Simple Layout and Plenty of Space】The 160-page password logbook is designed to provide ample space to record passwords and other important information. It can store up to 414 passwords. In addition, it provides extra pages to record other information, such as email setup, card information, computer operating system information, software licenses, and more. The journal also includes 3 blank pages at the end for you to add additional notes.
- 【Palm-sized Size & Premium Quality】 This password notebook has an ideal size, 4.3" x 5.7", for carrying around, whether in a purse or pocket. Its sturdy glue binding allows the notebook to unfold smoothly and is more comfortable to use. The inner pages are made of high-quality 100GSM thick paper, which can effectively reduce ink penetration and ensure a cleaner and neater writing effect. The overall design takes into account both portability and durability, making it an ideal choice for recording important passwords.
- 【A-Z Tabs for Quick Search 】Our password book comes with alphabetical tabs to help you find the password you need quickly and easily. Alphabetically organized tabs ensure that you can quickly flip to the right section, saving you the time and hassle of searching for your password.
A 2026 preprint proposes one possible direction: a terms.txt file paired with an origin-enforced access exchange using Web Bot Auth signatures, signed intent, delegation tokens, HTTP 402 negotiation, and signed receipts. This is a proposal in a preprint, not an adopted standard or evidence that a particular site has implemented it. Separately, RSL CAP documents a version 1.0 draft licensing flow involving a license file and token. A draft and a research proposal should not be treated as universally supported mechanisms.
How to decide what to deploy
- If you want compliant crawlers to avoid paths: publish and maintain robots.txt rules. Treat them as public crawl preferences, not a lock.
- If you want search indexing or presentation controlled: use page-level robots directives where appropriate, and make sure the crawler can fetch the page to see them.
- If content must not be accessible to unauthorized clients: enforce authentication or denial at the server or edge. Do not rely on a User-Agent check or a policy declaration as the sole gate.
- If you want to distinguish purposes or verify bot identity: signed credentials may be part of an authorization design, but first define the trust roots, lifecycle, delegation, failure behavior, and enforcement point. Check what crawlers and infrastructure actually support before depending on interoperability.
For any policy, make its scope explicit: which hosts and paths it covers, which purposes it addresses, and what response an unauthorized or unidentified client receives. Keep the policy and the enforcement configuration aligned; a permission statement that the server never checks remains a statement, not a control.
Quick Recap
Best Value
Rank #4
- Bookbound planner helps you keep track of passwords and favorite websites
- Room for over 200 entries; 3.5 x 6 inch page sizes
- User name and security questions field
- Tips for what makes a strong password; web resources; notes pages
- Printed on quality paper containing 30% post-consumer waste; black simulated leather cover; 3.63 x 6.13 x .21 inches
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

