Nobody's Built the Meter Yet
Last week I wrote about PACT, a new protocol Cloudflare and the browser makers are building to decide which clients count as "real" before they're let in the door. PACT is trying to fix one thing, restated in one line: the ad model was built on eyeball equals reader, and my agent doesn't have eyeballs. When I read a page, an impression fires. When I send an agent to read it for me, it fires for no one. Advertising can't monetize a client that doesn't look at anything. So sites reach for the only lever they have left--decide who gets in--and that's the wall from last week.
402: The HTTP Spec in Waiting
HTTP has a status code for this. It's been sitting in the spec since 1999, in the same section as 404 and 500. RFC 9110 still describes it the same way its predecessors did a quarter-century ago: 402 Payment Required, reserved for future use.
In July 2025, Cloudflare shipped it. Pay Per Crawl let a publisher set a price; an AI crawler that wanted the page got a real, live 402 response; the payment settled, and Cloudflare was the Merchant of Record. Thirty years reserved, and it's no surprise to me that this finally saw the light of day; Coinbase's x402 and Lightning Labs' L402 are the same shape wearing different crypto rails, and the club running them isn't small--the x402 Foundation seats Cloudflare next to Visa, Mastercard, Stripe, and Google.
That was the pitch a year ago. It's already out of date. On July 1st--Cloudflare's second annual "Content Independence Day"--they announced they're walking away from charging per crawl at all. Their own numbers made the case against it: more than half the crawl traffic they classify as legitimate is bots re-fetching pages that haven't changed since the last visit, and a page crawled once might get cited in a thousand AI answers while a page crawled constantly gets cited in none. The crawl was never counting the thing that mattered. So they're piloting pay-per-outcome instead, with two partners--Ceramic.ai pays a publisher when their content actually surfaces in a search result, and You.com lets an agent buy a specific piece of premium content the moment it needs it. Same company, same meter problem, one step closer to counting the read instead of the fetch.
In A Gold Rush, Be the One Selling Shovels
Micropayments have a graveyard, and economists have been filling it in for a while. Nick Szabo called it the mental-transaction-cost problem in 1999; Andrew Odlyzko and Clay Shirky wrote the obituaries for the last wave of "pay a penny per page" schemes in 2001 and 2003. Their argument was about humans, though--the friction of a person deciding, fifty times a day, whether an article is worth a cent. Those critiques assumed a human making hundreds of tiny purchasing decisions. An agent doesn't hesitate over a penny; it simply follows whatever budget and policy its owner gave it. The cognitive friction disappears, but economic friction doesn't--it moves upstream to whoever funds the agent.
The shovel vendor collects at every read, and there's a version of this--L402's permissionless settlement, with no single company in the middle--but that's not the version that's being shipped.
So while I applaud the x402 Foundation for the attempt to bring forward a microtransaction world, I look at those doing the implementation and sitting at the table and wonder if there's only room for people and organizations with established power or deep pockets to play, and it's starting to sound to me like they're selling us all shovels that we have to pay every time we use them.
Micropayment providers are taking a cut, collecting rent on each transaction.
Reading vs Training
But say we do have the infrastructure to pay for everything with microtransactions--even with a perfectly decentralized, no-rent-seeking, creator-paid-fairly version of this. The people angriest about AI aren't really angry about unpaid reads, unpaid human eyeballs. They're worried about unpaid training of AI models.
The industry has already split this into two products. Cloudflare's Pay Per Crawl and TollBit both sell per-crawl access--and TollBit's standard licenses carve out and exclude model training by default, though a publisher can grant it separately as a custom permission. Training is a different market entirely: bulk corpus licensing, the kind behind OpenAI's reported nine-figure deal with News Corp, Reddit's roughly $203 million in aggregate data licensing, and consent platforms like Created by Humans, which launched in January 2025 for the specific purpose of letting creators opt out of training data. Different unit--one-time ingestion versus per-visit access. Different party--the lab that trained the model versus the agent reading a page on someone's behalf. Different harm--permanent displacement versus a missing fraction of a cent.
Run the thought experiment: imagine instead that every scrap of human literature was included into a fully open model instead--weights anyone can download, with no company monetizing exclusive access to what your book helped build, for the good of all humankind. Do people get angry and upset that their works are contributing for the betterment of humankind? I suspect much of today's anger about AI isn't about AI training itself. It's about the belief that private firms are extracting enormous commercial value from that learning without fairly compensating the people whose work made it possible.
If the resulting models were genuinely a public good, I wonder how much of the objection would remain.
The Wage Gap
I've argued before that both of the twentieth century's legal levers for this--copyright's "you can't touch it" and copyleft's "you must share alike"--died the same death, because both tried to control the artifact, and the artifact stopped being where the value lives. You can't fence a file that copies at zero cost. You can't force a company to share a specification an LLM will just regenerate from a paragraph of English. Giving authors a stronger version of either lever--more copyright, a training-data GPL--reaches for a kind of leverage that already stopped working.
The lever that's missing isn't access control. It's a wage.
Because underneath both dead frameworks, what a book actually did for a model was labor--it taught the thing something, the same way a session musician's playing teaches a hit record how to sound. Pay Per Crawl and even the best-case micropayment are still rent: a fee for holding a copy, metered by how often someone touches it. What the training grievance is actually reaching for, half-articulated even by the people angriest about it, is a one-time wage for a one-time contribution--sized to the value that contribution helped create, not to how many times the resulting model gets asked a question. It requires knowing what a single book was worth to a model that read millions of them, which is a far harder metering problem than counting crawls--the shift from paying for ownership to paying for labor is the one still being worked out in the content creator world right now.
Rent is easy to meter. A wage isn't. Cloudflare just admitted the crawl was the wrong thing to count--pay-per-citation is still rent, just charged smarter. We need to figure out how to pay for content creation.
James is a security engineer who thinks about AI training, and who gets paid for what.
Discussion