← Bot Directory/Meta-ExternalAgent
Bot directory / ai-training

Meta-ExternalAgent: Robots.txt & Crawl Policy Reference

Comprehensive guide to Meta-ExternalAgent, Meta's AI training crawler. Learn how to block or allow data collection for Llama models.

AI Summary: Meta-ExternalAgent is Meta's primary background crawler used to collect data for training foundation AI models, including the Llama family. Blocking this bot opts your site out of Meta's broad AI data harvesting.

Role and policy boundary

Meta-ExternalAgent operates autonomously in the background, scraping the web to build massive datasets for machine learning. This is distinct from Meta-ExternalFetcher, which operates on behalf of a user. If you wish to protect your intellectual property from being used to train Meta's AI models, this is the primary User-Agent to target.

A robots rule is a declaration of intent; it does not replace authentication, authorization, or rate limiting. Start with a dedicated group:

configuration / code
User-agent: Meta-ExternalAgent
Allow: /
Disallow: /staging/
Disallow: /internal/

To stop access for the entire site, use:

configuration / code
User-agent: Meta-ExternalAgent
Disallow: /

Avoid assuming that User-agent: * expresses the same business intent. A wildcard can affect assistant and training crawlers too, and it makes later audits harder because the source of the decision is less specific.

Layered verification

Verify the same URL through each control plane instead of assuming that one green signal represents the whole request path. Compare the bot-specific robots group, the page-level metadata, and the response headers captured at the public edge.

Meta officially states that Meta-ExternalAgent respects robots.txt. To opt out of AI training by Meta, add a specific Disallow rule for this bot. Note that blocking this bot does not affect how your links appear when shared on Facebook or Instagram (which uses facebookexternalhit).

The Policy Engine evaluates the selected user-agent, path scope, and the other supplied layers independently. It can therefore explain why a bot is allowed while another is blocked, rather than returning one blended website score.

Page-level directives can still override the intended outcome for indexing:

configuration / code
<meta name="robots" content="noai, noimageai">
configuration / code
X-Robots-Tag: noai, noimageai

If a response uses these tags, the report marks the result as blocked or conflicting even if the crawler-specific robots group is permissive. This is especially important for canonical pages served through an edge cache where headers may differ from the origin response.

WAF and Nginx remediation examples

To enforce a block at the network layer and prevent bandwidth consumption from Meta's AI training sweeps, you can use a WAF rule:

configuration / code
{
  "description": "Block Meta AI Training Crawler",
  "expression": "lower(http.user_agent) contains \"meta-externalagent\"",
  "action": "block"
}

Use your platform's actual middleware response pattern rather than copying this simplified example without review. Never place a secret, verification token, or internal policy identifier in a public response header.

configuration / code
map $http_user_agent $block_meta_externalagent_private {
    default 0;
    ~*meta-externalagent 1;
}

server {
    location ~ ^/(admin|account|private|licensed|internal|api)/ {
        if ($block_meta_externalagent_private) { return 403; }
        try_files $uri $uri/ =404;
    }
}

Review checklist

Use this checklist after every policy change and after a CDN or WAF migration. Record the request URL, User-Agent, HTTP status, final redirect, and the exact evidence used to reach the decision.

Verify that the dedicated group appears before relying on a wildcard, test a representative public and private path, and compare live response headers with robots.txt. Keep the policy close to the content owner's intent and record whether the site wants discovery, citation, or no access at all.


Need to optimize your entire site for AI search visibility? Run a comprehensive audit with Geolify.ai.