Cloudflare launches Identity-Aware AI Gateway to track who is using AI with verified identities

2 Sources

Share

Cloudflare unveiled Identity-Aware AI Gateway, attaching verified identities to every AI request leaving company networks. IT teams can now see which employee or automated system sent prompts, set spending limits, and flag risky content automatically without deploying new systems.

Cloudflare Tackles Uncontrolled Enterprise AI Usage

Cloudflare launched Identity-Aware AI Gateway, a service designed to attach verified identities to every AI request leaving company networks

1

. IT teams and security teams can now track who is using AI by identifying which employee or automated system sent specific prompts to model providers. The service enables organizations to set spending limits for individuals or teams and flag risky content automatically, all without requiring new systems

2

.

Real-Time Visibility and Budget Controls Address Cost Spikes

A companion feature called User Insights learns normal AI usage patterns for each person and automated system on a network, then alerts teams when activity breaks established baselines

2

. Individual AI requests keep getting cheaper, but employees and bots fire off far more of them, causing bills to spike with little warning

1

. Traditional tools cap AI spending at the account level but cannot identify who generated the costs. User Insights checks whether employees push simple tasks through high-powered models that lighter, less expensive options could handle, surfacing efficiency opportunities

2

.

Zero-Trust Access Integration Eliminates Blind API Keys

The identity capability works by connecting AI Gateway with Cloudflare Access, the company's zero-trust access product

1

. Companies can replace blind, shared API keys that make attribution impossible by integrating with their Identity Provider and ZTNA infrastructure

2

. Requests are authenticated against existing identity providers, with user and device posture validated before anything reaches model providers. The verified identity is written directly into request logs

1

.

Security Risks Mitigated Through Automated Filtering

Employee names, passwords, and confidential files can pass through to outside AI providers with nobody noticing under current approaches

1

. Funneling all AI traffic through a single point enables automatic filters that strip employee names, passwords, and other sensitive data from requests before they reach external AI providers

2

. Rate limits prevent runaway usage before it hits invoices, while repeat requests can be cached to cut redundant costs

1

.

Enterprise Adoption Signals Shift Toward Secure and Compliant AI Adoption

Max Baumgarten, security engineer at Flexport Inc., noted that shared API keys make it "almost impossible to tell who is using an AI service"

1

. The freight logistics company deployed Cloudflare Access in front of AI Gateway so requests now carry authenticated identities, allowing existing identity policies to be applied at the gateway. Chief Technology Officer Dane Knecht explained that fear of surprise bills and accidental leaks pushes companies to lock down AI access, but connecting access controls directly to AI Gateway flips that dynamic

1

. Teams gain freedom to work with any AI model while IT obtains real-time visibility, guardrails, and cost control. AI Gateway launched in September 2023, with security controls added to the zero-trust platform since August last year

1

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved