3 Sources
[1]
Cloudflare launches Identity-Aware AI Gateway to track who is using AI
Cloudflare Inc. today launched Identity-Aware AI Gateway, a service that attaches a verified identity to every artificial intelligence request leaving a company network. Information technology and security teams can now see which employee or automated system sent a given prompt to a model
[2]
Cloudflare Gives Companies Full Visibility to Audit & Analyze AI Use
Cloudflare, Inc. today launched Identity-Aware AI Gateway, giving IT and security teams their clearest view yet into how employees use AI at work. For the first time, companies can see exactly which employee or agent sent a request to an AI model, set individual or team-level spending limits, and
[3]
Cloudflare Launches Identity-Aware AI Gateway And User Insights
Cloudflare launched Identity-Aware AI Gateway, giving IT and security teams their clearest view yet into how employees use AI at work. For the first time, companies can see exactly which employee or agent sent a request to an AI model, set individual or team-level spending limits, and automatically
Share
Copy Link
Cloudflare unveiled Identity-Aware AI Gateway, linking every AI request to a verified employee or system identity. IT teams can now monitor and manage AI usage, set spending limits per user or team, and flag risky content automatically. The companion User Insights feature detects unusual behavior by learning normal AI usage patterns across networks.
Cloudflare launched Identity-Aware AI Gateway, addressing two critical challenges facing enterprises: spiraling AI costs and security blind spots
1
2
. IT teams can now track who is using AI by attaching a verified identity to every AI request leaving company networks. The service integrates with existing infrastructure, requiring no new systems while delivering visibility and control over employee AI usage that was previously impossible3
.The Identity-Aware AI Gateway connects directly to Cloudflare Access, the company's zero-trust access product, eliminating blind shared API keys that make attribution impossible
1
. Companies integrate with their Identity Provider and Zero Trust network access infrastructure to validate user and device posture before requests reach AI models. Verified identities are written directly into request logs, giving security teams precise accountability2
. Max Baumgarten, a security engineer at Flexport, confirmed that shared API keys made it "almost impossible to tell who is using an AI service" before implementing the solution1
.The companion User Insights feature learns baseline AI usage patterns for every person and automated system on a network
2
3
. When spending spikes beyond normal levels for a specific user or system, IT teams receive immediate alerts. The feature also identifies efficiency opportunities by checking whether employees are pushing simple tasks through expensive, high-powered AI models when lighter alternatives could handle the workload. This behavior anomaly detection addresses a growing problem: while individual AI requests keep getting cheaper, employees and bots fire off far more of them, causing bills to spike with little warning1
.Related Stories
IT teams can set spending limits at individual or team levels, preventing runaway usage before it hits invoices
2
. Rate limiting stops excessive requests in real-time, while automatic filters strip employee names, passwords, and other sensitive data from requests before they reach outside AI providers1
3
. The system also caches repeat requests to cut redundant costs. These capabilities address security risks where confidential files can pass through to external AI models with nobody noticing, a concern that has pushed companies to lock down AI access entirely.Dane Knecht, Cloudflare's Chief Technology Officer, framed the launch as a fundamental shift in enterprise AI strategy. "When security is clunky, it becomes a speed bump that slows down innovation," Knecht explained
2
. Fear of surprise bills and accidental data leaks has driven companies to restrict what teams can build. "Connecting our access controls directly to AI Gateway flips that dynamic," he said. "Teams get the freedom to work with any AI model they choose. IT gets real-time visibility, guardrails, and the budget controls they actually need"1
. The AI Gateway itself dates back to September 2023, with security controls added to Cloudflare's zero-trust platform since August last year1
. The new identity-aware capabilities represent the latest evolution in helping enterprises balance innovation speed with governance requirements as AI usage continues its rapid expansion across organizations.Summarized by
Navi
[3]
25 Aug 2025•Technology

18 Aug 2026•Technology
01 Jul 2026•Technology

1
Technology

2
Technology

3
Science and Research
