3 Sources
[1]
Cloudflare launches Identity-Aware AI Gateway to track who is using AI
Cloudflare Inc. today launched Identity-Aware AI Gateway, a service that attaches a verified identity to every artificial intelligence request leaving a company network. Information technology and security teams can now see which employee or automated system sent a given prompt to a model provider. The service also lets them set spending limits for an individual or a team and flag risky content automatically. Cloudflare said it requires no new systems. A companion feature called AI Spend goes at the cost problem from another angle. It learns what normal AI usage looks like for each person and each automated system on a network, then alerts teams when something breaks that pattern. Enterprise AI use is growing quickly and two problems are growing with it. Individual AI requests keep getting cheaper. Employees and bots are firing off far more of them, and bills spike with little warning. The security side is quieter. Employee names, passwords and confidential files can pass through to outside AI providers with nobody noticing. Today's tools cap AI spending at the account level. They cannot name who ran up the bill. What was actually in the request does not show up in the logs either, so IT teams end up cleaning up after the fact. Chief Technology Officer Dane Knecht said clunky security becomes a speed bump and that fear of surprise bills and accidental leaks is pushing companies to lock down AI access. "Connecting our access controls directly to AI Gateway flips that dynamic," Knecht said. "Teams get the freedom to work with any AI model they choose. IT gets real-time visibility, guardrails, and the budget controls they actually need." The identity piece comes from wiring AI Gateway into Cloudflare Access, the company's zero-trust access product. Companies that do so can drop the blind, shared application programming interface keys that make attribution impossible. Requests are authenticated against an existing identity provider and zero-trust network access setup. User and device posture are validated before anything reaches the model provider, and the verified identity is written into the request log. Funneling all AI traffic through a single point does other work as well. Repeat requests can be cached to cut redundant costs. Rate limits stop runaway usage before it hits the invoice. Automatic filters strip employee names, passwords and other sensitive data out of requests before they ever reach an outside AI provider. Model choice gets scrutiny too. AI Spend checks whether staff are pushing simple tasks through high-powered models that a lighter and cheaper option could handle, then surfaces those cases. Max Baumgarten, a security engineer at Flexport Inc., said shared API keys make it "almost impossible to tell who is using an AI service." The freight logistics company put Cloudflare Access in front of AI Gateway. Requests now carry an authenticated identity, and Baumgarten said the identity policies Flexport already had can be applied to them at the gateway. AI Gateway dates back to September 2023. The security controls are newer, and Cloudflare has been adding them to its zero-trust platform since August last year.
[2]
Cloudflare Gives Companies Full Visibility to Audit & Analyze AI Use
Cloudflare, Inc. today launched Identity-Aware AI Gateway, giving IT and security teams their clearest view yet into how employees use AI at work. For the first time, companies can see exactly which employee or agent sent a request to an AI model, set individual or team-level spending limits, and automatically flag risky content - all without building new systems or disrupting how people work. A companion feature, User Insights, goes further by learning what normal AI usage looks like for every person and automated system on a network and alerting teams the moment something breaks that pattern. AI use inside companies is growing fast, and two problems are growing with it: rising costs and security blind spots. On the cost side, even as individual AI requests get cheaper, employees and automated bots are sending far more of them and bills are spiking with little warning or explanation. On the security side, sensitive information like employee names, passwords, and confidential files can quietly pass through to outside AI providers with no one noticing. Today's tools can cap overall AI spending across an account, but they can't tell you who triggered those costs or what was sent, leaving IT teams managing damage after the fact instead of preventing it. "When security is clunky, it becomes a speed bump that slows down innovation. Right now, companies are wary of surprise AI bills or accidental data leaks, so their instinct is to lock down access and restrict what teams can build," said Dane Knecht, CTO of Cloudflare. "Connecting our access controls directly to AI Gateway flips that dynamic. Teams get the freedom to work with any AI model they choose. IT gets real-time visibility, guardrails, and the budget controls they actually need." Together, AI Gateway and User Insights allow enterprises to: * See Exactly Who's Sending What: By connecting AI Gateway with Cloudflare Access, every AI request is now tied to a verified identity whether that's an employee or an automated system. * Catch Unusual Behavior Before It Becomes a Problem: User Insights tracks each user's AI activity over time and builds a user baseline. When spending spikes well beyond what's normal for a specific user or system, IT gets an alert. * Surface Efficiency Opportunities That Are Easy To Miss at Scale: User Insights checks whether employees are using high-powered models for simple tasks that lighter, less expensive models could handle so efficiency gains are easy to find. * Enforce Identity-Based Access and Authentication: Companies can replace blind, shared API keys by integrating with their Identity Provider (IdP) and Zero Trust (ZTNA) infrastructure. This validates user and device posture before sending requests to the model provider without slowing adoption, recording verified identities directly in request logs.
[3]
Cloudflare Launches Identity-Aware AI Gateway And User Insights
Cloudflare launched Identity-Aware AI Gateway, giving IT and security teams their clearest view yet into how employees use AI at work. For the first time, companies can see exactly which employee or agent sent a request to an AI model, set individual or team-level spending limits, and automatically flag risky content?all without building new systems or disrupting how people work. A companion feature, User Insights, goes further by learning what normal AI usage looks like for every person and automated system on a network and alerting teams the moment something breaks that pattern. AI Gateway and User Insights allow enterprises to see exactly who?s sending what by connecting AI Gateway with Cloudflare Access, every AI request is now tied to a verified identity whether that's an employee or an automated system. User Insights tracks each user's AI activity over time and builds a user baseline. When spending spikes well beyond what's normal for a specific user or system, IT gets an alert. User Insights checks whether employees are using high-powered models for simple tasks that lighter, less expensive models could handle so efficiency gains are easy to find. Companies can replace blind, shared API keys by integrating with their Identity Provider (IdP) and Zero Trust (ZTNA) infrastructure. This validates user and device posture before sending requests to the model provider without slowing adoption, recording verified identities directly in request logs. Instead of managing AI usage piecemeal across every tool and model provider, all requests flow through a single point. That gives IT immediate visibility across the board, the ability to cache repeat requests and cut redundant costs, rate limiting to stop runaway usage before it hits the invoice, and automatic filters that strip out employee names, passwords, and other sensitive data before they ever reach an outside AI provider.
Share
Copy Link
Cloudflare unveiled Identity-Aware AI Gateway, linking every AI request to a verified employee or system identity. IT teams can now monitor and manage AI usage, set spending limits per user or team, and flag risky content automatically. The companion User Insights feature detects unusual behavior by learning normal AI usage patterns across networks.
Cloudflare launched Identity-Aware AI Gateway, addressing two critical challenges facing enterprises: spiraling AI costs and security blind spots
1
2
. IT teams can now track who is using AI by attaching a verified identity to every AI request leaving company networks. The service integrates with existing infrastructure, requiring no new systems while delivering visibility and control over employee AI usage that was previously impossible3
.The Identity-Aware AI Gateway connects directly to Cloudflare Access, the company's zero-trust access product, eliminating blind shared API keys that make attribution impossible
1
. Companies integrate with their Identity Provider and Zero Trust network access infrastructure to validate user and device posture before requests reach AI models. Verified identities are written directly into request logs, giving security teams precise accountability2
. Max Baumgarten, a security engineer at Flexport, confirmed that shared API keys made it "almost impossible to tell who is using an AI service" before implementing the solution1
.The companion User Insights feature learns baseline AI usage patterns for every person and automated system on a network
2
3
. When spending spikes beyond normal levels for a specific user or system, IT teams receive immediate alerts. The feature also identifies efficiency opportunities by checking whether employees are pushing simple tasks through expensive, high-powered AI models when lighter alternatives could handle the workload. This behavior anomaly detection addresses a growing problem: while individual AI requests keep getting cheaper, employees and bots fire off far more of them, causing bills to spike with little warning1
.Related Stories
IT teams can set spending limits at individual or team levels, preventing runaway usage before it hits invoices
2
. Rate limiting stops excessive requests in real-time, while automatic filters strip employee names, passwords, and other sensitive data from requests before they reach outside AI providers1
3
. The system also caches repeat requests to cut redundant costs. These capabilities address security risks where confidential files can pass through to external AI models with nobody noticing, a concern that has pushed companies to lock down AI access entirely.Dane Knecht, Cloudflare's Chief Technology Officer, framed the launch as a fundamental shift in enterprise AI strategy. "When security is clunky, it becomes a speed bump that slows down innovation," Knecht explained
2
. Fear of surprise bills and accidental data leaks has driven companies to restrict what teams can build. "Connecting our access controls directly to AI Gateway flips that dynamic," he said. "Teams get the freedom to work with any AI model they choose. IT gets real-time visibility, guardrails, and the budget controls they actually need"1
. The AI Gateway itself dates back to September 2023, with security controls added to Cloudflare's zero-trust platform since August last year1
. The new identity-aware capabilities represent the latest evolution in helping enterprises balance innovation speed with governance requirements as AI usage continues its rapid expansion across organizations.Summarized by
Navi
[3]
25 Aug 2025•Technology

18 Aug 2026•Technology
01 Jul 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
