2 Sources
[1]
Cloudflare launches Identity-Aware AI Gateway to track who is using AI
Cloudflare Inc. today launched Identity-Aware AI Gateway, a service that attaches a verified identity to every artificial intelligence request leaving a company network. Information technology and security teams can now see which employee or automated system sent a given prompt to a model provider. The service also lets them set spending limits for an individual or a team and flag risky content automatically. Cloudflare said it requires no new systems. A companion feature called AI Spend goes at the cost problem from another angle. It learns what normal AI usage looks like for each person and each automated system on a network, then alerts teams when something breaks that pattern. Enterprise AI use is growing quickly and two problems are growing with it. Individual AI requests keep getting cheaper. Employees and bots are firing off far more of them, and bills spike with little warning. The security side is quieter. Employee names, passwords and confidential files can pass through to outside AI providers with nobody noticing. Today's tools cap AI spending at the account level. They cannot name who ran up the bill. What was actually in the request does not show up in the logs either, so IT teams end up cleaning up after the fact. Chief Technology Officer Dane Knecht said clunky security becomes a speed bump and that fear of surprise bills and accidental leaks is pushing companies to lock down AI access. "Connecting our access controls directly to AI Gateway flips that dynamic," Knecht said. "Teams get the freedom to work with any AI model they choose. IT gets real-time visibility, guardrails, and the budget controls they actually need." The identity piece comes from wiring AI Gateway into Cloudflare Access, the company's zero-trust access product. Companies that do so can drop the blind, shared application programming interface keys that make attribution impossible. Requests are authenticated against an existing identity provider and zero-trust network access setup. User and device posture are validated before anything reaches the model provider, and the verified identity is written into the request log. Funneling all AI traffic through a single point does other work as well. Repeat requests can be cached to cut redundant costs. Rate limits stop runaway usage before it hits the invoice. Automatic filters strip employee names, passwords and other sensitive data out of requests before they ever reach an outside AI provider. Model choice gets scrutiny too. AI Spend checks whether staff are pushing simple tasks through high-powered models that a lighter and cheaper option could handle, then surfaces those cases. Max Baumgarten, a security engineer at Flexport Inc., said shared API keys make it "almost impossible to tell who is using an AI service." The freight logistics company put Cloudflare Access in front of AI Gateway. Requests now carry an authenticated identity, and Baumgarten said the identity policies Flexport already had can be applied to them at the gateway. AI Gateway dates back to September 2023. The security controls are newer, and Cloudflare has been adding them to its zero-trust platform since August last year.
[2]
Cloudflare Launches Identity-Aware AI Gateway And User Insights
Cloudflare launched Identity-Aware AI Gateway, giving IT and security teams their clearest view yet into how employees use AI at work. For the first time, companies can see exactly which employee or agent sent a request to an AI model, set individual or team-level spending limits, and automatically flag risky content?all without building new systems or disrupting how people work. A companion feature, User Insights, goes further by learning what normal AI usage looks like for every person and automated system on a network and alerting teams the moment something breaks that pattern. AI Gateway and User Insights allow enterprises to see exactly who?s sending what by connecting AI Gateway with Cloudflare Access, every AI request is now tied to a verified identity whether that's an employee or an automated system. User Insights tracks each user's AI activity over time and builds a user baseline. When spending spikes well beyond what's normal for a specific user or system, IT gets an alert. User Insights checks whether employees are using high-powered models for simple tasks that lighter, less expensive models could handle so efficiency gains are easy to find. Companies can replace blind, shared API keys by integrating with their Identity Provider (IdP) and Zero Trust (ZTNA) infrastructure. This validates user and device posture before sending requests to the model provider without slowing adoption, recording verified identities directly in request logs. Instead of managing AI usage piecemeal across every tool and model provider, all requests flow through a single point. That gives IT immediate visibility across the board, the ability to cache repeat requests and cut redundant costs, rate limiting to stop runaway usage before it hits the invoice, and automatic filters that strip out employee names, passwords, and other sensitive data before they ever reach an outside AI provider.
Share
Copy Link
Cloudflare unveiled Identity-Aware AI Gateway, attaching verified identities to every AI request leaving company networks. IT teams can now see which employee or automated system sent prompts, set spending limits, and flag risky content automatically without deploying new systems.
Cloudflare launched Identity-Aware AI Gateway, a service designed to attach verified identities to every AI request leaving company networks
1
. IT teams and security teams can now track who is using AI by identifying which employee or automated system sent specific prompts to model providers. The service enables organizations to set spending limits for individuals or teams and flag risky content automatically, all without requiring new systems2
.A companion feature called User Insights learns normal AI usage patterns for each person and automated system on a network, then alerts teams when activity breaks established baselines
2
. Individual AI requests keep getting cheaper, but employees and bots fire off far more of them, causing bills to spike with little warning1
. Traditional tools cap AI spending at the account level but cannot identify who generated the costs. User Insights checks whether employees push simple tasks through high-powered models that lighter, less expensive options could handle, surfacing efficiency opportunities2
.The identity capability works by connecting AI Gateway with Cloudflare Access, the company's zero-trust access product
1
. Companies can replace blind, shared API keys that make attribution impossible by integrating with their Identity Provider and ZTNA infrastructure2
. Requests are authenticated against existing identity providers, with user and device posture validated before anything reaches model providers. The verified identity is written directly into request logs1
.Related Stories
Employee names, passwords, and confidential files can pass through to outside AI providers with nobody noticing under current approaches
1
. Funneling all AI traffic through a single point enables automatic filters that strip employee names, passwords, and other sensitive data from requests before they reach external AI providers2
. Rate limits prevent runaway usage before it hits invoices, while repeat requests can be cached to cut redundant costs1
.Max Baumgarten, security engineer at Flexport Inc., noted that shared API keys make it "almost impossible to tell who is using an AI service"
1
. The freight logistics company deployed Cloudflare Access in front of AI Gateway so requests now carry authenticated identities, allowing existing identity policies to be applied at the gateway. Chief Technology Officer Dane Knecht explained that fear of surprise bills and accidental leaks pushes companies to lock down AI access, but connecting access controls directly to AI Gateway flips that dynamic1
. Teams gain freedom to work with any AI model while IT obtains real-time visibility, guardrails, and cost control. AI Gateway launched in September 2023, with security controls added to the zero-trust platform since August last year1
.Summarized by
Navi
[2]
25 Aug 2025•Technology

01 Jul 2026•Technology

Yesterday•Technology

1
Technology

2
Technology

3
Technology
