Skip to content

UPDATED 09:00 EDT / AUGUST 05 2026

SECURITY

Cloudflare launches Identity-Aware AI Gateway to track who is using AI

Cloudflare Inc. today launched Identity-Aware AI Gateway, a service that attaches a verified identity to every artificial intelligence request leaving a company network.

Information technology and security teams can now see which employee or automated system sent a given prompt to a model provider. The service also lets them set spending limits for an individual or a team and flag risky content automatically. Cloudflare said it requires no new systems.

A companion feature called User Insights goes at the cost problem from another angle. It learns what normal AI usage looks like for each person and each automated system on a network, then alerts teams when something breaks that pattern.

Enterprise AI use is growing quickly and two problems are growing with it. Individual AI requests keep getting cheaper. Employees and bots are firing off far more of them, and bills spike with little warning. The security side is quieter. Employee names, passwords and confidential files can pass through to outside AI providers with nobody noticing. Today’s tools cap AI spending at the account level. They cannot name who ran up the bill. What was actually in the request does not show up in the logs either, so IT teams end up cleaning up after the fact.

Chief Technology Officer Dane Knecht said clunky security becomes a speed bump and that fear of surprise bills and accidental leaks is pushing companies to lock down AI access.

“Connecting our access controls directly to AI Gateway flips that dynamic,” Knecht said. “Teams get the freedom to work with any AI model they choose. IT gets real-time visibility, guardrails, and the budget controls they actually need.”

The identity piece comes from wiring AI Gateway into Cloudflare Access, the company’s zero-trust access product. Companies that do so can drop the blind, shared application programming interface keys that make attribution impossible. Requests are authenticated against an existing identity provider and zero-trust network access setup. User and device posture are validated before anything reaches the model provider, and the verified identity is written into the request log.

Funneling all AI traffic through a single point does other work as well. Repeat requests can be cached to cut redundant costs. Rate limits stop runaway usage before it hits the invoice. Automatic filters strip employee names, passwords and other sensitive data out of requests before they ever reach an outside AI provider.

Model choice gets scrutiny too. User Insights checks whether staff are pushing simple tasks through high-powered models that a lighter and cheaper option could handle, then surfaces those cases.

Max Baumgarten, a security engineer at Flexport Inc., said shared API keys make it “almost impossible to tell who is using an AI service.” The freight logistics company put Cloudflare Access in front of AI Gateway. Requests now carry an authenticated identity, and Baumgarten said the identity policies Flexport already had can be applied to them at the gateway.

AI Gateway dates back to September 2023. The security controls are newer, and Cloudflare has been adding them to its zero-trust platform since August last year.

Photo: Wikimedia Commons

Send us a news tip

Send us a News Tip

  • This field is for validation purposes and should be left unchanged.

Sign in or create an account

SIGN IN

OR

New User? SIGN UP

Join us

SIGN UP

Bio

Ethics statement

Extract the signal from the noise

Get SiliconANGLE updates and analysis.

Contact us

Partner with us

Contact us

Guest inquiry