Mon, 10 Aug 2026

Cloudflare targets AI blind spots with identity-aware monitoring and control

Cloudflare has launched Identity-Aware AI Gateway, giving security and IT teams a way to link AI activity to individual employees and automated agents, monitor what is being sent to models and apply spending controls in real time.

The launch addresses two growing concerns for CISOs: limited visibility into enterprise AI use and the risk that sensitive information could be sent to external model providers without proper oversight. Cloudflare said existing controls can limit overall account spending, but often cannot identify who triggered the cost or what information was included in a request.

Identity-Aware AI Gateway connects Cloudflare’s AI Gateway with Cloudflare Access, allowing each request to be associated with a verified user or automated system. The capability is designed to replace shared API keys, which make attribution difficult and limit the ability to apply existing identity and access policies.

Cloudflare’s technical documentation says the integration can use authenticated identity data in logs, analytics, routing and spend controls.

Moving beyond blanket restrictions

A companion feature, User Insights, establishes a baseline of normal AI activity for each employee and automated system. It can alert security teams when a user’s activity or spending rises sharply above that pattern, helping identify unusual behaviour before it becomes a larger security or cost incident.

The feature also examines whether employees are using high-powered models for relatively simple tasks that could be handled by less expensive alternatives. For CISOs, this links AI governance with financial accountability and operational efficiency, rather than treating security as a reason to block experimentation.

“When security is clunky, it becomes a speed bump that slows down innovation,” said Dane Knecht, CTO of Cloudflare.

“Connecting our access controls directly to AI Gateway flips that dynamic. Teams get the freedom to work with any AI model they choose. IT gets real-time visibility, guardrails, and the budget controls they actually need.” Dane Knecht

The gateway provides a central control point for AI traffic across tools and model providers. Proposed controls include rate limiting, request caching, spending limits and filters that can remove employee names, passwords and other sensitive data before it reaches an external provider. Cloudflare’s AI Gateway documentation also describes analytics, logging, caching and model-control capabilities.

Related:  PodChats for FutureCISO: Breaking the reactive cycle with intelligence-led cyber risk in the AI era

For Max Baumgarten, security engineer at Flexport, the identity layer is particularly important. “Our teams can adopt AI tools without creating a separate authentication system for every client,” he said.

For CISOs, the immediate value is clearer accountability: knowing who or what initiated an AI request, what controls applied and when usage deviated from an established pattern.

Related Stories

MORE STORIES