SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
Cloudflare launches identity-aware AI gateway for firms

Cloudflare launches identity-aware AI gateway for firms

Thu, 6th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Cloudflare has launched Identity-Aware AI Gateway, a product designed to give companies more visibility into how employees and automated systems use artificial intelligence tools.

The service links AI requests to named employees or agents, allowing IT and security teams to see who submitted a prompt, apply spending limits at the user or team level, and flag material that may contain sensitive data or other risks.

The launch aims to address two issues that have emerged as workplace use of AI tools has grown: rising costs from increasing volumes of model requests, and limited oversight of what information workers or software agents send to external AI providers.

Many existing controls focus on account-wide spending caps but do not identify the source of individual costs or requests. Cloudflare's approach adds identity data to those requests by connecting the gateway with its Access product, part of the company's Zero Trust portfolio.

A companion feature, User Insights, is designed to track patterns in AI use by individual employees and automated systems. It builds a baseline for each user and can alert IT teams when activity or spending moves outside that pattern.

This is intended to help organisations spot sudden increases in AI consumption and identify cases where workers may be using more expensive models for relatively simple tasks. The system can also apply rate limiting, request caching, and filters for employee names, passwords, and other sensitive information.

For companies trying to set rules around AI access, one challenge has been the widespread use of shared API keys. These keys can make it difficult to determine which employee used a particular service or to apply existing identity policies consistently across tools.

Dane Knecht, Chief Technology Officer at Cloudflare, said the company believes that problem has slowed broader AI adoption in some businesses.

"When security is clunky, it becomes a speed bump that slows down innovation. Right now, companies are wary of surprise AI bills or accidental data leaks, so their instinct is to lock down access and restrict what teams can build," said Dane Knecht, Chief Technology Officer at Cloudflare.

"Connecting our access controls directly to AI Gateway flips that dynamic. Teams get the freedom to work with any AI model they choose. IT gets the real-time visibility, guardrails, and budget controls they need," Knecht said.

Identity controls

At the centre of the launch are identity-aware controls at the gateway layer. Rather than relying on a generic credential shared across a department or application, the system can validate the user and device before a request is sent to a model provider, then record that verified identity in request logs.

That gives companies a central point from which to monitor AI traffic across tools and providers, instead of managing controls separately in each application. It also reflects a broader shift among technology suppliers to position AI governance as an extension of existing cybersecurity and access management systems rather than a standalone function.

This structure allows organisations to apply policies based on individuals, teams, or agents without changing how employees access AI tools. It can also detect risky prompts and sensitive information in real time without interrupting normal workflows.

Customer view

Flexport is among the companies using the setup described by Cloudflare. The logistics group highlighted the difficulty of tracing AI usage when teams rely on shared credentials.

"Shared API keys make it almost impossible to tell who is using an AI service or apply the access rules we already have for employees. Putting Cloudflare Access in front of AI Gateway gives each request an authenticated identity and lets us use our existing identity policies at the gateway. Our teams can adopt AI tools without creating a separate authentication system for every client," said Max Baumgarten, Security Engineer at Flexport.

The launch adds to a growing market for products aimed at governing corporate AI use as more businesses allow staff to work with external large language models and AI assistants. Vendors across security, cloud infrastructure, and identity management are trying to address the same concerns: who is using AI, what data is being shared, and how quickly costs can rise as usage spreads across a large workforce.

Cloudflare's latest move places that monitoring at the network and access layer, focusing on tying every request to an authenticated identity and watching for unusual behaviour over time.