Cloudflare introduces Identity-Aware AI Gateway and User Insights. These features link every AI request to a verified identity and flag anomalous usage. This allows IT teams to see who is sending which prompts to an AI model and to set spending limits per user or team.
By connecting the AI Gateway to Cloudflare Access, every AI request is assigned a verified identity, whether it comes from an employee or an automated system. Companies can replace shared API keys by integrating with their Identity Provider (IdP) and Zero Trust Network Access (ZTNA) infrastructure. The solution validates the user and device posture before sending a request to the model provider, and immediately records the identity in the request logs. All traffic thus passes through a single point, where filters remove names, passwords, and other sensitive data before it reaches an external provider.
Per-user baseline
The User Insights feature learns what normal AI usage looks like for each person and each automated system on a network. It then builds a baseline around that. If a specific user’s usage deviates significantly from that pattern, IT receives an alert. Additionally, User Insights checks whether employees are using heavy-duty models for simple tasks that a lighter, more cost-effective model could also handle.
“When security is clunky, it becomes a speed bump that slows down innovation,” says Dane Knecht, CTO of Cloudflare. According to him, linking access control to AI Gateway reverses that dynamic. Teams can work with any AI model, while IT gains real-time visibility, guardrails, and budget controls.
The core of AI Gateway is free to use at Cloudflare, with enterprise costs primarily stemming from Workers usage, logging, and the existing Enterprise contract. The features work without organizations having to build new systems.
Tip: Cloudflare launches AI security posture management for Zero Trust