Cloudflare expands AI Gateway with identity controls and AI workspace

Cloudflare has added identity controls to AI Gateway, letting enterprises track requests and manage spending and security policies.

Cyber security alert and danger concept, hand typing on laptop with red warning triangle icon. Digital data breach, virus protection, system error, online threat, technology risk.

Cloudflare has introduced an open-source AI workspace alongside new controls designed to give enterprise IT teams more visibility into employee and automated AI activity.

The company announced Cloudflare OS, a browser-based workspace for connecting AI tools with internal company systems, as well as Identity-Aware AI Gateway and User Insights. The latter two add identity, spending, and security controls to AI requests passing through Cloudflare's infrastructure.

Cloudflare OS was developed from an internal platform used by the company's employees. Cloudflare said staff use the system for tasks including research, document creation, workflow automation, and building applications connected to internal data.

The software is now available through Cloudflare's open-source repository and runs within an organization's own Cloudflare account. Cloudflare said organizations will also be able to access the platform directly through the company or work with implementation partners, including Presidio and Happy Cog.

Cloudflare OS connects AI tools with internal applications and data while applying existing access policies to those connections. Cloudflare Access authenticates users and requests before access to company systems is granted.

AI agents begin without permissions and receive access based on the task they are performing. Gatekeepers, Cloudflare's governed connectors for internal systems, define what an agent can access or change and whether an action requires human approval.

Employees access Cloudflare OS through a browser and can use it for research, documents connected to live data, automated workflows, and internal applications. Apps created in the workspace can have their own databases and access controls and can be shared with other employees.

Cloudflare OS is designed to work with different AI model providers through AI Gateway rather than requiring organizations to standardize on a single provider. Administrators can also apply budgets and rate limits or route selected workloads to different models.

Matthew Prince, Cloudflare co-founder and CEO, said the platform was developed from tools the company built for its own workforce.

"Our employees get AI tools connected to the systems they actually use, and security isn't something IT has to bolt on afterward," Prince said.

Adding identity and spending controls to AI traffic

The new Identity-Aware AI Gateway adds more granular controls to that traffic by linking individual AI requests to authenticated identities. When used with Cloudflare Access, request logs can identify whether an employee or automated system initiated a request.

Organizations can replace shared API keys with existing identity providers and Zero Trust policies, allowing AI Gateway to associate requests with authenticated users or systems. User and device posture can also be checked before requests are sent to an AI model provider.

"Shared API keys make it almost impossible to tell who is using an AI service or apply the access rules we already have for employees," Max Baumgarten, security engineer at Flexport, said. "Putting Cloudflare Access in front of AI Gateway gives each request an authenticated identity and lets us use our existing identity policies at the gateway."

Identity information also allows administrators to apply AI spending controls at the user or team level. Cloudflare said organizations can set budgets and rate limits, rather than restricting expenditure only at the broader account level.

AI Gateway can also cache repeated requests, reducing the number of identical queries sent to external models. Organizations can configure filters to identify and remove information such as employee names and passwords before a request reaches an external AI provider.

Cloudflare is pairing those controls with User Insights, which analyzes activity associated with individual users and automated systems. The system establishes usage baselines and alerts administrators when activity differs from established patterns, including unusual increases in spending.

The feature also identifies instances where more expensive models are being used for tasks that Cloudflare says can be handled by smaller models. Administrators can use that information alongside routing, budget, and rate-limit controls in AI Gateway.

Dane Knecht, Cloudflare CTO, said the integration between Cloudflare Access and AI Gateway is intended to give IT teams more visibility into AI activity while applying controls at the gateway level.

"IT gets real-time visibility, guardrails, and the budget controls they actually need," Knecht said.

These controls are also used within Cloudflare OS, where internal systems, documents, and applications can be made available to employees and AI agents under defined authentication and access policies.

Because the software is open source and runs within an organization's Cloudflare account, Cloudflare said customers retain control over the processes, internal system connections, and other configurations they build on the platform.

Cloudflare is also working with systems integrators to tailor deployments to existing technology environments, industry requirements, and compliance needs. Presidio and Happy Cog are among the implementation partners named by the company.