Cloudflare Can Now Tell Your Boss Exactly Which AI You Used and When

For the past two years, a quiet war has been playing out inside corporate networks. Employees discovered that AI tools made them faster, smarter, and harder to replace — so they used them, often without asking. IT teams watched unidentified bursts of traffic flow toward OpenAI, Anthropic, and a dozen other model providers, with no way to know who was doing what, what data was leaving the building, or how much it was costing. That window is now closing.
Cloudflare this week launched what it calls Identity-Aware AI Gateway, a product that does something the company's earlier AI traffic tools deliberately did not: it attaches a real human identity to every single request routed through its network to an AI model. Not a device fingerprint. Not an IP address. A named employee, authenticated through the identity systems enterprises already run.
The mechanics matter here. When a request passes through Cloudflare's gateway, it is now cross-referenced against the user's authenticated session — the same login that gets them into their corporate email or Slack. From that moment, every model call is logged against that identity. Security teams get a dashboard showing which employee sent how many requests to which models, flagged by content risk level, timestamped, and auditable. IT administrators can set spending caps at the individual or team level. Exceed the limit, and the requests stop.
Cloudflare also shipped a companion feature called User Insights, which aggregates behavioral patterns across the workforce — surfacing, for instance, that a particular department is sending unusual volumes of requests to an external model at odd hours, or that a single user account is burning through token budgets at a rate inconsistent with its stated function. The company frames this as anomaly detection for AI governance. A more direct description: it is a behavioral monitoring system for AI use, and it runs passively, without requiring employees to install anything new or change how they work.
The timing is not accidental. Regulatory pressure on AI data handling is intensifying across multiple jurisdictions simultaneously. The EU AI Act has begun imposing compliance obligations on high-risk applications. Financial regulators in the United States have signaled that AI-assisted decisions in credit, insurance, and trading will face heightened scrutiny. Legal departments at large firms are increasingly asking whether employees have been feeding client data to third-party models — and finding they genuinely do not know the answer. Cloudflare is selling the answer to that question.
What the company's press materials handle delicately, but what any enterprise security professional will say directly, is that the primary threat model here is not external attackers. It is internal employees doing things the organization did not sanction. Shadow AI — the use of AI tools outside approved procurement channels — has become the new shadow IT, and it carries compounded risks: data exfiltration through model prompts, accidental exposure of trade secrets, regulatory liability from processing personal data through unvetted third parties, and budget bleed that is essentially invisible until it hits a credit card statement. Identity-Aware AI Gateway is architected to eliminate the plausible-deniability gap that shadow AI currently lives in.
There is a tension here worth naming plainly. The same infrastructure that gives a CISO visibility into rogue AI spend also gives an employer a granular record of how every worker interacts with AI on the job — which models they prefer, what kinds of tasks they offload, how often, and at what cost. That data has obvious operational value. It also has obvious potential for use in performance management, workforce reduction decisions, and labor negotiations. Cloudflare does not address this tension in its launch materials, and no external regulator currently requires it to. Whether enterprise deployments will come with meaningful employee notice is, at this point, entirely a matter of each company's internal policy.
For Cloudflare, the strategic logic is straightforward: the company already sits in the traffic path between corporate networks and the internet for a significant share of the Fortune 500. Adding identity-awareness to AI traffic is an incremental infrastructure change for them and a significant governance leap for their customers. It also deepens lock-in considerably — once a compliance team has built audit workflows around Cloudflare's AI logs, switching costs rise sharply. The product is genuinely useful. It is also a very deliberate expansion of what the company knows about everything flowing through its pipes.
Who is covering this (11+ outlets)
- Search Engine WatchCloudflare releases its own AI visibility tool because ... why not?
- CotéRelative to your interests, Friday
- Express ComputerCloudflare introduces AI monitoring tools for enterprise governance
- mid-east.infoCloudflare Gives Companies Full Visibility to Audit & Analyze AI Use - Middle East Business News and Information
- WebProNewsCloudflare Ties Real Identities to Every AI Request to Tame Rogue Agents and Shadow Usage
- TechnoSportsCloudflare Just Made Shadow AI Spending a Thing of the Past
- Analytics InsightCloudflare Gives Companies Full Visibility to Audit & Analyze AI Use
- itwire.comCloudflare Gives Companies Full Visibility to Audit & Analyse AI Use | iTWire
- SecurityBrief AsiaCloudflare launches identity-aware AI gateway for firms
- wallstreet:onlineCloudflare Gives Companies Full Visibility to Audit & Analyze AI Use
- SiliconANGLECloudflare launches Identity-Aware AI Gateway to track who is using AI
See what people are saying about this story on X.
