Cloudflare has updated its zero trust capabilities with a view against problematic AI use on the network.
Additions to Cloudflare One, the cloud platform’s zero trust service, are headlined by changes to its secure web gateway (SWG), giving security teams the ability to block unauthorized AI applications and restrict the types of data that can be uploaded to them, while holding complete security and privacy reviews of AI tools being used on the network.
This is paired with a reporting feature that gives security teams real-time traffic insights, providing a data-driven view of an organization’s AI usage.
The updates see AI Security Posture Management (AI-SPM) integration in a bid to tackle shadow AI. This is the low-key, unmanaged usage of AI apps in an organization, which can lead to unsanctioned and invisible data leaks.
The firm claimed its Shadow AI report surfaces detailed analytics drawn from Cloudflare Gateway, mapping every connection to various identified AI services and linking that usage back to individual users, devices, bandwidth consumption, and geography.
Once organizations can see the landscape, administrators then assign permission labels to an AI app. Those labels can then feed directly into Cloudflare Gateway policies; unapproved tools may be blocked at the network edge, for example, and in-review apps can be contained behind data-loss-prevention rules, file-upload restrictions, or full browser isolation.
Approved services can continue as usual, meanwhile, but with audit logging switched on for compliance.
For deeper data investigations using Cloudflare Log Explorer, pre-built SQL queries can help analysts trace suspicious spikes in usage, search for blocked attempts to capture personal data, or reconstruct a single user’s interactions with an unsanctioned model.
By keeping those logs inside the Cloudflare environment, users can potentially avoid sending data for third-party analysis, bolstering Cloudflare’s security operations (SecOps) posture.
The SecOps shift has benefited security firms such as Fortinet in recent years, with recent billing growth attributed to SecOps.
Palo Alto Networks, meanwhile, has shown skepticism over a unified approach, arguing that network security will always remain a separate platform unto itself.
Rivals such as Zscaler have also augmented SecOps features in their own zero trust offerings in recent weeks.
MCP: potential USP in AI-SPM
With its AI-SPM release, Cloudflare is going up against similar offerings from Zscaler, Palo Alto, and CrowdStrike.
While the updates tout USPs in the form of prompt detections and firewall-like filters for large language model (LLM) queries, these features are more data privacy-focused than network security-relevant.
A possible differentiator is Cloudflare One’s embedding of AI model interactions, as focused on the model context protocol (MCP).
This open standard, introduced by AI firm Anthropic, endeavors to standardize the way AI systems – particularly LLMs – integrate and communicate with external data sources, tools, and systems. Recent months have seen both Oracle and Google Cloud introduce MCP-related updates in light of agentic AI workloads on the network, alongside VMware.
In an open beta, Cloudflare’s MCP Server Portals provide a single wraparound URL through which every MCP server must pass before it can talk to LLMs. This sees prompt traffic and tool calls logged in one location, potentially making it easier to audit who accessed which server and why.
Upcoming MCP enhancements promised by Cloudflare include tighter controls that block servers operating outside a portal, real-time prompt-injection screening, one-click deployment of Cloudflare-hosted MCP servers, and machine-learning analytics that flag anomalous behavior in the log stream.
Comments