Most companies today have no idea which employee prompted which AI model, how much it cost, or whether sensitive data leaked out in the request. API keys are shared, logs are blind, and by the time the monthly invoice arrives, the damage is done.
Cloudflare's Identity-Aware AI Gateway, launched August 5–6, 2026, solves that by integrating Cloudflare's existing AI Gateway with Cloudflare Access (its Zero Trust product). Every AI request leaving a corporate network now carries a verified employee or agent identity, giving IT teams per-user visibility, spend controls, and security guardrails — without requiring employees to log into each AI app separately ![]()
![]()
![]()
.
How it ties employee identities to AI requests
The gateway sits behind Cloudflare Access. Before any request reaches an AI model provider, the user must authenticate against the organization's existing identity provider (IdP) ![]()
. When the request arrives through an Access-protected custom domain, Cloudflare validates the user and device posture and writes the verified Access user ID into request metadata as .