Cloudflare announces new Zero Trust tools for secure AI adoption at scale

San Francisco-based Cloudflare has unveiled powerful new capabilities for Cloudflare One, its Zero Trust platform, designed to help organizations securely adopt, build and deploy emerging generative applications. With these new features, Cloudflare is giving customers the ability to automatically understand, analyze and set controls on how generative AI is used throughout their organization – enhancing the productivity and innovation of their without sacrificing security or standards.

“Cloudflare is the best place to help any business roll out AI securely,” said Matthew Prince, CEO and co-founder at Cloudflare. “We are the only company today that can offer the security of a Zero Trust platform with a full set of AI and inference development products – all backed with the scale of a global network. The world’s most innovative companies want to pull the AI lever to move, build and scale fast, without sacrificing security. We are in a unique position to help that innovation–and help bring AI to all businesses safely.”

With its new features, Cloudflare is giving customers the ability to automatically understand, analyze and set controls on how generative AI is used throughout their organization – enhancing the productivity and innovation of their teams without sacrificing security or privacy standards.

“The Cloudflare Developer Platform and Workers are central to our ability to provide user-programmable functionality. It is just one example of how we leverage Cloudflare capabilities to enhance our technology and deliver to our clients,” said Christopher Naidoo. Head of Digital IT Operations at Investec

Across every team – from finance and marketing to engineering and design – companies are using generative AI to work faster, streamline daily tasks, and create powerful new applications. However, this widespread adoption is frequently occurring without security or privacy in mind. For example, employees may accidentally paste confidential company information into chatbots, or engineers may deploy AI-driven without the input of their security teams. To prevent these risks, businesses need to understand and manage the use of AI so all employees can use it efficiently and safely – with security built in by default.

Cloudflare is introducing AI Security Posture Management (AI-SPM) into its Zero Trust platform to allow organizations to safeguard against a range of potential threats posed by the wide adoption of AI , enabling businesses to move faster with the confidence that AI is being used safely by all teams. Now, with the of all features, security teams will be able to discover how employees are using AI with Cloudflare’s new Report. They will also be able to protect against Shadow AI, easily and automatically enforcing AI policies at the edge of Cloudflare’s network, ensuring consistent security for every employee, no matter where they work.

“Discord is where the world builds relationships,” said Mark Smith, Director of Infrastructure at Discord. “Cloudflare helps us deliver on that mission, connecting our internal engineering team to the tools they need. With Cloudflare, we can rest easy knowing every request to our critical apps is evaluated for identity and context — a true Zero Trust approach.”

AI Prompt Protection Safeguard sensitive data without fully restricting AI usage: With AI Prompt Protection, security teams will also be able to identify potentially dangerous or risky employee interactions with AI models, and flag those prompts and responses. Policies can now be enforced inline at the prompt level to mitigate risk early on, and warn the employee about, or block them from, submitting sensitive data into an untrusted AI provider. Finally, with Zero Trust MCP Server Control, all MCP traffic will be able to gain visibility of AI model interactions with tools outside the business, by consolidating all MCP tool calls into a single Now, with centralized insights, security teams can set user-level policies at both the gateway and individual MCP server levels.