Cloudflare has officially launched its AI Security for Apps service, making it generally available to customers. This new offering aims to detect and neutralize threats targeting applications built with artificial intelligence. The company is also rolling out enhanced capabilities, including the detection of custom topics, and is making AI endpoint discovery a free feature for every Cloudflare customer, spanning Free, Pro, and Business plans. This move provides universal visibility into where AI is being deployed across internet-facing applications.
The announcement also details an expanded partnership with IBM, which will leverage Cloudflare's security solutions for its cloud customers. Additionally, a collaboration with Wiz aims to offer mutual clients a consolidated view of their AI security posture.
A Shifting Attack Surface
Traditional web applications operate with predictable functions, allowing for rule-based security. AI-powered applications, however, process natural language inputs and generate unpredictable outputs, creating a dynamic and less defined attack surface. This inherent unpredictability opens doors for attackers to manipulate large language models (LLMs) for unauthorized actions or data exfiltration. Risks like prompt injection, sensitive data disclosure, and unbounded resource consumption are now prominent concerns, as highlighted in the OWASP Top 10 for LLM Applications.
The stakes rise significantly when AI applications gain agentic capabilities, enabling them to perform actions like processing refunds, modifying accounts, or accessing customer data. A single malicious prompt in such scenarios can immediately escalate into a critical security incident.
Rick Radinger, Principal Systems Architect at Newfold Digital, commented on the evolving landscape: "Most of Newfold Digital's teams are putting in their own Generative AI safeguards, but everybody is innovating so quickly that there are inevitably going to be some gaps eventually."
