Cloudflare Tames AI Costs with Identity

Cloudflare's AI Gateway now offers identity-aware analytics and user insights to control AI costs and detect rogue behavior.

Cloudflare AI Gateway dashboard showing user insights and cost controls
Cloudflare
Visual TL;DR
Knowledge GapsDriver
nearly 60% of organizations cite lack of understanding as a governance obstacle
From the articleA Stanford University report highlighted that nearly 60% of organizations cited knowledge gaps as their primary obstacle to responsible AI governance.
Runaway AI CostsDriver
organizations struggle with uncontrolled AI spending and security blind spots
From the article 5 mentionsOrganizations wrestling with runaway AI costs and security concerns now have a new weapon.
Cloudflare AI GatewayCore
central hub for all AI interactions, routing requests and applying controls
From the article 9+ mentionsCloudflare has announced major updates to its AI Gateway, introducing identity-aware analytics that aim to bring clarity and control to AI spending and behavior.
Identity-Aware AnalyticsContext
new features pinpoint who is using AI resources and how they are utilized
From the article 2 mentionsCloudflare has announced major updates to its AI Gateway, introducing identity-aware analytics that aim to bring clarity and control to AI spending and behavior.
User InsightsEffect
detecting rogue behavior and establishing normal usage baselines for each identity
From the article 5 mentionsBeyond identity verification, Cloudflare is rolling out User Insights, a new tab within AI Gateway that is now generally available to all AI Gateway customers at no extra cost.
Control AI SpendingOutcome
organizations gain clarity and control over their AI resource consumption
From the article 3 mentionsCloudflare has announced major updates to its AI Gateway, introducing identity-aware analytics that aim to bring clarity and control to AI spending and behavior.
Enhanced AI GovernanceOutcome
tackling security issues by tying every AI request to a verified identity
From the article 3 mentionsThis provides a unified surface for observation, security, and governance.
Contents(3)

Organizations wrestling with runaway AI costs and security concerns now have a new weapon. Cloudflare has announced major updates to its AI Gateway, introducing identity-aware analytics that aim to bring clarity and control to AI spending and behavior. The new features are designed to pinpoint exactly who is using AI resources and how they are being used, tackling a significant blind spot for many companies.

The challenge of understanding AI usage is widespread. A Stanford University report highlighted that nearly 60% of organizations cited knowledge gaps as their primary obstacle to responsible AI governance. This isn't just about budget overruns; it's also a critical security issue. Cloudflare's new offering, detailed on their blog, tackles this by ensuring every AI request is tied to a verified identity and by establishing a baseline of normal usage for each identity.

Identity at the Forefront

Cloudflare's AI Gateway acts as a central hub for all AI interactions, routing requests to various models like those from OpenAI, Anthropic, or Google through a single point. This provides a unified surface for observation, security, and governance. The integration with Cloudflare Access means that organizations can now front their AI Gateway with a custom domain, protected by Access policies. This allows authentication via SAML-supported identity providers such as Okta or Entra, eliminating the need for risky shared API keys.

Crucially, every authenticated request will now carry the user's identity, appended to request metadata as cf.user_id. This allows for granular filtering of logs, analytics, and spend by the specific individual or agent making the request. This identity-centric approach transforms AI Gateway into a powerful budgeting tool. Organizations can now set per-user spend limits, automatically blocking further requests or falling back to less expensive models once a budget is hit. This directly addresses pain points like those experienced by Flexport, an early adopter. Max Baumgarten, Staff Security Engineer at Flexport, noted that shared API keys made it nearly impossible to track usage or apply existing employee access rules. Cloudflare Access, he explained, assigns an authenticated identity to each request, enabling the use of established identity policies at the gateway.

User Insights: Spotting the Anomalies

Beyond identity verification, Cloudflare is rolling out User Insights, a new tab within AI Gateway that is now generally available to all AI Gateway customers at no extra cost. This feature analyzes the traffic flowing through the gateway to build a behavioral profile for each account, whether human or agent. It learns what constitutes normal activity for an account and flags deviations. This is particularly important for distinguishing between legitimate but high usage from a busy engineer and potentially rogue behavior from an agent that has gone off the rails.

The system scores entire sessions rather than individual requests, recognizing that what might seem like an anomaly for one user could be normal for another. For instance, a $500 cost increase might be standard for a heavy user, but a $50 session from an agent that typically spends $5 could signal a significant problem. User Insights tracks costs, identifying waste in areas like low cache hit rates or oversized context windows, but its unique value lies in assessing whether an account's behavior is within its established norms.

Broader Implications for AI Governance

This development is a significant step in operationalizing responsible AI governance. By tying AI usage to verified identities and baselining behavior, Cloudflare is providing the visibility needed for both security and financial accountability. In the near future, the platform plans to allow organizations to use identity provider groups to set spend limits and control model access, enabling granular policies like giving specialized teams access to frontier models while capping usage for others, all mapped to existing group structures.

For startups and enterprises alike, this addresses a fundamental challenge: how to embrace the power of AI without succumbing to its potential for unexpected costs and security vulnerabilities. The ability to monitor and control AI usage at an individual or agent level is becoming non-negotiable as AI tools become more embedded in workflows. This move by Cloudflare positions its AI Gateway as a more mature, enterprise-ready solution for managing the complex realities of AI adoption.

© 2026 StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training requires a license. See our terms.
Daniel Singer

Written by

Daniel Singer

Editor, StartupHub.ai

Daniel Singer is the editor of StartupHub.ai, a technology expert and thought leader on AI and its applications across sectors, from fintech and healthcare to developer tooling and consumer software. He writes and tests the tools covered here thoroughly and regularly, and built StartupHub.ai to give founders, operators and buyers a clearer read on what they are actually being sold.