Zero Trust Controls for the AI Era

Large language models (LLMs) such as OpenAI’s GPT can generate code, draft reports, and answer complex questions, making them increasingly attractive to engineering and business teams alike. But every prompt sent to these services is data that leaves your organization’s control. And because LLMs are often used as sounding boards for difficult problems, that data is frequently sensitive.

Banning the services outright is one response — some companies and even countries have gone that route — but it forces teams to give up genuinely useful tools. Cloudflare One for AI takes a different approach: a set of features designed to let organizations use AI services while keeping a Zero Trust security posture. The tools extend Cloudflare’s existing Gateway, Access, and Data Loss Prevention (DLP) products to cover the specific challenges of AI adoption.

Finding Out What Your Team Actually Uses

LLM services are easy to sign up for and even easier to start using, which makes them a classic Shadow IT problem. IT teams often know employees are experimenting with AI, but they don’t know which services, how many seats to license, or what features are actually needed. On the security side, the concern is that prompts may contain context that should never leave the organization — and even if one vendor is approved, employees may keep using alternatives.

Cloudflare One customers on any plan can now review AI usage. By deploying Cloudflare Gateway, administrators can passively observe how many users are selecting which AI services, providing the data needed to scope enterprise licensing plans. Administrators can also block specific services with a single click — useful if, say, ChatGPT is the approved model and you want to prevent team members from continuing to use alternatives. But the goal is not to block all AI outright; it’s to enable safe use.

A complete suite of Zero Trust security tools to get the most from AI

For budget and security teams, this visibility solves two problems at once: it turns guesswork about licensing into concrete usage data, and it surfaces which AI tools pose data-control risks before they become a problem.

Securing API Access for Training Data

Many teams want to train AI models with their own data or connect plug-ins so the services can provide better, context-aware guidance — much as Cloudflare’s own engineers have done to help customers configure Workers and Access policies. That requires securely sharing training data and granting plug-in access to an AI service. Cloudflare One’s security suite extends beyond human users to cover API access.

Administrators can create service tokens that external services must present to reach data made available through Cloudflare One. These tokens can be provided to systems making API requests, with every request logged and tokens revocable with a single click. Policies can then be created to allow specific services access to training data, verifying the service token and optionally extending the check to country, IP address, or mTLS certificate.

BLOG-1776 Embedded Image - efwDxT

Where human access is involved, policies can require authentication with an identity provider and an MFA prompt before sensitive data or services are reachable. And when teams are ready to open up infrastructure for AI connections, Cloudflare Tunnel creates an encrypted, outbound-only connection to Cloudflare’s network, where every request is checked against the access rules configured for the protected services. There is no need to poke holes in firewalls.

BLOG-1776 Embedded Image - 12JzsN
BLOG-1776 Embedded Image - jFh0Bg

Access control secures the data your organization deliberately exposes to AI tools. It still leaves a gap: the data your employees might overshare on their own.

Stopping Oversharing at the Source

Even with approved services and careful access policies, people make mistakes. A developer pasting code with embedded secrets into a chat prompt, or an analyst uploading a spreadsheet full of customer records, can turn an AI experiment into a security incident. The LLM ecosystem will likely evolve better data management features, but organizations shouldn’t have to wait to adopt these tools.

Cloudflare’s DLP service provides a safeguard. Administrators first define the data that matters — using preconfigured checks for social security numbers or credit card numbers, or custom regular expressions. Then they build granular rules about how that data can be shared with AI services. The controls are flexible enough to allow, for example, a specific Active Directory or Okta group to upload sensitive data for approved projects while everyone else is blocked.

BLOG-1776 Embedded Image - MY9oAW
BLOG-1776 Embedded Image - gXKJHp

These DLP controls cover data in motion at the gateway. But misconfigurations inside SaaS applications are another risk vector — a new plug-in might give an external service more access than intended, for example. Cloudflare’s Cloud Access Security Broker (CASB) scans SaaS applications for potential issues, from files accidentally made public to GitHub repositories with incorrect membership controls. The CASB integrations with AI services are under development and will soon be available

An Evolving Set of Controls

The utility of AI services will only grow, and so will the risks. The approach here is to bring AI-specific controls into Cloudflare One and continue expanding them as the services — and the ways teams use them — evolve. For teams that want to start using LLMs inside a Zero Trust framework rather than block them, the tools are available now through Cloudflare Gateway, Access, DLP, and the forthcoming CASB integrations. Cloudflare One is available at no cost for teams of up to 50 users.