Governing the AI Explosion

Generative AI is being adopted at a pace that often outstrips an organization's ability to govern it. Employees across all functions are using both sanctioned and unsanctioned tools, while AI agents are beginning to handle authentication credentials and interact with sensitive resources autonomously. Security teams are tasked with building an AI security strategy in real time, often before the business has fully defined its own adoption plans.

This problem is significant, but it is not unmanageable. A Secure Access Service Edge (SASE) architecture, which converges networking and security into a single cloud-delivered service, can be extended to address these new risks. The key is applying the same principles of visibility, access control, and data protection that already govern web and application traffic to the use of AI.

Cloudflare’s SASE platform is one of the few that also operates in the AI infrastructure space, providing everything from developer tools like Workers AI and AI Gateway to security products like Firewall for AI. This positions it to help organizations govern AI usage without stifling innovation.

New AI Security Posture Management (AI-SPM) capabilities are now built directly into the platform, including:

  • Shadow AI reporting for visibility into employee AI usage.
  • Confidence scoring for managing risk associated with AI providers.
  • AI prompt protection to block malicious inputs and prevent data loss.
  • Out-of-band API CASB integrations to detect misconfigurations in AI providers.
  • Tools to manage and secure Model Context Protocol (MCP) deployments.
BLOG-2889 Hero Image

These features sit alongside existing SASE functionality, allowing an organization to view its AI security posture in a single dashboard. The combined platform is designed to be a flexible foundation for implementing an AI security strategy, regardless of whether an organization is aggressively adopting AI or taking a more cautious approach.

Defining Risk Tolerance

The first step in securing AI is determining the organization's risk appetite. This requires identifying the most pressing security concerns, relevant legal obligations, and how the business intends to use AI. Key questions to answer include:

  • What sensitive data—such as PII, PHI, financial records, or source code—must not be shared with certain AI tools?
  • Are there business decisions that should not be delegated to AI, such as those involving social scoring or personality evaluation, which may be prohibited by regulations like the EU AI Act?
  • What compliance frameworks (e.g., HIPAA, GDPR, SOC2) require audit trails of AI tool usage and prompts?
  • Are there sanctioned enterprise versions of AI tools that employees must use due to more favorable data retention and privacy terms?
  • Are there AI tools that employees must avoid entirely due to reliability concerns or geographic risk?
  • How will you guard against misconfigurations in AI providers that could expose sensitive data?
  • What is the corporate policy on autonomous AI agents and the adoption of MCP?

Organizations will answer these questions differently. Some will mandate broad adoption of AI tools, while others will restrict employees to a curated set. Some will race to deploy MCP-based agents, while others will wait until they can be properly secured. The right answers depend on the organization's specific goals, but SASE provides the flexible enforcement points to execute any of these strategies.

Starting with a SASE Foundation

Before adding AI-specific controls, an organization must have a solid SASE deployment in place. This consolidates security and networking functions into a single platform, replacing a patchwork of point solutions.

SASE provides the essential visibility and control needed for AI security by enabling an organization to:

  • Discover and inventory the AI tools employees are using.
  • Monitor prompts and responses to understand what data is being shared.
  • Scan and block sensitive data from being entered into AI tools using Data Loss Prevention (DLP).
  • Redirect traffic from unsanctioned AI providers to educational pages or approved enterprise alternatives via the Secure Web Gateway (SWG).
  • Secure agentic AI deployments through integrated MCP tooling.

For organizations new to SASE, a secure internet traffic deployment guide is the recommended starting point. Those already running SASE can move directly to applying these controls to generative AI traffic.

See Your AI Stack First

Visibility is the prerequisite for securing any AI deployment. You cannot build effective policy around tools you don't know exist. Shadow AI — unsanctioned applications that employees adopt on their own — is common. Salesforce research cited in Cloudflare's analysis found that more than half of surveyed knowledge workers admitted to using unsanctioned AI tools. That usage is often well-intentioned productivity gains, but it still needs to be discovered and governed.

Cloudflare offers two complementary paths to that discovery.

Inline discovery via Secure Web Gateway

The most direct route is the Secure Web Gateway (SWG). After deploying the WARP client in Gateway proxy mode on user devices, you can inspect traffic to determine which AI applications — sanctioned or not — are actually in use. The Application Library and Shadow IT dashboards let you see how many users engage with a specific app, and you can tag applications as Approved, Unapproved, In Review, or Unreviewed. Those statuses then feed directly into SWG policies that control access. The forthcoming Application Confidence Scores will automate the assessment of SaaS and Gen AI apps at scale.

BLOG-2889 Image 2

Cloudflare's Shadow IT dashboard displays application usage by status.

Out-of-band discovery via CASB

Organizations that don't run a device client still have an option. Cloudflare's API-based Cloud Access Security Broker (CASB) integrations for Google Workspace, Microsoft 365, and GitHub connect to your SaaS environment. When you integrate CASB with your SSO provider, you can see whether users have authenticated to any third-party AI applications. This gives you high-fidelity visibility into your SaaS environments, including sensitive data exposure and suspicious user activity, without requiring on-device software.

BLOG-2889 Image 3

An API CASB integration with Google Workspace surfaces LLM integrations as third-party app findings.

Build a Risk Management Framework

Visibility only sets the stage. The next step is enforcing controls that manage the risk you've identified. Cloudflare's SASE platform provides monitoring, policy enforcement, user coaching, and misconfiguration prevention for AI providers.

Monitor prompts and responses

With TLS decryption enabled, the AI Prompt Protection feature provides visibility into the exact prompts and responses exchanged with supported AI applications. You move beyond knowing which tools are used to understanding exactly what data they carry. This can be paired with DLP profiles to detect sensitive data in prompts — and you can choose to block or just monitor.

BLOG-2889 Image 4

A log entry captured by AI prompt protection shows a detected prompt.

Write granular policies in Gateway

Cloudflare Gateway policies can be built on application categories, approval status, users, user groups, and device status. Through the unified policy builder, you can:

  • allow approved AI apps outright while blocking unapproved ones
  • redirect users from unapproved apps to approved alternatives
  • restrict access to applications based on user group or device security posture
  • enable prompt capture only for high-risk groups, like contractors or new hires
  • place certain applications behind Remote Browser Isolation (RBI) to prevent file uploads or data pasting
BLOG-2889 Image 5

The Gateway policy builder lets you filter by application status.

Gate access to internal LLMs

Cloudflare Access can restrict access to your organization's proprietary or internally hosted models, including those running on Workers AI. Policies can require that only specific data scientists gain access to a model fine-tuned on customer data, for example, with access granted based on identity, user group, device posture, and contextual signals.

Audit third-party AI providers

New API CASB integrations cover popular providers like OpenAI (ChatGPT), Anthropic (Claude), and Google Gemini. These out-of-band integrations report on posture management findings so you can track:

  • misconfigurations in sharing settings
  • API key management hygiene
  • DLP profile matches in attachments
  • risky features toggled on, such as autonomous web browsing or code execution
BLOG-2889 Image 6

The OpenAI CASB integration identifies posture risks, risky enabled features, and DLP-detectable attachments.

Data Protection as the Final Layer

Access control is not complete without data protection. Cloudflare's DLP tooling scans and blocks sensitive data being entered into AI tools, using policies that adapt to your organization's specific traffic patterns. These are authored in the Gateway policy builder, so you can write rules that detect and block an SSN, phone number, or address before it reaches an external service.

AI Prompt Protection extends this with inline semantic classification of user interactions. Prompts are bucketed into meaningful topics: PII, credentials and secrets, source code, financial information, code abuse and malicious code, and prompt injection or jailbreak attempts. You can build granular policies on those classifications — for instance, blocking non-HR employees from prompting ChatGPT in a way that returns PII while permitting HR during compensation planning.

Applying these most advanced DLP rules requires TLS decryption so the platform can inspect the traffic in transit.

BLOG-2889 Image 7

A sample policy blocks ChatGPT prompts that may return PII for employees in engineering, marketing, product, and finance groups.

Bringing MCP Under Security Control

Model Context Protocol (MCP) servers have become a primary entry point for AI agents to interact with enterprise data — they translate agent requests into API calls, enable dataset comprehension, and trigger real actions. As those servers accumulate access, they become security assets that need the same oversight as other critical infrastructure. Cloudflare is responding by making MCP security controls a core part of its SASE platform.

Managing Authorization Sprawl

MCP servers commonly rely on OAuth for authorization, with the server inheriting the permissions of the authorizing user. This respects least-privilege for the user in theory, but in practice it leads to authorization sprawl: over time, agents collect permissions far beyond what they started with, making them attractive targets for attackers.

Cloudflare Access now applies Zero Trust principles to MCP server access, treating every request as unverified until proven otherwise. This continuous verification prevents the accumulation of implicit trust that drives authorization sprawl, ensuring secure authentication as agentic workflows expand.

A Portal for Centralized MCP Governance

Cloudflare's MCP Server Portal is a new SASE feature designed to centralize the management, security, and observation of enterprise MCP infrastructure. Instead of requiring users to configure one-to-one connections between every MCP client and server, the Portal exposes a single endpoint that users configure once in their MCP client. New MCP servers become available to users automatically as administrators register them.

The security motivation goes beyond convenience. Without centralized control, MCP deployments form "a tangle of unmanaged one-to-one connections" that expose organizations to prompt injection, tool injection via malicious servers, supply chain attacks, and data leakage. By routing all MCP traffic through Cloudflare, the Portal provides:

  • Centralized policy enforcement and visibility into MCP activity
  • Administrator review and approval before servers are made available
  • Least-privilege presentation of tools and servers to end users
  • Prevention of unvetted or malicious third-party server usage
BLOG-2882 Image 2

One Platform for AI Security Posture

Cloudflare's SASE brings together multiple AI security capabilities that are often spread across separate products. For employee-facing AI protection, the Secure Web Gateway (SWG) supports fine-grained access policies, Shadow IT visibility, and inline AI prompt inspection. Out-of-band, the CASB offers API-based integrations for visibility and control. Cloudflare Access applies Zero Trust to corporate LLMs hosted on Workers AI or elsewhere.

The newly introduced MCP security controls work alongside Cloudflare's Remote MCP Server platform, and all controls are accessible from the same unified dashboard. An AI-SPM overview dashboard aggregates these controls into a single view.

BLOG-2889 Image 9

Cloudflare's positioning also reflects its broader product stack — as a vendor offering both SASE and AI infrastructure, the platform can be paired with developers' AI building blocks such as Workers AI, AI Gateway, remote MCP servers, Firewall for AI, and AI Labyrinth. This places security posture management alongside AI infrastructure strategy rather than as an afterthought.

The MCP security features described here are the opening of a longer roadmap, with ongoing work to deepen support for MCP infrastructure and security controls across Cloudflare's platform.