Cloudflare has published a new approach for catching rogue AI behavior with identity-aware analytics in its AI Gateway. The idea is to connect AI traffic monitoring with who or what is making a request, which app is involved, and what policy should apply.
That context matters because suspicious behavior is often hard to spot from model prompts alone. A request that is normal for one tool or user may be unusual for another, especially when agents begin chaining actions across services.
Cloudflare’s post fits into a wider push to treat AI systems as part of enterprise security infrastructure. Teams need logs, identity, rate patterns, and policy signals to understand whether an assistant is helping, leaking, or acting outside its intended role.
The approach depends on adoption and configuration. Analytics can flag risk only when traffic flows through systems that preserve enough identity and policy context to make anomalies visible.