Cloudflare is adding security controls for Model Context Protocol traffic, the emerging standard that lets AI agents connect to tools and data sources.
The company says Cloudflare Gateway can identify MCP requests with protocol-level heuristics. That signal gives security teams a way to discover “shadow” MCP traffic on managed networks, enforce access through approved servers, and block direct connections that bypass the organization’s controls.
The practical problem is easy to miss. MCP makes it simpler for agents to use business systems, but it also creates a new path from a user’s machine or agent runtime to sensitive tools. If those connections are invisible to network policy, companies may not know which servers agents are talking to or what data paths have been opened.
Cloudflare’s update does not remove the need to review individual MCP servers or the permissions they request. It gives administrators a monitoring and enforcement layer for a protocol that is quickly becoming part of enterprise AI deployments.