Cloudflare OS moves the enterprise workspace into the browser
More than 4,000 apps, automations, and tools in 30 days. An estimated 10,000 hours saved by one sales organization over the same period. These are Cloudflare’s early internal results for Cloudflare OS. They also explain what the company is trying to build: not another desktop operating system, but a controlled environment where employees can put AI agents to work.
Traditional operating systems manage local hardware, files, applications, and users. Cloudflare OS focuses on a different problem. AI agents need access to company data, software, workflows, and business context. They also need permissions to take actions. Connecting all of these components safely is becoming a core enterprise infrastructure problem.
Cloudflare OS puts that environment in a browser and runs it inside the customer’s Cloudflare account. The interface starts with a conversation. An employee can ask an agent to conduct research, create presentations or spreadsheets, generate documents, build full-stack applications, or automate workflows. A terminal is not required.
The important part is not the chat interface. It is what sits behind it. The agent can connect to approved enterprise systems and perform work using company context. Its outputs remain subject to access controls and can be stored in isolated databases before they are shared with other employees.
Rita Kozlov, VP of Product at Cloudflare, makes the distinction explicit: “Cloudflare OS isn’t a traditional desktop OS.” She says it instead “reimagines the workplace computing environment for AI.”
Cloudflare built the system first for its own workforce. Kozlov said employees across the company now use it daily. During the previous 30 days, they created more than 4,000 apps, automations, and tools. Cloudflare also estimates that its sales team saved about 10,000 hours by automating work such as territory planning and proposal creation. These figures are Cloudflare-reported results, not independent benchmarks, so executives should treat them as evidence of internal adoption rather than proof of equivalent returns elsewhere.
The larger business case is clear. The constraint on enterprise AI is shifting from access to models toward integration and control. A model can produce an answer in seconds. Giving an agent enough company context and system access to complete useful work, without giving it excessive authority, is much harder.
Cloudflare OS is designed to address that constraint at the infrastructure level. If the approach works at enterprise scale, companies can give employees access to AI-driven workflows without creating a separate integration stack for every department and use case. That could reduce development effort and shorten deployment cycles.
For executives, this is the metric that matters. The value of an AI workspace will not come from how many employees can open a chatbot. It will come from how much governed business work agents can complete across existing systems.
Open source gives enterprises more control over models, integrations, and long-term dependence
Cloudflare made Cloudflare OS open source. That choice matters because an enterprise AI environment can accumulate far more dependency than a conventional software tool. It may contain connections to internal systems, business processes, agent skills, security policies, company context, and model configurations. Moving away from such a platform can become expensive if those components are proprietary.
Cloudflare wants customers to retain control over this layer. Organizations can configure their own models, integrations, policies, branding, and agent capabilities. They are not required to standardize on one AI model provider. This means a company can use different models as its requirements, economics, or security policies change.
The model choice is particularly important. AI markets are moving quickly, and the best model for one workload may not be the best model for another. Coding, document processing, reasoning, and high-volume routine work can have different requirements for accuracy, latency, privacy, and price. An infrastructure layer that does not depend on one model gives CIOs more room to optimize these decisions over time.
Cloudflare OS is intended to work with AI technology from OpenAI, Anthropic, Google, Microsoft, Meta, and open-source ecosystems. Technology analyst Carmi Levy argues that this application-agnostic design lets Cloudflare coexist with AI products already deployed inside an enterprise. He also says the open-source architecture “minimizes the potential for vendor lock-in” as companies adapt their technology stacks to AI.
Open source does not remove lock-in by itself. An enterprise may still become dependent on Cloudflare’s hosting, security services, architecture, operational tooling, or proprietary surrounding products. Executives should therefore distinguish source-code access from practical portability. The relevant questions are whether workloads can move, how much integration work must be repeated, and what happens to security policies, data, and agent configurations if the infrastructure provider changes.
Still, source access gives enterprises an additional form of control. Teams can inspect the platform, adapt it to internal requirements, and connect proprietary systems without placing every business process inside a closed product. This can also matter for organizations with strict security, audit, or regulatory requirements.
Kozlov puts Cloudflare’s position more strongly: “You cannot put your company into software you do not own.” She argues that organizations need the ability to inspect and customize the platform, connect their own systems, and make the environment their own.
The strategic issue for C-suite leaders is therefore not open source as an end in itself. It is optionality. AI models, prices, providers, and enterprise requirements will change. Infrastructure decisions made today may last longer than the models running on them. An architecture that keeps the model layer replaceable gives the enterprise more leverage as that market evolves.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
AI agents need stricter access controls because they can act
Cloudflare OS gives every AI agent zero permissions by default. Access is granted only when a specific task requires it. This is a critical design choice. Once an AI system can modify data, execute workflows, or create resources, access control becomes more important than the quality of its answers.
Cloudflare builds this model on Cloudflare Workers, Dynamic Workers, Durable Objects, and Access, its zero-trust network access product. Access verifies users and requests instead of assuming that an authenticated employee or agent should have broad access to internal systems. Organizations define their own policies based on their security requirements.
The core principle is least privilege. An agent asked to prepare a sales proposal may need access to specific customer records and document tools. It does not automatically need access to unrelated databases or administrative systems. Restricting permissions limits the potential impact of incorrect agent actions, compromised credentials, malicious prompts, or excessive automation.
Cloudflare adds another control through governed connectors called “gatekeepers.” Administrators can define what an agent can read, what it can change, and which actions require human approval. They can also impose budgets and rate limits or direct different tasks to different AI models.
These controls address a basic problem with enterprise agents. Traditional AI assistants mainly generated content for a person to review. Agentic systems can go further. They can use software, interact with internal data, create applications, and initiate business processes. Greater autonomy increases potential productivity, but it also increases the consequences of mistakes.
Rita Kozlov, VP of Product at Cloudflare, describes the issue directly: “Because agents act on people’s behalf and produce work others can access and modify, they require a new security model.” Cloudflare therefore tracks the resources required by an agent so that appropriate access controls remain attached when its work is shared.
For CIOs and CISOs, this changes the deployment question. It is not enough to ask whether a model is secure or whether enterprise data is encrypted. Leaders need to know exactly what an agent can do after receiving a request, which systems it can reach, what information it can expose, and where human authorization remains mandatory.
Cloudflare’s design addresses those questions at the infrastructure level. The approach is sound: start with no authority, grant only task-specific access, and preserve those controls as agent-generated work moves between users. The real test will be operational. Enterprises will need policies that are precise enough to reduce risk without creating so many approval steps that automation loses its value.
Cloudflare’s internal deployment shows scale
Cloudflare employees created more than 4,000 apps, automations, and tools with Cloudflare OS over a 30-day period. During the same period, the company estimates that its sales team saved about 10,000 hours by automating manual work, including territory planning and proposal creation.
Those numbers give Cloudflare a useful internal case study. The company originally built Cloudflare OS for its own workforce, and Rita Kozlov, VP of Product at Cloudflare, said employees “across every team” now use it daily. That level of internal deployment matters because it exposes an AI platform to real business workflows rather than isolated demonstrations.
The 10,000-hour figure is particularly relevant to executives because it connects AI use to a measurable operating resource: employee time. Automating proposal preparation and territory planning can reduce repetitive work and increase the time sales staff have available for customer-facing activity. The business value, however, depends on whether those saved hours translate into higher output, lower costs, faster sales cycles, or other measurable results.
Executives should therefore treat the figures as evidence of adoption and automation capacity rather than a general ROI benchmark. Cloudflare has shown that employees can create a high volume of software and automated workflows through the platform. It has not shown that another enterprise should expect the same productivity gains.
There is another important measurement issue. The number of applications or automations created is not itself a business outcome. A smaller number of frequently used workflows may generate more value than thousands of lightly used tools. Enterprises adopting this type of platform should track sustained usage, hours actually eliminated, process completion times, error rates, AI operating costs, and financial outcomes.
Cloudflare’s internal experience still strengthens its case. It suggests that the company has tested the product against its own systems and workflows before offering it as broader enterprise infrastructure. It also provides a concrete indication of where agentic AI can deliver near-term value: structured, repetitive knowledge work that consumes employee time but can be executed through controlled access to existing data and software.
For C-suite leaders, that is the practical benchmark. Deployment volume matters less than verified business impact. A successful AI operating environment must turn agent activity into lower process costs, faster execution, or greater employee capacity while maintaining security and control.
Cloudflare is selling integration as the core value of its AI platform
Cloudflare’s main competitive claim is not that it has created a new desktop operating system. It is that enterprises need one place to manage the infrastructure required by AI agents. Cloudflare OS combines access control, AI connectivity, enterprise context, workflows, and supporting infrastructure under a common architecture.
Technology analyst Carmi Levy makes this distinction clear. “This very much is not Windows, macOS, or Linux, and it isn’t an operating system by its common definition,” he said. In his view, the OS label gives enterprise IT buyers familiar language for discussing a new infrastructure category.
That positioning matters because AI deployment has moved beyond choosing a model. Enterprises must connect models to corporate data, authenticate users and agents, route requests, control permissions, monitor spending, and integrate AI with existing applications. If those functions come from separate systems, IT teams must build and maintain the connections between them. Integration becomes the constraint.
Cloudflare is trying to reduce that work by presenting these functions as a cohesive platform. Levy describes Cloudflare OS as “more cohesively bundled” and infrastructure-focused than competing approaches. It provides what he calls a “single pane of glass” for organizations that otherwise face the task of connecting separate AI-aware networking and infrastructure components.
Microsoft and Google already cover much of the same territory through broad portfolios. Levy points to Microsoft’s Azure, Entra, Fabric, Windows, and Microsoft 365 products, which collectively provide many elements of an AI enterprise environment. Google has Gemini, Workspace, Vertex AI, and Cloud Run. His distinction is that these companies have not packaged those components under a single OS-style identity in the same way Cloudflare has.
Branding alone does not create technical integration. Executives should evaluate whether Cloudflare actually reduces the number of systems, policies, and operational processes their teams must manage. They should also examine whether centralized administration provides consistent identity, security, observability, and cost controls across different models and applications.
There is also a concentration trade-off. Consolidating infrastructure can lower integration costs and simplify accountability. It can also increase dependence on one strategic infrastructure provider. Cloudflare’s open-source approach may reduce some of this risk, but buyers still need to assess service portability, operational dependencies, resilience requirements, and switching costs.
Levy sees infrastructure integration as Cloudflare’s main advantage. “While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor,” he said. That could reduce the amount of AI integration work handled internally.
For CIOs, the decision should come down to measurable operational complexity. A successful platform should reduce deployment time, duplicated controls, integration maintenance, and the number of separate systems required to govern AI. If Cloudflare OS delivers those results, its value is much broader than the OS name suggests.
Model independence gives enterprises more freedom to change their AI stack
Cloudflare OS is designed to work with AI technology from OpenAI, Anthropic, Google, Microsoft, Meta, and open-source providers. This application-agnostic strategy addresses an important enterprise requirement: companies should not have to redesign their AI infrastructure every time they adopt a different model or application.
That matters because no single model is necessarily optimal for every workload. Enterprises may select models based on accuracy, speed, cost, data handling requirements, regional availability, or the specific task being performed. Those decisions can also change quickly as providers release new models and alter pricing.
Cloudflare separates the infrastructure layer from those model choices. An organization can maintain common access policies, integrations, and workflows while using different AI providers. Levy says this approach allows employees to enter familiar workflows after signing in while Cloudflare handles the supporting infrastructure.
The business benefit is optionality. A company that can change models without rebuilding its surrounding controls has greater freedom to negotiate costs and adopt better technology. It can also route different workloads to different models rather than forcing every business function onto one provider.
This flexibility is especially relevant for companies already running several AI platforms. Many large enterprises will not start with a clean environment. They may already use Microsoft services for productivity, OpenAI or Anthropic models for particular applications, Google technology for other workloads, and internally hosted open-source models for workloads with different security or cost requirements. Cloudflare’s strategy is to govern and connect these environments rather than require their replacement.
Levy said Cloudflare OS can “play nice” with OpenAI, Anthropic, Google, Microsoft, Meta, and open-source layers. He also argues that its open-source architecture “minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities.”
Executives should not interpret compatibility as complete portability. Models differ in APIs, context limits, tool use, security capabilities, performance, and output behavior. Switching providers can still require application testing and workflow changes. Model independence at the infrastructure level reduces this work; it does not eliminate it.
There is also a governance requirement. Giving business units access to multiple models can create uncontrolled spending and inconsistent security practices if model choice is unmanaged. Enterprises need central policies that determine which providers can receive which data, which workloads can use higher-cost models, and when particular requests must remain inside approved environments.
Cloudflare’s position is therefore strongest when model choice and central governance work together. CIOs get the ability to change providers and use multiple models while maintaining common infrastructure controls. In a market where models and economics are changing rapidly, preserving that flexibility is a practical strategic advantage.
Cloudflare ties every AI request to a verified identity
Shared API keys create a basic governance problem. They can show that an application accessed an AI model, but they may not show which employee or AI agent initiated each request. Cloudflare is addressing this with Identity-Aware AI Gateway, a new service currently in beta.
The gateway integrates with Cloudflare Access, its zero-trust network access product. Enterprises can connect identity providers such as Okta or Microsoft Entra rather than relying on shared API credentials. Each AI request is then associated with an Access-verified identity, whether the request comes from a person or an AI agent.
This identity layer gives security teams much finer visibility. Administrators can review logs, analytics, and AI spending by user. They can identify duplicated activity, set usage limits, and investigate unusual behavior. Companies can also put custom domains in front of their AI gateways, giving IT a controlled entry point for model access.
The most important benefit is accountability. AI agents can generate large volumes of requests and increasingly act on behalf of employees. IT therefore needs to know who initiated activity, which agent executed it, and what resources were consumed. A generic API credential is not sufficient for this level of governance.
Cloudflare also allows enterprises to filter data before requests reach external model providers. Filters can remove employee names, passwords, and other sensitive information. This reduces the chance of staff or agents unintentionally sending confidential data outside approved boundaries.
For CIOs and CISOs, identity should be treated as a prerequisite for governed AI adoption. Organizations cannot reliably manage permissions, investigate incidents, attribute costs, or enforce individual policies if AI traffic cannot be traced to an authenticated source. As autonomous agents become more common, machine identities will require the same discipline already applied to human access.
There are limits. Identity verification establishes who or what made a request; it does not establish whether the request was appropriate. Enterprises still need authorization rules, data classification, monitoring, and controls over what agents may do after authentication. Identity-Aware AI Gateway provides the attribution layer needed to make those controls more precise.
The strategic value is therefore broader than login security. Cloudflare is connecting AI consumption to enterprise identity, creating a common record for security, compliance, and cost management. That gives executives a clearer answer to a critical governance question: who is using AI resources, and under whose authority?
AI spend and user insights target uncontrolled AI costs at the user level
A single uncontrolled AI session generated a $30,000 bill for one Cloudflare customer, according to Rita Kozlov, VP of Product at Cloudflare. The employee had left what Kozlov described as a “rogue AI session” running. User Insights identified the activity, allowing the company to disable access before costs increased further.
The example shows a structural issue with enterprise AI spending. Consumption is variable. Agents can generate repeated requests, process large context windows, or continue operating with limited human attention. A configuration error or uncontrolled workflow can therefore turn into a material expense quickly.
Cloudflare is addressing this through AI Spend and User Insights. AI Spend monitors each user’s behavior over time and establishes a baseline for normal AI consumption. When spending moves outside that established pattern, IT receives an alert.
User Insights adds more detailed analysis. It identifies factors that can increase costs, including oversized context windows and low cache-hit rates. A context window is the information sent to a model as part of a request. Sending more context generally requires more processing and can increase model charges. Poor cache utilization can also cause systems to repeatedly process information that might otherwise be reused.
Cloudflare product managers Ming Lu, Kenny Johnson, and Ayush Kumar described a specific method for identifying unusual sessions in a company blog post. The system compares session costs with the account’s historical activity. It calculates the 95th-percentile session cost over the preceding 30 days. A session costing more than twice that benchmark is considered a “strong candidate for anomalous behavior.”
That threshold provides useful automation, but executives should not treat it as a complete financial control. A statistical anomaly can be legitimate, while steady but inefficient consumption may remain below the threshold. Cost management therefore requires both anomaly detection and policies governing budgets, model selection, context size, usage rates, and workload value.
Identity integration strengthens this process. Because Cloudflare can associate requests with verified users, administrators can move from knowing that AI spending increased to identifying who or what generated the increase. That improves investigation, accountability, and remediation.
The next management challenge is connecting cost with value. A high-cost AI session is not necessarily wasteful if it produces a high-value result. Conversely, inexpensive requests repeated across thousands of employees can create significant aggregate cost without delivering useful outcomes. CFOs and CIOs need measures such as cost per completed workflow, cost per user, automation savings, and business output alongside total model expenditure.
Cloudflare’s $30,000 customer example is useful but remains a vendor-reported case rather than independent research. The same applies to the company’s anomaly-detection methodology. Enterprises should validate thresholds against their own usage patterns before using them for automated enforcement.
The direction is clear. AI cost control needs to move beyond monthly provider invoices. Organizations need attribution, real-time monitoring, behavioral baselines, and rapid intervention. Cloudflare is integrating those capabilities with identity and security controls, giving IT and finance teams a more detailed view of where AI budgets are being consumed and why.
Prompt classification gives enterprises context for how employees use AI
Knowing who used an AI model is not enough. Enterprises also need to know what the model was used for. Cloudflare is developing prompt classification to categorize requests into activities such as coding and writing. This adds business context to the identity and spending data captured elsewhere in its platform.
The goal is to separate legitimate business activity from personal use and potentially harmful behavior. Once IT can classify AI traffic by purpose, it can see which activities are consuming company resources and determine whether those activities match approved business use.
This becomes more important as employees gain access to external AI models through company systems. An unusual volume of prompts could indicate harmless experimentation, unauthorized personal work, or an attempt to transfer sensitive information. Request volume alone cannot reliably distinguish among those cases. Classification gives security teams more information for investigation.
Cloudflare product managers Ming Lu, Kenny Johnson, and Ayush Kumar described the challenge in a company blog post: “Once business traffic is separated from everything else, personal use becomes visible.” They added: “From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk.”
Prompt classification should not, however, be treated as proof of user intent. A coding prompt may support an approved project or an unauthorized activity. A writing request could contain confidential data even if its category appears routine. Automated classifiers can also make mistakes. Enterprises will still need identity information, data controls, behavioral history, and human investigation for higher-risk cases.
There is a workforce governance issue as well. Detailed prompt monitoring can expose sensitive information about employee activity. CIOs, CISOs, HR leaders, and legal teams should establish clear rules for what is collected, how long it is retained, who can review it, and how it can be used. Regulatory and employment requirements will vary across countries.
The business value is strongest when classification informs policy rather than simply producing more monitoring data. Enterprises could use it to identify departments where AI delivers clear value, detect unapproved use cases, refine model access, or determine where employees need sanctioned AI tools.
For executives, the objective should be visibility with purpose. Knowing that an employee sent 1,000 AI requests says little about business value or risk. Knowing who made those requests, what category of work they supported, what data they contained, and how much they cost creates a stronger basis for governance.
Cloudflare is building one governance layer for identity, security, usage, and cost
Cloudflare’s broader strategy becomes clearer when its new products are considered together. Cloudflare OS provides the workspace and agent infrastructure. Identity-Aware AI Gateway attributes model requests to verified users and agents. AI Spend monitors consumption. User Insights identifies unusual costs. Prompt classification adds context about how AI is being used.
The common objective is centralized governance. Enterprises deploying multiple models and agents need to answer a small set of critical questions: who is using AI, which models are involved, what information is being sent, what actions agents can perform, and how much the activity costs. Those questions become difficult to answer when each application, model provider, and department maintains separate controls.
Technology analyst Carmi Levy identifies visibility as a major weakness in earlier enterprise AI deployments. He said projects have “crashed and burned” when users unintentionally exhausted token allocations. Tokens are the units many AI providers use to measure model input and output, making them an important driver of variable AI costs.
Cloudflare’s response is to apply controls above individual models. Because its services can work with existing AI providers, an enterprise does not necessarily need separate governance processes for every model. Administrators can gain a consolidated view of usage and apply controls such as identity verification, spending limits, rate limits, and filters that remove sensitive data before requests reach external providers.
Levy argues that these capabilities provide “single-point visibility” into what AI is being used, how it is being used, and where productivity gains may exist. He also points to more precise allocation of resources and automated anonymization as ways to strengthen security while enterprises expand AI adoption.
This approach addresses a real operating constraint. Adding another AI model is relatively easy. Governing thousands of users and agents across many models, applications, data sources, and departments is much harder. Without common controls, every additional deployment can add security policies, spending records, identity mappings, and monitoring systems for IT teams to reconcile.
Centralization does introduce its own risk. A platform handling identity, AI routing, access policy, monitoring, and cost data becomes an important part of enterprise infrastructure. Executives should assess availability, data residency, auditability, regulatory requirements, incident response, and provider concentration before consolidating these functions. Cloudflare’s open-source strategy may improve flexibility, but it does not remove those operational dependencies.
C-suite leaders should also insist on business metrics alongside governance metrics. More visibility does not by itself produce value. Enterprises should connect AI consumption with workflow completion times, employee capacity, error rates, operating costs, revenue outcomes, and security incidents. This makes it possible to distinguish productive AI investment from activity that simply consumes more computing resources.
Levy’s final assessment captures Cloudflare’s strategic position. Vendors that reduce the need for IT teams to assemble AI infrastructure independently and help enterprises answer AI-specific management questions, he said, “will gain advantage over vendors that aren’t looking at the bigger picture.”
That is the central case for Cloudflare’s new portfolio. The company is not competing primarily on the intelligence of an AI model. It is competing on the enterprise infrastructure around those models. As companies move from AI experiments to autonomous workflows, control over identity, permissions, data, and spending becomes a prerequisite for scaling.
In conclusion
Cloudflare’s bet is that the main enterprise AI problem is no longer access to powerful models. It is control. Companies need to connect agents to real business systems without losing track of identity, permissions, sensitive data, or cost.
Cloudflare OS addresses that problem at the infrastructure level. Its browser-based workspace, least-privilege security, model-neutral architecture, identity controls, and spending tools form a coherent proposition. Open source also gives enterprises more flexibility as models, providers, and economics change.
The early numbers are promising but limited. Cloudflare reports more than 4,000 apps, automations, and tools created internally in 30 days and an estimated 10,000 hours saved by its sales team. Those figures show adoption, not proven enterprise ROI. Buyers should measure process time, operating cost, error rates, security outcomes, and sustained usage before drawing broader conclusions.
For executives, the key decision is not whether Cloudflare OS deserves to be called an operating system. The useful question is whether it can reduce the integration and governance burden created by enterprise AI. If it can give agents enough access to produce meaningful work while keeping authority, data, and spending under control, Cloudflare will be addressing one of the harder constraints on scaling agentic AI.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


