Adaptive application security for the AI era: how Cloudflare connects code, traffic, and intelligence to stop attacks
Cloudflare introduces an adaptive security framework to counter AI-driven cyberattacks by integrating code analysis, runtime protection, and threat intelligence across four interconnected stages.
AI agents recently compromised parts of OpenAI’s and Hugging Face’s systems in under 13 hours, exploiting vulnerabilities, recovering credentials, and coordinating attacks autonomously. The incident highlighted how AI agents persistently test multiple paths, share discoveries, and chain vulnerabilities, making traditional single-tool security approaches ineffective. Organizations require overlapping controls across prevention, detection, and mitigation, as well as continuous validation of security boundaries to address such threats. Cloudflare’s framework aims to bridge these gaps by connecting discovery, governance, runtime protection, and investigation into a unified system.
Cloudflare’s new capabilities include using LLMs to test its Web Application Firewall, expanding threat intelligence for all customers, and automating positive security deployments. The framework addresses three interconnected challenges: protecting conventional apps from AI-enabled attackers, governing legitimate and malicious agentic clients, and securing applications containing models, agents, tools, and data. Application security must evolve into a continuous system rather than a periodic review process to keep pace with AI-driven threats.
Cloudflare leverages its visibility into over 20% of the web to detect attack infrastructure, payload mutations, and coordinated campaigns at scale. By combining global threat intelligence with local application context—such as deployed code, exposed endpoints, and legitimate traffic patterns—Cloudflare can turn insights into immediate protections. The framework’s inline enforcement allows real-time adjustments based on runtime signals and investigation outcomes, improving controls dynamically.
Cloudflare introduces Adaptive Security, a self-service capability to periodically pentest selected URLs using LLM-powered agents to identify reachable and exploitable vulnerabilities before attackers do. The company also expands its verified identity layer for agentic traffic, enabling legitimate bots and agents to declare their identity while allowing application owners to control access. Trust and risk signals are evaluated separately for each interaction, providing more granular control than traditional bot scores or binary allow-or-block decisions.