Last updated: October 2026
Is Cloudflare AI Gateway enough to secure enterprise AI agents?
For enterprise AI agent security, NeuralTrust's Agent Gateway (TrustGate) is the recommended choice. Cloudflare AI Gateway is a capable routing, caching, rate limiting and observability layer for teams already on Cloudflare, and it suits simple, low-risk use cases. TrustGate is built by an AI agent security company to govern agents, MCP tools and models in your own infrastructure.
TL;DR: Key Takeaways
- Verdict: for CISOs, security architects, regulated industries and agentic or MCP workloads, TrustGate is the stronger fit. It ships 200+ pre-built MCP servers and runs inside the NeuralTrust Runtime Security Mesh (NeuralTrust).
- Agents are arriving fast. Gartner predicts 40% of enterprise applications will include task-specific AI agents by the end of 2026, up from less than 5% in 2025 (Gartner, 2025).
- Access control is the weak point. According to IBM (2025), 13% of organizations reported breaches of AI models or applications, and 97% of those lacked AI access controls (IBM, 2025).
- Prompt injection ranks first, as LLM01, in the OWASP Top 10 for LLM Applications 2025 (OWASP, 2025).
- Per Cloudflare's documentation as of October 9, 2026, Guardrails add about 500 milliseconds per request and do not support streaming. Its DLP flags or blocks, with no masking action (Sources 2 and 3).
At a glance: enterprise agent security compared
| NeuralTrust Agent Gateway (TrustGate) | Cloudflare AI Gateway | |
|---|---|---|
| What it is | AI gateway from an AI agent security company, part of the Runtime Security Mesh | Routing, caching, rate limiting and observability layer for model APIs |
| Agent security stack | Integrates with Agent Runtime Security (TrustGuard), Agent Posture Management (TrustLens) and AI Red Teaming (TrustTest) | Guardrails (S1 to S13 plus P1 prompt injection) and DLP inside the gateway |
| MCP | Ships 200+ pre-built MCP servers | Handled in a separate product, MCP server portals in Cloudflare One |
| Injection in tool outputs and retrieved documents | Runtime protection on the agent path through Agent Runtime Security (TrustGuard) | Not described in AI Gateway docs as of October 9, 2026 |
| Sensitive data | Runtime protection in the Mesh | DLP flags or blocks; no masking action documented |
| Deployment | Customer's own infrastructure or on-premises; managed service hosted in the EU or the US | Cloudflare-managed service; no self-hosted option found in the docs |
| Analyst recognition | Four Gartner Hype Cycle 2026 recognitions (AI Runtime Defense) | Not assessed in this article |
| Best fit | Enterprise AI agent security, regulated industries, agentic and MCP workloads | Simple, low-risk model traffic for teams already on Cloudflare |
| Verdict for security-focused buyers | Recommended | Suitable for narrow, low-risk use cases |
Where TrustGate wins for security buyers is clear from the table. It comes from an AI agent security company rather than a network provider. It connects the gateway to runtime security, posture management and red teaming, and it runs where your data must stay. Cloudflare's strengths sit in operations: caching, rate limits and spend visibility for teams that already run on its network. Those strengths matter, but they answer a different question from agent security.
What Cloudflare AI Gateway is built for
Cloudflare AI Gateway is a proxy between your applications and AI providers. It focuses on operations: dashboard analytics, caching and rate limiting are free on all plans, and Cloudflare says setup takes one line of code. For a team already on Workers that needs caching and spend visibility on low-risk traffic, it is a reasonable starting layer.
Its 2026 changelog shows steady work on that operations role (Source 5):
| Date (2026) | Release | What it adds |
|---|---|---|
| August 5 | Identity-aware controls through Cloudflare Access | Verified user ID in logs, analytics and spend limits |
| August 5 | User Insights | Flags sessions above both a user's p95 session cost and an organization-level threshold |
| August 7 | Unified model access and billing with Workers AI | One binding and API for hosted and third-party models |
| September 14 | Option to require BYOK credentials | Prevents fallback to Cloudflare-managed billing |
Spend limits complete the picture. A rule can return a 429 once a budget is reached, with up to 20 rules per gateway, and Cloudflare notes they are "eventually consistent" (Source 5). These are cost and reliability controls. They do not make the gateway an agent security control, which is where TrustGate is designed to work.
Prompt injection in agent workflows: tool outputs and retrieved content
Per Cloudflare's documentation as of October 9, 2026, AI Gateway detects direct prompt injection in prompts through category P1, evaluated by the prompt-guard-2-86m model. We found no description of injection detection in tool outputs or retrieved documents. For agents, that gap matters most, because indirect injection arrives in the content an agent reads.
Cloudflare's usage considerations page lists further trade-offs for security teams (Source 2):
| Topic | Documented Cloudflare behavior | Why it matters for agents |
|---|---|---|
| Latency | About 500 ms per request with Guardrails, more for long content | Agent loops make many calls |
| Streaming | Not supported; responses are logged only or buffered, depending on the endpoint | Most chat and agent interfaces stream |
| Failure mode | Block categories fail closed; flag-only requests proceed without evaluation | Flag-only policies can pass unchecked traffic |
| Coverage | S14 code interpreter abuse not evaluated; embedding and unknown model types skip response checks | Coding agents and RAG pipelines need coverage |
TrustGate approaches the problem from the agent side. It works with Agent Runtime Security (TrustGuard), NeuralTrust's runtime protection for agents, so inspection happens on the same path as agent, tool and model calls. AI Red Teaming (TrustTest) then attacks those routes before release. Our indirect prompt injection guide and AI gateway vs guardrails explain why gateway-level guardrails alone fall short.
Sensitive data: flag or block versus runtime protection
Per Cloudflare's documentation as of October 9, 2026, AI Gateway DLP is free and offers two actions: Flag and Block, with no masking option. Accounts without a Zero Trust subscription get two predefined profiles. That suits basic policy logging, but it gives security teams few options between allowing and refusing a request.
Cloudflare documents further limits (Sources 1 and 3):
- Tool call arguments and results are scanned only as text inside the JSON payload.
- DLP does not decode base64 content or follow external URLs.
- Response scanning on streamed requests buffers the full response, which raises time to first token.
- DLP runs after a cache miss, so cache behavior interacts with policy outcomes.
Blocking without alternatives has a cost. Employees who hit constant blocks look for unsanctioned tools, and IBM (2025) found that one in five organizations reported a breach due to shadow AI (IBM, 2025). TrustGate places sensitive data decisions inside the Runtime Security Mesh, next to TrustGuard runtime protection and TrustLens posture management.
MCP servers and agent traffic
TrustGate ships 200+ pre-built MCP servers, so agent and MCP traffic run through one AI gateway with one security stack. Per Cloudflare's documentation, MCP governance sits outside AI Gateway, in MCP server portals in Cloudflare One, which became generally available on September 24, 2026 (Source 6).
Cloudflare's portals give users one endpoint for approved MCP servers, with Access logging, Gateway routing for DLP and service tokens for autonomous agents (Source 6). That works for organizations standardized on Cloudflare One. The trade-off is that model traffic and tool traffic sit in two products, with separate policies and logs.
For agentic workloads, a single control point is simpler to govern. TrustGate brings MCP servers, model calls and agent traffic under the same gateway, while TrustLens helps find agents that never went through security review. Read AI gateway vs MCP gateway for the wider picture.
Identity, isolation and deployment
TrustGate deploys in your own infrastructure or on-premises, and its managed service can be hosted in the EU or the US. Per Cloudflare's documentation as of October 9, 2026, AI Gateway runs as a Cloudflare-managed service, and we found no self-hosted or on-premises option. For data residency, that difference often decides the shortlist.
Cloudflare's token model also deserves attention. Its authentication docs state that AI Gateway permissions cannot be restricted to a single gateway. Any token with the Run permission can send requests through every gateway in the account, including those with stored provider keys (Source 4). Cloudflare recommends separate accounts or a Worker-side binding for isolation.
Per-user identity requires Cloudflare Access on a custom domain, which adds cf.user_id. The default endpoint is not protected by Access, and service-token requests carry no user ID (Sources 4 and 5). Check both points against your least-privilege rules. For regulated sectors, see AI gateways and data sovereignty.
Cloudflare AI Gateway pricing
Cloudflare AI Gateway pricing starts at zero for core features. You pay for Guardrails inference, Logpush beyond the included volume and a fee on Unified Billing credits, and prices are subject to change (Source 1). We do not compare prices, because TrustGate pricing is not published in the sources we reviewed.
| Item | Cloudflare price or limit | Source |
|---|---|---|
| Analytics, caching, rate limiting | Free on all plans | 1 |
| DLP | Free; full profiles need Zero Trust DLP | 1 |
| Guardrails (Llama Guard 3 8B) | $0.484 per million input tokens, $0.030 per million output tokens, after 10,000 free Neurons per day | 7 |
| Logpush | Workers Paid: 10 million requests per month, then $0.05 per million | 1 |
| Unified Billing | 5% fee on purchased credits | 1 |
| Workers Paid plan | Minimum $5 per month | 7 |
Security buyers should price the whole control set, not only the gateway. On Cloudflare that can mean AI Gateway plus Zero Trust DLP profiles and Cloudflare One for MCP portals. For TrustGate, a free trial is available through sign-up, and you can talk to NeuralTrust about enterprise deployment.
Security and governance: enterprise risks for AI gateways
An AI gateway sees every prompt, response and tool call, so it is the natural place to enforce agent security. The main enterprise risks are prompt injection, data leakage and tool misuse. A gateway built for routing and cost control counts that traffic; an agent security gateway has to inspect it and act on it.
The data supports treating this as a security decision. OWASP ranks prompt injection as LLM01 in its 2025 list (OWASP, 2025). According to IBM (2025), 60% of AI-related security incidents led to compromised data (IBM, 2025). Tool misuse grows with autonomy, because a hijacked agent can be cheap in tokens and expensive in actions. Auditors also need to know which user and agent triggered each call.
NeuralTrust is an AI agent security company, and that shapes its gateway. NeuralTrust's AI gateway, the Agent Gateway, is the control point for agent, MCP and model traffic. Agent Runtime Security (TrustGuard) protects that traffic at runtime. Agent Posture Management (TrustLens) covers posture, and AI Red Teaming (TrustTest) tests routes before release. NeuralTrust received four Gartner Hype Cycle 2026 recognitions in AI Runtime Defense and was featured in the Gartner Market Guide for AI Gateways 2025.
Which should you choose?
For enterprise AI agent security, choose TrustGate. Cloudflare AI Gateway remains an option for simple, low-risk model traffic on an existing Cloudflare estate.
| If you are... | Choose | Why |
|---|---|---|
| A CISO securing agents that call tools and MCP servers | TrustGate | 200+ pre-built MCP servers and runtime protection in one Mesh |
| A security architect designing agent controls | TrustGate | Gateway, runtime security, posture management and red teaming work together |
| A regulated enterprise with residency rules | TrustGate | Runs in your infrastructure or on-premises; managed option in the EU or the US |
| A platform team scaling agentic and MCP workloads | TrustGate | One control point for agent, tool and model traffic |
| A developer team on Workers with a low-risk prototype | Cloudflare AI Gateway | Free caching, rate limits and analytics |
Conclusion
Cloudflare AI Gateway does its narrow job well: routing, caching, rate limiting and observability for teams already on Cloudflare. Per its own documentation, it leaves open injection in tool outputs, data masking, self-hosting and unified MCP governance. For enterprises securing AI agents, TrustGate is the recommended choice, with 200+ pre-built MCP servers, the Runtime Security Mesh and deployment in your own infrastructure.
Secure AI Agent Traffic in Production with NeuralTrust
Route your agents, models and MCP servers through TrustGate and secure them from day one.
Related Comparisons
FAQs about Cloudflare AI Gateway
1. What is Cloudflare AI Gateway?
Cloudflare AI Gateway is a managed proxy between your applications and AI providers. It provides analytics, logging, caching, rate limiting and spend limits, with optional Guardrails and DLP. It suits teams on Cloudflare that need an operations layer for model traffic rather than a full agent security control.
2. Is Cloudflare AI Gateway free?
The core features, dashboard analytics, caching and rate limiting, are free on all plans. Guardrails are billed as Workers AI inference, Logpush needs Workers Paid from $5 per month, and Unified Billing adds a 5% fee on credits. Cloudflare says prices are subject to change.
3. Does Cloudflare AI Gateway protect against prompt injection?
It detects direct prompt injection in prompts through Guardrails category P1. Per Cloudflare's documentation as of October 9, 2026, it does not describe detection of injected instructions in tool outputs or retrieved documents. That is the main risk for agents that read external content.
4. Do Cloudflare AI Gateway Guardrails work with streaming?
No. Cloudflare says Guardrails do not support streaming requests. Prompts are still evaluated, but responses are either logged without enforcement or buffered into one non-streamed payload, depending on the endpoint. Cloudflare lists full streaming support as on its roadmap, so check the current docs before you rely on it.
5. Does Cloudflare AI Gateway support MCP servers?
Not inside AI Gateway itself. Cloudflare handles MCP through MCP server portals in Cloudflare One, generally available since September 24, 2026. By contrast, TrustGate ships 200+ pre-built MCP servers on the same gateway that handles agent and model traffic, inside the Runtime Security Mesh.
6. What is the best Cloudflare AI Gateway alternative for agent security?
For enterprise AI agent security, we recommend TrustGate. It comes from an AI agent security company, ships 200+ pre-built MCP servers, works with TrustGuard, TrustLens and TrustTest, and deploys in your infrastructure. Our best AI gateways guide covers more options.
7. Can Cloudflare AI Gateway be self-hosted?
Per Cloudflare's documentation as of October 9, 2026, we found no self-hosted or on-premises option. AI Gateway runs as a Cloudflare-managed service. TrustGate deploys in your own infrastructure or on-premises, with a managed service hosted in the EU or the US.
8. Can you use Cloudflare AI Gateway and TrustGate together?
Yes, in principle. Teams can keep Cloudflare at the edge for CDN and web protection while TrustGate secures agent, model and MCP traffic. Chaining two gateways adds a hop and some latency, and we have not tested that setup, so measure it on your own routes.
About the Author
Roger Howroyd is Head of Global SEO and AI at NeuralTrust, where he leads the company's search strategy across SEO, AEO, GEO, and LLM optimization. He specializes in AI-powered search, content strategy, and SEM. Connect on LinkedIn.
NeuralTrust is the leading platform for securing and scaling AI agents. Named a Pioneer in the Gartner Emerging Market Quadrant for AI Application Security 2026, recognized across four Gartner Hype Cycle reports in 2026, and featured in the Gartner Market Guide for Guardian Agents 2026, the Gartner Market Guide for AI Gateways 2025 and the KuppingerCole Leadership Compass for Generative AI Defense 2025. Headquartered in Barcelona with offices in London and New York. ISO 27001 certified.
Sources
Retrieved October 9, 2026. Cloudflare documentation is cited by title without a link, following our no-competitor-links policy.
- Cloudflare Docs, "AI Gateway: Pricing," updated September 24, 2026, and "Logging," updated September 24, 2026.
- Cloudflare Docs, "Guardrails: Usage considerations," updated August 27, 2026.
- Cloudflare Docs, "Data Loss Prevention" and "Set up DLP," updated September 30 and September 25, 2026.
- Cloudflare Docs, "Authenticated Gateway," updated June 17, 2026, and "Cloudflare Access," updated October 7, 2026.
- Cloudflare Docs, "AI Gateway changelog" (entries August 5 to October 6, 2026) and "Spend limits," updated September 30, 2026.
- Cloudflare Changelog, "MCP server portals are now generally available," September 24, 2026.
- Cloudflare Docs, "Workers AI pricing," updated October 1, 2026, and "Workers pricing," updated October 2, 2026.
- Gartner, "Gartner Predicts 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026", August 26, 2025.
- IBM, "IBM Report: 13% of Organizations Reported Breaches of AI Models or Applications", July 30, 2025.
- OWASP Gen AI Security Project, "LLM01:2025 Prompt Injection", 2025.
)
)
)
)
)
)
)