Cloudflare has open sourced Cloudflare OS, an internal platform built to control, isolate, and audit how AI agents access sensitive data and external tools. The system uses capability-based access controls and Gatekeeper services that hold credentials on an agent’s behalf, allowing policies to be enforced without exposing secrets directly to agent code. Cloudflare said the platform was designed to address security gaps in agent frameworks by limiting what agents can reach and by making their actions attributable and reviewable.
A central feature is an observation log that records every resource an agent reads and uses that history to re-check whether downstream actions should still be allowed, extending beyond tool-permission models such as Model Context Protocol. Cloudflare said agent execution is isolated through Dynamic Workers, sandboxed browser frames, Durable Object Facets, and SQLite-backed application state, while model traffic is routed through Cloudflare AI Gateway for attribution, rate limiting, and budget controls. The company said Cloudflare OS is being released as open source before a broader managed product launch, with dashboard, development container, and Slack-integrated workspace features still in development.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Cloudflare announced and open sourced Cloudflare OS, an internal agent platform built around capability-based access controls, Gatekeeper services, and an observation log that records what data agents actually read. Cloudflare also published two GitHub repositories: a core repository and a starter deployment modeled on its internal use.
Cloudflare employees have used the first version of Cloudflare OS internally since May. The platform was used to manage and audit how AI agents access resources and propagate sensitive data inside the company.
After a GitHub user complained that Cloudflare OS deployment failed mid-process for Workers Free plan users without early warning, Cloudflare updated the deployment flow to alert users at the start that the backend requires a Workers Paid plan. A Cloudflare representative also responded on the GitHub issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
11 references tracked. Mallory keeps watching after this page renders.
infoq.com
Open sourcethenewstack.io
Open sourcearstechnica.com
Open sourcehelpnetsecurity.com
Open sourceblog.cloudflare.com
Open sourceblog.cloudflare.com
Open sourceblog.cloudflare.com
Open sourceblog.cloudflare.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.