Cloudflare has launched Cloudflare OS, an open-source, browser-based workspace designed specifically for the era of AI agents. The company positions it as a replacement for traditional operating systems, which it says were built to manage hardware and files, not autonomous AI workflows. The OS connects AI agents, enterprise data, internal systems, and workflows in a single secure environment, and it is available now through Cloudflare's open source repository.
The product arrives alongside new security, identity, and spending tools, including Identity-Aware AI Gateway and AI Spend, which give operations teams visibility into what both human employees and AI agents are doing. The move signals a shift in how enterprise infrastructure is being packaged for AI, with Cloudflare attempting to own the layer between AI models and company operations.
An operating system for agents, not just people
Cloudflare OS is not a traditional desktop OS. It runs inside an enterprise's Cloudflare account and begins with a conversation. Users can ask an agent to research topics, create documents and slides, build full-stack applications, or automate workflows without opening a terminal. Outputs are shareable but stored in isolated databases with access controls.
"Cloudflare OS isn't a traditional desktop OS," said Rita Kozlov, VP of product at Cloudflare. "It reimagines the workplace computing environment for AI."
The platform is built on Cloudflare Workers, Durable Objects, and Access, the company's zero trust network access tool. Agents start with zero permissions by default and are granted access only to the tools required for a specific task. Governance connectors, which Cloudflare calls gatekeepers, let administrators control what AI can see, what it can change, and when human sign-off is required. Admins can also set budgets and delegate tasks to different models.
Because agents act on behalf of people and produce work that others can access and modify, the company says a new security model is required. Cloudflare OS tracks the resources an agent uses so that access controls follow its work when it is shared.
Cloudflare built the OS for internal use first. Over the last 30 days, employees have used it to create more than 4,000 apps, automations, and tools. The company said its sales team saved an estimated 10,000 hours by automating tasks like territory planning and proposal creation.
"We open sourced Cloudflare OS so any organization can build 'Your Company OS,'" Kozlov said. "You cannot put your company into software you do not own."
One pane of glass vs. stitching pieces together
Tech analyst Carmi Levy said Cloudflare deserves credit for packaging the offering as an operating system, even though it is not one by the common definition. The terminology implies familiarity to enterprise IT buyers who are struggling to understand how to incorporate AI platforms into infrastructure not designed for it.
Microsoft has marketed a combination of Azure, Entra, Fabric, Windows, and Microsoft 365 as an operating system of sorts, Levy said, but has not pulled all the pieces into a common brand. Google's Gemini, Workspace, Vertex AI, and Cloud Run are circling similar territory. Cloudflare OS, he said, is more cohesively bundled and infrastructure-focused, offering a single pane of glass for buyers worried about stitching together AI-aware networking pieces.
"While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor, which potentially frees IT planners from having to integrate all the AI pieces on their own," Levy said.
An infrastructure-first, application-agnostic approach means Cloudflare OS can coexist with existing AI applications. It works with OpenAI, Anthropic, Google, Microsoft, Meta, or open source models, allowing employees to continue working in familiar workflows after sign-in. Its open-source architecture also minimizes vendor lock-in as enterprises evolve their stacks, Levy added.
Tracking identity and spend for humans and AI
As AI agents multiply, tracking their usage has become a security and cost problem. Cloudflare's Identity-Aware AI Gateway, now in beta, integrates with Access to give admins visibility into what users - both human and AI - are requesting from AI models. Every request is tied to Access-verified identities, and enterprises can filter logs, analytics, and spend for each user. IT teams can track redundancies, limit usage rates, and strip out sensitive data before requests go to outside model providers.
A companion feature called AI Spend tracks user behavior over time to create a baseline of normal AI usage. When spending deviates from that pattern, the system alerts IT. A new tab called User Insights tracks cost and identifies overspend caused by issues like low cache-hit rates or oversized context windows. The feature scores sessions against account history using a 95th percentile session cost over the previous 30 days. Anything above 2x that threshold is flagged as a strong candidate for anomalous behavior.
Kozlov cited one Cloudflare customer whose employee left a rogue AI session running, generating a $30,000 bill. "User Insights helped them identify the problem and shut off access before the problem was further exacerbated," she said.
Cloudflare is also building prompt classification functionality that sorts requests into categories like coding or writing, which can help enterprises understand what AI is being used for. Once business traffic is separated from everything else, personal use becomes visible. "From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk," the product managers said.
Why this matters for operations teams
For operations professionals, the practical takeaway is that AI usage can no longer be managed with manual oversight. The Identity-Aware AI Gateway and AI Spend tools address the visibility problem that has dogged recent AI deployments, where projects "crashed and burned" as users blew through token allocations, Levy said. These platforms provide single-point visibility into what is being used, how it is being used, and where the potential lies for raising productivity.
They overlay with existing models and enhance security with more precise control over resource allocations, plus automated anonymization protocols that prevent inadvertent sharing of sensitive data. For operations managers, the question is no longer whether AI agents will be adopted, but who is using them, what they cost, and whether their access is controlled. Teams that need to build these oversight skills can find structured training through AI for Operations resources, or a dedicated AI Learning Path for Operations Managers.
Vendors who free IT from assembling their own AI implementations, and who answer AI-specific questions, "will gain advantage over vendors that aren't looking at the bigger picture," Levy said.
Your membership also unlocks: