Cloudflare this week released Cloudflare OS, a browser-based, open source workspace that connects AI agents, enterprise data, internal systems, and workflows in one secure environment. The company says traditional operating systems were designed to manage hardware, files, and users on devices, but the agentic AI era demands an entirely different approach. The new platform spares companies from building fresh infrastructure while integrating zero-trust access, governed connectors, model routing, and enterprise context directly in the browser.
The OS operates within an enterprise's Cloudflare account and is accessible through the company's open source repository right now. According to Rita Kozlov, Cloudflare's VP of product, the workspace "begins with a conversation" where users can ask agents to research, build slides, create spreadsheets and documents, develop full-stack apps, or automate workflows without needing a terminal. Kozlov estimated that over the past 30 days, internal Cloudflare users created more than 4,000 apps, automations, and tools using the OS. During that same period, she claimed the company's sales team saved roughly 10,000 hours by automating previously manual tasks like territory planning and proposal creation. The platform runs on Cloudflare Workers, Dynamic Workers, Durable Objects, and Access—the company's zero trust network access tool—with agents starting at zero permissions by default and granted access only to tools required for a specific task. Outputs remain in isolated databases with access controls, and governed connectors called gatekeepers give admins control over what AI can see, what it can change, and when human sign-off is required.
The report notes that Cloudflare OS is "more cohesively bundled" and infrastructure-focused than competing offerings, providing a single pane of glass platform for buyers worried about integrating disparate AI-aware networking pieces. Tech analyst Carmi Levy explained that while Microsoft has marketed the combination of Azure, Entra, Fabric, Windows, and Microsoft 365 as an operating system of sorts, it hasn't pulled all the pieces into a common brand, and Google's Gemini, Workspace, Vertex AI, and Cloud Run are "circling similar territory." Kozlov said open source is critical because "you cannot put your company into software you do not own," and organizations need to inspect the platform, customize it, connect their own systems, and make it their own. Alongside the OS, Cloudflare launched Identity-Aware AI Gateway—now in beta—which gives admins visibility into what users, both human and AI, are requesting from AI models and ties every request to Access-verified identities. A companion feature, AI Spend, tracks each user's behavior over time to establish a baseline of normal AI usage and alerts IT teams when spending deviates from that pattern.
The report explains that Cloudflare's infrastructure-first, application-agnostic approach means the OS can coexist with whatever AI applications already exist in an enterprise, whether from OpenAI, Anthropic, Google, Microsoft, Meta, or open source layers. Levy noted that the Identity-Aware AI Gateway and AI Spend address the visibility problem that has plagued many recent AI deployments where enterprises failed to monitor usage, causing projects to "crash and burn" as users unknowingly blew through token allocations. The new User Insights tab scores sessions and compares them against account history using a 95th percentile session cost over the previous 30 days, with anything above 2x that percentile flagged as a "strong candidate for anomalous behavior." In one case, Kozlov said a Cloudflare customer had an employee who left a rogue AI session running, generating a $30,000 bill, and User Insights helped them identify the problem and shut off access before it worsened. Because organizational processes, internal system connections, and context aren't locked into a vendor product or AI model provider, customers can use whatever models they choose. Levy said vendors who free IT from having to independently assemble the pieces of their own AI implementations, and who help them with answers to AI-specific questions, "will gain advantage over vendors that aren't looking at the bigger picture." The open-source architecture also minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities. Positioning infrastructure as an operating system may redefine how enterprises evaluate AI procurement, shifting the conversation from application features to foundational control. Organizations that delay governance and spend visibility risk discovering cost overruns only after cultural adoption makes rollback politically impossible.

