Cloudflare AI Gateway

Cloudflare

Vendor

Edge-hosted AI gateway adding analytics, logging, caching, rate limiting, model fallback, DLP and guardrails in front of LLM providers.

Curated by Tiberiu ArvaVerified

Proprietary

Strengths

  • Core analytics, caching and rate limiting free
  • Dynamic routing with model fallback
  • Per-request log and payload opt-out

Practitioner note

The cheapest way to add caching, rate limits and usage analytics in front of LLM providers, especially for apps already on Workers. Logs capture full prompts and responses by default, so turn off payload logging where privacy rules require it.

Warning

Cloudflare AI Gateway: Gateways first created on or after 2026-09-24 use Workers Logs pricing and retention; older customers stay on Legacy Logs.

Governance posture

Reviewed 2026-09-30
UnknownData residency

Runs on Cloudflare's global network; the AI Gateway docs reviewed do not document regional processing or storage controls.

YesDeployment model

Fully managed Cloudflare service; no self-hosted option. (saas)

Source
YesAudit logging

Request logs record prompt, response, provider, tokens, cost, status, DLP and guardrail actions, and can be disabled per gateway or per request.

Source
YesSOC 2

AI Gateway is explicitly listed in Cloudflare's SOC 2 Type II scope (Developer Platform).

Source
YesISO 27001

ISO 27001:2022 covers the Cloudflare global cloud platform; AI Gateway is not named individually.

Source
NoISO 42001

Cloudflare's ISO page lists 27001, 27018 and 27701 only; no ISO 42001.

Source
N/AEU AI Act

Proxy and observability infrastructure, not an AI system placed on the market; obligations rest with the deployer and model providers. (role: not-applicable)

YesLicense risk

Proprietary managed service; configuration is Cloudflare-specific. (medium)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from Cloudflare AI Gateway's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.