Seville, Spain
Seville, Spain
+(34) 624 816 969
The emergence of generative artificial intelligence and, above all, autonomous agents, is forcing companies to rethink the foundations of their technological infrastructure. Traditional operating systems, designed to manage hardware, files, and users, fall short in an environment where machines not only execute orders but also make decisions, generate content, and collaborate with each other. In this context, Cloudflare has presented its most ambitious proposal to date: an "operating system" for the AI era that runs directly in the browser and promises to centralize agents, data, workflows, and security policies in a single workspace.

Table of contents [Show]
Cloudflare OS is not a conventional operating system like Windows, macOS, or Linux. It does not manage local processes or RAM. Instead, it presents itself as a secure, AI-equipped workspace that integrates with a company's internal systems. It is available as an open-source project in Cloudflare's repository and is accessed through a browser, running within the organization's Cloudflare account.
Cloudflare's Vice President of Product, Rita Kozlov, explains it clearly: "Cloudflare OS is not a traditional desktop operating system. It reinvents the workplace IT environment for AI." The idea is that users can interact with a conversational agent that performs searches, creates documents, spreadsheets, presentations, and even full-stack applications, all without needing a terminal. Results can be shared, but they are stored in isolated databases with granular access controls.
This browser-based approach eliminates the need to deploy additional infrastructure, something many companies will appreciate, especially those already dealing with the complexity of integrating AI into their processes. Furthermore, being open source, organizations can inspect the platform, customize it, and connect it to their own systems, avoiding dependence on a single vendor.
One of the most interesting aspects of Cloudflare OS is its architecture, built on existing company components: Cloudflare Workers, Durable Objects, and Access, its zero-trust network access (ZTNA) tool. AI agents start with zero permissions and are only granted the tools necessary for specific tasks. This is crucial in an environment where agents act on behalf of employees and generate work that others can modify.
Administrators can configure Access policies, AI models, branding, and custom skills. Additionally, so-called "gatekeepers" or regulated connectors allow controlling what AI can see, what it can modify, and when human approval is required. Budgets, rate limits, and task delegation to different models based on cost or capability can also be established.
This obsession with security is no coincidence. As Kozlov notes, "since agents act on behalf of people and generate work that others can access and modify, they require a new security model." Therefore, Cloudflare OS tracks the resources each agent needs, so access controls accompany their work when shared.

Cloudflare has not launched this product in a vacuum. The company has been using it internally for months, and the results are impressive. According to Kozlov, in the last 30 days, employees from all teams have created more than 4,000 applications, automations, and tools using Cloudflare OS. The sales team, for example, has automated tasks like territory planning and proposal preparation, saving approximately 10,000 hours of manual work.
These numbers demonstrate that the proposal is not just theoretical but has a real impact on productivity. For companies looking to optimize their operations, the possibility of employees creating their own tools without IT intervention is a paradigm shift. However, it also poses challenges in terms of governance and control, something Cloudflare attempts to address with its security and identity management approach.
Technology analyst Carmi Levy has noted that Cloudflare OS arrives at a time when companies are desperately seeking ways to integrate AI into their existing infrastructures. While Microsoft has marketed the combination of Azure, Entra, Fabric, Windows, and Microsoft 365 as a sort of operating system, and Google has done the same with Gemini, Workspace, Vertex AI, and Cloud Run, Cloudflare presents a more cohesive and infrastructure-focused offering.
"While competitors' offerings often leave the arduous task of infrastructure to corporate decision-makers, Cloudflare positions itself as a single provider," Levy says. This frees IT planners from having to integrate all AI components on their own, a process that can be complex and error-prone.
Moreover, being application-agnostic, Cloudflare OS can coexist with any existing AI solution, whether from OpenAI, Anthropic, Google, Microsoft, Meta, or open source. This reduces the risk of vendor lock-in, a concern for many organizations.
One of the most pressing issues in enterprise AI adoption is the lack of visibility into who uses which model and at what cost. To address this, Cloudflare has launched Identity-Aware AI Gateway, currently in beta. This tool integrates with Access and allows administrators to see what users (human or AI) request from models, replacing shared API keys with identities verified through providers like Okta or Entra.
Each request is linked to an identity, and IT teams can filter logs, analytics, and spending by user. They can also detect redundancies, limit usage rates, and apply filters that remove sensitive data before requests reach external providers. This is especially relevant for complying with regulations like GDPR.
The complementary feature, AI Spend, tracks each user's behavior over time to establish a baseline of normal usage. If spending deviates from that pattern, the system alerts the IT team. For example, a Cloudflare customer discovered that an employee had left an unauthorized AI session running, generating a $30,000 bill. Thanks to User Insights, they were able to identify the problem and block access before the situation worsened.

The arrival of Cloudflare OS and its complementary tools has profound implications for the sector. On one hand, it offers a comprehensive solution for companies that want to adopt AI without having to build infrastructure from scratch. On the other, it raises the need for IT professionals to adapt to a new management model where AI agents are first-class citizens.
The visibility provided by Identity-Aware AI Gateway and AI Spend is crucial to avoid the failures that many AI implementations have suffered, where users exhausted token allocations without anyone noticing. As Levy notes, "these platforms offer a global view of what is being used, how it is being used, and where the potential lies to raise the productivity bar."
For IT departments, this means that managing users and devices is no longer enough; now they must also manage agents, permissions, and AI budgets. Tools like Cloudflare's facilitate this task, but they also require a mindset shift. Security must adapt to an environment where agents can act autonomously, and identity management must extend to non-human entities.
In this sense, Cloudflare's initiative aligns with other market trends, such as the growing importance of security in software development and the need for more efficient cloud resource management. We can see parallels with the rise of virtualization and containerization, where tools like KubeVirt and EVPN are solving mobility and scalability problems.
Also relevant is the debate about the limits of AI and its impact on cybersecurity, as addressed in our analysis of the AI model OpenAI hasn't released yet. The ability to control and audit AI usage will be fundamental to avoiding risks.
Cloudflare OS represents a serious attempt to redefine the workplace for the AI era. By offering an open-source, browser-based platform with a clear focus on security and identity, the company positions itself as a key player in the digital transformation of businesses. However, its success will depend on adoption by organizations and Cloudflare's ability to maintain its promise of openness and flexibility.
For IT professionals, this is a time of opportunity and challenge. Managing AI will require new skills and tools, but it will also offer the possibility of automating repetitive tasks and focusing on higher-value activities. As always, the key will be finding the balance between innovation and control, something Cloudflare seems to have understood well.
At ForgeNEX, we will closely follow the evolution of this platform and its impact on the technology ecosystem. Meanwhile, we recommend our readers explore the possibilities offered by open source and identity management, as we have already seen in articles on Linux server hardening and logical architecture in data management.
The era of AI agents has arrived, and with it, the need for a new operating system. Cloudflare has taken the first step. Who will follow?
Original source: ComputerWorld. Analysis and adaptation by ForgeNEX.