TechSignal.news
Cybersecurity

Cloudflare Wires Identity Checks Into AI Traffic, Zscaler Expands Federal Access

New controls tie AI requests to verified user identity before reaching models. Federal zero trust distribution expands through Carahsoft partnership.

TechSignal.news AI5 min read

Identity-Enforced AI Gateway Closes Attribution Gap

Cloudflare launched Identity-Aware AI Gateway on August 5, 2026, requiring authenticated user identity on every AI request leaving enterprise networks. The service connects directly to Cloudflare Access, the company's zero trust network access product, and validates user and device posture before traffic reaches OpenAI, Anthropic, or other model providers. Each request is logged with verified identity, replacing shared API keys that obscure who generated what output.

The immediate buyer implication: enterprises can now enforce the same "never trust, always verify" controls on AI traffic that they apply to SaaS and internal apps. Most organizations treat AI model access as shared infrastructure — developers and analysts use the same API key, making forensic attribution after a data leak or policy violation nearly impossible. Identity-Aware AI Gateway writes the requesting user into the audit trail, turning AI endpoints into zero trust-protected resources rather than open pipes.

This matters because AI adoption is outpacing governance. Security teams cannot enforce acceptable use policies, data loss prevention rules, or compliance boundaries when they cannot identify who sent what prompt. Cloudflare's approach extends existing identity provider integrations and posture checks to a new attack surface without requiring a separate control plane. Organizations already running Cloudflare Access for web app or SSH access can add AI request enforcement through the same policy engine.

The architecture positions Cloudflare against Zscaler, Palo Alto Networks, and other SSE/SASE vendors adding AI traffic inspection. Most competitors focus on detecting sensitive data in prompts or responses — a necessary but insufficient control. Identity enforcement answers the "who" question before the "what" question, which is required for any meaningful incident response or policy refinement.

Zero Trust Execution Remains Immature Despite Strategic Consensus

HPE and Cybersecurity Insiders released a global Zero Trust report in late 2025 surveying 851 IT, networking, and cybersecurity professionals. Organizations rated their Zero Trust implementations an average of 6 out of 10 for maturity. The report identifies a 65-percentage-point gap between respondents who call Universal ZTNA essential and those who have fully deployed it.

The data validates what most enterprise security teams already know: Zero Trust remains a portfolio of partial deployments rather than an enforced architecture. The report recommends explicit "first" strategies — access-first, platform-first, identity-first, network-first, or cloud-first — acknowledging that most buyers cannot implement all pillars simultaneously. It also calls for retiring legacy VPN, converging SD-WAN and SSE into integrated SASE, and deploying Universal ZTNA across all users, devices, and resources.

For procurement teams, the survey provides quantitative justification to consolidate overlapping tools and retire incremental upgrades in favor of platform buys. The 65-point ZTNA gap supports business cases for replacing VPN with identity-aware access controls. The maturity score arms CISOs with board-ready evidence that partial Zero Trust adoption creates measurable risk, particularly as regulators and cyber insurance providers expect documented progress.

The report implicitly favors vendors that span users, devices, sites, and clouds under a unified decision plane. Point products that secure only one surface — remote users but not site-to-site traffic, for example — are on the wrong side of the recommended trajectory. Organizations still running legacy VPN alongside cloud SSE should treat the report as a mandate to pick a convergence path rather than operate both indefinitely.

Zscaler Expands Federal Distribution and Deepens Identity Integration

Zscaler expanded its partnership with Carahsoft on August 1, 2026, broadening distribution of Zero Trust Exchange to federal, state, and local government buyers. Separately, Zscaler invested in Saviynt and announced a strategic partnership integrating Saviynt's identity governance and privileged access management into Zero Trust Exchange. The Saviynt integration ties identity lifecycle, entitlement management, and least-privilege enforcement directly into Zscaler's access control plane.

The Carahsoft expansion matters because federal Zero Trust mandates — including CISA's operational technology guidance released in recent weeks — require agencies to demonstrate architecture progress by fiscal deadlines. Carahsoft holds contracts that simplify procurement for agencies operating under continuing resolutions or compressed buying cycles. Zscaler's Federal Risk and Authorization Management Program authorization combined with Carahsoft's contracting vehicles removes friction for agencies treating Zero Trust as a compliance checkbox rather than a multi-year transformation.

The Saviynt partnership addresses a persistent Zero Trust weakness: most ZTNA platforms enforce access policies but lack visibility into whether the requesting identity should have the entitlement in the first place. Identity governance platforms like Saviynt track who has access to what across SaaS, on-premises, and cloud infrastructure, but enforcement happens downstream in individual applications. Integrating the two means access decisions reflect current entitlement state rather than stale group memberships or orphaned accounts.

For enterprise buyers, the Saviynt integration makes Zscaler a stronger answer to "identity-first" Zero Trust strategies outlined in the HPE report. Organizations already running Saviynt for IGA can extend policy enforcement to network access without replacing their identity stack. Those evaluating competing platforms should ask whether identity governance integrations are bidirectional — meaning policy changes in the IGA platform automatically update access controls — or simply one-way log forwarding.

What to Watch

Identity-aware AI controls will become table stakes for SSE/SASE vendors within 12 months. Buyers should add "per-user AI request attribution" to RFPs for secure web gateway and ZTNA platforms. The HPE survey's maturity and deployment gaps will appear in audit findings and board risk reviews; security leaders should prepare roadmaps that close the Universal ZTNA gap with specific vendor selections and timelines. Federal buyers under Zero Trust mandates should confirm that shortlisted vendors hold both FedRAMP authorization and GSA Schedule or Carahsoft contract vehicles to avoid procurement delays.

zero-trustidentity-managementAI-securitySASEfederal-cybersecurity

Technology decisions, clearly explained.

Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.

More in Cybersecurity