HomeSecurityCloudflare OS: Open AI Workspace for Enterprises

Cloudflare OS: Open AI Workspace for Enterprises

Cloudflare announced Cloudflare OS on August 5 , 2026 , as part of Agents Week, an open-source platform that aims to become the secure workspace for AI agents and enterprise applications. Kenton Varda's announcement is not about a new operating system for computers, but a different approach to everyday work with AI.

The project is available under the Apache 2.0 and the source code is available in the official GitHub repository. Cloudflare presents it as a combination of an agent workspace, governance framework, and application platform, running on top of Workers, Durable Objects, and Dynamic Workers.

See also: Claude or Copilot in a Greek business: Why AWS Bedrock Frankfurt is changing the game

Cloudflare OS: What it is and what it isn't

The name OS is intentional, but it doesn’t describe a traditional operating system. It doesn’t replace Windows, Linux, or a mobile operating system. Instead, it acts as a layer on top of Cloudflare’s infrastructure, where humans set a goal and agents leverage corporate knowledge, tools, and data to make it happen.

Kenton Varda, creator of Cloudflare Workers and Sandstorm.io, explains that the OS has two meanings. On the one hand, it is an operating environment for an AI-powered enterprise productivity. On the other hand, it is an AI workload management system, similar to the role of a traditional operating system for applications.

The approach was first tested internally. According to the announcement, the use began in May 2026 and by August, thousands of employees were using the platform daily. Phoronix’s analysis notes that the project aims to simultaneously replace part of the productivity tools and orchestrate agents.

The three building blocks of Cloudflare OS

The first element is the agent workspace. It opens from the browser and requires no programming knowledge. Employees can request research, documents, or presentations based on live corporate data, while agents can write and run code in an isolated execution environment.

The company’s skills library plays a central role. Every employee can contribute processes, knowledge, and reusable templates, making a team’s expertise available across the organization. At the same time, automated workflows continue to operate in the background, without requiring ongoing intervention from the IT team.

The second element is Gatekeepers, or access controllers. These are workers per service that are interposed before any access to an internal system. The rule might allow an agent to read issues from a specific repository but not the source code, hide certain fields, or apply rate limits.

Human-in-the-loop approvals are asynchronous. So an agent doesn’t have to stop their entire work until a handler responds. The approval request proceeds in parallel, and the action is completed only when the relevant rules are satisfied. This granular policy reduces the need for general, excessive permissions.

Cloudflare OS Controlled Access

The third element is Gadgets, i.e. small, modifiable applications created within the same environment. Each application runs as an isolated instance, with a Dynamic Worker, Durable Object Facet and its own SQLite database. The logic is reminiscent of Sandstorm.io's Grains, but adapted to Cloudflare's infrastructure.

Client-server communication uses Cap'n Web for remote object calls. Outbound networking is disabled by default so that an application built for a specific purpose cannot arbitrarily gain access to the internet. This model separates data and limits the possibility of lateral movement.

See also: AISI incident: AI created fake GitHub identities to scam developers

Zero-trust security without permanent permissions

The most important architectural choice is zero permissions by default. Each agent starts with no access to resources and is granted only the specific permission required for a task. Access is granted on a per-resource basis, by explicit grant, rather than inherited from a general account or a large set of corporate credentials.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The model is based on Cloudflare Access, which authenticates every user and every request. Gatekeepers add the operational granularity: what data an agent can see, what changes they are allowed to make, and when human approval is required. For security managers, this means clearer control and better traceability.

Cloudflare OS does not impose a specific AI model. Through the Cloudflare AI Gateway, organizations can choose a provider on a per-job basis and avoid vendor lock-in. Consumption can be attributed per user, team, or workspace, with budgets and rate caps. Local models are also supported via Ollama.

Isolated Cloudflare OS applications

What it offers to businesses

Cloudflare is positioning Cloudflare OS at the enterprise market, with interest from financial services, retail, healthcare, and digital businesses. The main argument is that organizations retain ownership of what they build and run the platform within their own Cloudflare account, rather than transferring core business knowledge to an external software-as-a-service.

This differentiates the project from the closed versions of ChatGPT Enterprise, Microsoft Copilot, and Claude Enterprise. The open source license allows for internal control of the code, while the architecture maintains model independence. However, openness does not eliminate operational costs, customization needs, or dependency on the Workers infrastructure.

Cloudflare says that a managed deployment through the Dashboard will be available soon. For larger-scale implementations, it mentions partners like Presidio and Happy Cog. Enterprises can try out the platform via os.cloudflare.app, while the core project and a deployment template are already publicly available.

See also: Perplexity Finance: The free AI Bloomberg killer has arrived on Wall Street

Cloudflare OS AI Business Network

The Greek dimension: from PoPs to DORA

For Greek businesses, the focus is on network topology and compliance. Cloudflare has points of presence (PoPs) in Athens and Thessaloniki, while select European Union regions can support data residency requirements and the GDPR framework, depending on the service configuration and contractual commitments.

Banks, insurance companies and government agencies could consider the model for internal workflows, provided they first map out data categories, DORA requirements and retention rules. The technical value of zero trust alone is not enough; clear roles, action logging and testing are needed before production use.

How to start a team with Cloudflare OS

The first step is to review the code and development template on GitHub and confirm that the account has the Workers Paid plan. Then, a team can choose a limited internal purpose, such as searching for documentation or writing reports, and specify which resources are allowed to be visible.

Gatekeepers should then be designed on a per-service basis, with minimal permissions, rate limits, and human approval paths. The security team should review the behavior of the Gadgets, disable outbound networking, and perform cost-per-use. Only after these steps does it make sense to expand to sensitive systems.

Cloudflare OS FAQ

Is it a real operating system? Not in the traditional sense. It's a workspace, governance, and application platform for AI agents, running on Cloudflare infrastructure.

Should a company use a Cloudflare model? No. The Cloudflare AI Gateway allows for connectivity to different model providers, and local models are also supported via Ollama. The choice can be made on a per-task and cost basis.

What does zero permission by default mean? Agents have no initial access to corporate data or services. Each permission is explicitly granted, per resource and per purpose, through controlled Gatekeepers.

Is it production ready in Greece? The project is available as open source, but the managed version from Dashboard is awaited. Each Greek organization needs its own architecture, cost and compliance review before production deployment.

announcement via Business Wire shows that Cloudflare OS isn’t just trying to add another AI assistant. It’s trying to shift control of agents, data, and applications back to the organization. If the model proves to be as secure and flexible in practice as it promises, it could be a significant alternative for businesses that want AI without permanent reliance on a closed ecosystem.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS