Cloudflare Wants to Be Your Service Assurance Control Plane

Cloudflare Connectivity Cloud and the service assurance pitch

13
Cloudflare Connectivity Cloud, UC Today
Service Management & ConnectivityExplainer

Published: August 1, 2026

Rebekah Carter - Writer

Rebekah Carter

Cloudflare is betting that agent runtime, private access, policy, and rollout tooling belong in one control plane. Its own 2026 outage history shows the exact test buyers should run before believing that pitch.

Cloudflare had at least three global-scale reliability incidents between November 2025 and June 2026, in the same stretch it’s been asking enterprises to route more of their most sensitive traffic through that same control plane. But the interesting thing is, that’s not a reason to dismiss the pitch.

Actually, it could be the exact kind of test environment a service assurance buyer needs to run before buying into a new solution.

In April, Cloudflare expanded Agent Cloud with Dynamic Workers, Artifacts, Sandboxes GA, Think, and a wider model catalog.

A day later, Cloudflare Mesh arrived to give agents, developers, and private systems a safer way to talk without exposing internal infrastructure.

In June, Cloudflare added the Cloudflare One Stack and a Design Partner program, pushing secure AI and SASE rollout into partner-led deployment. Then came PACT, with Mozilla, Google, Microsoft, and Shopify involved in a privacy-first protocol for human and bot traffic.

This is no random product roadmap, it’s a thesis, one Cloudflare has actively been testing. Right now, Cloudflare is one of the core companies that hasn’t just recognized AI security and governance as problems, they’re actually taking ownership, with a suite of systems built to function as the control layer of agentic work.

TL;DR: Does Cloudflare’s Control Plane Hold Up?

TL;DR

  • The shipping record is there: Agent Cloud, Cloudflare Mesh, Cloudflare One Stack, and PACT all arrived between April and June 2026.
  • The reliability record needs scrutiny too: Cloudflare had a six-hour BGP-related outage in February 2026, then a June degradation during a wider mess that also hit Teams, Zoom, and X.
  • Agent identity is still the awkward gap: Cloudflare Mesh controls where agents go, but buyers need production proof showing who sponsored access and who shut it down.

What Do Cloudflare’s Own 2026 Outages Mean for Its Service Assurance Pitch?

Both 2025 and 2026 were rough years for Cloudflare on a reliability front, but that doesn’t mean it’s not worth taking its suggestion that enterprises should route more of their own sensitive traffic through the same system seriously.

On February 20, 2026, a configuration change to Cloudflare’s Bring Your Own IP pipeline unintentionally withdrew customer route advertisements via BGP, making affected services unreachable from the internet for six hours and seven minutes. That wasn’t a cyberattack, by the way, just an internal change with an impact nobody caught in time.

That followed two earlier global incidents in November and December 2025, serious enough that Cloudflare declared “Code Orange: Fail Small” an internal all-hands priority status the company says it had only invoked once before specifically to stop configuration changes from taking down its network at global scale again.

Then on June 22, 2026, a Cloudflare service degradation coincided with outage reports spiking simultaneously for Microsoft Teams, Zoom, X, Reddit, and Canva: a visible, real-time illustration of exactly the concentration risk buyers are testing.

None of this makes Cloudflare’s Connectivity Cloud pitch wrong. If anything, it makes the pitch’s core claim, that it’s worth consolidating onto a single, well-run control plane, more interesting.

What is Cloudflare Connectivity Cloud?

Cloudflare Connectivity Cloud is Cloudflare’s answer to an exhausting enterprise problem: too many users, apps, clouds, networks, vendors, policies, and now AI agents all pulling in different directions.

Cloudflare describes it as a single cloud platform for secure any-to-any connectivity across corporate networks, the public Internet, data centers, cloud apps, on-prem systems, users, and data. In other words, Cloudflare’s giving us the connective tissue between security, networking, application delivery, developer infrastructure, and AI access control.

That positioning made sense before agents arrived. Forrester research, cited in Cloudflare’s own Connectivity Cloud materials, found that 52% of IT and security teams had taken on hybrid-worker security in the previous five years, 46% had picked up public-cloud app responsibility, and 53% had absorbed more regulatory-compliance work. That’s a lot of extra surface area landing on teams already struggling.

Add AI agents, and you’ve got even more to handle, which is why Cloudflare is stretching its system to cover AI agent security, private access, Cloudflare One, Cloudflare Mesh, and Cloudflare SASE, too. Obviously, Cloudflare isn’t the only one moving in this direction, Cisco’s made some serious upgrades to its AI governance and control toolkit too. Cloudflare’s just focusing more on the wider network strategy, and edge-native security.

Key Takeaways

  • In five years, 52% of IT and security teams added hybrid-work security to the job. Another 53% took on more compliance work.
  • Connectivity Cloud now covers agent security, private access, One, Mesh, and SASE under one positioning.

What Do AI Agents Mean for SASE and Zero Trust?

AI agents mean SASE and Zero Trust now have to govern non-human identities that reach far more systems, far faster, than any hybrid worker did.

Hybrid work already made security complicated. Employees work from home, branches, airports, customer sites, and whatever coffee shop has a socket free. That pushed buyers toward ZTNA and Cloudflare SASE because broad VPN access started to look ridiculous. AI agents just added a new flavor to the problem buffet.

Machine agents aren’t just logging into your tools like a regular person, then sitting there, waiting to be called. They’re connecting with tools, querying databases, writing code, triggering workflows, opening tickets, and using APIs. If the access model isn’t solid, one useful agent can easily turn into a serious insider threat.

Companies are recognizing this at scale. Anthropic even acquired Stainless because it understood that agent standards are becoming a board-level issue. Industry research tracked by UC Today in 2026 shows enterprises already averaging 12 agents, with that number expected to rise 67% within two years, while 68% of IT leaders say they’re struggling to keep up with standards like MCP.

The tougher question isn’t whether the agent completes the task. It’s who approved the access, which system it reached, when that access expired, and whether anyone can prove what happened.

Key Takeaways

  • Enterprises run 12 AI agents on average, and that number could climb 67% within two years.
  • Meanwhile, 68% of IT leaders can’t keep pace with agent standards such as MCP.

Learn more about securing the enterprise in the age of AI agents here.

UC Awards 2026 Categories Announced

UC Today has announced all 25 categories for the UC Awards 2026, recognizing excellence across workplace technology, collaboration, CX, AI, and employee experience.

Explore the full UC Awards 2026 category list

What Did Cloudflare Launch For AI Agents In 2026?

Cloudflare’s April Agent Cloud update was substantial, though its real test is whether the identity gaps this piece keeps flagging get closed as fast as new features ship.

The headline feature was Dynamic Workers, isolated runtimes for AI-generated code that Cloudflare says can spin up in milliseconds, scale to millions of concurrent executions, and run up to 100x faster than containers, per Cloudflare’s April 2026 announcement; none of those figures have been independently benchmarked.

The rest of the launch filled in the missing machinery. Artifacts gives agents Git-compatible storage for code and data. Sandboxes GA gives them persistent Linux environments with a shell, filesystem, and background processes.

Think adds support for longer, multi-step agent work inside the Agents SDK. The expanded model catalog gives developers one place to reach proprietary and open-source models.

The whole system is bigger than ever, too. Workflows now supports 50,000 concurrency and 300 creation rate limits for durable background agents, per Cloudflare’s own capacity figures, which so far have no named enterprise deployment attached to them. That shows Cloudflare isn’t only chasing chatbot traffic.

It’s planning for lots of agents running at once, across real workflows, though Artifacts, Sandboxes GA, and Think are all new enough that none has a public production track record yet.

Key Takeaways

  • Dynamic Workers spin up in milliseconds, with Cloudflare claiming up to 100x container speed for AI-generated code.
  • Workflows now supports 50,000 concurrency, built for many agents running at once, not just chatbot traffic.

What Is Cloudflare Mesh, And Why Does It Matter?

Cloudflare Mesh is the piece that makes Agent Cloud truly exciting.

Without it, agents can run, but they’re stuck at the edge of the business, asking for access like a visitor. Mesh gives agents, developers, devices, servers, and private services a private network path through Cloudflare, with Cloudflare One policies sitting over the traffic.

AI agents need a lot of internal access, and it’s not always simple. They need staging environments, private APIs, databases, MCP servers, ticketing systems, logs, and sometimes code repositories. If the answer is “give the agent VPN access,” someone in security should probably start sweating.

Per Cloudflare’s April 2026 launch materials, Cloudflare Mesh routes private IP traffic through its global network, with Gateway policies, Access rules, DNS filtering, traffic inspection, DLP, and device posture checks applying to Mesh traffic. The more interesting detail is Workers VPC. Agents built on Workers can reach private databases, internal APIs, and MCP servers without those systems being exposed to the public Internet.

Mesh controls what the agent can reach. MCP controls what the agent can do once it gets there.

Cloudflare still has work to do on agent identity, especially sponsor ownership, task limits, and revocation. Even so, Cloudflare Mesh gives the Connectivity Cloud pitch more substance than most agent-infrastructure stories.

Key Takeaways

  • Workers VPC lets agents reach private databases and MCP servers without public internet exposure.
  • Mesh controls where an agent can go; MCP controls what it can do once there. Cloudflare still needs to prove identity maturity.

How does Cloudflare One connect SASE, security, AI adoption, and rollout?

The SASE pieces are all here, from ZTNA and CASB to DLP, browser isolation, email security, and experience monitoring. Cloudflare One connects them through a shared policy layer that also has to handle GenAI tools and agents. Buyers should press Cloudflare on the operational cost. Does one policy model reduce work, or does every new agent create another exception?

That’s particularly useful when shadow AI is already causing a real mess; Microsoft Research found 71% of staff members using agents without always waiting for them to be approved.

Cloudflare One can detect unsanctioned AI use, control access to tools like ChatGPT, Claude, and Gemini, and inspect prompts for PII. By Cloudflare’s own self-reported figures, it protects around 20% of the web, supports roughly 80% of the top 50 GenAI companies, and delivers SASE services from 300+ cities.

Case studies back this up: Indeed deprecated its VPN in about three months for 13,000+ employees and contractors. Delivery Hero replaced VPNs for 40,000 employees and cut bandwidth costs by 90%. Werner reported a 50% drop in malicious or suspicious emails, according to Cloudflare’s own published customer case studies.

The messy part is migration. Old VPN estates tend to contain forgotten groups, strange app mappings, and policies nobody wants to touch. Cloudflare One Stack can inventory those apps, convert Zscaler definitions, move groups and policies, and create new resources through the API.

The newest piece of that consolidation story landed July 20, 2026: Cloudflare Internal DNS went generally available, putting authoritative and recursive DNS for private networks on the same control plane as public DNS, Zero Trust, and networking.

The claim is easy to test. Split-horizon DNS often relies on separate systems that drift apart. Cloudflare answers with centrally managed DNS Views, where record changes can spread in seconds instead of waiting for TTL expiry.

Key Takeaways

  • Cloudflare One stands out most when buyers want SASE, AI governance, and migration handled through one rollout.
  • Cloudflare protects ~20% of the web and ~80% of the top 50 GenAI companies, from 300+ cities.
  • Indeed retired its VPN in 3 months for 13,000+ employees; Delivery Hero replaced VPNs for 40,000 employees, cutting bandwidth cost 90%.
  • Internal DNS’s July 2026 GA is a concrete, checkable test of the consolidation pitch: ask for the before-and-after on split-horizon drift, not just the announcement.

How Do VoidZero, Private Origins, And PACT Extend Cloudflare?

VoidZero gives Cloudflare a smoother path into the developer workflow. The June acquisition brought Vite, Vitest, Rolldown, and Oxc into Cloudflare’s orbit, per Cloudflare’s June 4, 2026, acquisition announcement, which put Vite at more than 130 million weekly downloads. Its own Vite plugin also achieved 13.9 million weekly downloads, more than 10% of Vite’s total volume.

That scale cuts both ways: folding four fast-moving open-source projects into one vendor roadmap is also a new supply-chain surface for buyers to track.

Going forward, AI coding agents are going to create a lot of rough, fast-moving software. Cloudflare wants that code moving from laptop to Workers to its global network with less friction.

Private origins pulls the same thread from the infrastructure side. Cloudflare’s closed beta, as of Cloudflare’s own 2026 description, lets customers route traffic to private origins without public Internet exposure, so WAF, bot management, rate limiting, caching, Workers, and other application services can sit in front of internal APIs, MCP servers, AI-agent backends, and operational tools.

PACT pushes the idea onto the open web. Cloudflare is working with Mozilla, Google, Microsoft, and Shopify on Private Access Control Tokens, designed to help humans and authorized bots prove traffic isn’t malicious without forcing CAPTCHAs, logins, or invasive tracking, though its real-world anti-bot efficacy is still unproven outside pilot partners.

So yes, Cloudflare One, Cloudflare Mesh, and Cloudflare SASE remain the buyer center. But these side moves show the same bet from three angles: agents will write code, reach private systems, and create web traffic. AI agent security has to follow all three.

What Evidence Should Cloudflare Still Prove To Enterprise Buyers?

Cloudflare’s 2026 story is getting harder to dismiss. Agent Cloud, Cloudflare Mesh, One Stack, SASE, and private access now fit together as a credible platform pitch. The missing piece is proof that all of it works under real enterprise pressure.

That Forrester result matters, but only within its lane. It validates Cloudflare’s platform strategy, AI development capabilities, and roadmap. It doesn’t prove the control plane will stay available. Four buyer tests matter most:

  • Agent identity: Who authorized the agent, what task gave it access, what did it reach, and who can revoke it?
  • Migration quality: “Hours, not months” needs app totals, policy counts, conversion failures, and references.
  • AI workload: Anthropic’s Mythos found thousands of serious bugs, but independent review still reported a 9.4% false-positive rate. Detection creates cleanup work.
  • Resilience: One control plane is convenient until every dependent service feels the same outage.

Teams should be asking directly: what’s the actual blast radius when Cloudflare’s control plane has a bad day, and what’s changed operationally, not just apologetically, since February’s six-hour outage.

Will Cloudflare’s Connectivity Cloud Control Plane Hold Up?

The verdict: The platform pitch is credible and the pieces genuinely connect, but Cloudflare has funded shipping speed faster than incident transparency, and buyers should read the roadmap accordingly.

Cloudflare’s best 2026 argument isn’t that it shipped more AI features than its competitors; it’s that the pieces connect in a way buyers can interrogate better.

Agent Cloud answers the runtime question. Cloudflare Mesh answers the private access question. Cloudflare One answers the policy question. Cloudflare One Stack answers the rollout question, at least in theory. Put together, Cloudflare Connectivity Cloud starts to look like a serious control layer for agentic work.

For CTOs, Cloudflare is making the case that evaluating a SASE platform now means asking how it handles agents, MCP servers, delegated access, prompt data, private APIs, and partner-led migration. For CISOs, AI agent security has to move from “interesting project” to access-governance discipline. For infrastructure leaders, Cloudflare SASE deserves attention because Cloudflare is trying to collapse several messy projects into one operating model.

That pattern, fast shipping paired with thin incident detail, points to a real priority order: Cloudflare has funded velocity faster than it has funded transparency, and buyers should read the roadmap accordingly. If it can show that, the awards case becomes much stronger: Cloudflare Connectivity Cloud won’t be interesting because it talks about AI agents. It’ll be interesting if the control plane really does hold up.

For a service assurance buyer specifically, add three more asks to that list: published incident post-mortems with real root-cause detail, a clear account of what changed after “Code Orange: Fail Small,” and a straight answer on how much of daily business traffic now depends on a single control plane having a good day.

Explore the Best Connectivity / Infrastructure Solution Award

The UC Awards 2026 will recognize the platforms proving they can hold up as a genuine, resilient control plane for enterprise connectivity, not just a well-marketed one.

Learn more about the Best Connectivity / Infrastructure Solution Award

Frequently Asked Questions

Is Cloudflare Connectivity Cloud replacing traditional network security tools?

That's the sales pressure behind the story, but buyers shouldn't treat it like a clean swap from one system to another, at least not yet. Cloudflare Connectivity Cloud can replace pieces of VPN, ZTNA, SWG, CASB, DLP, and app security stacks. The real question is which tools it can retire without creating fresh dependency risk.

Who should care most about Cloudflare's 2026 AI-agent push?

CTOs, CISOs, infrastructure leaders, and service owners should probably all have this on their radar. AI agent security gets even trickier than usual when agents start reaching into private apps, APIs, ticketing systems, logs, and code repositories. Product teams always see momentum. Security teams see everything that can go wrong.

Does Cloudflare Mesh make AI agents safe by itself?

Cloudflare Mesh doesn't make an agent safe by default, and Cloudflare doesn't claim that it does. It gives agents a cleaner route into private systems. Safety still depends on access limits, MCP policy, revocation, audit records, and human checks when the stakes rise.

How should buyers compare Cloudflare SASE with Zscaler, Netskope, or Cisco?

Ask which SASE platform can govern workers, agents, SaaS apps, private systems, prompt data, DLP, and migration without leaving the team to clean up the mess later. Cloudflare SASE has a good case when buyers care about reach, developer tooling, private access, and rollout speed. The competitors aren't dead weight, though. Each brings real advantages.

Does Cloudflare One Stack replace implementation partners?

Not really. Cloudflare One Stack can help AI agents read diagrams, map policies, translate vendor concepts, and generate deployment steps. It's still worth working with reputable partners for architecture decisions, politics, exception handling, testing, and migrating or changing the weird old systems nobody documented properly.

Connectivity
Featured

Share This Post