AI Model Policy Enforcement
Cloudflare Zero Trust Gateway · rknewtonlab.com
Policies Active
How enforcement works
๐Ÿ’ป
Employee
Device
→
๐Ÿ”’
Cloudflare
WARP
→
โšก Gateway Policy Engine
โœ… Allow ยท Prec 3500 ยท Google Gemini
๐Ÿšซ Block ยท Prec 4500 ยท DeepSeek
→
โœ…
Approved
Provider
Test prompt
๐Ÿ”ต
Google Gemini
generativelanguage.googleapis.com
โœ… APPROVED
Policy: AI-Demo: Allow Google Gemini
Precedence: 3500  ·  Action: Allow
Domains: gemini.google.com, aistudio.google.com, generativelanguage.googleapis.com
Result will appear here
๐Ÿ”ด
DeepSeek
api.deepseek.com
๐Ÿšซ BLOCKED
Policy: AI-Demo: Block DeepSeek
Precedence: 4500  ·  Action: Block
Domains: deepseek.com, api.deepseek.com, chat.deepseek.com
Result will appear here
Active Gateway HTTP Policies · AI Model Control View in Dashboard →
Prec.Policy NameTraffic ExpressionActionStatus
1000AI-Demo: Allow Sanctioned AI Gatewayhttp.request.host == "gateway.ai.cloudflare.com"ALLOW● ACTIVE
3000AI-Demo: Allow Workers AI Playgroundhttp.request.host in {...}ALLOW● ACTIVE
3500 ★AI-Demo: Allow Google Geminiany(http.request.domains[*] in {"gemini.google.com" "aistudio.google.com" "generativelanguage.googleapis.com"})ALLOW● ACTIVE
4000AI-Demo: DLP Block PII in AI Promptsany DLP profile match on AI providersBLOCK● ACTIVE
4500 ★AI-Demo: Block DeepSeekany(http.request.domains[*] in {"deepseek.com" "api.deepseek.com" "chat.deepseek.com"})BLOCK● ACTIVE
5000AI-Demo: Block Unsanctioned AI Applicationsapp in {ChatGPT, Claude, Perplexity, Mistral...}BLOCK● ACTIVE
6000AI-Demo: Block ALL AI (Content Category)any(http.request.domains[*] in {AI category})BLOCK● ACTIVE
★ Newly created policies. Rules evaluated in precedence order โ€” lower number wins first.