Guides / Cloudflare Gateway

Gateway AI detection, for teams that "already block AI"

Cloudflare Gateway makes blocking a category one click, which is why so many startups believe their AI problem is solved. Their own Gateway logs usually disagree. This guide shows how to make them talk.

Layer: DNS + HTTP (Zero Trust)
Identity: user email via WARP enrollment
Format: CSV log export
Per-user table: yes
Run a free audit on a Gateway export
The myth

"We block the AI category" vs what logs show

Category blocking is real protection against the obvious tools. It is also where the visibility usually stops.

The belief

  • "The AI category is blocked, so staff cannot use AI tools."
  • "Anything new gets categorized eventually, so we are covered going forward."
  • "If something slipped through, our people would mention it."

What audits find

  • Embedded AI riding inside sanctioned SaaS on its own subdomains, categorized as productivity, not AI.
  • Wrappers and niche tools that sit uncategorized for weeks while the category catches up.
  • Blocked-category attempts continuing daily, which is demand your policy frustrates but does not answer.

The audit matches raw hostnames against a register updated daily, with 3,900+ tools mapped to the model provider behind them. That is how a "productivity" subdomain gets identified as the AI feature it is.

Worked scenario

The startup that had it handled

An 80-person SaaS startup, full Zero Trust rollout, WARP on every laptop, AI category blocked for six months. Sample data; the sequence is the point.

The bet

The CTO bet a security engineer lunch that the audit would come back empty. They exported 30 days of Gateway DNS logs, 92,000 lines with user emails, and uploaded them.

The result

17 AI tools, all reached, none in the blocked category at the time of use. Twelve were AI features inside tools the company itself had sanctioned: the design suite, the CRM, two note-taking apps, the video platform.

The one that stung

A meeting-bot transcriber was attending calls on a founder's personal account, categorized as "conferencing", training terms unstated. The blocked category never had a say.

datetime,email,query,resolver_decision "2026-09-12T10:02:41Z","[email protected]","ai.exampledesign.com","allowed" "2026-09-12T10:03:15Z","[email protected]","app.exampledesign.com","allowed" "2026-09-12T10:07:22Z","[email protected]","meetscribe.example","allowed" "2026-09-12T10:09:03Z","[email protected]","chatgpt.com","blocked" "2026-09-12T10:11:38Z","[email protected]","api.meetscribe.example","allowed" "2026-09-12T10:14:56Z","[email protected]","notionai-style.example","allowed"

The shape of the finding: blocked consumer chatbot, allowed embedded-AI subdomains. Category policy caught line four and missed the rest.

The export

Getting Gateway logs out of Zero Trust

Gateway writes DNS queries and HTTP requests as separate log streams. Either works; DNS is broader, HTTP is deeper.

DNS logs: start here

  • Every resolution from enrolled devices, with the user's email attached.
  • Columns that matter: datetime, email, query, resolver decision.
  • Broadest coverage, smallest files, catches apps and browsers alike.

HTTP logs: when you have them

  • Proxied requests with hostnames and actions; paths are stripped by the parser anyway.
  • Better hit-count fidelity for heavily used tools.
  • Use whichever stream your plan retains longer.

Export mechanics

  • CSV download from the Zero Trust logs view over your window, or a slice from your Logpush destination.
  • Any header-row CSV parses automatically; no field mapping needed.
  • Caps: 5,000 lines / 2 MB free, 2,000,000 lines / 25 MB full.

Uploads are read once and discarded. Only hostnames, identities and timestamps feed the report; reports live 90 days and are deletable earlier.

The embedded-AI problem

Why sanctioned SaaS is the blind spot

The startup's twelve embedded findings were not exotic. They are what every modern SaaS stack now looks like.

Features ship on subdomains

Vendors bolt AI onto existing products via ai., copilot. or assistant. hostnames. The parent domain stays "productivity"; the feature's hostname is where the AI lives.

Procurement never saw them

The contract predates the feature. Nobody re-reviewed terms when the AI assistant appeared in the sidebar, and our analysis finds 85.5% of AI tools say nothing about training anyway.

The register tracks them separately

Depth-aware entries mean ai.vendor.com can carry its own verdict while vendor.com stays unflagged. The methodology page shows the walk-up logic.

Output

What the report returns for a Gateway export

Report sectionWith Gateway DNS or HTTP logs
Summary tilesFull totals across allowed and blocked traffic.
Tool tableEvery matched tool, including embedded-AI subdomains, with dated training verdicts.
Per-user tableUser emails from WARP enrollment: the cleanest identity column of any source in this series.
Blocked vs allowedResolver decisions preserved, so category-block effectiveness is measurable.
Sanctioned splitYour approved list vs observed, which is where embedded AI inside sanctioned SaaS becomes visible as its own line.
CSV + PDFFull-report tier, ready for the risk register and the board.
Gateway edges

Details that change your read

Coverage equals enrollment

  • Gateway sees devices running WARP or sitting behind enrolled locations. Unenrolled personal devices are outside the audit's frame.
  • State that scope in your findings; it keeps the report defensible.

Blocked rows are data, not noise

  • Keep blocked resolutions in the export. Attempt volume against blocked AI shows unmet demand, the strongest argument for sanctioning an alternative.

Office DNS vs device DNS

  • Location-based DNS logs attribute to the site; WARP device logs attribute to the person.
  • Mixed exports work, showing both shapes side by side as sources.

Startups change fast

  • Tool sprawl in a growing startup shifts monthly, so re-run monthly while headcount doubles.
  • The free tier can carry that cadence for small teams: 1 preview a day, 3 a month, detailed on the free audit page.

Flip through a real report before you upload anything

The sample evidence pack shows exactly how embedded-AI findings render: the tool table, the sanctioned split, the per-user emails. Sample data, no signup.

Open the sample PDF
The loop

Verdicts back into Gateway policy

1. Precision blocks

Block-verdict hostnames from the report CSV become custom Gateway rules. Blocking ai.vendor.com while keeping vendor.com is exactly the granularity category policy lacks.

2. Sanction the demand

High attempt counts against blocked chatbots mean staff need a sanctioned one. Enterprise tier, no-training terms, on the approved list before the next run.

3. Re-run and compare

Same window monthly. Embedded-AI count and sanctioned share are the two numbers startup boards actually track. Costs live on the pricing page.

Block-first cultures should still read detect before you block: the startup's real exposure was in tools no block rule had ever considered.

FAQ

Gateway export questions

DNS logs or HTTP logs: which should I export?

DNS for breadth, HTTP for hit fidelity. If unsure, DNS: it covers every enrolled device and app, and the files are smaller.

We already block the AI category. Is an audit redundant?

That is the exact case this guide's scenario covers. Category blocks miss embedded and uncategorized AI; the audit measures what actually got through.

Do user emails appear in the report?

Yes, as the per-user table's identities, in your account only. The uploaded file itself is discarded after the run.

Does a Logpush slice work instead of a console export?

Yes. Any CSV with a header row parses, whatever path it took out of Cloudflare.

What about devices not running WARP?

They are outside Gateway's view and the audit's frame. Note the enrollment scope in your findings, or audit the office network's DNS separately.

How often should a fast-growing team re-run?

Monthly while headcount and tooling churn. Small teams often fit the free tier's cadence; growing ones graduate to a plan allowance.

Measuring the block

Three numbers that grade your category policy

Because Gateway exports keep resolver decisions, the audit doubles as a scorecard for the blocking you already do.

Leak rate

Allowed AI tools divided by total AI tools observed. The startup's leak rate was 17 of 18: one blocked chatbot, seventeen allowed somethings. Most teams guess the inverse.

Attempt pressure

Blocked resolutions per week against AI domains. Rising pressure with no sanctioned alternative predicts workarounds: personal hotspots, home laptops, pasted screenshots.

Embedded share

Matched tools living on subdomains of sanctioned SaaS, as a share of all findings. This is the number that reframes the meeting from "block harder" to "review terms".

Zero Trust teams

Who runs this in a Cloudflare shop

Zero Trust deployments concentrate ownership, which makes this the fastest audit loop in the series.

The Zero Trust admin

Exports the log slice and later writes the precision rules. In many startups this is one person and one afternoon, end to end.

The founder or CTO

Reads the tiles and the embedded share, decides which vendors get a terms review. The annotated report tour is the fastest way to prep that read.

Whoever owns vendors

Takes the control-verdict list into renewal conversations: enterprise tier, no-training clause, SSO. The audit's dated verdicts are the negotiating leverage.

Total elapsed time for the startup in the scenario: 40 minutes of work, one lunch lost, twelve vendor terms reviews that were overdue anyway.

Win the lunch bet with your own logs

Export thirty days of Gateway DNS, upload, and see the free totals. If it comes back empty, you earned the bragging rights.

Run the free audit