Lifestyle
Cloudflare Launches Application Profiles: Countering AI-Driven Attacks by "Allowing Only Normal Requests"
On September 29, 2026, Cloudflare announced Application Profiles, a feature that learns what normal traffic to a website looks like and flags requests that don't fit. It affects businesses that protect their sites with Cloudflare, not ordinary visitors. Here is how it works, its limits and why Cloudflare says it matters as AI makes attacks easier.
About 5 min read

What happened
On September 29, 2026, Cloudflare announced Application Profiles on its official blog, in a post written by Daniele Molteni and Zhiyuan Zheng. Cloudflare says the feature analyzes the structure and format of HTTP requests (the messages a browser or app sends to a website) and detects deviations, helping customers significantly reduce their attack surface, meaning the range of ways an attacker can try to get in.
Cloudflare ties the launch to AI: the company says customers commonly ask how to defend against attacks that use frontier AI models, the most advanced AI systems, because large language models (LLMs) let non-technical people launch attacks with a single prompt and automatically adapt their tactics based on how an application or firewall responds. Cloudflare also says traditional managed rules, which look for patterns of known attacks, remain important, but relying solely on "patching faster" is not sustainable.
Read the full description
Sources are collected, independently checked, then reviewed by Jev.
How it works: from "blocking the bad" to "allowing only the good"
According to Cloudflare, it already provides positive security for APIs (the interfaces that programs use to exchange data) through Schema Learning and Schema Validation, and now extends this to web applications with Application Schema Profiles. Profiles can cover the parts of a request such as path variables and query parameters in the web address, headers and cookies, as well as JSON or form-encoded request bodies, and learn data types along with constraints such as value ranges and string lengths. For example, if a search field never contains special characters, only letters and numbers would be expected there.
Cloudflare says learning runs automatically once a week for each zone. An operation, which Cloudflare defines as a type of request identified by its HTTP method, hostname pattern and path pattern, needs at least 1,000 successful (2xx, meaning the site answered normally) requests in the previous seven days to learn its fields, and at least 10,000 to learn data boundaries. Validation results are only attached to requests as metadata, a label recording whether the request fit the profile, and take no action on their own; customers must separately create Security Rules to block requests.
| Aspect | Traditional managed rules (negative security) | Application Profiles (positive security) |
|---|---|---|
| Basis for judgment | Whether a request resembles a known attack | Whether a request matches the learned normal structure |
| Requires known attack signatures | Yes | Cloudflare says no |
| Default behavior | Handled according to rules | Flags only; blocking requires customer-created rules |
| Cloudflare's positioning | Still important | A complement that reduces the attack surface |
Limitations and caveats
- Cloudflare says successful requests may also come from bots and scanners, so learned profiles should be reviewed before enforcing blocks.
- Cloudflare says a request not matching the profile is not necessarily malicious, and recommends starting in observation mode, where mismatches are recorded but nothing is blocked.
- Cloudflare says multipart forms, GraphQL and XML (other formats for sending data to a site) are not currently supported, and enumerations, fields limited to a fixed list of values, can contain at most three values.
- Cloudflare says the feature does not enforce required parameters or parameter uniqueness, and will not block requests merely because a new parameter appears.
What it means for general readers
Ordinary website users do not need to do anything. The feature mainly affects administrators of enterprise websites that use Cloudflare. Cloudflare presents AI-automated attacks as the reason for the launch and describes the approach as moving beyond looking only for requests that resemble known attacks toward allowing only requests that match what is expected. Cloudflare also says it has trialed a model hosted on its Workers AI platform on the profiles of four applications and plans to bring LLM insights into the dashboard; its roadmap also includes on-demand learning and excluding automated traffic, all of which remain future plans.
Frequently asked questions
What are Application Profiles?
According to Cloudflare, they learn the normal structure and format of requests from a website's real traffic and flag requests that deviate from it, a positive security approach.
Does it block requests automatically?
No. Cloudflare says validation results are only attached to requests as metadata; customers must create their own Security Rules to block non-matching requests.
Who can use it?
Cloudflare says customers who already have API Security can use it now; enterprise customers without API Security can join a closed beta by invitation.
What does this have to do with AI?
Cloudflare says large language models make attacks easier to launch and able to adapt automatically, so it launched protection that does not rely on known attack signatures; it also plans to use LLMs to help determine which fields matter most.
Do ordinary internet users need to take action?
No. This is a server-side protection setting for website operators; ordinary users need to do nothing when browsing websites.
Browse the latest news in this topic
Lifestyle
Cloudflare open-sources Streamline: a demo of using its cloud services to add graphics to live streams and burn subtitles into videos
On October 2, 2026, Cloudflare launched and open-sourced Streamline, a developer playground showing how developers can combine Stream, Workers, Containers and Durable Objects to build their own video processing pipelines, such as adding graphics to live streams in real time or adding subtitles to videos. This article explains what it is, how it works, its limitations, and what it means for viewers and developers.
Lifestyle
Google unveils Gemini 4 Argon: cyber defenders get it first, everyone else still has to wait
On September 30, 2026, Google announced Gemini 4 Argon, which it calls its new frontier (most advanced) AI model. For now it is available only to trusted cyber defenders through the Fairwind Program. Here is what Google says the model can do, what it will cost developers, how Google says it is managing the risks, and what it means for everyday users. All figures come from Google itself.
Lifestyle
NVIDIA: CoreWeave Begins Offering Vera Rubin NVL72, With Cognition as First Production Customer
According to the NVIDIA blog, AI cloud provider CoreWeave now offers NVIDIA's next-generation Vera Rubin NVL72 systems, plans to offer the Vera CPU and launched CoreWeave Forge. This matters mainly to companies building AI agents, and could eventually mean faster AI tools for everyday users.
Lifestyle
Google Cloud makes Spanner Omni generally available: its Spanner database can now run in companies' own data centers and on other clouds
Google Cloud says Spanner Omni, a version of its Spanner database that businesses run themselves, is now ready for real-world use in their own data centers, on other clouds or on a laptop. This matters to organizations that want Spanner outside Google Cloud, but they take on the running of it. Here are the features, licences and trade-offs Google Cloud describes.
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family