Cloudflare replaced its security vendors with 200 in-house AI agents, and says most firms shouldn’t

Cloudflare’s bug bounty triage costs $58 a month. Its chief security officer says the company runs the job on Anthropic’s Claude Sonnet model, and that switching to Anthropic’s security-specialized Mythos model for the same work would have run to roughly $200,000 a month. The figure, shared at a press briefing in Sydney, is Cloudflare’s proof point for a wider claim: the right AI model for a job is not always the most powerful one.

Grant Bourzikas, Cloudflare’s chief security officer, described the change at a press lunch during the company’s user conference in Australia. The bug bounty program previously relied on staff reading every incoming report. Sonnet now sifts submissions, checks whether each is a duplicate, and scores how likely a report is to deserve human attention. Bourzikas framed the result as a program that needs less routine work, and as evidence that teams must learn to match models to tasks rather than defaulting to the strongest available option.

The Mythos comparison traces to earlier this year. Under Project Glasswing, Anthropic’s closed initiative pairing defensive security teams with its frontier models, Cloudflare pointed the unreleased Mythos preview at its own production code and reported that the model linked minor flaws into functional exploits spanning more than 50 repositories, compiling and running proof-of-concept code on its own. That capability is overkill for triage, which is why Cloudflare chose a cheaper general model for the repetitive filtering work and reserved the frontier tool for the harder problem of finding new vulnerabilities.

The bug bounty automation is one piece of a larger in-house build. Bourzikas said Cloudflare operates over 200 production security agents handling vulnerability management, escalation, architecture analysis, and binary control, and that response times are down roughly 80 percent. One architecture agent alone contains 55 sub-agents that weigh a vulnerability together with the controls, privileges, and systems that surround it, including how they interact. The transition took about three years, and the security team turned out more work during January through June 2026 than it managed across the whole of 2025, all with a staff 25 percent smaller. Third-party security tools have been pulled from parts of Cloudflare’s edge-core network.

Our mission is simple: reliable news backed by careful research. Help us continue that mission.

Back evidence-based news

The company also designed the system to be model-agnostic, so agents can swap between models based on price, security requirements, data location, and the task at hand. Bourzikas described workflows where one model does the main work and a second checks or contradicts the result, with a Chinese open-weight model such as Kimi running as primary in some cases and Claude Opus as backup. Cohen said the harness lets Cloudflare control costs and keep its options open, moving between models without rebuilding the workflow around any one of them.

Bourzikas was explicit that most organizations should not follow Cloudflare’s example. He said the company’s business and its unusual set of infosec challenges make its buy-versus-build calculus different from everyone else’s, and that Cloudflare does not believe every organization should build its own software. Cohen echoed the caution, saying not every company should build what Cloudflare’s security team has built, and that most people at the company should leave agent and application development alone.

Cloudflare also sees AI reshaping the vendor-customer relationship. Cohen said the industry is moving away from packaged software toward forward-deployed engineers who continuously build tools for clients, and she tied the company’s recent round of about 1,100 job cuts to that shift, saying some eliminated roles no longer justified their cost once automation handles more of the work. She said she expected Cloudflare’s headcount to settle back at roughly its pre-layoff level.

Sources: Cloudflare has mostly ditched third party security tools, suggests not trying that at home (The Register, Aug 4, 2026); ‘Block, allow, optimise or charge’: Cloudflare says AI has broken the web’s commercial bargain (Mi3, Jul 29, 2026); Claude Mythos AI Built Working Exploits Across 50 Cloudflare Repos, Then Refused To Demo (AI Europe, May 19, 2026)

Scroll to Top