Knowing who used AI is only the first step in enterprise AI governance
When an employee or AI agent suddenly consumes significantly more tokens, management will usually ask whether the increase reflects legitimate business demand, inefficient usage or personal work being performed with corporate resources.
The AI bill cannot answer that question on its own.
The same increase could come from a critical release, an agent caught in a repeated-call loop or a corporate account being used for a personal project. These situations may look similar in a cost report, but they represent very different risks.
Can token consumption alone identify personal AI use?
No. Token volume, usage time and behavioural anomalies are investigation signals. None of them can independently prove that an AI activity was corporate or personal.
The organisation must connect usage with the actual user, application, device, business project, workload, data and financial owner before it can make a credible assessment.
An identity-aware AI gateway can establish who used AI. Behavioral analytics can show whose activity changed. Business context is still required to determine whether that activity was authorised.
What does Cloudflare Identity-aware AI Gateway solve?
In its August 2026 article, “Catching rogue AI behavior with identity-aware analytics,” Cloudflare explains that enterprises need verified identity on AI requests and a behavioural baseline for each user or agent.
The integration between Cloudflare Access and AI Gateway can attach an authenticated user ID to request metadata, allowing administrators to analyse logs, analytics and spending by the person who made the request. Identity-aware AI Gateway with Cloudflare Access is currently in open beta, while User Insights is generally available to AI Gateway customers.
User Insights moves the investigation away from: Who spent the most?
towards: Whose AI usage suddenly stopped looking like their own?
This can provide an early indication of compromised credentials, an agent running out of control or an unexpectedly expensive workload.
Cloudflare explicitly states that User Insights does not determine intent and does not automatically block an account. It surfaces activity that has moved outside a normal baseline. Cloudflare is also developing prompt classification for workload categories such as coding and writing, but this remains a future capability.
From a governance perspective, this means anomaly detection can produce an investigation lead, but it cannot independently prove employee misuse or personal activity.
Why does anomalous usage not necessarily mean misuse?
A marketing employee consuming several million tokens on a Saturday evening may be performing personal work, or preparing multilingual materials for a Monday product launch.
Meanwhile, a developer whose usage remains stable during office hours may never trigger an anomaly, even while using corporate model access for a personal commercial product.
Tokens do not carry a business-use or personal-use label. High consumption does not necessarily indicate waste, and activity during working hours does not necessarily belong to the enterprise. Even when a prompt is relevant to an employee’s role, that does not prove that the work was authorised.
The organisation therefore needs to distinguish three layers:
Identity establishes who used AI. Behavioral analytics shows what changed. Business context helps establish whether the work genuinely belonged to the enterprise.
The Business Context Layer proposed by Master Concept
From Master Concept’s advisory perspective, enterprises can build a Business Context Layer around the AI gateway. The governance framework is to describe the identity, access, application, project, workload, data and financial signals required to assess AI usage purpose.
| Context | Core question | Governance value |
| Identity | Which employee, contractor or agent used AI? | Establish accountability |
| Access | Did the request come from a managed, compliant environment? | Assess access risk |
| Application | Was an approved enterprise application used? | Validate the usage channel |
| Project | Is the activity linked to a valid project or work order? | Validate business purpose |
| Workload | What type of task was AI performing? | Add purpose context |
| Data | Was the information approved for that model? | Assess data risk |
| Cost ownership | Which department or project owns the expense? | Establish financial accountability |
No single signal can determine intent reliably. Confidence comes from several signals supporting the same conclusion.
Establishing accountable identity and business ownership
Enterprises should reduce the use of shared API credentials that cannot be attributed to an individual or service. AI activity should be associated with an employee, contractor, service account or agent.
Cloudflare AI Gateway supports custom metadata for identifiers such as users, teams and applications. When a request reaches AI Gateway through a custom domain protected by Cloudflare Access, the authenticated Access user ID can be stored as cf.user_id.
Identity alone is not enough. The organisation must also know which application generated the request, which project it belongs to and which department or cost centre is accountable.
Cloudflare AI Gateway spend limits can be scoped by model, provider and custom metadata. Once a cumulative limit is reached, later requests can be blocked or handled through a lower-cost route.
Project attributes should not depend entirely on manual user entry. Otherwise, personal activity can simply be labelled as customer work. A stronger design inserts the Project ID automatically through an approved application and verifies project status, team membership and budget ownership through internal systems.
This turns into an ambiguous statement: An employee consumed one million tokens.
into a more meaningful record: An employee consumed one million tokens through an approved application for an active client project.
Cloudflare AI Gateway currently stores up to five custom metadata entries per request. An enterprise should therefore avoid encoding its entire governance model into every request. A more practical design sends a small set of identifiers—such as the user, application, project, environment and cost centre, then resolves business owners, data classifications and approved models through an internal registry.
Legitimate work can still create unacceptable data risk
A genuine business task can still violate enterprise policy. An employee may be supporting a real customer engagement while sending personal information, source code, credentials or contract content to an unsuitable model. In that situation, the issue is data governance and provider risk rather than personal use.
Cloudflare AI Gateway DLP can inspect prompts sent to models and responses returned by providers, then flag or block sensitive information according to policy.
Workload classification can also provide context—for example, software development, customer support, content production, research or data analysis—but classification should remain an investigation input rather than an automated misconduct verdict.
A coding request may support a personal project, while a writing request may be entirely legitimate corporate work.
Does the enterprise need to retain every prompt?
Not necessary.
Organisations should use a risk-based, minimum-necessary approach rather than retaining every prompt and response by default.
Cloudflare AI Gateway logs can contain prompts, model responses, token usage, cost, model and duration. Payload storage can also be disabled while metadata such as model, provider, token usage, status, cost and duration continues to be recorded.
For routine activity, identity, application, project, model, token usage, cost and risk outcome may be sufficient. Detailed payload logging and human review can be reserved for anomalies, DLP matches, unapproved applications, suspicious devices or missing business ownership.
The objective should be an explainable governance record, not an unlimited employee-surveillance system.
How should the enterprise respond after detecting an anomaly?
Not every anomaly should result in an immediate block.
Activity from an approved application, managed device and valid project may only require documentation and continued monitoring. When usage is unusual but the business purpose remains unclear, the organisation can request confirmation from the user or business owner.
Legitimate but inefficient usage may call for training, model guidance or spending controls. Stronger action, such as model restriction, credential isolation or blocking. It should be reserved for unknown identities, unapproved applications, sensitive data or credential risk.
Cloudflare also recommends beginning in monitoring mode so that the organisation can learn normal baselines before applying enforcement.
This reduces the risk of treating productive employees as threats while avoiding the opposite assumption that activity is safe simply because it remains within a historical pattern.
AI governance should begin with policy, not a token limit
A spending limit can control cost. It cannot define acceptable use.
The enterprise must first decide which people may use which models, through which applications, for which business purposes and with which categories of data.
The NIST AI Risk Management Framework is intended for voluntary use and organises AI risk management around Govern, Map, Measure and Manage. These functions support governance responsibility, contextual understanding, risk measurement and management action.
ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System. It treats AI governance as an organisational system of policies, objectives, processes, risk treatment and continuous improvement rather than as a single monitoring product.
Neither framework can determine whether an individual prompt is personal. Their relevance here is more fundamental: organisations must define accountability, acceptable use and risk tolerance before configuring gateways, identity controls, DLP, metadata and spending policies.
From Master Concept’s advisory perspective, the next step is to create a Business Context Layer connecting identity with applications, projects, devices, workloads, data and financial ownership. The real question for enterprises isn’t simply who consumed AI tokens. It’s whether those tokens were spent on work the organization has explicitly authorized, is willing to invest in, and is prepared to own the associated risks for. Please contact the advisory team at Master Concept for more information!
FAQ
Can Cloudflare User Insights automatically identify personal use?
No. It identifies users and agents that depart from their normal behavioural baselines, but it does not determine intent or automatically block an account.
Does high token consumption indicate misuse?
Not necessarily. Large code analysis, document processing and research workloads may legitimately require substantial token volumes. Usage must be evaluated against the approved project and workload.
Is the Business Context Layer a Cloudflare feature?
No. It is a governance framework proposed in this article by Master Concept to connect gateway data with enterprise applications, projects, data and financial ownership.






![[Free Webinar] Road to COP17: Unifying Enterprise Data with Planetary-Scale Geospatial AI](https://masterconcept.ai/wp-content/uploads/2026/09/Webinar-261007-Unifying-Enterprise-Data-with-Planetary-Scale-Geospatial-AI-_1280x720px-scaled.png)