Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
Cloudflare Workers AI is served from Cloudflare's US-incorporated global operator, running inference on its own GPU edge network at physical locations that are not publicly disclosed; EEA-only processing is available only through an opt-in Custom Regions configuration rather than as a default. The composite lands in elevated-risk territory primarily because of the two highest-weighted dimensions: legal exposure is low, since Cloudflare's US status subjects the serving path to FISA 702 and CLOUD Act process independent of EU data regionalization, and serving residency is weak absent a customer-configured regional commitment specific to Workers AI. This is offset by a genuinely strong security posture — six current, sourced certifications including ISO 27001/27018/27701, SOC 2 Type II, and BSI C5 — and a reasonably documented contractual posture via a published DPA and sub-processor list. Serving retention is middling: AI Gateway logs full prompt/response content by default but offers a configurable opt-out, and Cloudflare does not train on customer prompts. Given the unresolved US jurisdictional exposure and unverified EEA-only inference guarantee, Stav's operational verdict is routed-only, with sovereign EEA serving achievable only if the customer contractually confirms and enables Workers-AI-specific regional data localization.
Workers AI inference runs on Cloudflare's global GPU edge network whose physical locations are unpublished, and EEA-only processing is only available via an opt-in Custom Regions/Data Localization Suite configuration rather than a default guarantee.
Certifications & legal documents
Cloudflare is a US-incorporated entity subject to FISA Section 702 and CLOUD Act process, and this reach persists regardless of where EU inference traffic is regionalized, since most EU-state requests still route through US legal process absent a ratified executive agreement.
AI Gateway logs full prompt/response content by default, but customers can configurably suppress payload logging via a header, and Cloudflare states it does not train models on customer prompts.
The platform carries multiple current, sourced certifications (ISO 27001, 27018, 27701, SOC 2 Type II, PCI DSS, BSI C5) with no unresolved breach findings, though recent outage clusters are a resilience rather than security-control concern.
A standard Customer DPA and a published sub-processor disclosure page exist, but specific SCC coverage and audit-rights terms for Workers AI specifically were not independently verifiable in this research.
Risk assessment
Cloudflare is a US company subject to FISA Section 702, which allows the US government to compel disclosure of the content of non-US persons' communications via specific selectors, independent of where the underlying infrastructure sits. source ↗
LEGAL_EXPOSURECloudflare's network experienced a major global outage on November 18, 2025 (internal Bot Management configuration bug affecting a large share of Internet traffic), a further ~25-minute, 28%-of-traffic outage on December 5, 2025, and a cluster of 13 separate regional/service incidents (including Workers AI) between August 7–14, 2026, indicating recurring operational fragility on a platform many enterprises now depend on for a single vendor stack. source ↗
RESILIENCEWorkers AI inference runs on Cloudflare's own GPU clusters, but the specific physical/geographic locations of those clusters are not published; regulated customers are advised to verify residency guarantees directly with Cloudflare before relying on 'EU region' assumptions. source ↗
DATA_RESIDENCYCloudflare's transparency reporting confirms it receives and evaluates CLOUD Act-style cross-border government requests for user/customer data; the UK is the only jurisdiction with a ratified CLOUD Act executive agreement, meaning most EU member-state requests must still route through US MLAT/legal process. source ↗
LEGAL_EXPOSURECloudflare AI Gateway (commonly fronting Workers AI) logs the full user prompt and model response content by default; customers must explicitly send a header to suppress payload logging or disable logging entirely to avoid persistence of prompt/response content. source ↗
SERVING_RETENTIONThe operating entity is US-headquartered and incorporated; EU customers contract with and serve legal notice on a US legal entity, which is the underlying driver of the CLOUD Act/FISA exposure regardless of edge server location. source ↗
GOVERNANCESafeguards
Cloudflare states it does not train any LLMs itself and does not use customer content to train large language models offered via Workers AI; AI-assistant features (e.g., Cloudy) use customer prompts only as in-context input, not for training, and are not stored for that purpose. source ↗
Cloudflare offers a Data Localization Suite / Custom Regions capability that lets customers regionalize AI inference so LLM prompts and responses are kept within a defined set of countries for data-localization purposes. source ↗
Cloudflare publishes semi-annual Transparency Reports detailing categories of government/law-enforcement legal process received (subpoenas, FISA orders, CLOUD Act requests) and its policy of requiring valid legal process before disclosing customer data absent an emergency. source ↗
Cloudflare publishes a standard Customer DPA and a dedicated GDPR sub-processor disclosure page listing downstream vendors, giving customers a documented basis for third-country transfer and audit review. source ↗
Cloudflare's Workers AI platform inherits the broader Cloudflare platform's SOC 2 Type II and ISO 27001 certifications and GDPR-oriented compliance posture. source ↗
AI Gateway supports metadata-only logging (via a request header) that records usage/cost/performance metadata while explicitly skipping storage of prompt and completion payload content, giving customers a configurable low-retention option. source ↗
Privacy-policy issues
US CLOUD Act / FISA 702 reach over the operator source ↗
As a US company, Cloudflare (and by extension Workers AI serving infrastructure) can be compelled under FISA Section 702 to disclose the content of non-US persons' communications, a risk that persists even when inference is regionalized to EU metros.
Default prompt/response logging in AI Gateway source ↗
Without explicit customer configuration (headers or gateway settings), AI Gateway logs store the full user prompt and model response text, which is retained until a plan-based storage cap is hit or the customer deletes it, creating a serving-boundary data trail that regulated customers must actively manage.
Unpublished inference physical location for Workers AI source ↗
Cloudflare does not publish the specific geographic locations of the GPU clusters that perform Workers AI inference, so customers with strict data-residency mandates cannot independently verify EU-only processing without a direct commitment from Cloudflare.