What happened
On Sept 29, 2026, Cloudflare published an adaptive AI-era application security framework connecting risk discovery, agent governance, runtime protection, and AI-powered response — alongside new capabilities: LLM-conducted penetration testing of its WAF (frontier models iteratively mutating attack payloads across XSS/SQLi/CMDi/SSRF/LFI/Log4j), expaned threat intelligence for all customers, and automated positive-security deployment.
Why it matters
Cloudflare runs 20%+ of the web and its LLM-WAF-pentest capability becomes a self-service 'Adaptive Security' feature all customers can use — a first at platform scale. It directly addresses the new class of machine-speed, self-improving AI attackers and gives WAF hardening an AI-driven continuous-validation loop.
Applicability
Defenders running internet-facing apps behind a WAF should evaluate Cloudflare's adaptive security/LLM pentesting capability for continuous validation and new detection coverage; relevant to both AI-assisted and conventional apps.