# Cloudflare says AI models found detection gaps in its WAF

- Published: 2026-09-29T13:00:00.000Z
- Updated: 2026-09-29T14:24:35.136Z
- Section: Models
- Topics: Security, Research, Agents
- Page: https://aidailyjournal.com/en/n/2026/09/29/cloudflare-says-ai-models-found-detection-gaps-in-its-waf/
- Sources: [Cloudflare](https://blog.cloudflare.com/adaptive-ai-waf-testing)

## Summary

Cloudflare built a tester that starts with known exploits and adapts each request based on what the WAF blocks or allows. The models could alter encodings, parts of the HTTP request and techniques, but had no access to source code or the WAF’s internal rules. The system ran in an authorized customer staging environment across six attack categories, with 1,107 attempts.

Cloudflare says the vast majority of attacks were blocked. After removing malformed, benign, duplicate and out-of-scope requests, the company reviewed those that were not blocked and used them to create new detections and strengthen the WAF. The company stresses that a request getting through the firewall is only a lead for human review, not a confirmed exploit, and that the application still needs to contain an exploitable vulnerability; keeping systems up to date remains one of the strongest defenses.

## Why it matters (editorial interpretation)

The case suggests that models can help test application defenses adaptively, but their results still require human validation and do not by themselves confirm vulnerabilities. For development teams, it reinforces the value of turning unblocked attempts into new rules without replacing system updates and fixes.

_Summary written by AI Daily Journal in its own words, based on the sources above. For details, read the original articles._
