Layer 4: Governance & security
The same platform secures what you built: the model path, the user path, the tool path.
In this layer: AI Gateway, AI Security for Apps + WAF, Secure MCP.
These are the shields you can explore in Step 6 (optional). Full walkthroughs: Shield 1: AI Gateway, Shield 2: AI Security for Apps + WAF, Shield 3: Secure MCP.
AI Gateway
What it is: Every model call through one control point: Guardrails, DLP, rate and spend limits, routing, logs.
Use it when: Shield 1: route your agent through agent-gateway and block injection and card numbers.
// wrangler.jsonc: "vars": { "AI_GATEWAY_ID": "agent-gateway" }
await env.AI.run(model, input, { gateway: { id: env.AI_GATEWAY_ID } });
// Guardrails block: error 2016 · DLP block: error 2029
Basics: AI Gateway · Guardrails · DLP
Advanced: Spend limits · Dynamic routing
AI Security for Apps + WAF
What it is: The WAF reads prompts on endpoints labelled cf-llm: injection score, PII, unsafe and custom topics.
Use it when: Shield 2: block a prompt-injection or a staff-discount fishing attempt before it reaches your Worker.
# WAF custom rule expression (Security > Security rules)
(http.host eq "<TEAM_HOSTNAME>"
and cf.llm.prompt.injection_score lt 20)
Basics: AI Security for Apps · Get started
Advanced: Unsafe and custom topics · WAF custom rules
Secure MCP
What it is: Access in front of your MCP server, an MCP server portal with only approved tools, Gateway and DLP on tool traffic.
Use it when: Shield 3 (bonus): the agent may call your tools, an unauthenticated caller may not.
Basics: MCP server portals · MCP governance
Advanced: Service tokens · Securing MCP servers