$58 a month versus $200,000 a month — that stark gap is what Cloudflare’s chief security officer, Grant Bourzikas, gave reporters when describing how the company uses AI to triage incoming bug-bounty reports.
Bug-bounty automation with Anthropic’s Claude Sonnet
Bourzikas told The Register at a press lunch in Sydney that Cloudflare moved from manual processing of bug-bounty submissions to an AI-driven pipeline. The company uses Anthropic’s Claude Sonnet model at roughly $58 a month to sift incoming reports, deduplicate them, and assess whether each submission is likely to require human attention. Bourzikas said the alternative—using Anthropic’s security-specific Mythos model for the same task—would “burn through around $200,000 a month.” The result, he said, is a bug-bounty program that “requires less scutwork” and routes only the higher-probability issues to analysts.
Over 200 autonomous agents and the move away from third-party security tools
Cloudflare has, according to Bourzikas, built more than 200 autonomous agents to handle internal security needs. Those agents form the backbone of a broader shift: the company has “ditched almost all third-party security tools” and replaced them with home-grown applications, some developed with AI assistance. Bourzikas warned this is not a one-size-fits-all recommendation. “We are not believers in the SaaSpocalypse. We do not think every bank on the planet should start building all their own software systems,” he said, stressing that Cloudflare’s scale and security software expertise shape its buy-versus-build calculus.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Staffing changes, roles that ‘make no sense,’ and evolving skills
Cloudflare’s strategic embrace of automation dovetailed with a recent round of layoffs: Stephanie Cohen, the company’s chief strategy officer, tied some of the 1,100 job cuts to AI-driven change. She told reporters that some roles “make no sense” now that AI enables more automation and different patterns of customer engagement, and she expressed a “guess” that headcount would eventually return to pre-layoff levels.
Bourzikas framed a second workforce tension: the mix of domain knowledge and AI fluency the company needs. He said developers with five to ten years’ experience can sometimes be a poor fit because the translation between a product idea and code—now mediated by AI—can break down. By contrast, he said, a very recent college graduate with a year’s experience but excellent prompt-writing skills can be “more appropriate for some jobs.”
Stephanie Cohen’s pitch: Cloudflare as intermediary for AI access to publisher content
Cohen described a wider market hypothesis: she believes current AI offerings lack a sustainable business model tied to the content they consume. She argued that AI companies “do not pay to access most of the content scraped to feed their large language models and search services,” and suggested that services like “Google's AI-powered search” can deliver fewer clicks to publishers, harming their ability to monetize.
Cloudflare proposes to act as an intermediary using its position “between users and content providers.” Cohen said the company would offer AI firms a way to pay publishers for access to content, possibly using micropayments, and that “Cloudflare will of course charge for this service.” When asked why publishers should trust Cloudflare to occupy that gatekeeping role, Cohen pointed to an earlier company decision—adding SSL connections for all customers—as an “expensive choice” intended to demonstrate commitment to building a better internet. She also argued the vendor relationship itself will change, with vendors placing “forward-deployed engineers” at client sites and shifting away from packaged software sales.
What this means for technologists, publishers, and enterprise customers
- Technologists and security teams: Expect more automation in triage and internal tooling. Cloudflare’s example shows how model selection (Sonnet versus Mythos, in their case) can be driven by economics as much as capability, and that bespoke agents can replace third-party tooling where an organization has the resources to build and maintain them.
- Publishers and content creators: Cloudflare is actively pitching itself as a commercial intermediary that could enable AI companies to pay for content access, including through micropayments. Publishers will have to weigh whether trusting a network intermediary offers better terms than the status quo.
- Enterprise customers and procurement leaders: Cloudflare’s leaders explicitly caution that their approach is not broadly prescriptive. The company’s move away from SaaS security tools underscores a choice point for buyers—buy packaged offerings or invest in internal, AI-assisted engineering—and Cloudflare’s executives are arguing the vendor-customer relationship itself will evolve.
Cloudflare’s account compresses three linked bets: that lightweight models can economically automate high-volume security chores, that autonomous agents and in-house tools can replace third-party products at scale, and that a network provider can monetise and moderate access to publisher content. Bourzikas’ admonition—don’t try this at home—frames the experiment as one tailored to Cloudflare’s capabilities; Cohen’s plans for an intermediary role pose the sharper question for the market: will publishers accept a new gatekeeper offering paid access to the very content that feeds today’s AI systems?




