Summary
- Cloudflare reported second-quarter revenue of $696.1 million, 36% higher than a year earlier, and raised full-year revenue guidance.
- The company is tying part of its growth strategy to AI agents, answer engines, developer workloads, and rising machine-to-machine internet traffic.
- Its results suggest AI spending is spreading beyond model and chip providers into networking, security, and application infrastructure.
Cloudflare has raised its full-year revenue outlook after second-quarter sales climbed 36%, as AI-driven applications create new demand for the networking, security, and computing infrastructure sitting between users, software, and the wider internet.
The US infrastructure company reported revenue of $696.1 million for the quarter ended 30 June, compared with $512.3 million a year earlier. Current remaining performance obligations, a measure of contracted revenue expected to be recognised within the next 12 months, increased 35%, while Cloudflare reported record growth across paying customers, large customers, and developers using its platform.
Full-year revenue is now expected to reach between $2.864 billion and $2.870 billion, while the company forecast third-quarter revenue of $736 million to $737 million. Cloudflare remains loss-making on a GAAP basis, recording a $205.7 million operating loss during the quarter, although non-GAAP operating income reached $96.1 million.
AI has become central to the company’s explanation for where further growth could come from. Cloudflare argues that answer engines, autonomous agents, and software interacting directly with other software are altering traffic patterns on the web, creating demand not only for computing capacity but also for security, routing, access controls, developer infrastructure, and mechanisms capable of handling automated activity at high volume.
AI spending moves beyond compute
Much of the investment associated with generative AI has been concentrated on semiconductor supply, model training, and data centre construction, yet production systems require another layer of infrastructure once applications begin sending real traffic. Requests have to move between users, agents, APIs, models, databases, and business applications, while organisations still need to authenticate activity, block malicious requests, maintain performance, and understand what automated systems are doing.
Cloudflare already operates across several of those layers through content delivery, DNS, application security, zero trust networking, serverless computing, AI inference, and tools intended to control the way applications communicate with external models. That portfolio gives it several routes to benefit if AI changes the volume or nature of network activity, although the company does not separately disclose exactly how much current revenue is generated by AI-related workloads.
That distinction matters because almost every infrastructure company now has an AI growth narrative, while revenue can still be driven by conventional security, networking, web performance, and cloud modernisation projects. Cloudflare’s 36% growth demonstrates strong overall demand, but the contribution made specifically by agents and AI applications is less precise than the broad description of an AI-driven internet may imply.
The direction of traffic nevertheless creates practical questions that conventional web architectures were not designed to answer. A website serving a human visitor behaves differently from an API receiving thousands of automated requests from agents able to browse, transact, compare information, call external tools, or interact with other software without a person approving each step.
Machine traffic changes the security boundary
Greater automation increases the importance of deciding which non-human actors can access a service and what they are permitted to do once connected. Traditional bot management often concentrates on distinguishing legitimate visitors from scraping, fraud, credential attacks, or other automated abuse, whereas agentic applications create a larger grey area in which automated traffic may be authorised, commercially useful, and still capable of consuming substantial resources or behaving unexpectedly.
Companies therefore need identity and policy mechanisms that work for software agents as well as employees and customers. Rate limits, API permissions, authentication, logging, network segmentation, and application security controls become more important when an automated system can make decisions and generate traffic continuously rather than wait for a human to click through every interaction.
That transition creates an opening for network providers because much of the enforcement can happen before traffic reaches an organisation’s own application. Cloudflare already occupies that position for a large number of internet services, allowing it to sell security and policy controls alongside the network capacity carrying the requests.
The commercial attraction is that more automated traffic can increase both infrastructure use and the need to control it. Customers will still need to decide whether new AI-specific products solve problems that cannot be handled through existing API management, security, and observability tools, rather than paying an additional premium because established services have acquired an agent label.
Infrastructure concentration follows application growth
The same demand can deepen dependence on a relatively small group of companies positioned at important internet control points. Cloudflare combines network reach with security, compute, data, and developer services, while hyperscale cloud companies are pursuing similar opportunities through their own integrated platforms.
For European organisations, architecture choices therefore extend beyond individual product features because AI applications can add another dependency to existing relationships with global cloud and network providers. An application may use one company for models, another for cloud infrastructure, another for edge security, and several external APIs, leaving resilience dependent on how those services interact and how easily workloads can be moved when one component fails or changes commercial terms.
That does not necessarily argue against large infrastructure platforms because scale can provide security expertise, global network capacity, and operational resilience that individual organisations would struggle to reproduce. It does make concentration, portability, observability, and incident planning part of the cost of adopting more interconnected AI systems.
Cloudflare’s results show why infrastructure companies are competing aggressively for that position. The business already has rapidly growing revenue before agent traffic reaches anything close to its possible scale, while every additional AI application creates requests that have to be routed, authenticated, monitored, secured, and executed somewhere.
The next phase of AI investment will consequently be measured not only in processors and model subscriptions but in the less conspicuous infrastructure required to make automated software dependable on production networks. Cloudflare’s raised outlook does not establish that AI agents are already responsible for most of its growth, but it does show why companies controlling those network layers expect machine-generated traffic to become a significant commercial market.












