HIPAA Wasn’t Written for AI Agents. It Applies to Them Anyway

In short, healthcare is adopting AI agents faster than almost any other industry. More than 85% of Epic’s customers already use Epic AI, Epic’s Agent Factory will let every health system build agents of its own from 2027, and 43% of health systems were piloting agentic AI at the start of this year. Every one of those agents runs next to Protected Health Information (PHI), and PHI comes with rules that were not written for autonomous software but land on it anyway: minimum necessary access, audit controls, business associate agreements, a 60-day breach clock. This post maps those rules onto what agent infrastructure must provide (identity, per-request authorization, live inventory, an audit trail across every hop), then shows where Tigera Lynx fits and what it does not do. It is written for the platform and security leaders who will be asked to produce the record.

Healthcare was supposed to be the cautious one. Regulated to the bone, allergic to unvetted vendors, still running a fax machine somewhere in the basement. Instead, it is adopting AI agents faster than almost anyone.

At HIMSS in March 2026, Epic previewed Agent Factory, a visual builder for health systems to create, customize, and Continue reading

Worth Reading: Don’t Fight the Users’ Desire Paths

Chris Siebenmann publishes articles written from an interesting perspective: he’s a Unix herder at a university (based on my ancient, similar experience, that’s usually worse than herding cats).

In one of his recent articles, he applied the desire paths ideas to IT: don’t fight how people are doing things; either kindly nudge them in the right direction, or help them get stuff done the way they like to get it done, but in the least harmful way. I could definitely use some of his wisdom decades ago 🤷🏻‍♂️.

Kendaraan Modular Otomotif untuk Melintasi Sungai Lumpur Vulkanik

Di era teknologi otomotif yang semakin maju, kendaraan modular pengangkut robot penyusun jalur logistik menawarkan inovasi signifikan untuk mengatasi tantangan medan ekstrim seperti sungai lumpur vulkanik. Saat ini, kebutuhan akan sistem logistik yang mampu beroperasi di lingkungan alam yang sulit semakin mendesak, terutama di wilayah yang rawan aktivitas vulkanik dan kondisi medan berlumpur berat. Kendaraan modular ini menjadi jawaban tepat untuk memperkuat rantai pasok sekaligus meningkatkan efisiensi pengiriman barang dan peralatan di wilayah terpencil dengan medan yang sulit dilalui.

Pentingnya Peran Sungai Lumpur Vulkanik dalam Dinamika Logistik Otomotif

Sungai lumpur vulkanik merupakan fenomena alam yang melahirkan medan berlumpur dengan kandungan material vulkanis yang bersifat abrasif dan korosif. Keberadaan sungai lumpur ini seringkali menjadi hambatan utama bagi kendaraan konvensional yang digunakan dalam keperluan logistik, terutama di daerah-daerah bencana atau lokasi proyek besar yang memerlukan mobilisasi massal. Untuk itu, inovasi otomotif berbasis modular menjadi sebuah kebutuhan wajib dalam menghadirkan kendaraan yang tak hanya kuat dan tahan lama, tetapi juga versatile untuk beradaptasi dengan kondisi medan yang berubah-ubah.

Kendaraan Modular: Definisi dan Keunggulan dalam Otomotif Modern

Konsep kendaraan modular sendiri mengacu pada sistem desain kendaraan yang komponen dan fungsinya dapat disesuaikan atau diganti secara fleksibel sesuai kebutuhan misi lapangan. Dalam konteks pengangkutan robot Continue reading

Teknologi Gudang Anti Tikus Terbaru di Indonesia dengan Lorong Resonansi Akustik

Indonesia semakin menunjukkan kemajuan signifikan dalam bidang teknologi penyimpanan hasil pertanian, terutama melalui inovasi gudang anti tikus yang dikembangkan dengan teknologi lorong resonansi akustik. Temuan terbaru ini memberikan solusi berbasis ilmu pengetahuan untuk permasalahan klasik yang selama ini menghambat sektor agrikultur, yaitu kerusakan hasil panen akibat serangan tikus. Dalam artikel ini, kita akan membahas secara lengkap perkembangan teknologi ini, manfaat yang bisa diperoleh, serta dampaknya bagi petani dan distribusi pangan di Indonesia.

Pengenalan Teknologi Gudang Anti Tikus dengan Lorong Resonansi Akustik

Teknologi gudang anti tikus merupakan inovasi penyimpanan hasil panen yang dirancang khusus untuk mengurangi atau bahkan menghilangkan gangguan tikus secara efektif. Bahasan utama teknologi ini adalah penggunaan lorong resonansi akustik, yaitu prinsip fisika gelombang suara yang dapat mengusir tikus tanpa menggunakan bahan kimia berbahaya.

Teknologi ini dikembangkan oleh sejumlah peneliti Indonesia yang tengah fokus pada peningkatan efektivitas gudang batu sebagai media penyimpanan. Gudang batu sendiri telah lama dipakai oleh petani tradisional karena daya tahan dan kemampuannya menjaga kelembapan hasil panen. Namun, kelemahan utama adalah mudahnya tikus masuk dan merusak hasil panen. Dengan tambahan lorong resonansi akustik, gudang ini menjadi inovasi yang sangat relevan saat ini, di mana kebutuhan akan teknologi ramah lingkungan dan hemat biaya semakin tinggi.

Prinsip Kerja Continue reading

Introducing Clef: our open-source decision models, and new RL fine-tuning platform

Over the last few weeks, there has been lots of buzz around decision models such as Typesafe AI’s Jev System One model. While classifier models have been around for some time, Jev introduces a new decision model concept into the world of AI — a model that produces bounded structured outputs cheaply, quickly and consistently that can be added into a workflow when a decision is required. These models are capable enough to work over any set of inputs without constantly retraining the model to incorporate new classification categories. This contrasts with the world of Large Language Models (LLMs), which are largely non-deterministic, but are open-ended enough to reason and generate text and tool calls for agentic workloads. 

Today, we’re releasing two Cloudflare-trained decision models, Clef and Clef-flash, hosted on Workers AI. Clef is currently the leader when evaluated against the Jev Decision Index, you can view full results on the live benchmark demo site. These models are smarter, faster, and fully Jev-API compatible, so you can experiment with these hosted models easily. We’re fully open-sourcing these models on Hugging Face under an Apache 2.0 license for you to run locally and experiment with yourselves. 

Lastly, Continue reading

Collective Communications: The Operations Behind Every AI Network Flow

This post, part of a series on AI data center networking, clarifies the traffic patterns arising from collective communications during GPU operations. It highlights key operations like broadcast, scatter, gather, and reduce, explaining their significance for both training and inference, especially in Mixture-of-Experts models. Understanding these patterns aids in optimizing network performance.

The post Collective Communications: The Operations Behind Every AI Network Flow appeared first on /overlaid.

One year later: Sovereign AI and the fight for choice

It's Birthday Week, when we traditionally ship presents to the Internet. This year, two of them come from Europe: EuroLLM, which covers all 24 official EU languages, and Apertus, Switzerland's fully open model, trained on more than 1,500 languages. Both were built by public universities and research institutions. Both are coming to Workers AI, and you can request access today.

We're also launching hands-on workshops that help government cyber agencies and critical infrastructure operators build AI defenses that work with any model. The first runs in Singapore in October.

Today's announcements follow from an argument we made a year ago, when questions about AI access and sovereignty were swirling in national capitals. Our answer was choice: the freedom to pick the right tools for the job, and to switch when you need to.

Since then, those conversations have hardened. Attackers have used frontier models to run cyber attacks. Access to some frontier models now depends on where you are. Calls to restrict open models are getting louder. Put it all together and it's easy to conclude that AI sovereignty is zero-sum: every model another country controls is one you can't count on, so the safe move is to build walls.

Continue reading

Introducing Workers KV Instant — powered by Quicksilver

Today, we’re introducing Workers KV Instant, a new mode for Workers KV that pushes your changes globally for instant availability without cold read penalties.

Workers KV has been one of our most popular services on the Developer Platform since launching during Birthday Week in 2018. It’s great for quickly accessing data like static assets and user configuration that is written occasionally but read frequently. We use it ourselves across many Cloudflare products.

We also have another key-value store, Quicksilver, which we’ve blogged about many times since introducing it in 2020. We designed Quicksilver for incredibly fast global replication and low-latency access, and nearly every request to Cloudflare looks up at least one key in Quicksilver. People have asked us for years, but we’ve never made Quicksilver available to our customers.

We’re changing that today with Workers KV Instant. KV Instant mode provides the same API as Workers KV, but powers it using Quicksilver. KV Instant offers 100 times faster p99 reads and immediate updates, with no need to wait for a TTL to expire. It’s not for every type of data, but, for infrequently updated application configuration data — the same thing we use Quicksilver for ourselves — KV Instant shines. Continue reading

Cloudflare OS: your company’s agent workspace, managed for you

Cloudflare OS gives everyone in your organization an agent workspace that knows how your company works and connects to its data and systems. Today, we're opening the waitlist for fully managed Cloudflare OS deployments.

If I asked you to prepare for an important customer meeting later today, what would you do? You might learn how your company typically runs customer meetings, review the account in your CRM, check recent support tickets and product usage, then turn it into a short presentation to review with the group. Now imagine doing that another 100 times this month.

Every team has work like this. With Cloudflare OS, you can ask your agent to handle the work for you, build a tool for your team, or move between the two as the work evolves.

Last month, we announced Cloudflare OS and shared the open source repository. Since then, thousands of organizations have started using it to work with company data, produce docs and slides, build tools for their teams, and automate work with agents.

With a few clicks in the Cloudflare dashboard, you’ll be able to launch your organization’s own agent workspace. Just tell us what custom domain you want to use, what Cloudflare Continue reading

Announcing Cloudflare K2: serverless event streams

With traditional Remote Procedure Call (RPC) architectures, there exists a core challenge: producers and consumers must align in scale and in time. If your producers send too much data for your consumers to handle or if your consumers or downstream services become unavailable, events are dropped. This problem is compounded with multiple consumers that need to independently process the data. For example, an ecommerce backend may emit events when transactions are completed, which need to be read by an analytics system and a fraud detection service.

We can solve this by decoupling our producers and consumers — inserting a service in the middle that absorbs writes while allowing independent readers to consume at their own pace.

Today we are launching Cloudflare K2 in public beta to solve this problem. K2 is a durable event streaming primitive on the Developer Platform. You send events to a K2 stream, which stores them as an ordered log. Consumers can read them in a variety of ways, for example by splitting up reads across a set of consumers, or delivering all messages to all consumers. It's fully serverless, scales to vast quantities of data, and supports long-term retention, so even long periods of consumer downtime do Continue reading

We want you to build the next Git platform on Cloudflare

GitHub was built for a world where humans write code, organize it into repositories, and collaborate through branches, commits, issues, and pull requests.

But the next generation of software is going to be built differently because it is going to be built by a different kind of developer: agents.

Agents are already writing more code than ever before — they’re fixing bugs, building features, writing tests, reviewing changes, updating dependencies, and doing the routine maintenance required to keep an application running.

So in this new world where you have hundreds, or even thousands, of agents working on the same codebase at the same time, what does the foundation look like?

How do agents know what other agents are working on? What happens when they make conflicting changes? How do you review everything they produce? How do you keep track of not just what changed, but why a change was made?

And so the burning question is: What does the next GitHub look like?

We want you to help us answer it, by building it out.

Earlier this year, we launched Artifacts, a versioned filesystem that speaks Git and can scale to millions of repositories. From the start, we designed Continue reading

AI Search is now generally available

Cloudflare’s AI Search combines Workers AI, Vectorize, R2, and Browser Run into a fully managed index and retrieval pipeline. Since we launched AI Search over a year ago, we’ve seen developers use it to power a wide range of search use cases, from searching internal documentation to powering search for their websites. We use AI Search ourselves to power search on our own blog and developer docs.

Starting today, AI Search is generally available. And as part of it, we've expanded and improved our support for multimodal formats beyond text, adding native image embeddings, optical character recognition (OCR) for PDFs, and support for larger files.

As part of general availability, we’ll start billing for AI Search on November 1, 2026, and continue to offer a generous free tier on all Workers plans.

New: multimodal embedding and retrieval

An image is more than the sentence used to describe it. Product texture, screenshot state, chart relationships, document layout, and fine visual detail can all disappear when pixels are compressed into a caption.

AI Search now preserves both signals: it embeds image pixels directly for visual retrieval while retaining captions for textual understanding. To keep these richer representations efficient, AI Search Continue reading

Support for modern cryptographic algorithms in Workers

Today, Cloudflare Workers is adding support for post-quantum-resistant algorithms within Web Crypto. These are defined in Modern Algorithms in the Web Cryptography API draft community group report, and include:

  • ML-KEM-768 and ML-KEM-1024 for key encapsulation
  • ML-DSA-44, ML-DSA-65, and ML-DSA-87 for signatures
  • encapsulateBits(), decapsulateBits(), encapsulateKey(), and decapsulateKey()
  • getPublicKey()
  • SubtleCrypto.supports()
  • JWK import and export for these algorithms

For developers preparing for the post-quantum transition, these opt-in Web Crypto APIs make it easier to experiment with ML-KEM and ML-DSA without bundling a separate cryptographic implementation. They do not provide a full migration path, but rather building blocks that can be used to validate your integration.

This support is available behind the webcrypto_modern_algorithms compatibility flag while the specification is still moving.

Background

Web Crypto is one of those APIs you only notice when it lacks the primitive you need. If you want to experiment with newer post-quantum algorithms in a JavaScript environment, it’s hard. You either cannot build the protocol directly on top of Web Crypto, or you bring your own cryptography implementation in JavaScript or WebAssembly.

Neither option is ideal. They put the burden of selecting and maintaining cryptographic implementations on implementers, who see their applications get larger Continue reading

Introducing Cloudflare Basin: an open, serverless data platform, now generally available

During Birthday Week 2025, we announced the Cloudflare Data Platform, a suite of products that ingest, store, and query your analytical data. Today, we’re announcing that the platform is generally available, and we’re giving it a new name: Cloudflare Basin.

Basin is a serverless data analytics platform built on Apache Iceberg, the open standard for data lakes, and R2 Object Storage. The Basin family includes:

  • Basin Pipelines, formerly Cloudflare Pipelines, receives events from Workers, HTTP, or Cloudflare Logpush, transforms them with SQL, and writes them as Apache Iceberg tables or files in R2.
  • Basin Catalog, formerly R2 Data Catalog, manages Iceberg metadata and automatically maintains tables to keep them fast and cost-efficient.
  • Basin SQL, formerly R2 SQL, is our serverless, distributed SQL engine for querying Apache Iceberg tables directly on Cloudflare.

Basin brings an end-to-end analytics platform to the Developer Platform, enabling you to collect data from a variety of sources, such as apps, infrastructure, devices, and other Cloudflare services, then query it to answer analytical questions.

We set out to build a data platform last year when we saw two fundamental developments that changed how modern data applications were being built. First, Apache Iceberg Continue reading

NAN132: The AI-Augmented Engineer

Garrett Masters talks with Eric Chou about the concept of the AI-Augmented Engineer. Together they discuss how IT professionals can use Python and NetMiko to automate tasks and even connect AI directly to lab environments. Garrett also shares practical advice on prompt engineering, the importance of context management, and how engineers can safely adopt AI... Read more »

TCG085: Enterprise Salescraft with Drew Meli

William Collins and guest Drew Meli explore the realities of buying enterprise SaaS and infrastructure. They cover the common engineering misconceptions about enterprise sales, navigating rigorous security reviews, establishing clear proof of value criteria, and how AI is reshaping buying behaviors. AdSpot Sponsor: Gartner AI is rewriting your cloud architecture, your operating model, and your... Read more »

Managing Claude Code Sessions Through Lynx

At Tigera, we spend a lot of time thinking about agent security: identity, policy, runtime controls, and the record left behind after an agent acts.

Coding agents create an interesting problem because, in most organizations, they didn’t arrive through the front door.

Few companies ran a platform evaluation and rolled Claude Code out to 500 developers. Developers installed it themselves. By the time security and platform teams started asking how coding agents should be governed, they were already running on laptops with access to source code, credentials, SSH keys, kubeconfigs, internal services, and whatever else the developer could reach.

The long-term answer is increasingly clear I think: move coding agents into isolated environments you control.

Anthropic’s sandboxing work draws filesystem and network boundaries using OS primitives such as bubblewrap and seatbelt. Its reference devcontainer includes an egress firewall. Docker has introduced sandboxes for running coding agents, and Kubernetes-based approaches can add stronger workload isolation, network policy, and disposable development environments.

That direction makes sense.

Isolation governs what an agent can do. A gateway governs what it can send.

And unlike a complete move to remote development environments, the second boundary is something you can introduce today.

Start with one environment Continue reading

1 2 3 … 3,908