Cloudflare’s AI Security for Apps has revised the enumeration exposed by the cf.llm.prompt.unsafe_topic_categories field. Any WAF custom rule that references a category that was removed or renamed will stop matching that category, even though the rule syntax remains valid.
Changed Category List
The service now publishes a new set of category identifiers for unsafe topics. The exact identifiers have been altered, but the change is limited to the values themselves; the field name and overall detection mechanism stay the same.
Effect on Existing WAF Rules
Rules that previously used cf.llm.prompt.unsafe_topic_categories with a now‑obsolete identifier will continue to load, but the condition will never evaluate to true for that identifier. This can lead to missed detections for prompts that would have been flagged under the old list.
Operational Steps
- Export or list all custom WAF rules that reference
cf.llm.prompt.unsafe_topic_categories. - Compare each referenced identifier against the current list of supported categories.
- Replace any removed or renamed identifiers with the appropriate current value.
- Validate the updated rules in a staging environment before promoting to production.
Related CloudNinjas coverage: security.
What This Means For Practitioners
Teams should treat the category update as a maintenance window: audit rule sets, adjust expressions, and verify that detection behavior aligns with the new taxonomy. Ongoing monitoring of Cloudflare documentation will help catch future adjustments before they affect rule efficacy.
