This week Cloudflare dropped a number: its Impact program has crossed $100 million in cumulative donated service value, timed with the company's 16th anniversary. But what we find more interesting than the figure itself is the underlying logic—free users in exchange for threat intelligence, which then feeds paid products—and the fact that this playbook is now being copied into AI infrastructure.
What this is
Cloudflare's Impact isn't ad-hoc charity—it's a systematic free security bundle covering independent news sites, human rights organizations, local election bodies, public schools, and more. The core program, Project Galileo, launched in 2014 and now protects more than 3,500 domains across 120+ countries. In 2025 alone, it blocked 38.5 billion DDoS (distributed denial-of-service) attacks, phishing emails, and other threats—an average of 105.4 million per day.
Industry view
Supporters call it the essence of the Cloudflare business model: free users—especially the ones under the heaviest attack—become its threat intelligence feed. That data flows back into paid products, transforming Cloudflare from a CDN (content delivery network) into a cybersecurity heavyweight. Now the same playbook is being applied to AI: products like Workers AI and AI Gateway are essentially about making AI invocations cheaper and safer—the same logic, new arena.
But skeptics exist. Critics argue that so-called philanthropy is essentially cloud vendors trading data monopoly and brand narrative for free service—wrapping commercial behavior in mission-driven language, and quietly crowding out genuinely non-profit organizations. Meanwhile, Cloudflare's AI infrastructure push hasn't yet produced obvious synergies with Impact; the charity narrative and the AI commercial story remain two parallel tracks. Whether they converge is still an open question.
Impact on regular people
For enterprise IT: Once AI applications go live, traffic ingress and data security increasingly depend on middle-layer providers like Cloudflare. Procurement can no longer be priced alone—security capabilities must be on the shortlist.
For individual careers: Phishing and DDoS risks facing remote workforces have multiplied over the past few years. Cybersecurity literacy for ordinary employees is shifting from a nice-to-have to a hard requirement.
For consumer markets: Programs that sound remote—"protecting African anti-corruption journalists," "U.S. local election websites"—run on the same infrastructure underneath. Ordinary users' privacy and security increasingly hang on this invisible network.