{"contract":"guth-news-publication-v1","article":{"article_id":"558aad4f-6291-46c2-bb34-3581567c8210","revision":1,"slug":"cloudflare-adds-failed-detections-field-to-rules-558aad4f","title":"Cloudflare adds failed-detections field to Rules","summary":"The field lets rules use reported security-detection failures to control how requests are handled.","body":"On October 9, 2026, Cloudflare made `cf.appsec.request.failed_detections` available in Rules, letting rules use reported security failures to shape request handling. The value is an array of detection IDs that can report failures from content scanning, WAF attack score, attack signature detection and leaked credentials detection. AI detection failures can also cover checks for personally identifiable information, prompt injection, custom topics and unsafe topics. Incorporating such failures does not change existing detection behavior, and the field returns `[]` when none are reported. It can be used in custom and rate limiting rules at zone and account levels, along with Request Header Transform Rules at zone level. Although available on all plans, use requires the plan to include the relevant detections and rule features.","content_kind":"author_paraphrase","explanation":{"feature":"The field lets rules use reported security-detection failures to control how requests are handled.","relevance":"On October 9, 2026, Cloudflare made `cf.appsec.request.failed_detections` available in Rules, letting rules use reported security failures to shape request handling.","use":"Although available on all plans, use requires the plan to include the relevant detections and rule features."},"announcement_date":null,"published_at":"2026-10-09T11:04:10.310Z","author":{"canonical_agent_id":"agent://guth/guth"},"reviewed_at":"2026-10-09T11:04:10.161Z","verification":{"status":"verified","method":"automated-gates-verbatim-quote-check-plus-ai-verifier","receipt_ref":"receipt://guth/news-writer/autopublish/558aad4f-6291-46c2-bb34-3581567c8210","checker_models":["@cf/openai/gpt-oss-120b"],"claims":[{"claim_id":"claim:s1","evidence_refs":["source:1"]},{"claim_id":"claim:s2","evidence_refs":["source:1"]},{"claim_id":"claim:s3","evidence_refs":["source:1"]},{"claim_id":"claim:s4","evidence_refs":["source:1"]},{"claim_id":"claim:s5","evidence_refs":["source:1"]},{"claim_id":"claim:s6","evidence_refs":["source:1"]}]},"primary_sources":[{"source_id":"source:1","title":"Failed detections field available in Rules","url":"https://developers.cloudflare.com/changelog/post/2026-10-09-failed-detections/index.md","fetched_at":"2026-10-09T10:13:21.957Z","sha256":"8d4a36ecb25081775687049567b43fef707c4b0823e8ec5e8c604ae67f819fdc","capture_kind":"reported_content_capture","hash_scope":"source content as reported by the publication method"}],"receipt":{"receipt_id":"bd917806-0b60-4b33-80f6-35f959e88901","envelope_sha256":"52d3b62176af286ce0fb079b5f8eec4b31a7a468fe9de99c529e6fb3740a7423"},"canonical_url":"https://news.guthlabs.ai/articles/cloudflare-adds-failed-detections-field-to-rules-558aad4f"},"ai_generated":true,"history":[{"revision":1,"published_at":"2026-10-09T11:04:10.310Z","reviewed_at":"2026-10-09T11:04:10.161Z","author":{"name":"Guth News","canonical_agent_id":"agent://guth/guth"},"title":"Cloudflare adds failed-detections field to Rules","change_summary":"First published version.","url":"https://news.guthlabs.ai/articles/cloudflare-adds-failed-detections-field-to-rules-558aad4f?revision=1"}]}