Skip to main content
Sovereignty through openness

Cloudflare's Birthday Week: Two European Open Models and AI Security Defenses Built for Choice

Cloudflare's Birthday Week brings two European open-source language models to its platform and new hands-on security workshops for governments. The company argues that true AI sovereignty means choice and independence—not isolation—letting nations build defenses that work across any model rather than depending on a single provider.
A glowing globe sits atop a tiered platform surrounded by colorful spheres against a dark, starry background.
A glowing globe sits atop a tiered platform surrounded by colorful spheres against a dark, starry background.

It's Birthday Week, when Cloudflare ships presents to the Internet. This year, two come from Europe: EuroLLM, which covers all 24 official EU languages, and Apertus, Switzerland's fully open model trained on more than 1,500 languages. Both were built by public universities and research institutions and are coming to Workers AI, available for request today.

Cloudflare is also launching hands-on workshops that help government cyber agencies and critical infrastructure operators build AI defenses that work with any model. The first runs in Singapore in October.

These announcements follow an argument Cloudflare made a year ago, when questions about AI access and sovereignty were swirling in national capitals. The company's answer was choice: the freedom to pick the right tools for the job and to switch when needed.

Since then, conversations have hardened. Attackers have used frontier models to run cyber attacks. Access to some frontier models now depends on geography. Calls to restrict open models are getting louder. The conclusion often drawn: AI sovereignty is zero-sum—every model another country controls is one you can't count on, so the safe move is to build walls.

Cloudflare sees it differently. India, Japan and Singapore focused on open-sourced models, and people across Asia-Pacific built tools on them for rural citizens, elderly patients and the nurses who care for them. Cloudflare's own security team built AI defenses that work with any model, so losing access to one doesn't mean losing your defenses.

Helping build a better Internet has always meant more options, not fewer. We don't think any country should have to depend on one company for its AI. That includes us.

— Cloudflare

Two European Open Models on Workers AI

In February, Cloudflare CEO Matthew Prince told the India AI Impact Summit 2026 in New Delhi that decentralized, affordable access to AI is a matter of national resilience. Models from India, Japan and Singapore added months earlier were the company's first proof. The summit series moves to Geneva in June 2027, with a mission of “prosperity and progress for all.”

EuroLLM supports 35 languages, including all 24 official EU languages, many of which are underserved by existing open models. It was developed with support from Horizon Europe, the European Research Council and EuroHPC by a consortium including Instituto Superior Técnico, the University of Edinburgh, Instituto de Telecomunicações, Université Paris-Saclay, Unbabel, Sorbonne University, Naver Labs and the University of Amsterdam. Trained on the MareNostrum 5 supercomputer, it outperforms similar-sized models on EU multilingual benchmarks and machine translation, according to the consortium. Access is available to request on Workers AI.

Apertus (Latin for “open”) is Switzerland's first large-scale, fully open, multilingual language model. It was trained on more than 15 trillion tokens across more than 1,500 languages, with 40% of training data in languages other than English. Developed by ETH Zurich, EPFL and the Swiss National Supercomputing Centre (CSCS) as part of the Swiss AI Initiative, it is built by public institutions for the public good. Its architecture, weights, training data and methods are all published. The model was designed with Swiss and European rules such as the EU AI Act and GDPR in mind, respecting training opt-outs, removing personal data and preventing memorization. Trained on CSCS's Alps supercomputer with more than 10,000 GH200 GPUs, Apertus significantly outperforms leading closed and open models on rare and regional languages, from Romansh and Swiss German to low-resource languages across Asia and Africa. Access is available to request on Workers AI.

What People Built Last Year

Last year's national models didn't sit on a shelf. Since Cloudflare added them to Workers AI, hundreds of students, startups, small businesses and public servants across Asia-Pacific have built on them, many at buildathons run with local partners.

Form Mitra (India): Benefit forms written in dense English shut out many of the rural, low-literacy and visually impaired citizens they're meant for. Students at the Indian Institute of Technology Delhi built Form Mitra at a buildathon with CyberPeace: a voice-guided assistant that walks people through forms in any of 22 Indian languages, using AI4Bharat's IndicTrans2 model.

MedBridge (Singapore): Many nurses caring for Singapore's elderly patients come from across Southeast Asia and don't speak local dialects, so critical clinical information can get lost in translation. MedBridge guides patients through health conversations in 14 languages, including Hokkien and Cantonese.

Anshin Concierge (Japan): For elderly residents, people with disabilities and anyone less comfortable with digital tools, determining which public service to call in a moment of need can be overwhelming. Built as a hackathon prototype, Anshin Concierge lets people describe their problem in their own words (“my knees hurt,” “a strange screen appeared on my phone”) and connects them to the right Tokyo Metropolitan Government support desk, by phone or web page, in one tap.

AI Defenses That Don't Depend on One Model

Governments want to use AI to defend essential services and national infrastructure. Frontier models can find vulnerabilities at scale—and they can find them for defenders too. But a defense built on one model is only as dependable as your access to that model, and governments have watched access to critical models get constrained with little warning.

Cloudflare faced the same problem. Over the past year, its Security team, working with teams across the company, set out to build AI defenses that don't depend on any one model. They built a harness: an orchestration layer that coordinates multiple AI models working in parallel to hunt for vulnerabilities, verify findings and prioritize threats. Cloudflare published what it learned about using frontier and open models together, open-sourced the harness so any organization can run it with models of its choice, and laid out the layered architecture it uses to stop attackers armed with frontier models from finding vulnerabilities in the first place.

Because the harness works with any model, closed or open, losing access to one provider doesn't switch defenses off. When Cloudflare walked governments through it, the most common reaction was relief, followed by practical questions: how to stand it up in their own environments, under their own rules. Briefings quickly turned into requests for hands-on training.

Today Cloudflare is launching a program of hands-on workshops for government cybersecurity agencies and critical infrastructure operators. Participants build their own AI security harness and layered defenses and leave knowing how to adapt both to their organization. The modules are plug-and-play, designed to slot into national AI skilling and cyber resilience programs. The first workshop runs in Singapore this October, at Singapore International Cyber Week.

Come Build With Us

None of this happened alone. Partners like CyberPeace in India and Code for Japan helped turn open models into working tools. Organizations running national AI programs, cyber agencies or critical infrastructure can request access to EuroLLM and Apertus or start with the harness at policy-team@cloudflare.com.

A year ago, we said choice is the path to AI sovereignty. This year showed it's the path to AI security, too.

— Cloudflare

Felipe Santos

“Artificial intelligence can process the world in milliseconds, but only the human heart can give meaning to every second lived” – Mr. Santos