Dear Alibaba Cloud user,
On March 2, 2026, WAF AI Application Protection enters public preview with a major upgrade. This release introduces architectural changes that affect your current configurations and billing. Read this announcement carefully and take the required actions before the upgrade date.
What's changing
1. Feature optimization and refactoring
The new version rebuilds the core detection logic for AI Application Protection, improving detection accuracy and response efficiency. It also adds keyword blacklist detection and support for custom chunk sizes, and simplifies the configuration experience.
2. Integration with AI Guardrails
The new version integrates with AI Guardrails, Alibaba Cloud's dedicated content security product. This enables more intelligent detection of prompt injection attacks and interception of content security risks.
AI Guardrails is a separate, commercial product. When WAF AI Application Protection calls AI Guardrails, you are charged for AI Guardrails usage — separate from your WAF bill. The WAF feature itself has no additional cost.
WAF AI Application Protection is designed to eliminate the need for code modification during the integration of security with AI applications, enabling out-of-the-box use with flexible security handling options.
3. Configuration reset
Due to the architectural changes, all existing AI Application Protection configurations will be purged, including assets and templates. Alibaba Cloud will notify you by SMS and email before the purge occurs.
Billing summary
| Item | Billed to | Cost |
|---|---|---|
| WAF AI Application Protection feature | WAF product bill | No additional cost |
| AI Guardrails calls (triggered by WAF) | AI Guardrails product bill | Based on actual usage |
If you do not enable AI Application Protection after the upgrade, no AI Guardrails calls are made and you are not charged.
Potential impact
Configuration loss: Your existing configurations cannot be migrated. All assets and templates will be purged.
Manual re-enablement required: After the upgrade, AI Application Protection is not enabled automatically. Go to the AI Application Protection page in the WAF console to re-enable it.
New billing: Enabling the new version triggers AI Guardrails calls, which are billed based on actual usage.
Public preview stability: As a public preview release, this version may encounter issues. Contact technical support if you do — we will respond promptly.
Required actions
Before the upgrade
Keep your contact information current. Alibaba Cloud will send configuration purge notifications by SMS and email. Verify that your contact details are up to date.
Back up your existing configurations. If you want to preserve your current protection settings for reference, export and save them before the upgrade.
Disable AI Application Protection. After you receive the configuration purge notification and before the official upgrade, go to the WAF console and manually disable AI Application Protection. This prevents unintended interceptions or protection failures caused by lost configurations.
NoteIf you do not want to use the new version or incur AI Guardrails fees, leave the feature disabled after the upgrade. You will not be charged.
After the upgrade
Test in a non-production environment first. Enable AI Application Protection in a staging or test environment, verify compatibility and performance, then roll out to production.
Re-enable in the WAF console. Go to the AI Application Protection page in the WAF console and enable the service. Review AI Guardrails pricing and monitor your usage.
If you have questions about this upgrade, contact your account manager.
The Alibaba Cloud WAF Product Team January 30, 2026