F5 AI Security Platform
by F5, Inc.
Discover, red-team, govern and guard enterprise AI apps, models and agents from one model-agnostic F5 platform.
F5 AI Security Platform bundles F5 AI Guardrails, F5 AI Red Team, shadow-AI discovery, an AI Gateway and newly announced workforce AI controls into one model-agnostic layer for securing enterprise AI apps, models and agents. Built on F5's $180 million CalypsoAI acquisition, it targets CISOs in regulated industries that need runtime protection and audit trails on-premises, air-gapped or in the major public clouds.
F5 AI Security Platform is F5's umbrella offering for securing enterprise AI applications, models, agents and the APIs and MCP tool calls that connect them, launched on 22 June 2026 as an extension of F5's Application Delivery and Security Platform (ADSP). Its core comes from CalypsoAI, the Ireland- and US-based inference-security startup F5 agreed to buy for $180 million in September 2025 and closed on 29 September 2025; that technology became F5 AI Guardrails and F5 AI Red Team, both generally available since 14 January 2026. Guardrails sits in front of models, inspects prompts and responses against prebuilt and natural-language custom policies, and can block, audit or redact prompt injection, jailbreaks, PII leakage and toxic output, recording why each prompt was accepted or blocked and exporting events to third-party SIEMs. AI Red Team sends swarms of autonomous agents against models and agents, drawing on a threat library F5 says grows by more than 10,000 attack patterns a month, and turns findings into Guardrails policies. The June launch added network-based shadow-AI discovery from the acquired Denver startup SurePath AI; an AI Gateway with MCP Gateway capabilities followed in August 2026, and an agentless Workforce AI Security module covering employee and coding-agent AI use was announced on 15 September 2026. The platform is model-agnostic and runs in AWS, Azure and Google Cloud, private cloud, on-premises and fully air-gapped environments, including Red Hat OpenShift AI. F5 cites roughly 98% security efficacy in independent SecureIQLab testing and a Market Shaper placement in Gartner's 2026 Emerging Market Quadrant for AI Application Security, but it publishes no list pricing or named customers, and PeerSpot showed zero user reviews in September 2026.
CISOs and AI security leads at enterprises in regulated industries, especially those already running F5 for application delivery and WAF, who need one platform to discover, red-team and guard AI apps and agents, including on-premises or air-gapped.
One model-agnostic control point that blocks prompt injection and sensitive-data leakage at runtime, with red-team findings feeding policy and audit-ready logs for regulators.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, CIOs, CTOs, Security Teams, Enterprise Developers
- Deployment
- Hybrid, Self-hosted, Multi-cloud
- Founded
- 1996
- Headquarters
- Seattle, USA
- Team Size
- 500+
Key Features
- ✓F5 AI Guardrails (runtime protection)
Inspects every prompt and response in front of public or private models, then blocks, audits or redacts prompt injection, jailbreaks, PII leakage and toxic output.
- ✓F5 AI Red Team
Swarms of autonomous attack agents probe models and agents using a threat library F5 says grows by 10,000+ patterns monthly; findings convert directly into Guardrails policies.
- ✓Shadow AI and MCP discovery (from SurePath AI)
Network-based, out-of-band discovery inventories sanctioned and unsanctioned AI apps, agents and MCP server connections and classifies each workflow's intent without per-app integration.
- ✓Agent visibility and explainable audit logs
Records system prompts, instructions, model reasoning and tool calls with guardrail attribution, explains why each prompt was allowed or blocked, and exports events to third-party SIEMs.
- ✓Natural-language policies and compliance templates
Security teams write bespoke policies in plain language on top of prebuilt controls for GDPR, HIPAA, PCI, PHI and the EU AI Act, speeding an audit-ready rollout.
- ✓AI Gateway with MCP Gateway
Added in August 2026, it controls traffic and enforces policy across AI applications, models, agents and MCP tools from a single control point.
- ✓Air-gapped and self-hosted deployment
Runs in AWS, Azure, Google Cloud, private cloud, on-premises or fully air-gapped environments, including an F5 AI Security Operator for Red Hat OpenShift AI.
Use Cases
- •Protect customer-facing GenAI in regulated industries
Place Guardrails in front of a banking or healthcare chatbot or RAG assistant to block prompt injection and redact PII before answers reach customers, keeping audit trails for regulators.
- •Red-team models and agents before launch
Run AI Red Team campaigns against a new model or agent pre-production, then turn the attack paths it finds into runtime Guardrails policies without rebuilding rules by hand.
- •Inventory shadow AI and MCP usage
Use network-based discovery to map which AI tools, agents and MCP servers employees actually use, sanctioned or not, so governance policy starts from real usage data.
- •Sovereign or air-gapped AI
Self-host guardrails and red teaming next to on-premises vLLM inference on OpenShift so prompts, responses and logs never leave a classified or data-sovereign environment.
- •Model risk review before approval
Compare candidate foundation models using F5's CASI model risk leaderboard and red-team results before approving them for enterprise use, documenting the decision for auditors.
Ideal For
Best For
- ✓Enterprises already standardized on F5's Application Delivery and Security Platform for application delivery, WAF and API security
- ✓Regulated financial services and healthcare firms that need audit-ready runtime controls on customer-facing GenAI
- ✓Air-gapped, on-premises or data-sovereign AI deployments where SaaS-only guardrails are ruled out
- ✓Security teams that want red teaming and runtime guardrails from one vendor, with test findings feeding enforcement policy
- ✓CISOs who need an inventory of shadow AI, agents and MCP server connections across the workforce
Not Ideal For
- ✗Developer teams that want open-source, CI-integrated red teaming on every pull request - independent comparisons note there is no OSS tier or self-serve plan
- ✗Startups and small teams that need published, self-serve pricing; every component is licensed through F5 sales
- ✗Teams without GPU capacity for self-hosting - Red Hat's OpenShift reference deployment recommends three 24 GB-VRAM GPU nodes for the scanners and red-team models
Deployment
Market Analysis
Pros
- ✓Covers discovery, red teaming, governance and runtime protection in one platform, reducing AI security tool sprawl
- ✓Genuine on-premises and fully air-gapped deployment, plus AWS, Azure and Google Cloud
- ✓Red-team findings feed directly into runtime Guardrails policies, closing the test-to-protect loop
- ✓Explainable enforcement: logs why each prompt was blocked, with SIEM export and prebuilt GDPR, HIPAA and EU AI Act controls
- ✓F5 cites roughly 98% efficacy in independent SecureIQLab testing plus Gartner and KuppingerCole analyst placements
Cons
- ✗No public pricing, free tier or trial; licences and container-registry credentials come only through F5 sales
- ✗Self-hosting is GPU-heavy: Red Hat's reference OpenShift deployment recommends three NVIDIA A40-class (24 GB VRAM) GPU nodes for scanners and red-team models
- ✗Almost no independent user feedback: PeerSpot had zero reviews in September 2026 and Hacker News and Reddit show no practitioner discussion
- ✗Campaign-based, security-team red teaming rather than developer-first CI gating, with no open-source tier
- ✗Assembled quickly from acquisitions (CalypsoAI in 2025, SurePath AI in 2026), and Workforce AI Security was announced but not yet shipping as of September 2026
Pricing
Enterprise (AI Guardrails, AI Red Team, AI Security Platform)
Contact for pricing
- ✓Model-agnostic runtime guardrails for public and private models
- ✓Automated agentic red teaming
- ✓Shadow AI and MCP discovery
- ✓Public cloud, private cloud, on-premises and air-gapped deployment
- ✓Licence and container-registry credentials issued via F5 sales
F5 publishes no list pricing for any AI Security Platform component; buyers must contact F5 sales, and self-hosted deployments need an F5 AI Guardrails licence plus container-registry credentials issued by F5. There is no free tier, self-serve plan or open-source edition, and no public trial terms. The metering basis (per model, per request or per user) is not disclosed, and self-hosting adds separate GPU infrastructure cost.
Security & Compliance
Sources
This page was written from 13 sources, 8 on domains other than f5.com.
- 1.f5.com — ai security platformvendor
- 2.f5.com — ai guardrailsvendor
- 3.f5.com — f5 ai security platform control enterprise riskvendor
- 4.f5.com — f5 accelerates ai security with integrated runtime protectiovendor
- 5.f5.com — what are ai guardrailsvendor
- 6.securityweek.com — f5 to acquire calypsoai for 180 million
- 7.geekwire.com — f5 expands further into ai security with surepath ai acquisi
- 8.techzine.eu — f5 launches ai security platform and buys surepath ai
- 9.docs.redhat.com — rh f5 ai guardrails
- 10.redhat.com — f5 ai guardrails quickstart answering hard questions
- 11.giskard.ai — calypsoai f5 alternatives ai red teaming
- 12.peerspot.com — calypsoai reviews
- 13.prnewswire.com — f5 expands ai security platform with f5 workforce ai securit
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
DeepKeep
AI security platform covering red teaming, an AI firewall, agent attack-surface scanning and runtime controls for coding agents
Armadin
Autonomous offensive security: AI agent swarms that chain your weak spots into proven attack paths before an attacker does
WitnessAI
Network-layer AI security and governance for employee AI use, models, apps and agents
Ascerta
Enterprise AI management: measure the ROI, cost and adoption of every AI initiative, agent and coding tool