Key Takeaways

  • F5 introduced a new AI Security Platform and acquired SurePath AI to strengthen AI discovery and governance.
  • Rising enterprise use of generative and agentic AI is widening risks such as shadow AI and prompt injection.
  • Industry frameworks from NIST and ISO are increasingly shaping how security teams implement AI oversight.

F5 unveiled the F5 AI Security Platform and acquired SurePath AI to deepen visibility into enterprise AI network usage. The acquisition arrives as organizations accelerate the adoption of generative and agentic AI, necessitating continuous, adaptive governance frameworks.

Security teams face immediate technical and governance challenges as they attempt to map employee tool usage, monitor data flowing into prompts, and ensure predictable model behavior. This environment creates operational demand for platforms that centralize visibility across AI workloads.

At the core of the F5 AI Security Platform is a continuous, adaptive loop that governs, discovers, tests, and protects enterprise AI workloads. The platform is designed for on-premises, private cloud, hybrid, air-gapped, and public cloud environments, addressing deployment constraints in regulated industries with strict data residency requirements.

Shadow AI usage, spanning unsanctioned integrations and experimental workflows, continues to expand visibility gaps. According to Gartner in 2023, 73% of organizations were already using or piloting generative AI, while only 21% had formal governance policies in place. This governance deficit directly drives enterprise risk exposure.

SurePath AI provides network-based AI discovery without requiring direct integration into applications. This architecture allows enterprises to detect both authorized and shadow AI usage with minimal operational friction. By analyzing agent tool calls and workflow intent, the technology maps how AI systems operate across the network in real time.

This visibility is integrated directly into the broader platform. Findings from SurePath AI feed into F5 AI Red Team testing and F5 AI Guardrails, establishing a continuous loop that identifies risky behavior, tests systems against adversarial attack patterns, and enforces runtime boundaries. This automated testing replaces ad hoc assessments with continuous runtime protection.

The platform executes several core capabilities to secure AI operations. Governance defines boundaries for prompts, outputs, and data access. Discovery reveals active AI system usage. Testing evaluates models and agents before deployment to identify vulnerabilities. Runtime protection enforces rules that actively block prompt injection, excessive autonomy, and data leakage, while an underlying observability layer maintains the audit trails required by regulated sectors.

Current regulatory and industry frameworks strongly align with these governance requirements. The NIST AI Risk Management Framework provides a structural reference for evaluating AI risks, while standards such as ISO 23894 and ISO 42001 establish formal requirements for AI management systems.

Agentic AI introduces specific operational risks, such as privilege escalation and unauthorized data exfiltration, because agents can authenticate, call external tools, and access data autonomously. Model integrity also remains a primary concern; a 2023 report from Forrester found that 51% of organizations identified model security and integrity as top AI risk management challenges. With global spending on AI-centric systems projected to reach $300 billion by 2026 according to IDC, enterprise investment in AI security controls is accelerating rapidly.

Security solutions limited to chatbot wrappers fail to address the full spectrum of enterprise risk. The chief product officer at F5 noted that enterprises run AI deeply integrated behind APIs and across autonomous agents. The platform centralizes continuous control across the environments where these models, agents, and APIs actually operate.

Deploying formalized AI security platforms enables teams to accelerate AI initiatives by satisfying the oversight requirements of regulators and risk committees. Implementing clear governance and runtime visibility allows organizations to unlock stalled AI projects with confidence in their monitoring and testing protocols.

To support varying compliance thresholds, from financial services prioritizing auditability to healthcare organizations enforcing strict data residency, the platform avoids mandated architecture changes by utilizing lightweight deployment through network redirects.

Providers such as Palo Alto Networks, Microsoft, and IBM have expanded their AI security offerings with approaches tailored to runtime controls, model governance, or API protection. F5 addresses the market by connecting these layers, delivering consistent security controls across enterprise networks, applications, models, and agents.

The 2026 State of Application Strategy Report indicates that 98% of organizations are preparing for agentic AI. As workloads shift toward autonomous behaviors, a single misconfiguration or exploit can amplify rapidly if malicious agents gain access to enterprise authentication mechanisms and internal toolsets.

The integration of SurePath AI into the F5 AI Security Platform targets the immediate demand for visibility into actual, rather than intended, enterprise AI usage. By combining continuous runtime protection with adversarial testing against verified attack patterns, organizations can enforce strict security controls across multicloud and air-gapped environments. As agentic systems scale and regulatory expectations mature, comprehensive AI governance platforms will be required to maintain operational security and model integrity.