Stay current to protect your environment with F5 Hardened Releases.Learn more

Gartner® identified F5 among third-party leaderboards in July 2026 Gartner Custom-Built AI Agent Security Guide report

Industry Trends | September 11, 2026

In its July 2026 Custom-Built AI Agent Security Guide, Gartner states that, “AI agents introduce new security risks such as indirect prompt injection and rogue agents that can cause business losses.” In that context, model selection becomes a security consideration in its own right.

F5 Labs releases an updated Comprehensive AI Security Index (F5 CASI) leaderboard each month to give organizations an evidence-based view of how leading models withstand common prompt-injection and jailbreak attacks. And we’re pleased that Gartner has identified F5 in its report.

Model selection has traditionally centered on capability, speed, and cost. Those factors still matter, but they are no longer sufficient when a model is connected to sensitive data, external tools, and business-critical systems. The security characteristics of the model shape the risk entering the application before any additional control is applied.

CASI isn’t designed to provide a verdict on whether a model is universally safe or unsafe. Instead, it offers practical input that takes into account the use case, data, permissions, deployment environment, and potential business impact, enabling organizations to make their own decisions about safety.

Model selection is becoming a security decision

Models with similar capabilities can present very different security profiles. One may resist common attacks more effectively, while another may require stronger compensating controls. Without comparative security data, organizations are left to make those decisions based on provider claims, reputation, or assumptions.

CASI brings greater discipline to that process by measuring model resistance to prompt-injection and jailbreak techniques, and presenting the results in a form that security, Al, and governance teams can use. F5 Labs also evaluates risk-to-performance and cost-of-security trade-offs, because the right model is not simply the one with the highest score. It is the one whose security, performance, and operating profile align with the intended use case.

For CISOs, this shifts model assessment from a technical preference to a governance requirement. The organization should be able to explain why a model was selected, what evidence informed the decision, which risks remain, and what controls are required before deployment. That record becomes especially important when models are updated, applications change, or the agent gains access to new data and tools.

Agentic risk extends beyond the model

Model resilience is only the starting point. Once a model is embedded in an agentic system, risk expands across identity, data, memory, prompts, tools, and the actions the agent is authorized to take. A resilient model can still be deployed with excessive permissions, connected to unsafe tools or exposed to poisoned context.

The fundamental shift is from evaluating what a model says to governing what an agent can do. An agent may interpret an objective, build a plan, choose tools, retrieve information, and act across multiple systems. The same request can therefore produce a different execution path and risk outcome, even when the user's intent has not changed.

Security teams need to define agency as part of the design. They should establish what the agent may decide, what it may access, which actions require approval, and which actions are prohibited. An internal research assistant and an agent authorized to modify production systems should not operate with the same permissions, safeguards, or monitoring thresholds.

Evidence must keep pace with change

Al security cannot be treated as a point-in-time assessment. Models are updated, providers adjust safety controls, applications gain new integrations, and attackers develop new techniques. A score that was useful at selection may no longer reflect current risk once the model or surrounding system changes.

CASI is complemented by the Agentic Resistance Score (ARS) leaderboard, which examines how models respond to persistent, adaptive, and multi-step agentic attacks over time. This matters because an adversarial agent can build context, change tactics, and pursue the same objective through multiple paths.

The monthly cadence is supported by F5 Labs threat intelligence, tracking how attack techniques and model behavior change over time. Together, CASI, ARS, and threat research provide a current evidence layer for model selection, architecture decisions, and control design. They do not replace application-specific testing, but they give security leaders a stronger starting point.

From assessment to control

Evidence has limited value if it does not change how the system is secured. Model and agent testing should inform the controls applied before and during deployment, including access restrictions, runtime guardrails, tool validation, data protection, and monitoring. Observed behavior in production should then feed back into new tests, policy changes, and tighter controls where needed.

This is the operating model behind the F5 AI Security Platform: evaluate Al risk, define governance, and enforce tailored protections across models, applications, and agents. The platform brings together assessment, adversarial testing and runtime security so organizations can move from identifying weaknesses to reducing exposure in production. F5 Labs research strengthens that cycle by grounding decisions in current model data and emerging attack patterns.

For CISOs, the objective is to eliminate avoidable Al risk and reduce residual risk to an acceptable, explainable, and governable level through evidence-led model selection, system-level testing, enforceable runtime controls, and continuous reassessment.

In our view, Gartner's identification of CASI comes as enterprises face pressure to move faster with Al without lowering the standard of control. Security leaders need a way to support AI adoption while remaining clear about the risk being accepted and the safeguards required. That means connecting model evidence to the architecture and operating controls surrounding every deployment.

A defensible program starts with three disciplines: measure the model, test the complete system, and control what the agent can access and do. Those disciplines must operate continuously because the underlying risk does not remain static. CASI, ARS, and F5 Labs threat intelligence provide evidence for those decisions, while the F5 Al Security Platform helps organizations put that evidence into practice.

The goal is not to slow Al adoption. It is to give CISOs a stronger basis for deciding where Al can be deployed, under what conditions, and with which controls, so organizations can move beyond isolated experiments and start scaling in a responsible and secure way. That is the operating discipline enterprise Al now requires.

Explore the latest F5 CASI and ARS Leaderboards and learn more about the F5 AI Security Platform.

______

Gartner, Custom-Built AI Agent Security Guide, Dennis Xu, Erik Wahlstrom, et al., 6 July 2026 GARTNER is a trademark of Gartner, Inc. and/or its affiliates.

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

Share

About the Author

Nirav Shah
Nirav ShahSVP, Product and Solution Marketing | F5

Nirav Shah is the Senior Vice President and Head of Products and Solution Marketing at F5, where he leads the strategic direction for Application Security and AI Security. Before joining F5, he spent eleven years at Fortinet in several leadership positions, most notably heading the AI-Powered SASE, SOC, and Secure Networking solutions. His extensive background also includes significant roles at Cisco Systems, where he spearheaded major initiatives for SD-WAN. With more than two decades of experience in the cybersecurity sector, he has an established record of launching market-defining products and building high-performance teams that align product development with sales and marketing for maximum impact. As a thought leader and USC alumnus, he is a frequent speaker at industry conferences and a regular contributor to leading publications on the intersection of AI and cybersecurity, while remaining dedicated to mentoring emerging cybersecurity professionals.

More blogs by Nirav Shah

Related Blog Posts

Securing the new control points in the AI journey
Industry Trends | 07/01/2026

Securing the new control points in the AI journey

AI architecture is fundamentally different than traditional IT environments and requires a different security strategy to protect critical AI workloads.

The patch window has closed. Here is how F5 is built for what comes next.
Industry Trends | 04/27/2026

The patch window has closed. Here is how F5 is built for what comes next.

As AI models have changed software security, the industry needs to adapt.

Best practices for optimizing AI infrastructure at scale
Industry Trends | 01/21/2026

Best practices for optimizing AI infrastructure at scale

Optimizing AI infrastructure isn’t about chasing peak performance benchmarks. It’s about designing for stability, resiliency, security, and operational clarity

Datos Insights: Securing APIs and multicloud in financial services
Industry Trends | 12/23/2025

Datos Insights: Securing APIs and multicloud in financial services

New threat analysis from Datos Insights highlights actionable recommendations for API and web application security in the financial services sector

Secrets to scaling AI-ready, secure SaaS
Industry Trends | 12/12/2025

Secrets to scaling AI-ready, secure SaaS

Learn how secure SaaS scales with application delivery, security, observability, and XOps.

How AI inference changes application delivery
Industry Trends | 11/19/2025

How AI inference changes application delivery

Learn how AI inference reshapes application delivery by redefining performance, availability, and reliability, and why traditional approaches no longer suffice.