Global bank secures enterprise AI at scale with F5
A global systemically important bank (G-SIB) selected F5 AI Guardrails and F5 AI Red Team to protect the enterprise’s AI platform.
One of the world’s largest global financial institutions built AI services for both internal and external-facing use cases across human resources, procurement, cybersecurity, and core business unit operations with secure infrastructure from F5.
Business challenge
More than two dozen global systemically important banks (G-SIBs) operate with such size, interconnectedness, and complexity that their failure could trigger a global financial crisis. So, their cybersecurity matters. One of the world’s largest G-SIB institutions recently prepared to roll out an enterprise AI platform across both internal operations and external-facing services, with planned use cases across human resources, procurement, cybersecurity, and core business units.
The bank needed to protect confidential data, enforce access controls, and comply with global regulatory frameworks such as the EU AI Act and ISO/IEC 42001, all without slowing the pace of AI adoption. The bank’s governance structure reflected the scale of the challenge, with involvement from the Chief Information Security Officer (CISO), Global Chief Information Officer (CIO), and Chief Privacy and Responsible AI Officer. Given the depth and scale of the project, a comprehensive rollout strategy was essential to ensure buy-in from multiple stakeholders.
The bank had more than 50 use cases ready to launch, but its internal auditors had no way to validate that the systems were safe to deploy. To move forward, the bank needed an AI security platform that could meet its data sovereignty and internal control requirements.
Solutions
The bank ran a competitive evaluation against multiple major AI security vendors. F5 passed every criterion and demonstrated top-tier security, compliance, and performance.
Speed was a critical selection factor. When the bank asked for guardrails aligned to the EU AI Act, F5 reacted swiftly, showcasing F5 AI Guardrails with validated protection against evolving attacks and more than a 98% accuracy rate. The bank later cited the speedy response and security efficacy as proof of what real partnership with F5 looked like.
F5 AI Red Team reinforced the F5 advantage by giving the bank’s security team concrete proof of how their AI systems actually behaved, plus the visibility needed to identify where data leaks could happen, how prompts could be manipulated, and where controls broke down in their specific environment.
Winning the evaluation was only half the challenge. Because the bank’s AI infrastructure was becoming central to daily operations, their architects needed proof that the F5 solution could run inline, fail closed on outage if needed, and do so without adding risk. That meant proving the solution against real enterprise-scale constraints, including high-volume data retention, structured storage limits, and autoscaling. It also meant integrating directly with the bank’s existing SIEM and identity infrastructure rather than asking teams to work around it.
The bank decided to deploy AI Guardrails and AI Red Team, self-hosting the solutions on bare metal on a dedicated, on-premises infrastructure that the bank fully owns and controls.
Results
Protect data and the AI platform from cyberattack
The F5 solution is designed to unify data-sovereignty and internal control capabilities. Specifically:
- AI Guardrails provides out-of-the-box and custom guardrails, driven by requirements set by the bank’s centralized AI and security teams, to detect and block data leakage, prompt injection, jailbreaks, and policy violations at runtime.
- AI Red Team delivers an extensive signature attack library, supplemented with custom-intent agentic attack capabilities, to continuously validate the platform’s resistance to real-world adversarial techniques.
Testing quickly showed measurable security impact, anchored by 90%+ protection rates across PII exposure, prompt injection, jailbreaks, and malicious content, all validated through AI Red Team testing and enforced through AI Guardrails.
Establish a path to secure AI adoption
That protection rate translated into real progress. By combining AI red teaming with adaptive guardrails, along with an architecture engineered for highly regulated environments, the bank can scale AI across the business with confidence in security and governance.
With the security architecture now validated, the bank is positioned to move ahead on secure, multi-disciplinary AI use cases across departments, disciplines, and core business units—the same use cases that were previously blocked.
Increase regulatory and governance readiness
AI Guardrails and AI Red Team are unified under one policy and reporting layer, so findings from offensive testing translate directly into runtime protections instead of sitting in a separate report. Within this closed-loop security architecture, a single, integrated view for the security organization feeds audit-ready evidence into the bank’s governance processes. This centralized reporting, aligned to EU AI Act and ISO/IEC 42001 requirements, gives the bank’s auditors the security proof they had been missing.
Ensure performance and operational resilience
Latency monitoring, model failover, and scalability validation are built into the design, so the bank’s AI platform is positioned to stay available and responsive under load without disrupting critical business operations once live.
With the security architecture validated, the bank is already looking beyond the initial AI Guardrails and AI Red Team deployment. As use cases expand and grow more autonomous and embedded across workflows, the bank is investigating additional F5 AI Security Platform solutions, including auto-remediation and agentic security capabilities.
Benefits
- Protect data and AI infrastructure from cyberattack
- Establish a path to secure AI adoption
- Increase regulatory and governance readiness
- Ensure performance and operational resilience
Challenges
- Large-scale AI rollout plans
- Maintaining security for confidential data
- Compliance with multiple strict regulations
- The need to satisfy many governing stakeholders