Frontline defense for frontier AI threats
Frontier AI is collapsing the patch window from weeks to minutes. Protect against threats with software that’s continuously hardened using the latest frontier AI models, while leveraging solutions that enforce protection in the data path before threats reach your apps, APIs, and AI models.
The frontier AI threat landscape
Zero-day attacks that have no signature
Frontier AI enables previously undiscovered attacks, which evade traditional defenses that depend on signatures to known vulnerabilities.
A patch window that’s measured in minutes
Threat actors can now exploit vulnerabilities within hours of discovery. Security teams are used to longer patch cycles, exposing critical gaps in protection.
Patch-driven exploits
Every patch release reveals vulnerabilities that attackers can reverse-engineer quickly, turning unpatched systems into easy targets before organizations can deploy updates.
We use frontier AI on both sides of the threat, to harden our code and to protect your applications
Security solutions that adapt to evolving threats
To combat frontier AI threats, organizations need comprehensive solutions that provide runtime protection, virtual patching, and AI-driven threat mitigation to block attacks and adapt to evolving risks.
Learn moreContinuous code-hardening
F5 harnesses the latest frontier AI models to continuously harden our code across the F5 Application Delivery and Security Platform, systematically finding and fixing vulnerabilities at machine speed.
Learn moreHardened software releases
F5 ships hardened software releases every six weeks with fixes from our 5-step model-agnostic AI scanning harness infrastructure, internal teams, and outside researchers.
Learn moreOur approach: A model-agnostic scanning infrastructure
F5 uses a 5-step AI scanning harness loop and the most advanced frontier AI models to help identify potential weaknesses earlier and validate improvements faster, hardening the products customers rely on to protect their most critical applications.
Using the most advanced frontier AI models, F5 runs a continuous scanning harness that finds, validates, and fixes vulnerabilities, hardening the products customers rely on. The approach is model-agnostic by design, so protection is never bound to a single vendor.
Defend the data path
F5 shifts protection to the runtime layer, blocking threats instantly before they can reach your applications or APIs. With solutions like AI-powered WAF, virtual patching, and real-time threat mitigation, F5 stops zero-days, AI-driven exploit chains, and unauthorized access while ensuring legitimate traffic is uninterrupted.
Products
F5 Distributed Cloud WAF
This AI-powered WAF improved baseline threat detection to 98% accuracy while reducing false positives to 1%.
F5 Distributed Cloud Web App Scanning
Automated vulnerability detection and virtual patching uncovers vulnerabilities with assigned CVE scores and severity levels to BIG-IP Advanced WAF, with automatic policy updates.
F5 Distributed Cloud Bot Defense
Detects and identifies AI agents, humans, and bots by assigning a trust score that governs their actions. This score controls what they can do, where they can operate, and how quickly they can act, blocking automated abuse.
F5 Distributed Cloud API Security
Continuously discovers APIs, including shadow and unmanaged endpoints, monitors for abuse and sensitive data exposure, controlling and protecting endpoints inline to stop threats before they reach your services.
F5 AI Guardrails
Inspects prompts and responses at the inference layer in real time, blocking prompt injection, data leakage, and unsafe output.
F5 AI Red Team
Continuously probes your models and AI applications for exploitable weaknesses, surfacing them the way an attacker would before one does.
Solutions
Web application and API protection
Converged WAF, API security, bot defense, and DDoS mitigation that enforce one consistent policy across every environment, closing the gaps that tool sprawl leaves open.
AI security
End-to-end protection for AI models, applications, and agents, from red teaming in development to runtime guardrails in production, across hybrid multicloud environments.
News and resources
Take action today

Security Summit: Security for the post-Mythos world
Frontier AI has fundamentally changed the vulnerability lifecycle. Models can now discover vulnerabilities at machine speed, and exploits increasingly appear before your security teams can patch them. Join F5 and industry leaders to discover best practices for securing apps, APIs, and models in the post-Mythos world.
Join us
Frequently asked questions
Frontier AI refers to the most advanced AI models available at a given time. In cybersecurity, it is used on both sides of the threat. Many models available broadly today are already very good at reverse engineering, web application penetration testing, red teaming, and vulnerability research. This is compressing the time between vulnerability discovery and exploitation, which collapses the patch window and leaves traditional patch cycles exposed. Models like Mythos and GPT-5.5-Cyber offer longer context windows, reduce safeguards that can limit security research, and can effectively use external tools to help attackers chain complex exploits across a codebase. F5's guidance is that there is no AI silver bullet; a WAF or WAAP is a key compensating control layer while your team patches your apps.
F5 uses frontier AI on both sides of the threat. It secures its own code using the latest frontier AI models to rapidly discover and fix vulnerabilities, and it delivers AI-powered runtime security across its portfolio to identify and block threats in real time, even when no patch exists yet. This pairs continuous code-hardening with data-path protection.
F5 shifts protection to the runtime layer in the data path, blocking threats before they reach your applications or APIs. Using AI-powered WAF, virtual patching, and real-time threat mitigation, F5 stops zero-days, AI-driven exploit chains, and unauthorized access. This acts as a key compensating control layer while your team patches your apps.
We harden F5 code with the same class of frontier AI models that attackers use, running a continuous five-step loop that ingests, analyzes, classifies, verifies, and fixes vulnerabilities at the source before they ship. The process is model-agnostic by design, so our security is never bound to a single vendor's model or release schedule, and findings are validated to remove noise rather than acted on blindly. We treat our position in your data path as the reason to hold a higher bar, not a lower one.
F5 secures AI at the inference layer, where the model executes and where traditional controls have no visibility. F5 AI Guardrails enforce real-time policy on prompts and responses to prevent data leakage and abuse, while F5 AI Red Team continuously probes your models for exploits and converts those findings into validated runtime guardrails. The same data-path enforcement that protects your applications extends to your APIs and agentic workloads, with consistent policy across hybrid and multicloud environments.

