Most organizations didn't plan their generative AI rollouts. A team stood up a chatbot, another connected a model to internal data, and now there's an agent quietly calling tools in production. Somewhere in that sprint from pilot to deployment, security was left to catch up.
That's the gap F5’s white paper, Securing GenAI: A 30-60-90 Day Framework, is built to close. Instead of treating AI security as a procurement checkbox or a one-time audit, our framework lays out a sequenced, 90-day path that takes teams from securing a single application to running a fleet-wide program to defending autonomous agents.
So what does this framework look like?
Day 0-30 is about discipline, not deployment speed
The temptation with any new GenAI application is to ship it. Yet our AI security framework calls for a different first move: treat model selection, red teaming, and guardrail design as the real work of the first 30 days, not friction to push through.
That means red-teaming the bare model to establish a security baseline, building the application on top of it, and then red-teaming the combined system to see whether the application made things more secure or less. It also means building guardrails across four distinct categories—existing regulations, AI-specific regulations, use-case threats, and red-team findings—so nothing gets missed because it didn't fit neatly into one bucket.
The output of this first phase is a repeatable loop: when a new zero-day threat surfaces, red team again, patch the guardrails, validate, and redeploy.

Day 30-60 turns one secured app into a program
Securing one application well is a good outcome. Securing 20 applications the same way, on the same cadence, with the same auditability, is a different problem entirely. This is where most organizations stall.
Our framework includes four pillars that turn ad-hoc security work into a scalable program:
- Defined red-team cadences tied to risk tier
- Establish a guardrail patch pipeline that can roll updates out (and back) across many applications at once
- Create a fleet-wide zero-day response process with real SLAs
- Provide SOC enablement so security operators can investigate AI incidents with the same fluency they bring to any other threat
This second phase is complete when an organization can answer, for every AI application, who owns it and when it was last tested.
Day 60-90 confronts a fundamentally different risk
Autonomous agents don't just respond to questions. They run continuously, reason through multi-step plans, and take real actions through tools. This means the security model built for request-and-response applications doesn't transfer cleanly.
Our framework's answer centers on two ideas. First, observability has to extend beyond logging outcomes to logging reasoning: every thought, tool call, and decision an agent makes, tied together so a post-incident review can reconstruct not just what happened, but how. Second, when an agent's reasoning veers somewhere risky, simply blocking that thought tends to break the agent mid-task. The framework instead points to thought injection—replacing a risky thought with a safer one that keeps the agent productive—paired with action-level controls like tool permissions and approval gates for high-impact moves. GenAI security isn't a single milestone you hit and move past. It's an operating rhythm that this framework is built to help security teams establish before the gaps in their AI deployments turn into incidents.
Read our white paper for the complete 30-60-90 day framework, including the Phase 1-3 checklists your team can put to work right away. Also, be sure to register for our upcoming webinar.
About the Authors

James White is an accomplished engineer and business leader with nearly two decades of experience in the enterprise software industry.
More blogs by James White
Related Blog Posts

Securing the new control points in the AI journey
AI architecture is fundamentally different than traditional IT environments and requires a different security strategy to protect critical AI workloads.

The patch window has closed. Here is how F5 is built for what comes next.
As AI models have changed software security, the industry needs to adapt.

Best practices for optimizing AI infrastructure at scale
Optimizing AI infrastructure isn’t about chasing peak performance benchmarks. It’s about designing for stability, resiliency, security, and operational clarity

Datos Insights: Securing APIs and multicloud in financial services
New threat analysis from Datos Insights highlights actionable recommendations for API and web application security in the financial services sector

Secrets to scaling AI-ready, secure SaaS
Learn how secure SaaS scales with application delivery, security, observability, and XOps.

How AI inference changes application delivery
Learn how AI inference reshapes application delivery by redefining performance, availability, and reliability, and why traditional approaches no longer suffice.

