Not long ago, enterprise AI was largely about helping people work faster. Employees used copilots to write code, summarize information, generate content, and answer questions. Then AI moved deeper into the enterprise, powering internal assistants and customer-facing applications.
Now we are entering a fundamentally different phase. Agentic AI systems don't just answer questions. They can browse, retrieve data, call APIs, invoke tools, execute workflows, and take actions, sometimes with little or no human involvement.
That's an extraordinary leap in capability. It’s also an extraordinary expansion of the attack surface, a topic I address in my presentation, “Securing AI in production,” in the F5 Post-Mythos Security Summit, which F5 is offering on-demand though Oct. 31.
“AI is becoming more capable, more connected, and more autonomous. The question isn't whether that will expand your attack surface. It's whether your security strategy will expand with it.”
When AI can act, behavior becomes the attack surface
Traditional applications are relatively predictable. Give them the same input under the same conditions and you generally expect the same output. Security teams have spent decades developing ways to protect the infrastructure, applications, APIs, identities, and data surrounding those interactions.
AI changes that equation because its behavior can be nondeterministic. With AI applications, behavior itself becomes part of the attack surface.
Consider everything involved in a modern AI interaction: prompts, models, enterprise data, APIs, retrieval-augmented generation (RAG) systems, tools, agents, and the actions those agents take. Every connection creates another place where something can go wrong or where an attacker can attempt to manipulate the system.
The risks are many. Prompt injection can influence how an AI system behaves, excessive agency can allow an agent to take actions beyond what was intended, and insecure Model Context Protocol (MCP) servers and unauthorized tool use can introduce additional paths to sensitive systems and data. Meanwhile, RAG workflows can be manipulated, and AI applications can expose sensitive information or generate harmful or inappropriate outputs.
All of these risks add to the security challenges organizations already face. As AI evolves from copilots to customer-facing applications to autonomous agents, organizations carry existing risks forward while adding new ones.
One technology shift, two expanding attack surfaces
Here is another reason this problem is becoming so difficult: Organizations aren't dealing with a single AI attack surface.
The first is the AI that people, and increasingly agents, are already using. Third-party AI services have made powerful models and tools readily accessible across the enterprise. Employees are under pressure to use AI to work faster and more efficiently, often without understanding what information they may be exposing or what risks a particular AI service introduces.
Simply blocking AI isn't a realistic answer. People find workarounds, and organizations risk pushing AI usage further outside the visibility of security and IT teams.
The second attack surface is the AI that organizations themselves are building and deploying. Here, the potential exposure stretches across applications, models, prompts, agents, APIs, tools, enterprise data, and the interactions among them.
Some failures may happen without an attacker ever entering the picture: an unsafe output, sensitive information inadvertently revealed, or an agent calling a tool it shouldn't. Others are deliberate attacks designed to manipulate models, poison knowledge sources, extract information, or cause agents to take unintended actions.
From the perspective of a customer, regulator, or security team, the consequences can look remarkably similar.
AI security can't become the price of AI innovation
This creates a difficult challenge for security leaders. Organizations want to move quickly with AI, and increasingly they need to. But every new AI application, agent, model, tool, and connection can introduce risks that traditional security approaches weren't designed to address.
To address these issues, organizations need increased visibility and control across these expanding AI attack surfaces, while allowing the business to keep moving. They need to protect AI interactions wherever they occur, address both accidental and adversarial behavior, and apply appropriate controls without creating another obstacle to AI adoption.
At F5, we believe there is a way to do that. We've developed an approach designed to help organizations discover, test, govern, and protect AI across the applications they build and the AI their workforce uses, while providing controls at the points where AI interactions actually occur.
I'll dig into that approach at the F5 virtual Post-Mythos Security Summit in my session, “Your AI is now an attack surface.” We'll look at how the AI threat landscape is changing, what organizations need to protect as AI becomes increasingly agentic, and how F5 can help organizations secure AI apps, models, agents, tools, APIs, and data without standing in the way of adoption.
AI is becoming more capable, more connected, and more autonomous. The question isn't whether that will expand your attack surface. It's whether your security strategy will expand with it.
Join me at the F5 Post-Mythos Security Summit to learn how to take control of the new AI attack surface.
About the Author
Related Blog Posts

Securing the new control points in the AI journey
AI architecture is fundamentally different than traditional IT environments and requires a different security strategy to protect critical AI workloads.

The patch window has closed. Here is how F5 is built for what comes next.
As AI models have changed software security, the industry needs to adapt.

Best practices for optimizing AI infrastructure at scale
Optimizing AI infrastructure isn’t about chasing peak performance benchmarks. It’s about designing for stability, resiliency, security, and operational clarity

Datos Insights: Securing APIs and multicloud in financial services
New threat analysis from Datos Insights highlights actionable recommendations for API and web application security in the financial services sector

Secrets to scaling AI-ready, secure SaaS
Learn how secure SaaS scales with application delivery, security, observability, and XOps.

How AI inference changes application delivery
Learn how AI inference reshapes application delivery by redefining performance, availability, and reliability, and why traditional approaches no longer suffice.