Stay current to protect your environment with F5 Hardened Releases.Learn more

How to select the right AI and application security partner

F5 Ecosystem | October 02, 2026

The integration of AI into applications has made it harder than ever to choose a cybersecurity partner. And unfortunately, organizations can’t delay that choice. Attackers, equipped with AI tools themselves, are finding and exploiting vulnerabilities faster than ever before.

There is no shortage of AI-enhanced apps to attack. According to the F5 2026 State of Application Strategy Report, 98% of organizations are preparing for agentic AI. However, 77% of those same organizations anticipate challenges managing AI agent access. And only 28% report streamlining developer workflows through a single AI management point.

This gap between AI adoption and AI security raises an important question: How should organizations extend application security to protect AI-enabled applications? To answer that question, it helps to understand where traditional application security remains essential and where AI introduces new security requirements.

The evolution of application security fundamentals

Application security protects applications and APIs from vulnerabilities, malicious traffic, abuse, and unauthorized activity. At runtime, organizations use controls such as web application firewalls (WAFs), API security, bot management, and distributed denial-of-service (DDoS) mitigation to protect applications and the services they expose.

Modern software architectures have made these processes more complex. Today’s apps are composed of numerous smaller services that communicate via APIs. These services are frequently spread out across multiple public cloud providers, on-premises data centers, and edge locations. Each connection along the way represents a possible entry point for attackers.

Modern web application and API protection (WAAP) commonly brings together four core runtime controls:

  • WAFs: Inspect HTTP and HTTPS traffic, and help block application-layer attacks before they reach applications.
  • API security: Discover and protect APIs, including shadow and unmanaged endpoints, while identifying malicious or abusive API activity.
  • Bot management: Distinguish legitimate automation from malicious bots and help prevent scraping, credential stuffing, account takeover, and other automated abuse.
  • DDoS mitigation: Protect application availability against attacks designed to overwhelm applications and services.

AI-enabled applications introduce risks that traditional application security controls were not designed to address. Protecting them requires more than adding new rules to an existing WAF.

Traditional application security controls primarily evaluate protocols, requests, code, traffic patterns, and known attack techniques. AI introduces an additional challenge: malicious instructions can be delivered through syntactically valid natural-language prompts, meaning security controls must also understand context and intent.

This new attack approach means that organizations need to place purpose-built controls around AI prompts and responses, sensitive data, model access, and agent and tool interactions, while also governing how AI is used across the workforce.

How application security extends to AI

Traditional application security technologies remain essential for AI-enabled applications, but their role differs from purpose-built AI security. Here’s how common approaches fit into the broader security architecture. For a deeper comparison of specific companies and their capabilities, click here.

Cloud-native WAFs

Cloud-native WAFs continue to protect the web application and API layer, but traditional WAF inspection alone does not address many AI-specific threats. Some cloud providers therefore pair their WAF capabilities with separate AI security services that inspect prompts and responses, detect prompt injection and jailbreak attempts, protect sensitive data, and enforce AI-specific guardrails.

Advantages

  • Native infrastructure integration: WAFs offered by cloud providers typically enable native integration with that cloud provider’s ecosystem, making it simple to deploy and manage the firewalls.
  • Security integration: Cloud-based WAFs can frequently be integrated with other AI and traditional cybersecurity capabilities as part of a defense-in-depth strategy. For example, you could add DDoS mitigation, bot management, and other services easily.
  • Global networks: Cloud providers often have large global networks, which help identify malicious activity and reduce latency for threat mitigation efforts. In addition, cloud providers and cybersecurity vendors often have research labs that provide daily threat intelligence to inform WAF rules.

Drawbacks

  • Closed ecosystem: WAFs offered by cloud providers mainly protect applications and AI workloads that live in their clouds.
  • Deployment constraints: Cloud-native WAFs are not always the right option for organizations with multicloud or hybrid environments.
  • Network complexity: When traffic is sent through a provider’s network, threats or other application issues can be difficult to uncover. For example, you might need to explore network configurations, DNS settings, caching behavior, or the application itself to discover a root cause.
  • Pay-as-you-go pricing: When providers charge by the number of rules or add-ons selected, it can be difficult to forecast expenses.

Application delivery and security platforms

Application delivery and security platforms help organizations consistently deliver, optimize, and protect applications and APIs across distributed environments. Some vendors are extending these platforms with AI gateway and AI security capabilities to manage inference traffic, govern model and agent access, and apply AI-specific security controls.

Advantages

  • Deployment flexibility: Some of these application delivery protection solutions are available as on-premises appliances, in the cloud, and in hybrid configurations.
  • Hybrid security model: These solutions might offer hybrid security that employs both signature-based attack detection and a positive security model, which learns typical application behavior and then identifies anomalies.
  • Multi-layer security: Application delivery protection solutions can often be integrated with other security offerings, such as WAFs as well as bot management, runtime visibility, DDoS mitigation, and API security tools.
  • Third-party integration: Some solutions can be integrated with third-party WAFs, allowing organizations to extend capabilities while avoiding vendor lock-in.

Drawbacks

  • Standalone limitations: Despite third-party integrations, some solutions are best for teams that are already using that provider for app delivery. If you only need security, opting for these solutions can introduce excessive costs and unneeded complexity.
  • Add-on costs: Some vendors offer capabilities such as API discovery or managed services only as paid add-ons, increasing total costs.

F5 AI Security Platform

The F5 AI Security Platform brings together discovery, governance, testing, and runtime protection across enterprise AI. F5 Workforce AI Security provides visibility into sanctioned and unsanctioned AI use, including the models, tools, prompts, and data being used across the workforce. F5 AI Gateway provides a control point for governing access to AI models, agents, and tools. F5 AI Red Team uses adversarial testing to identify vulnerabilities and weaknesses in AI systems, while F5 AI Guardrails enforces policies during AI interactions to help prevent sensitive data leakage, malicious activity, and policy violations.

Together, these capabilities extend application security to the new control points introduced by AI. The F5 AI Security Platform extends the F5 Application Delivery and Security Platform (ADSP) strategy to enterprise AI, bringing purpose-built AI security together with F5’s established application and API security capabilities.

Top features:

  • Continuous testing: Red teaming finds vulnerabilities and automatically remediates them.
  • Runtime protection: Teams can enforce guardrails to defend against runtime threats, such as prompt injection and jailbreaking.
  • Simplified policy creation: Natural language capabilities enable teams to easily author customized policies and controls.
  • AI workforce security: Organizations can uncover shadow AI, classify workflows by intent, and govern usage with enforceable controls.

The AI Security platform is an essential component of the F5 Application Delivery and Security Platform (ADSP), which provides advanced security and traffic management for apps and APIs. Deployable anywhere, the platform enables organizations to integrate AI security into application security without adding complexity.

Frequently asked questions

Can a WAF protect an AI application?

A WAF remains an important part of protecting an AI-enabled application because the application and its APIs are still exposed to traditional web attacks. However, WAF protection alone does not address AI-specific risks such as prompt injection, jailbreaks, malicious model outputs, or unsafe agent behavior. Organizations need AI-specific security controls alongside traditional web application and API protection.

How does AI security complement application security?

Application security protects the applications, APIs, and traffic that support AI systems. AI security adds controls designed specifically for the AI layer, including adversarial testing of models and agents, inspection of prompts and responses, protection against prompt injection and data leakage, governance of model and tool access, and visibility into enterprise AI use.

How does the integration of AI affect application security?
Securing AI-enabled applications requires more than adding new rules to a web application firewall (WAF). Traditional application and API security remains essential, but AI introduces additional risks at the model and interaction layers. Organizations also need to place guardrails around AI prompts and responses, test models and agents against adversarial attacks, govern access to models and tools, protect sensitive data, and maintain visibility into how AI is being used across the enterprise.

Learn more about the F5 AI Security Platform.

Share

About the Author

Louise Scully
Louise ScullySr. Mgr., PMM, AI Security & Threat Intelligence | F5

Louise Scully is a Senior Manager in Product Marketing for AI Security and Threat Intelligence at F5. Her career has spanned product marketing, product management, go-to-market strategy, communications, thought leadership, and category development across AI security and enterprise technology. Prior to joining F5, Louise led marketing at both CalypsoAI and Artomatix, helping bring AI technology and research to market.

More blogs by Louise Scully

Related Blog Posts

A new path to technical excellence for F5 partners
F5 Ecosystem | 07/21/2026

A new path to technical excellence for F5 partners

Introducing F5 Partner Foundations, a structured learning curriculum to build F5 partner engineer expertise with a clear pathway to specialization.

Secure-by-design storage for agentic AI: Why runtime visibility plus traffic control matters
F5 Ecosystem | 05/31/2026

Secure-by-design storage for agentic AI: Why runtime visibility plus traffic control matters

Learn how F5 is collaborating with NVIDIA to help protect agentic AI with secure-by-design AI infrastructure, runtime visibility, and traffic control.

Why sub-optimal application delivery architecture costs more than you think
F5 Ecosystem | 01/29/2026

Why sub-optimal application delivery architecture costs more than you think

Discover the hidden performance, security, and operational costs of sub‑optimal application delivery—and how modern architectures address them.

Architecting for AI: Secure, scalable, multicloud
F5 Ecosystem | 01/20/2026

Architecting for AI: Secure, scalable, multicloud

Operationalize AI-era multicloud with F5 and Equinix. Explore scalable solutions for secure data flows, uniform policies, and governance across dynamic cloud environments.

AppViewX + F5: Automating and orchestrating app delivery
F5 Ecosystem | 12/19/2025

AppViewX + F5: Automating and orchestrating app delivery

As an F5 ADSP Select partner, AppViewX works with F5 to deliver a centralized orchestration solution to manage app services across distributed environments.

F5 NGINX Gateway Fabric is a certified solution for Red Hat OpenShift
F5 Ecosystem | 11/11/2025

F5 NGINX Gateway Fabric is a certified solution for Red Hat OpenShift

F5 collaborates with Red Hat to deliver a solution that combines the high-performance app delivery of F5 NGINX with Red Hat OpenShift’s enterprise Kubernetes capabilities.