What's new with F5 ADSP
Updated: May 2026
Big news
F5 Initiatives that are moving the needle
Top Media Coverage
F5 in the news
- Network World: F5 tackles AI security with new platform extensions
- Fierce Network: F5 CEO: AI is driving urban sprawl across enterprise IT
- CRN: F5 CEO On ‘The Most Exciting Time’ In Two Decades As AI Accelerates App Delivery, Security: Exclusive
- SiliconANGLE: F5 announces platform-wide upgrades including Insight observability and AI security tools
- CRN: F5, Forcepoint Take On Biggest AI Security Gaps With End-To‑End Data Protection Collaboration
- SC Media: F5’s Jimmy White on managing runtime risk in enterprise AI systems
Recognition spotlight
Awards and recognition within the industry
IDC coverage of F5 NGINXaaS for Google Cloud:
IDC published a report titled F5 Launches Managed Cloud-Native ADC as a Service on Google Cloud Key highlights include “F5 NGINXaaS for Google Cloud addresses the growing demand for advanced application delivery capabilities delivered as a managed cloud service. This announcement by F5 reflects a broader industry trend toward ADCaaS and platform-oriented consumption models for application infrastructure”


Zeus Kerravala of ZK Research
published an excellent article,The Convergence Crisis: Why AI Adoption Demands a New Architectural Footprint. Enterprises are fighting a two-front war pitting AI adoption against a fractured infrastructure landscape across form factors making scaling difficult and stalling innovation through this “complexity tax”.
Product releases
Noteworthy product improvements or launches
Application delivery
Future-ready modernization with BIG-IP v21.1 announced at AppWorld strengthens an already industry-leading feature set by introducing innovative new capabilities. GA release details in Q3 PBR newsletter.
Better BIG-IP interoperability and manageability with BIG-IQ 8.4.1. BIG-IQ can now centrally manage BIG-IP up to v17.5.1.X and 21.0. Overall, BIG-IQ 8.4.1 represents a major improvement to the solution’s security posture—helping customers operate BIG-IP estates, services, and workloads more securely.
F5NGINXaaS for Google Cloud: A fully managed load balancer and application delivery services solution built for teams looking to streamline application delivery and security in Google Cloud without the hassle of managing infrastructure. Whether deploying APIs, microservices, web apps, or AI inference workloads, organizations can rely on F5 NGINXaaS (https://www.f5.com/products/nginx/f5-nginxaas-for-google-cloud) to deliver seamless performance, improved visibility, flexible customization, and enhanced security at scale. while eliminating operational complexity.
New Kubernetes hub launched: kubernetes.nginx.org brings together resources, tools, and guidance for running NGINX on Kubernetes
Simplified migration from ingress-nginx: New migration tool provides a guided path to move to NGINX Ingress Controller
Modernization to Gateway API made easier: ingress2gateway tool helps teams transition to Gateway API and NGINX Gateway Fabric
Gateway API 1.5 Conformance: Conforms NGINX Gateway Fabric to Kubernetes Gateway API 1.5 specifications to ensure compatibility with the latest Gateway API standards. This release makes us one of the few vendors to meet this standard.
NGINX OSS agentic observability enables real-time monitoring for MCP traffic directly in the data plane. It equips teams to gain real-time visibility into all AI agents—known or shadow—with MCP server tracing, latency, throughput, and error analysis. Coming soon to NGINX Plus.
General Availability of CrowdStrike Falcon for BIG-IP: This integration embeds CrowdStrike’s industry-leading Falcon sensor directly onto BIG-IP platforms or F5 systems, providing behavior-based endpoint detection and response (EDR), unified visibility, and improved regulatory compliance.
AI data delivery: First validated AI data delivery performance metrics are now available, with SecureIQLab validating up to 332% higher S3-compatible storage throughput with F5 BIG-IP and MinIO, giving F5 a concrete proof point for improving storage-to-compute performance in AI environments. Read the new report here.
Application security
AI Red Team’s model risk registry brings in CASI leaderboard data, enriching reports so customers can compare their AI system to all models tested (approx. 50) every month.
AI Guardrails’ agent fingerprints gives customers the ability to view the thoughts, actions, and behaviors of their agents (currently compatible with the OpenAI Chat Completions API) to understand actions, tool access, and decision-making.
AI Remediate connects AI Red Team and AI Guardrails by automatically turning prioritized adversarial findings into validated, optimized runtime protections. This capability is currently EA, available to customers with both AI Red Team and AI Guardrails.
Future-ready security and modernization with BIG-IP v21.1 announced at AppWorld strengthens an already industry-leading feature set by introducing innovative new capabilities. GA release details in Q3 PBR newsletter.
Virtual Patching with Distributed Cloud Web App Scanning and BIG-IP Advanced WAF: Integrating Web App Scanning and Advanced WAF enables scalable, automated vulnerability detection for BIG-IP customers, allowing SecOps to identify threats through automated penetration testing and rapidly deploy precise virtual patches. This integration streamlines vulnerability detection and exploit response, reducing time to protection.
API Security
Out-of-band API Discovery for BIG-IP Enhancement: API discovery integration with BIG-IP now allows for greater scale and resiliency, supporting integration with up to 100 virtual services per customer edge (CE) node, substantially expanding scalability to support API Discovery across larger BIG-IP estates. It also supports integration with BIG-IP high-availability (HA) pairs, through service discovery, providing automatic failover to new
active BIG-IP instances in fail over scenarios for greater continuity in API discovery in the event of a BIG-IP failover, ensuring API visibility.
Support for API Discovery for NGINX Ingress Controller: Introducing improved API Discovery for North-South traffic in Kubernetes clusters through integration with
NGINX Ingress Controller, allowing for out-of-band integration, and automatic identification and cataloging of APIs exposed via NGINX, providing complete visibility into external-to-internal API endpoints.
OWASP API Top 10 Vulnerability Mapping: Enhanced vulnerability reporting with OWASP API Top 10 mapping, including an OWASP label to provide clearer security context and standardized classification aligned with industry-recognized guidance, strengthening reporting consistency across dashboards and simplifying communication between security, development, and compliance teams.
OWASP API8 Security Misconfiguration - Stronger Protection Against API Misconfigurations: Enhanced API vulnerability detection delivers greater peace of mind by proactively identifying and addressing critical security misconfigurations in API responses, including automatic detection of missing TLS and crucial headers like X-Frame-Options, Content-Security-Policy (CSP), and Cache-Control.
OWASP API1 BOLA – Enhanced Protection Through Expanded JWT User Identification Across All Supported Locations and Query Parameter Coverage: Offering even greater API security extending Broken Object Level Authorization (BOLA) detection by helping organizations identify users and resources more comprehensively, plus providing greater context into the relationship between users and resources they are trying to access.
The November 2025 release enhances self-serviceability, search and filtering, and mitigation management. Details available in the release blog.
Expanded Vertical DDoS Detection and Mitigation: Enhanced vertical DDoS detection and mitigation capabilities has been designed to protect against sophisticated "Carpet Bombing" attacks, providing earlier, clearer visibility into these attacks that often go unnoticed due to their distributed nature. It ensures that multiple low-volume attacks across an IP range are quickly identified and addressed.
Enhancements to Routed DDoS Mitigation Analytics and Reporting: Gain deeper insights and greater visibility with upgraded reporting and DDoS attack analytics, delivering more robust, actionable insights to better understand and manage security posture.
Malware Detection: Enhanced File Size Support: Malware protection improves detection and protection capabilities to protect larger files, providing greater security posture flexibility and enabling comprehensive malware protection across a
wider range of file sizes.
Delivers robust new capabilities for defending applications against DDoS attacks. DDoS mitigation is now more flexible, with customer-configurable thresholds for Layer 7 detection, support for CAPTCHA and JavaScript challenges as protection actions, and expanded visibility into L3 / L4 events for managed load balancers. Rate limiting has been enhanced with persistent and timeout-based blocking, and denylist management is now streamlined for easier identification of duplicate entries.
Distributed Cloud Bot Defense for Agentic AI: Distributed Cloud Bot Defense now offers deeper visibility across application traffic, distinguishing humans, bots, and AI agents. Only trusted, verifiable AI agents are allowed to interact with applications, ensuring malicious or ungoverned activity is blocked while enabling safe, controlled agentic commerce. These new capabilities help organizations participate in the emerging agentic economy while safeguarding revenue from malicious automation.
Simplified Mobile Bot Defense Onboarding: Customers can access the
SDK along with required base configuration file, enabling independent integration into the mobile SDKs for iOS and Android, simplifying the onboarding process for Bot Defense for Mobile.
Simplified API Mode onboarding for Policy Management: Customers using API mode can manage and deploy policies directly through the Distributed Cloud console, allowing greater management efficiency for endpoints.
AI-Enabled Risk Scoring: Delivers outcome-based threat detection, reducing manual policy tuning and enabling faster, safer enforcement with improved accuracy. It combines signatures, attack indicators, and Machine Learning (ML) to assess request risk, assigning each request a High, Medium, or Low risk level, enabling risk-based blocking policies to be deployed with confidence, drastically reducing manual policy tuning and operational overhead. It empowers faster, safer transitions to blocking mode, minimizing false positives, enhancing detection of advanced threats, and delivering consistent protection across distributed environments.
XOps
F5 Insight for ADSP is now generally available. This observability and operational strategy solution provides unified visibility—built by F5 experts—that spans apps, delivery and security services, and infrastructure. It helps operational teams understand each other better and collaborate more effectively with actionable intelligence that spans the entire app stack. Best of all, it provides AI-generated guidance and natural language interactions to help ops teams answer tough questions, pinpoint bottlenecks and threats, build data-backed action plans, and prioritize to-do lists.
SOLUTIONS
Our solutions, powered by the F5 Application Delivery and Security Platform (ADSP), help you deliver and secure every application and API—anywhere. Backed by decades of expertise and a vibrant partner ecosystem, we meet you where your apps run and help you deliver exceptional experiences every time.
