F5 advances enterprise application security for AI and the post-quantum era

Applications of AI


New security innovations in F5 application delivery and security platform unify AI-driven protection, zero trust access, and post-quantum readiness across hybrid multicloud environments

LAS VEGAS – (BUSINESS WIRE) – Today at AppWorld, F5 (NASDAQ: FFIV), the global leader in delivery and security for all apps and APIs, announced new security features to better protect modern AI-driven applications. Integrated within the F5 Application Delivery and Security Platform (ADSP), this innovation brings together intelligent threat protection, zero trust access control, and crypto-agile architecture to help enterprises secure distributed applications and prepare for new post-quantum risks.


“Security teams don’t need more alarms; they need fewer gaps,” said Kunal Anand, chief product officer at F5. “ADSP closes the loop from risk discovery to protection enforcement, including moving from identified AI model vulnerabilities to validated runtime guardrails, AI-powered risk scoring, and a practical path to zero trust and post-quantum readiness. The point is simple: move faster while mitigating the threat landscape.”

AI-driven protection against modern threats

As organizations extend applications across data centers, hybrid multicloud, and edge environments, they require faster, more intelligent responses to emerging threats. F5 addresses this issue through AI-powered protection in F5 ADSP, automating risk-based web application firewall (WAF) capabilities to reduce operational overhead, improve threat detection, and bridge the gap between risk identification and mitigation.

F5 AI Remediate, a new feature in F5 ADSP, bridges the gap between identifying vulnerabilities in AI models with the F5 AI Red Team and enforcing validated runtime protections with F5 AI Guardrails. AI Remediate accelerates response time by automating the creation, optimization, and validation of targeted guardrail packages, enabling security teams to deploy evidence-backed protections into production with human approval. As part of ADSP, AI Remediate helps organizations quickly mitigate exposure without disrupting live AI applications and eliminate repetitive tasks while supporting responsible AI adoption.

Additionally, the latest F5 Distributed Cloud WAF release introduces AI-powered risk scoring, turning manual processes into automated protection. Results-based blocking policies enable CISOs, SecOps, and NetOps teams to eliminate threats, reduce operational burden, and accelerate time to protection while maintaining low false positive rates through layered analysis. These F5 Web Application and API Protection (WAAP) solutions minimize dependence on signature-level exceptions and cumbersome tuning for enterprises with critical application portfolios. Whether you’re protecting on-premises hardware or virtual systems, cloud-based SaaS applications, or containerized deployments, F5 delivers consistent enterprise-grade security across your entire ecosystem.

Security in the age of agent AI

F5 is introducing powerful capabilities within F5 Distributed Cloud Bot Defense to address the emerging challenges of AI-driven automation. These enhanced capabilities combat threats that increasingly impact both users and businesses, such as analytical distortions, automated exploitation, and attempts to impersonate AI agents.

Within F5 ADSP, Distributed Cloud Bot Defense now provides deeper visibility into your entire application traffic and clearly differentiates between humans, bots, and AI agents. Only trusted and verifiable AI agents are allowed to interact with your application, ensuring malicious or uncontrolled activity is blocked while enabling secure and controlled agent commerce. These new capabilities help organizations protect their bottom line from harmful automation and confidently participate in the emerging agent economy with unified governance and consistent policy controls for human, bot, and AI agent interactions.

ADSP has also integrated F5 Distributed Cloud Web App Scanning with F5 BIG-IP Advanced WAF to provide scalable, automated vulnerability detection for BIG-IP customers. Security teams can identify threats through automated penetration testing and quickly deploy accurate virtual patches. This integration streamlines vulnerability detection and exploit response, reducing time to protection. This approach demonstrates the benefits of F5’s platform: integrated security across hardware, software, and SaaS, providing unparalleled flexibility to protect applications and APIs in any environment.

Unified zero trust across hybrid multicloud environments

F5 has evolved the BIG-IP Access Policy Manager (APM) to BIG-IP Zero Trust Access, highlighting Zero Trust Application Access (ZTAA) capabilities as part of ADSP. Unlike SaaS-based Zero Trust Network Access (ZTNA) solutions, BIG-IP Zero Trust Access provides hybrid Zero Trust operations that continuously enforce identity and context-aware policies for modern cloud, SaaS, and legacy applications. Support Identity Aware Proxy, SSL VPN, or IPsec VPN on post-quantum cryptography (PQC)-enabled platforms with per-request validation that limits lateral movement to strengthen application security across diverse access environments. BIG-IP Zero Trust Access provides a seamless path to deploying Zero Trust principles while extending F5’s ADSP vision.

New API discovery and security options within F5 Distributed Cloud API Security provide flexibility and control for modern hybrid application environments. Enhancements include out-of-band detection across multiple data planes including BIG-IP, NGINX, Kong, and Apigee. In addition, F5 also introduces deployable API security software solutions for air-gapped, highly regulated, and cloud-constrained environments. This enables organizations to maintain full visibility and monitoring of their APIs without external connectivity and meet compliance and data sovereignty requirements. By seamlessly integrating with your existing architecture, F5 extends your ADSP vision with API discovery and security that fits any environment without disrupting application performance or workflow.

Building for the Next: Cryptographic Agility and Post-Quantum Readiness

F5 extends its leadership in PQC readiness by offering a comprehensive cryptographic agile solution within an integrated ADSP. By supporting a hybrid TLS cipher group, F5 provides instant post-quantum security while maintaining compatibility with existing cryptographic workflows, ensuring a practical, standards-compliant approach to future-proofing against quantum threats. As organizations continue to prepare for the ultimate Q-Day by addressing quantum safety requirements, F5 is now proactively enabling seamless quantum resilience, minimizing long-term risk and supporting security across hybrid infrastructures.

Taken together, F5’s latest security advances deliver on ADSP’s promise of seamless application delivery and robust cybersecurity across any deployment scenario. Businesses benefit from adopting an integrated platform approach to meeting their security needs.

According to Gartner®“Organizations should start by evaluating platform solutions, and many will find that they need to combine an API gateway with a CDN, WAF, or API threat protection solution. Again, the key is to look for existing platforms that are extensible, or new platforms that offer significant combination capabilities across protection categories. This approach minimizes the number of moving parts and prevents ‘proxy overload’, which can lead to excessive performance and availability risks.”1

F5’s platform-based approach gives enterprises the broadest choice to address users wherever they operate, reducing complexity and time-to-action while securing applications across hybrid cloud, multicloud, edge, or on-premises ecosystems. For more information, please see additional press releases focused on F5 ADSP.

Support material

About F5

F5, Inc. (NASDAQ: FFIV) is the world leader in delivering and securing every app. Backed by 30 years of expertise, F5 built the industry’s best platform, the F5 Application Delivery and Security Platform (ADSP), to deliver and secure any app, any API, anywhere, across on-premises, cloud, edge, hybrid, and multicloud environments. F5 is committed to innovating and partnering with the world’s largest and most advanced organizations to deliver fast, highly available, and secure digital experiences. Together, we help each other prosper and create a better digital world.

For more information, please visit f5.com.
Learn more about F5 Labs threat research at f5.com/labs.
To learn more about F5, our partners, and our technology, follow us below.

Blog | LinkedIn | X | YouTube | Instagram | Facebook

F5, BIG-IP, and NGINX are trademarks, service marks, or trade names of F5, Inc. in the United States and other countries. All other product and company names mentioned herein may be trademarks of their respective owners.

Gartner is a trademark of Gartner, Inc. and/or its affiliates.

[1] Gartner, Implementing Effective Application and API Security Management, April 10, 2025

###

Source: F5 Co., Ltd.

contact address

Dan Sorensen

F5

(650) 228-4842

[email protected]

holly lancaster

we. communication

(415) 547-7054

[email protected]





Source link