20 Aug 2026
In Part One of this series, we explored the forces driving AI security urgency – regulatory pressure, the rise of agentic AI, and a threat landscape evolving faster than traditional defences. In this post, we turn to the practical question: what does an effective AI security architecture actually look like, and how do organisations build one without slowing down innovation?
The answer lies in understanding three distinct but interconnected security domains: runtime protection, adversarial testing, and continuous observability. Let us examine each in detail.
Domain 1: AI Runtime Security – Guardrails That Go Beyond the Model
Most AI models come with some form of built-in safety features – system prompts, content filters, and fine-tuning designed to prevent harmful outputs. These are necessary but insufficient. Enterprise AI deployments require an additional layer of runtime security that sits between users, applications, and the AI model itself.
This is where AI guardrails come in. Unlike model-level safety features, enterprise AI guardrails are configurable, auditable, and enforcement-focused. They operate on several dimensions:
- Threat detection and blocking: Identifying and stopping prompt injection attempts, jailbreak patterns, and adversarial inputs in real time before they reach the model. F5 AI Guardrails maintains a library of over 10,000 adversarial attack patterns, updated monthly, giving enterprises protection against emerging techniques without requiring manual signature updates.
- Data loss prevention (DLP) at the AI layer: Scanning both inputs and outputs for sensitive data – PII, financial data, proprietary information, regulated health data – and enforcing configurable policies. This is critical for GDPR compliance and for preventing inadvertent data exposure through AI responses.
- Governance and compliance controls: Enforcing organisational policies, role-based access, and content moderation filters. Preset templates for GDPR, HIPAA, and the EU AI Act simplify compliance documentation and audit readiness.
- Low-latency enforcement: Runtime security must not create user-experience bottlenecks. Effective guardrail solutions use dynamic model routing and optimised inference paths to maintain performance while enforcing security policies.
Critically, enterprise-grade guardrails must be model-agnostic. Organisations are increasingly running multiple models – proprietary, open-source, and third-party API-based – across different environments. A guardrail solution that works only with specific models creates coverage gaps. F5 AI Guardrails is designed to protect any model, in any environment, including on-premises, air-gapped, private cloud, and hybrid deployments – an important differentiator for organisations with data sovereignty requirements in Germany, France, or the Middle East.
SecureIQLab independently tested F5 AI Guardrails against 19,679 adversarial test cases across 10 attack categories – validating its efficacy against real-world AI threats at scale.
Domain 2: AI Workload Vulnerability Testing – Red Team at Machine Speed
No security architecture is complete without continuous testing. For AI systems, this means adversarial red-teaming: systematically probing the AI with attack scenarios to identify vulnerabilities before attackers do.
Traditional penetration testing approaches – periodic, manual, and scope-limited – are fundamentally mismatched to the pace of AI development. Teams ship new model versions, update prompts, and change integrations frequently. Each change can introduce new vulnerabilities. Manual red-teaming simply cannot keep pace.
F5 AI Red Team addresses this with agentic, automated adversarial testing. It works by:
- Continuously probing AI models and agents with the latest attack patterns, drawn from a library of 10,000 scenarios that is updated monthly.
- Translating findings directly into active guardrail configurations – closing the loop between vulnerability discovery and protection deployment.
- Providing explainable results that security teams can understand, document, and present to auditors and regulators.
- Covering the OWASP Top 10 for LLMs, including prompt injection, insecure output handling, training data poisoning, and excessive agency.
The ability to automatically convert red team findings into deployed guardrails is a significant operational advantage. It eliminates the delay between knowing about a vulnerability and acting on it – a delay that, in fast-moving threat environments, can be the difference between prevention and breach.
Domain 3: AI Observability – See Everything, Act on What Matters
AI security requires a level of observability that goes beyond conventional logging. Security teams need to understand not just what an AI system is doing, but why – what inputs led to what decisions, what data was accessed, and where anomalies are emerging across the entire AI attack surface.
This is especially important for agentic AI, where a single orchestration flow can involve dozens of tool calls, API interactions, and model invocations. A security event in an agentic workflow may not look like a conventional security alert – it may appear as an unusual sequence of legitimate-seeming actions.
F5's approach to AI observability includes:
- Full traceability of AI interactions: Every prompt, every response, every tool call – with contextual metadata for forensic analysis.
- API discovery and monitoring: Continuously identifying AI-connected APIs and monitoring them for anomalous behaviour using ML-driven analytics.
- Shadow AI detection: Surfacing unsanctioned AI usage within the organisation, giving security teams visibility into risks they did not know existed.
- Integration with the F5 Application Delivery and Security Platform: Correlating AI security signals with broader application and network security data for unified risk management.
The Upgrade Path: From AI Security to Comprehensive AI Infrastructure Protection
For organisations already running F5 solutions – BIG-IP, NGINX, Distributed Cloud Services – F5 AI Security is a natural extension of an existing investment. The platform integration means:
- Existing WAF and API security policies can be extended to cover AI endpoints, without rebuilding security architectures from scratch.
- BIG-IP SSL Orchestrator provides full visibility into encrypted AI traffic, enabling inspection without creating performance bottlenecks.
- Distributed Cloud Bot Defense protects AI applications from automated abuse – a growing attack vector as adversaries use bots to probe AI systems at scale.
- NGINX-based deployments gain AI/ML workload security with advanced Layer 7 controls in Kubernetes environments.
For existing F5 customers, it is not a case of "replace what you have" – it is "extend your existing security investment to cover the AI layer you just deployed".
Building the Business Case: ROI of AI Security
Security investments require business justification. For AI security, the value case rests on four pillars: regulatory compliance (avoiding fines and enforcement actions under the EU AI Act and GDPR), incident prevention (the cost of a single high-profile AI security breach), operational efficiency (automated compliance documentation and continuous testing replacing manual processes), and competitive advantage (the ability to deploy AI faster and more confidently than competitors who are paralysed by security uncertainty).
Organisations that invest in AI security now are not just mitigating risk. They are building the trust infrastructure that will determine how quickly they can scale AI adoption – and how much of that value they can actually capture.
Explore F5 AI Guardrails and F5 AI Red Team at f5.com/products/ai-guardrails
To speak with an Exclusive Networks specialist about your AI security architecture, contact your regional partner today.
Latest blogs
View all BlogsFeatured
Blogs
Building AI Security That Actually Works: A Technical Deep Dive into F5 AI Guardrails and AI Red Team
Featured
Blogs
The AI Adoption Paradox: Why Your Biggest Opportunity Is Also Your Biggest Risk
Featured
Blogs
Falcon Adversary OverWatch: Stop hidden threats with 24/7 expert threat hunting
Featured
Blogs
Reduce data loss risk with smarter device control
Featured
Blogs
Falcon Firewall Management: Simplify host firewall control without adding complexity
Featured
Blogs