Reading Time: 12 minutes

Overview

Agent Fabric becomes one of the first enterprise AI control planes to broker F5 AI Guardrails inline, letting F5 customers govern every prompt and completion in Agent Fabric through the security stack they know and trust.

For years, enterprise security teams have invested heavily in building a trusted control stack for their network and application traffic. Enterprises use F5 for application delivery and security, to author policies once, and enforce them everywhere traffic flows. With the arrival of AI, a whole new class of traffic, prompts and completions, has started moving outside those controls.

Upon F5’s acquisition of CalypsoAI, runtime AI guardrails have become a standard control across one of the largest enterprise security and networking installed bases in the world. F5 AI Guardrails —part of the F5 AI Security Platform— inspects inbound prompts and outbound completions and returns a verdict, with detection organized into scanners, grouped into packages, and bound to projects: prompt injection, PII, toxicity, restricted topics, plus prebuilt EU AI Act and GDPR compliance packs.

Today, we are excited to extend Agent Fabric’s guardrail federation to support customers already using F5. Model proxies that are deployed on Agent Fabric’s Omni Gateway can now enforce F5 AI Guardrails inline as a first-class provider, alongside Amazon Bedrock Guardrails and Azure Content Safety. The gateway calls the F5 AI Guardrails Scan API to inspect every prompt and completion and acts on the verdict. There is no second proxy, no parallel inspection path, and no blind spots across both F5’s SaaS and customer-hosted Kubernetes deployments.

Why It Matters

Until now, organizations deploying Agent Fabric and seeking to leverage F5 AI Guardrails have faced a trade-off: either route LLM traffic through a separate F5 inspection layer, creating additional operational complexity and fragmented telemetry, or rely solely on native gateway controls without extending F5 AI Guardrails policies directly into their Agent Fabric-managed workflows.

Federating F5 AI Guardrails into the Agent Fabric control plane eliminates that trade-off. 

By federating F5 AI Guardrails into Agent Fabric, enterprises gain:

  • Unified governance and zero double-proxy overhead: Policy management for AI traffic lives in a single control plane. Omni Gateway routes LLM calls directly to the F5 AI Guardrails Scan API, inspecting inbound prompts and outbound completions inline before models are invoked or responses returned.
  • Support for Agentforce ecosystems: Organizations can apply consistent runtime security controls across Agentforce-powered agents, Agent Fabric workflows, and custom AI applications.
  • Proactive threat mitigation: Designed to block prompt injection, jailbreaks, toxicity, and unauthorized topics while reducing Personally Identifiable Information (PII) and protected data exposure at runtime.
  • Data residency and sovereign control: Flexible dual-deployment topology allows self-hosted Kubernetes deployments including private VPCs, allowing sensitive prompt and completion data to remain within customer boundaries.
  • Low-touch policy tuning: Security teams author and version scanners, blocklists, and sensitivity thresholds within the F5 console, which Omni Gateway picks up dynamically without requiring policy or code changes.
  • SOC back-correlation and compliance auditability: Decisions carry detailed telemetry and shared scan IDs for seamless correlation in the F5 console, simplifying compliance with regulations such as the EU AI Act, GDPR, and HIPAA.

Detailed Use Cases

Capability ThemeUse CaseBusiness Impact
Federated Guardrail EnforcementA bank standardized on F5 ADSP and F5 AI Guardrails enforces its existing F5 AI Guardrails scanner project on all LLM traffic flowing through the Omni Gateway, with the same block/audit behavior as its other F5 controls.The security team’s controls follow AI traffic everywhere. No need for a second proxy, no blind spots, no duplicated policy authoring.
Provider Choice per LLM APIA platform team attaches Bedrock, Azure Content Safety, or F5 AI Guardrails per LLM API from one gateway, chosen by which provider each business unit’s security team owns.One neutral governance plane across heterogeneous security stacks; a story no hyperscaler gateway can tell.
Prompt Injection & PII ProtectionA RAG application blocks prompt injection on the inbound prompt and PII leakage on the outbound completion using the customer’s F5 AI Guardrails scanner package, returning a clear, structured 403 on a block.Inbound and outbound protection with actionable, per-scanner error responses for calling applications.
Data Residency (Self-Hosted)A regulated enterprise runs F5 AI Guardrails self-hosted on Kubernetes in its own VPC; the policy targets the internal Moderator endpoint so no prompt or completion content ever leaves the customer boundary.Full guardrail coverage that satisfies residency and sovereignty requirements. The gateway never reaches the public internet for prompt inspection.
Zero-Touch Policy TuningA security team tunes a toxicity scanner’s threshold in the F5 console; the gateway picks up the new behavior with no policy change because it references the project, not the threshold.Faster iteration and clean separation of duties: security owns the rules, the platform team owns the plumbing.
SOC Back-CorrelationA SOC analyst correlates a gateway block to the exact F5 AI Guardrails scan in the F5 console using the shared scan identifier and per-scanner reasons.End-to-end explainability from gateway decision to Outcome Analysis detail — audit-ready by default.

Key Features

  • Inline F5 AI Guardrails policy for the Model Proxy: Evaluates the prompt before it reaches the upstream model and the completion before it returns to the client, with independently toggleable request and response phases.
  • Thin, provider-side integration via the Scan API: The policy references an F5 AI Guardrails project, endpoint, and token; scanners, packages, blocklists, and sensitivity remain authored provider-side. There is no rule duplication in the gateway.
  • Dual deployment topology: One policy serves both the F5 SaaS endpoint and a customer-hosted Kubernetes Moderator endpoint, with private-CA trust support for internal certificates. Migrating from SaaS to self-hosted changes only the endpoint and token, not the policy logic.
  • Bearer-token authentication via secret reference: A credential model distinct from Bedrock’s SigV4 and Azure’s subscription key; tokens are referenced indirectly and never stored or logged in plaintext.
  • Consistent enforcement semantics: Structured 403 on block listing every triggered scanner; fail-closed (503, default) or fail-open on provider error; configurable per-call timeout; full behavioral parity with the Bedrock and Azure reference policies.
  • Deterministic edge-case handling: An F5 AI Guardrails “None”/no-verdict response is treated as indeterminate and resolved by the configured fail mode, never a silent allow. Provider-side audit-mode detections are recorded without blocking.
  • Rich, correlatable telemetry: Every decision carries phase, action, and multi-value reason codes (prompt_injection, PII, toxicity, topic, data_leakage, compliance, and more), plus the F5 AI Guardrails scan ID for back-correlation to Outcome Analysis in the F5 console.
  • Author-time confidence: A “test provider” check validates endpoint and credentials before the policy touches live traffic, and the referenced project’s enabled scanners are surfaced read-only so authors know exactly what will be enforced.

What’s Next? 

F5 AI Guardrails for Agent Fabric is now generally available. At Dreamforce (September 15–17, 2026, San Francisco), organizations can engage with the Agent Fabric team to learn more about the integration and explore how to apply AI security and governance controls across agentic AI deployments.