- Sponsored
AI-adaptable security platforms are critical for autonomous decision-making
As private and public sector organizations build and scale autonomous workflows, the inevitable risks of data leakage and rogue agents continue to skyrocket, taking on new urgency and leaving traditional defenses struggling to keep pace.
At issue is how to establish the necessary guardrails for these increasingly powerful, yet easily manipulated, AI models. One thing is clear: Organizations must move beyond fragmented point products and adopt a centralized platform approach.
While technology experts have urged organizations for years to centralize their systems onto unified platforms for security and economic reasons, the risks — and the stakes for waiting — are escalating quickly, according to Nirav Shah, senior vice president for products and solutions at F5, an application delivery and security platform used by 80% of the Fortune Global 500.
AI has quickly advanced from personal chatbots to autonomous agents that make decisions, explains Shah during a Scoop News Group interview for CyberScoop, sponsored by F5.
According to Shah, enterprise adoption has “gone from just using [AI] for simple use cases where you can contain data to now, in the world of AI agents, which are autonomous. They are [often] making decisions without a human in the loop,” raising the concern, “how do we provide that end-to-end secure framework while the AI adoption is skyrocketing?”
Securing autonomous systems is fundamentally different from protecting legacy IT structures, he argues. “When we think about legacy IT solutions, there are predictable and defined solutions which are signature-based, and once you put those in control, you can protect [against] bad actors,” Shah noted. Today, both security teams and adversaries leverage the same dynamic core technologies, making those controls increasingly obsolete.
To address these emerging threats, Shah outlined a comprehensive, three-pronged approach to securing systems in the AI age:
Comprehensive discovery: Organizations cannot protect what they cannot see. Before deploying security controls, IT leaders must gain complete visibility into the AI-related usage on their networks. That calls for a centralized platform that knows what AI tools and AI agents are operating on their networks and “helps you understand the usage of the AI workforce,” Shah explained.
Robust guardrails: Once AI tools are discovered, organizations must establish firm boundaries to prevent exploitation and data loss. “We have all heard about these threats related to prompt injection, jailbreaking and data leakage. So, having the right guardrails — telling models and informing users what is allowed — is absolutely critical,” Shah stated. These guardrails block malicious inputs and prevent data leakage in real time.
Continuous monitoring: Security is a continuous operational loop. “Once you have that, we need to make sure that … we are also constantly checking the red team and getting the data to make sure all the models are behaving properly,” Shah advised. This ensures autonomous agents remain within permitted boundaries.
Shah stressed that these capabilities “should not be a point product. They all should come together as a platform that works in an integrated fashion to provide an end-to-end security with its model —whether it’s an agent, with an MCP (Model Context Protocol) — deployed anywhere.”
Recent real-world incidents illustrate the urgency of this platform approach. “Just look at what happened a few weeks ago, when OpenAI” revealed that an experimental AI evaluation model, without full instructions, found its way out of a test sandbox and “went out to the Hugging Face model and tried to do a few things that were not asked for.”
“It’s really important, before you go and start talking about technology, to understand how these models are behaving. What are the risks associated with it?” he cautioned, adding that deployment flexibility is crucial for public and private sector organizations.
Multi-model AI offers benefits but adds complexity to enterprise environments and creates added delivery, security and management challenges, requiring platforms capable of addressing security issues across models.
F5’s platform, for example, supports diverse environments — including on-premises, cloud, SaaS, and air-gapped systems — helping organizations maintain data sovereignty and meet compliance requirements.
As organizations look ahead, the core challenge is embracing productivity without exposing the enterprise to catastrophic enterprise AI risk, he said. “As AI adoption is going up, we are also seeing that the control, security and visibility of the AI has gone down,” Shah concluded, adding “So it’s really important to make sure you are finding a vendor who can deploy these technologies wherever you want.”
This article and the video interview were produced by Scoop News Group, for CyberScoop and underwritten by F5.
Learn more about how F5’s platform delivers and secures applications everywhere across the enterprise.