Shadow AI Moves Beyond Chatbots, F5 Targets Risks Hidden in Enterprise Networks

AI tools used without approval can leave companies unaware of what data employees share and which services their systems can reach. F5 is positioning its new platform as a way to expose and control that hidden activity across enterprise networks.

The issue is commonly described as Shadow AI, where staff use AI services outside official organizational oversight. This can make it difficult for security teams to identify the AI applications in use, the purpose of their use, and the data being handled.

F5 cited its 2026 State of Application Strategy report, which found that 88 percent of organizations face at least one AI-related operational or security challenge. The figure suggests that AI adoption has advanced faster than governance and security controls in many enterprises.

Network visibility without application-by-application integration

To strengthen discovery capabilities, F5 acquired SurePath AI, a developer of network-based AI discovery technology. The approach analyzes network traffic rather than requiring direct integration with every application.

This allows security teams to identify AI applications being used on the network and understand their intended purpose. It can also reveal relationships between AI agents and the services or servers they access.

The information gathered from network monitoring is sent to the F5 platform for analysis. F5 says protections can then be applied without changing the architecture of applications already in operation.

Protection extends to agents and APIs

F5 AI Security Platform is designed to cover AI applications, models, agents, and the APIs connecting them. Its scope reflects the way enterprise AI can authenticate, access data, use tools, and act with limited human intervention.

Chief Product Officer Kunal Anand said some AI security products remain too focused on an added layer around chatbots. He argued that this does not fully address AI operating behind APIs and within tightly regulated networks.

“Enterprise runs AI in networks that are tightly governed by specific regulations, behind APIs, and in AI agents that authenticate and act autonomously,” Anand said in a statement cited by tekno.kompas.com. He said the platform is intended to provide continuous control over models, AI agents, and APIs across different AI operating locations.

CapabilityPrimary Function
AI governanceApplies security, privacy, and regulatory policies to prompts, outputs, tool use, and data access.
AI discoveryProvides visibility into approved and unauthorized AI applications, agents, and activity.
AI security testingTests systems against more than 140,000 attack patterns in F5’s AI threat database.
AI runtime protectionApplies guardrails to limit AI behavior while systems are running.

F5 says its runtime protection can block prompt injection, excessive AI agent autonomy, and data leakage with effectiveness of up to 98.2 percent in independent testing. The platform also includes AI observability, recording AI interactions for audit trails and incident investigations.

Designed for regulated environments

The platform can be deployed on-premises, in air-gapped environments, and across private, hybrid, or public clouds, according to F5. That flexibility is relevant to financial services and government organizations with data residency and data sovereignty requirements.

The need for controls may grow as organizations prepare for agentic AI. The SOAS 2026 report states that 98 percent of organizations are preparing to adopt the technology, while governance systems have yet to fully match the pace of adoption.

A single configuration error can carry wider consequences when an AI agent can reach data, use multiple tools, and take action independently. F5’s approach centers on continuous visibility and control before AI activity expands beyond organizational oversight.

Related