F5 has introduced updates to its AI Gateway, now integrated into the F5 AI Security Platform. These enhancements offer enterprises a consistent control framework for AI models, agents, and tools to optimise both security and economic efficiency at scale. With the steady rise in AI usage, traditional measures for monitoring AI traffic have proven insufficient, leading to a fragmented landscape of proxies and tools.
According to F5's 2026 State of Application Strategy Report, 77% of companies report that inference has overtaken model training as the primary AI activity, with organisations typically managing seven AI models. As the scale of inference grows, the importance of tokenomics—an economic assessment of AI operations—becomes critical. However, a disjointed approach to security tools leaves businesses without reliable mechanisms for managing AI access.
Accelerating Innovation
Kunal Anand, Chief Product Officer at F5, observed, "We're watching enterprises race to deploy AI while struggling to control it. Every AI request carries economic, security, and governance implications, yet most organisations are relying on fragmented tools that address only part of the problem." The F5 AI Gateway is meant to centralise management of AI models and their associated components, thus offering businesses a means to balance innovation while maintaining security and oversight.
The single integrated F5 AI Gateway combines a Model Gateway for accessing models and optimising costs, an MCP Gateway for navigating agent-to-tool interactions, and AI Guardrails that enforce prompt and response protections. This centralised system allows budgetary controls, routing policies, and access directives to be uniformly applied across varied environments where models and agents operate.
Fine-Grained Access Control
AI gateways are increasingly necessary as they provide controlled access to models and MCP servers
AI gateways are increasingly necessary as they provide controlled access to models and MCP servers. F5 AI Gateway’s Model Gateway function monitors token usage—assigning them by provider, model, team, and user. This real-time attribution helps in enforcing budgets proactively, reducing token expenditure by as much as 60% without requiring application modifications.
Additional controls include a detailed audit trail that records interactions at the MCP level, simplifying developers’ ability to track approved servers. The AI Guardrails feature inspects all data exchanges, removing sensitive information before reaching models and preventing unauthorised data actions. This aligns with industry standards such as SOC 2, ISO, and HIPAA, giving regulated sectors the necessary compliance evidence.
Flexible Deployment
Introduced earlier, the F5 AI Security Platform provides continuous governance and protection for enterprise AI applications.
Comprising AI governance, usage control, security testing, and runtime protection, it ensures a comprehensive security lifecycle. The F5 AI Gateway supports deployment across diverse environments, including SaaS and multicloud, with plans for air-gapped solutions suited for regulated enterprises.
F5, the global pioneer in delivering and securing every app and API, introduces significant enhancements to the F5 AI Gateway and integrated the solution into the F5 AI Security Platform. The enhanced F5 AI Gateway seamlessly enforces policies on every AI request, giving enterprises a unified control plane to govern how AI models, agents, and tools are accessed and used, while optimising the economics of AI at scale.
Enterprises have moved past AI experimentation, but governance has not kept pace. AI traffic still moves through a patchwork of standalone proxies and monitoring tools that were never built for AI, with no guardrails in between.
Unified control plane
According to F5’s 2026 State of Application Strategy Report, 77% of organisations say inference, rather than model training or tuning, is now their dominant AI activity, and organisations are managing an average of seven AI models.
As inference scales, tokenomics is becoming an increasingly important consideration, with every model request carrying implications for cost, performance, and security. Yet the piecemeal approach to standalone tools to secure AI traffic leaves enterprises without consistent control over how models and agents are accessed and used.
Customers accelerate innovation
"We're watching enterprises race to deploy AI while struggling to control it," said Kunal Anand, Chief Product Officer at F5. "Every AI request carries economic, security, and governance implications, yet most organisations are relying on fragmented tools that address only part of the problem. The result is rising costs, increased risk, and operational complexity. F5 AI Gateway, integrated into the F5 AI Security Platform, provides a single control point for managing AI across models, clouds, agents, and applications. We believe every enterprise will need an intelligent control layer for AI. F5 is building that foundation, helping customers accelerate innovation while maintaining visibility, security, and control."
F5 AI Gateway brings three critical functions together in a single integrated solution:
- Model Gateway for model access and cost optimisation
- MCP Gateway for agent-to-tool governance
- AI Guardrails for prompt and response protection
Single integrated solution
Budgets, model routing policies and agent access controls are set once centrally and enforced across distributed environments wherever the models, agents and AI apps run, providing a single operations pane for AI platform ops, AI Security ops and finance teams.
Rapid adoption of AI is fueling the need for AI gateways. According to a recent Gartner® report, "AI gateways have emerged as a critical part of AI infrastructure, as enterprises need tools to support safe, efficient and controlled access to AI models and MCP servers. Adoption of AI gateways will continue to accelerate among large enterprises."
Fine-grained access controls
Organisations that cannot see which teams, models, and providers are consuming tokens cannot assess the value and costs of using AI. F5 AI Gateway puts tokenomics under control: the Model Gateway function attributes every token by provider, model, team, and user, per-team budgets enforce limits as spend occurs rather than after the invoice arrives; and automated optimisation — smart routing and model tiering, semantic caching, and GPU-aware load balancing — routes each request to the right model at the right cost. The solution is designed to reduce token spend by up to 60 percent, with no application changes.
As agents multiply, so do the MCP servers they call, usually with no central registry, no per-tool authorisation, and no record of what agents are doing. The MCP Gateway function of F5 AI Gateway provides fine-grained access controls that limit agents to the resources they are explicitly authorised to use, including APIs, data sources, and RAG systems.
Redacting sensitive data
A complete audit trail captures what was accessed, when, by which agent, and on whose behalf. MCP server registry gives teams a single source of truth for approved MCP servers, thereby removing friction for developers who would otherwise find it challenging to discover which servers and tools exist.
Personal data, health records, and intellectual property move through AI applications every day, and that data usually reaches external models uninspected while injection and jailbreak attempts go undetected. F5 AI Guardrails inspect every prompt and response, redacting sensitive data before it reaches the model, blocking injection and jailbreak attempts, and failing closed when a request cannot be evaluated. Full audit trails, SIEM export, data residency controls, and alignment with SOC 2, ISO, and HIPAA frameworks give regulated industries the evidence they need before putting AI into production.
Hybrid multicloud environments
F5 introduced the F5 AI Security Platform earlier this year to give teams continuous visibility, governance, and protection across enterprise AI applications, models, agents, and the APIs connecting them. Four integrated pillars — AI governance, AI usage control, AI security testing, and AI runtime protection — plus an overarching observability layer, create a persistent security lifecycle rather than a one-time compliance exercise.
F5 AI Gateway is where those pillars meet live traffic, putting policy into force at the point of interaction and controlling what AI can access, what it can expose, and, crucially, what it can cost the business. F5 AI Gateway is deployable across SaaS, hybrid SaaS, and hybrid multicloud environments, with air-gapped support planned for regulated and sovereign use cases.