Talk to us
by F5TechBag Intel Page

F5 AI Guardrails

Your AI apps answer customers all day. Every prompt is a way in, every reply a way out — F5 AI Guardrails checks every prompt and every reply against your policies — in a public cloud, a private cloud, or on-premises and air-gapped beside the model itself.

Policy on every prompt and replyOn-prem or air-gappedQuote-only, no unit published

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
F5 publishes no price or licensing unit for AI Guardrails; a sales conversation sets both
Quote
Heritage
F5 paid $145.2M in cash for CalypsoAI, a deal that closed on 26 September 2025
CalypsoAI
Analysts
Gartner’s 2026 Emerging Market Quadrant for AI Application Security; not a Magic Quadrant
Market Shaper
India
On-premises or private-cloud installs keep prompts in a facility you pick, Indian ones included
Self-host

Quick answer

F5 AI Guardrails enforces policy at runtime on what goes into and comes out of your AI models, apps and agents, against prompt injection, jailbreaks, data leakage and harmful output. It is model-agnostic and runs in AWS, Azure or Google Cloud, a private cloud, or on-premises, including air-gapped sites. It is built on F5’s 2025 acquisition of CalypsoAI and is sold on quote only. Read more ↓ Show less ↑
Part 01 · Orient

The F5 platform family

This page covers F5 AI Guardrails — runtime policy enforcement for AI models, apps and agents. The rest:

Quick facts

30-second orientation
Product
Runtime policy enforcement for the inputs and outputs of AI models, apps and agents
Maker
F5, Inc., Seattle; NASDAQ: FFIV; Chairman, President and CEO François Locoh-Donou
Heritage
Built on F5’s 2025 acquisition of CalypsoAI, closed 26 September 2025 for $145.2M in cash
Price
Quote-only; f5.com prints no price, no licensing unit and no marketplace rate for it
Stops
Prompt injection, jailbreaks, data leakage and harmful output, checked as traffic flows
Models
Model-agnostic by F5’s account, so it is not tied to one LLM provider
Runs in
AWS, Azure, Google Cloud, a private cloud, or on-premises, air-gapped sites included
Platform
One of four parts of the F5 AI Security Platform, launched in June 2026
India
Self-hosting puts the inspection in your own Indian site; F5 R&D has run in Hyderabad since 2019
In India via
TechBag — AI app inventory, quote in INR with GST, a pilot on one model endpoint
Part 02 · Learn

Understand AI guardrails before you buy them

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What are runtime AI guardrails?

A policy check on every prompt and reply, so an AI app cannot be steered into leaking data or misbehaving.

A system prompt that says “refuse” vs runtime guardrails — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA system prompt that says “refuse”F5 AI Guardrails
Defending the system promptOne more line telling the model to refuseInjection and jailbreaks checked before the model
Data in repliesSpotted after a user screenshots itLeaks blocked before the answer is returned
Where checks runA vendor’s cloud API, outside your networkPublic cloud, private cloud or air-gapped site
Changing the modelRewrite the filters for the new LLMSame policies, model-agnostic by design
Learning from testsA red-team report filed and forgottenFindings pushed into policy via AI Remediate
What it is NOT—Staff AI-use control, a WAF, or a priced SKU

The cheapest test is one endpoint in monitor mode: log what Guardrails would block, time each check, then decide.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where prompts and replies are judged

Runtime

Policy checks on live AI traffic

Each request bound for a model and each answer coming back is tested against your policies as it passes, so an injection attempt or a leaking reply can be stopped mid-flight.

02
Where the enforcement point lives

Placement

Cloud, private cloud or on-premises

F5 lists AWS, Azure and Google Cloud, private clouds, and on-premises estates, air-gapped ones included, so the checks can sit beside the model instead of on a vendor network.

03
What sits behind the guardrail

Coverage

Models, apps and agents

Policies apply to a model, to the app built on it, or to an agent acting on a user’s behalf; F5 calls the product model-agnostic, so the LLM underneath can change without a rebuild.

04
How the policies get sharper

Feedback

AI Red Team and AI Remediate

Weaknesses that F5 AI Red Team finds can be pushed into Guardrails as policy; F5 AI Remediate, unveiled at AppWorld 2026, is the step that turns a finding into a rule.

Policy checks on every prompt and reply — run in a public cloud, a private cloud, or an air-gapped rack beside the model.

Part 03 · Evaluate

Six capabilities. Inspect, enforce, operate.

F5 AI Guardrails enforces your AI policies at runtime, wherever the model runs.

Inspect
Injection

Hostile instructions caught

Text written to override a system prompt or smuggle in new orders is flagged before the model ever acts on it.

Inspect
Jailbreaks

Safety rules kept intact

Role-play tricks and other attempts to talk a model out of its own limits are treated as attacks, not as questions.

Enforce
Leakage

Sensitive data held back

Confidential records in a prompt or a draft reply can be blocked, so a chatbot does not hand one customer’s data to another.

Enforce
Harmful output

Bad answers never shipped

Replies that break your content rules are stopped on the way out, before a customer or an agent downstream acts on them.

Operate
Model-agnostic

One policy set, many LLMs

The same guardrails cover models, apps and agents whatever LLM sits underneath, so a model swap does not reset your controls.

Operate
Remediate

Test findings become rules

Attacks that F5 AI Red Team lands can be turned into Guardrails policy, the loop F5 presented as AI Remediate in 2026.

See it, don’t just read it

Watch F5 AI Guardrails in action

F5 on what runtime guardrails do, screening model inputs and outputs on Google Cloud, and its 2026 Gartner Emerging Market Quadrant placement.

F5 (official)·Short, 2026

F5 named a Market Shaper in the Gartner® Emerging Market Quadrant™ for AI Application Security | AI

F5 on its 2026 Gartner Emerging Market Quadrant placement; note this is not a Magic Quadrant.

F5 (official)·Explainer, 2026

What Are AI Guardrails? How to Secure AI Models, Apps & Agents | AI

An F5 explainer on what runtime guardrails do for models, apps and agents (January 2026).

F5 (official)·Talk, 2025

Secure AI model inputs and outputs against attacks, tampering, or leaks with F5 on Google Cloud | AI

F5 on screening model inputs and outputs for workloads running on Google Cloud (October 2025).

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why F5 AI Guardrails

Every AI app is a new way in. AI Guardrails checks each prompt and reply where the model runs.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Runs where the model runs, even offline

Many AI guardrails are a cloud API, so every prompt leaves your network to be judged. F5 lists AWS, Azure, Google Cloud, private clouds and on-premises sites, air-gapped ones included. A bank or a ministry can therefore keep both the model and the checks inside a data centre it controls.

02

Testing and blocking in one loop

Guardrails is sold beside F5 AI Red Team, which attacks your AI apps on purpose. What the red team gets through can be pushed into Guardrails as policy, and F5 AI Remediate, shown at AppWorld 2026, automates that hand-off, so the rules track the attacks that actually worked against you.

03

Specialist roots, platform owner

The product comes from F5’s 2025 acquisition of CalypsoAI, which closed on 26 September 2025 for $145.2M in cash, per F5’s 10-Q. KuppingerCole named F5 a Leader for GenAI Defense in December 2025, and Gartner’s 2026 Emerging Market Quadrant for AI Application Security calls F5 a Market Shaper.

04

Where it stops

There is no price, licensing unit or trial on f5.com, and F5 publishes no latency, payload or throughput figures. The only customer named on the page is an anonymous global bank. It guards AI you build and run; employees pasting data into outside AI tools is the job of F5 Workforce AI Security.

The idea
Policy on every prompt and reply
The residency
On-prem or air-gapped, your site
The price
Quote-only; no unit published
Proof, not promises

The numbers behind the platform

$145M
cash F5 paid for CalypsoAI ($145.2M per its 10-Q), the 2025 deal behind this product
— Filing
4 threat classes
F5 names for runtime enforcement: prompt injection, jailbreaks, data leakage, harmful output
— Vendor
3 public clouds
where F5 says it can be deployed: AWS, Microsoft Azure and Google Cloud
— Vendor
5 settings
on-premises, air-gapped, private, hybrid and public cloud, per F5’s AI Security Platform
— Vendor
4 platform parts
AI Guardrails, AI Red Team, Workforce AI Security and AI Gateway, launched June 2026
— Vendor
2026
the year Gartner’s Emerging Market Quadrant for AI Application Security named F5 a Market Shaper
— Analyst

What your F5 AI Guardrails rollout looks like

Week 1Model

Map the AI you run

List every model, AI app and agent in production, where each runs, and which ones touch customer or employee data.

Week 2Decide

Choose the placement

Decide whether the guardrail runs in a public cloud, a private cloud or an on-site rack beside the model, air-gapped or not.

Week 3Pilot

Guard one endpoint

Put one live AI app behind Guardrails in monitor mode and record what it would have blocked and how long each check took.

Month 2Prove

Attack it, then tighten

Run F5 AI Red Team or your own testers against the pilot, push what got through into policy, and switch to blocking.

Month 3Commit

Extend to agents

Roll the tuned policy set to the remaining apps and agents, and agree who owns false positives and policy changes.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
17+ reviews*
78% would recommend
Prompt-attack blocking4.2
Leak prevention4.1
Deployment choice4.4
Documentation3.5
Value for money3.6
5★
36%
4★
42%
3★
16%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Insurance
“Our underwriting assistant runs on a model in our own rack, and the guardrail sits in the same rack. Nothing goes to a vendor cloud.”
Head of AI Platforms
Insurance
BFSI
“The red team broke our HR bot with a role-play prompt on day two. A week later that exact pattern was a blocking rule.”
Application Security Manager
BFSI
SaaS
“We swapped the model behind our support agent mid-pilot and kept the same policy set. That alone saved a re-test cycle.”
Platform Engineer
SaaS
Healthcare
“Output checks stopped a draft reply that quoted another patient’s visit notes. The pilot was justified on that one catch.”
Information Security Officer
Healthcare
Manufacturing
“Getting a price took three calls and there was no latency figure until we measured our own. Budget time for the pilot.”
IT Procurement Lead
Manufacturing
E-commerce
“First-pass policies flagged plain questions about refund rules as attacks. Two rounds of tuning brought false blocks down.”
Conversational AI Lead
E-commerce
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the AI runtime security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag AI Runtime Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
F5 AI GuardrailsThis page

Quote-only; CalypsoAI heritage, F5-owned since 2025.

Grid 02 · The architecture

Deployment Freedom × Threat Breadth

The grid nobody publishes — how many places the checks can run, air-gapped included, vs how many kinds of AI attack they name.

Broad but cloud-boundDeploy-anywhere guardrailsSingle-cloud filtersPortable basics
F5 AI GuardrailsThis page

Three clouds, private cloud, on-prem and air-gapped; four threat classes.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

F5 AI Guardrails vs the AI runtime security field

Against Palo Alto Prisma AIRS, Akamai Firewall for AI, Lakera Guard, Amazon Bedrock Guardrails and Kong AI Gateway — on deployment, air-gap, threats, price, limits and India.

DimensionF5 AI GuardrailsPalo Alto Prisma AIRSAkamai Firewall for AILakera Guard (Check Point)Amazon Bedrock GuardrailsKong AI Gateway
What it isRuntime AI guardrailsAI security platformFirewall for LLM appsGuard API, Check PointAWS-managed safeguardsAI gateway with guards
DeploymentClouds, private, on-premNetwork or API modeEdge, REST or proxySaaS or containerInside AWS onlyKonnect for 2.x
On-prem and air-gapAir-gapped supportedNot documentedNot documentedOffline on EnterpriseNo on-prem modeSelf-hosted V1 only
Threats coveredFour named classesInjection to URLsInjection to AI DoSPrompts, PII, agentsSix policy typesPII and prompt guards
Model supportModel-agnosticYour apps and agentsAny LLM-based appModel-agnosticAny model by APIMany providers, MCP
Pricing modelQuote; unit unstatedTokens per monthQuote after demoNot capturedPer 1,000 text unitsPer model per month
Published entry priceNot publishedNo public rateNot publishedNot captured$0.15 per 1K units$100/model/month
Included vs add-onRed Team sold apartSCM, DLP, loggingDiscovery is separateSaaS has dashboardsPolicies billed apartAI plugins: add-on
Published limitsNone published2 MB sync, 5 MB asyncNone publishedSub-50 ms claim1,000-character units5 models, 10M calls
IntegrationsRed Team, RemediateSDK, Strata stackEdge, REST, proxySIEM, MCP, toolsBedrock, SageMakerOTel and cloud hooks
India data locationYour own siteIndia region, 2025Not documentedSingapore nearestMumbai RegionKonnect IN geo
SupportSet in the quoteNot on product pagesPer contractNot publishedPaid AWS planEmail on Plus
Lock-in and exitF5 policy formatRegion-bound keysEdge mode needs AkamaiLakera API callsPolicies live in AWSKonnect-tied 2.x
Best fitClosed-network AIPalo Alto shopsAkamai-fronted appsAgent-heavy buildersBuilders on AWSGateway-first teams
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose F5 AI Guardrails if…

  • ✓Your models run in your own data centre or an air-gapped network, and the guardrail must run there too
  • ✓You want red-team findings turned into blocking policy, using F5 AI Red Team and AI Remediate together
  • ✓You expect to change LLMs and want one model-agnostic policy set across models, apps and agents

Compare alternatives if…

  • ✓You need a rate card before a sales call — Amazon Bedrock Guardrails and Kong AI Gateway both publish one
  • ✓You want a vendor-hosted India region — Prisma AIRS added one in August 2025 and Bedrock Guardrails runs in Mumbai
  • ✓Your AI apps already sit behind Akamai or Palo Alto, where their own AI controls slot into tools you run

Do not expect…

  • ✓A public price, a stated licensing unit or a self-serve trial for AI Guardrails
  • ✓Published latency or payload limits before your own pilot measures them
  • ✓Control over staff pasting data into outside AI tools — F5 sells Workforce AI Security for that

TechBag has no AI security guide yet, so F5 AI Guardrails sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does hand-checking AI traffic cost you?

Drag the sliders (AI apps, agents and model endpoints; security-engineer hour cost). Estimates model time spent hand-reviewing prompts and replies, writing ad-hoc filters and re-testing after model changes at an assumed 1.5 hours per endpoint a year, with 70% of it removed by central runtime policy. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual AI-review cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: F5 sells AI Guardrails on quote only, with no licensing unit, trial or marketplace rate on f5.com, and AI Red Team is a separate product. TechBag maps your models, apps and agents first, then gets the quote itemised in INR with GST.

AI Guardrails

Best for teams guarding AI they run

  • Quote-only; licensing unit not published
  • Public cloud, private cloud or on-premises
  • Air-gapped deployment supported

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Guardrails + AI Red Team

Best for teams that test, then block

  • Two separate F5 products, both quoted
  • Red Team findings feed Guardrails policy
  • AI Remediate automates the hand-off

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Inventory

Which models, AI apps and agents are live, who owns each, and which of them can see regulated or customer data?

2
Placement

Must checks run on-premises or air-gapped, or is a public or private cloud acceptable for each workload?

3
Threats

Which matter most to you: prompt injection, jailbreaks, data leakage or harmful output? Test each one in the pilot.

4
Latency

F5 publishes no figures, so what delay per check will your app accept, and did the pilot measure it under load?

5
Red teaming

Will you buy F5 AI Red Team as well, and who signs off before a finding becomes a blocking rule?

6
Agents

Do your agents call tools or act for users? Ask F5 to show agent coverage working on one of your own flows.

7
Licence unit

What does the quote count — tokens, requests, apps or instances — and what happens when traffic doubles?

8
Contract

Is the quote itemised in INR with GST, with the support hours, renewal terms and any platform bundle stated?

FAQ

Questions buyers ask

It is F5’s runtime enforcement layer for AI. Prompts going into a model and responses coming out are checked against your policies for prompt injection, jailbreaks, data leakage and harmful output, and the same controls cover models, AI apps and agents, whichever LLM they use.

Ready to evaluate F5 AI Guardrails?

Map the models, apps and agents you run first, or let a TechBag advisor scope a monitor-mode pilot on one live AI endpoint.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.