Talk to us
by F5TechBag Intel Page

F5 AI Red Team

Your AI apps answer customers and your agents take actions. Someone should attack them before an outsider does — F5 AI Red Team sets swarms of attacker agents on your AI apps, models and agents — in AWS, Azure, Google Cloud or on your own OpenShift cluster — and pushes what they find into F5 AI Guardrails.

Agent swarms attack your own AIOpenShift keeps tests in IndiaQuote only; unit not published

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
F5 prints no AI Red Team price and no marketplace listing exists; the unit counted is not published
Quote
Analysts
Gartner Emerging Market Quadrant for AI Application Security, 2026; an emerging quadrant, not a Magic Quadrant
Market Shaper
Deploys
AWS, Azure or Google Cloud, or a certified Red Hat OpenShift operator on your own cluster
Cloud or on-prem
India
The on-premises operator keeps prompts and findings in your Indian facility; hosted locations are unstated
Your cluster

Quick answer

F5 AI Red Team attacks your own AI apps, models and agents with swarms of automated attacker agents, drawing on a database F5 says gains 10,000+ new attack patterns a month, then pushes what it finds into F5 AI Guardrails for runtime policy. It runs in AWS, Azure or Google Cloud, or on-premises as a certified Red Hat OpenShift operator. It is built on F5’s 2025 acquisition of CalypsoAI and is sold on quote only. Read more ↓ Show less ↑
Part 01 · Orient

The F5 platform family

This page covers F5 AI Red Team — the testing product, not the F5 AI Guardrails runtime product. The rest:

Quick facts

30-second orientation
Product
Automated adversarial testing of AI apps, models and agents by swarms of attacker agents
Maker
F5, Inc.; Chairman, President and CEO François Locoh-Donou
Heritage
Built on F5’s 2025 acquisition of CalypsoAI, which closed on 26 September 2025
Price
Not published on f5.com and not listed on any cloud marketplace; quote only
Licence
Its own product, quoted apart from F5 AI Guardrails; the licensing unit is not published
Attacks
F5 claims its attack database gains more than 10,000 new patterns every month
Output
Findings feed F5 AI Guardrails; F5 AI Remediate, shown at AppWorld 2026, links the two
Deploys
AWS, Azure or Google Cloud, or on-premises as a certified Red Hat OpenShift operator
India
On OpenShift in your own Indian data centre, tests and results stay with you
In India via
TechBag — AI target inventory, quote in INR with GST, first test cycle
Part 02 · Learn

Understand AI red teaming before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is AI red teaming?

Attacking your own AI on purpose — jailbreaks, prompt injection and misuse — so weak points surface before a real attacker finds them.

A one-off manual test vs automated attacker agents — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA one-off manual testF5 AI Red Team
How attacks are madeA consultant writes prompts by handSwarms of automated attacker agents
How often it runsOnce, before launchRepeated as the attack database grows
New techniquesWhatever the tester knew that week10,000+ new patterns a month, per F5
What a finding becomesA line in a PDF reportInput to F5 AI Guardrails policy
Where test data sitsOn the consultant’s laptopYour cloud account or OpenShift cluster
What it is NOT—A runtime blocker, or a published price

The cleanest test is one target, one run and one re-run after the fixes: read every finding with its owner, then decide on the rest.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Who does the attacking

Attackers

Swarms of attacker agents

Instead of one script replaying fixed prompts, AI Red Team sets many automated attacker agents loose on a target together, each probing a model, app or agent for a weak spot.

02
Where the attacks come from

Database

Attack-pattern database

The agents draw on an attack database that F5 says gains more than 10,000 new patterns every month, so a re-test later in the year meets techniques the first run never saw.

03
What happens to a finding

Hand-off

Findings into AI Guardrails

Results are pushed into F5 AI Guardrails, the runtime product; F5 AI Remediate, introduced at AppWorld 2026, ties a red-team finding to the guardrail policy meant to close it.

04
Where the tester runs

Runtime

Public cloud or OpenShift

Pick a public cloud, whether AWS, Azure or Google Cloud, or install the certified operator F5 ships for Red Hat OpenShift, so a regulated team keeps attack prompts and results in-house.

Attacker agents and a growing pattern database — run in three public clouds or on OpenShift, with findings sent to AI Guardrails.

Part 03 · Evaluate

Six capabilities. Attack, remediate, deploy.

F5 AI Red Team attacks your AI on purpose, then hands each finding to F5 AI Guardrails.

Attack
Agent swarms

Many attackers at once

Automated attacker agents work in parallel against one target, so testing no longer waits on a person writing jailbreak prompts by hand.

Attack
Attack database

A library that keeps growing

F5 claims more than 10,000 new attack patterns join the database each month, which is why a test should be repeated, not run once a year.

Remediate
Guardrails feed

Findings become defences

What a test uncovers is passed to F5 AI Guardrails, so a weakness found in testing can then be blocked in production by the sibling product.

Remediate
AI Remediate

Closing the loop

F5 AI Remediate, shown at AppWorld 2026, connects a finding to a Guardrails policy instead of leaving it as one more line in a PDF report.

Deploy
Public cloud

Hosted in three clouds

Run it in AWS, Microsoft Azure or Google Cloud, next to the models and AI apps your teams already host with one of those providers.

Deploy
OpenShift

On your own cluster

A certified Red Hat OpenShift operator installs it on-premises, for teams whose prompts, test data and results must not leave the building.

See it, don’t just read it

Watch F5 AI Red Team in action

F5 on continuous AI red teaming, how results are scored and reach guardrails, the AI Remediate launch, and the CalypsoAI deal behind the product.

F5 (official)·Webinar, April 2026

F5 AI Red Team: Continuous Testing. Explainable Results, Proven Resilience | On-demand Webinar

F5’s own session on the product, framed around testing that repeats rather than a one-off assessment.

F5 (official)·Episode, March 2026

Pop Goes the Stack | AI Red Teaming in Practice: Scores, guardrails, auto-remediation | AI

An F5 discussion of AI red teaming in practice: how results are scored and how they reach guardrails.

F5 (official)·Short, March 2026

Introducing F5 AI Remediate | AppWorld 2026

The AppWorld 2026 introduction of AI Remediate, the step between a red-team finding and a guardrail.

F5 (official)·Announcement, September 2025

F5 enters into agreement to acquire pioneer in enterprise AI security, CalypsoAI | AI Security

The September 2025 announcement of the CalypsoAI deal that this product line is built on.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why F5 AI Red Team

New jailbreaks appear every month. AI Red Team keeps attacking so you find them first.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Testing that keeps pace with new attacks

A manual red-team exercise is a snapshot; a jailbreak published next month is not in it. AI Red Team points swarms of automated attacker agents at your model, app or agent, and F5 says its attack database gains more than 10,000 new patterns every month. Re-running the same target therefore tests new techniques, not the old list.

02

A finding that turns into a control

Most red-team output ends as a report someone must translate into rules. Here the findings are pushed into F5 AI Guardrails, the runtime product, and F5 AI Remediate, introduced at AppWorld 2026, links each weakness to the guardrail policy meant to close it. The value is highest if you run both F5 products.

03

It runs where your models run

Attack prompts and the answers they draw out can be sensitive. F5 offers AI Red Team in AWS, Azure or Google Cloud, and also as a certified Red Hat OpenShift operator on your own premises. For an Indian bank or insurer, the OpenShift route keeps every prompt and finding inside its own data centre.

04

Where it stops

There is no public price and no published licensing unit. It tests; blocking in production is AI Guardrails, quoted on its own. TechBag has not verified which frameworks its reports map to. Gartner’s 2026 Market Shaper label sits in an Emerging Market Quadrant, not a Magic Quadrant, and the line dates from the CalypsoAI deal of September 2025.

The idea
Agent swarms attack your own AI
The residency
OpenShift on your Indian cluster
The price
Quote only; no published unit
Proof, not promises

The numbers behind the platform

10000+
new attack patterns F5 says join its red-team database every month
— Vendor
$145.2M
cash F5 paid for CalypsoAI, the deal behind this product, per its 10-Q
— Filing
3 clouds
public clouds it runs in: AWS, Microsoft Azure and Google Cloud
— Vendor
1 operator
certified Red Hat OpenShift operator for running it on your own premises
— Vendor
2026
the year Gartner called F5 a Market Shaper in its AI Application Security emerging quadrant
— Analyst
2025
KuppingerCole’s GenAI Defense Leadership Compass, dated December, naming F5 a Leader
— Analyst

What your F5 AI Red Team rollout looks like

Week 1Model

List what you would attack

Inventory the AI apps, models and agents in production or close to it, and rank them by the data and actions each can reach.

Week 2Decide

Choose cloud or OpenShift

Decide whether tests run in AWS, Azure or Google Cloud or on your own OpenShift cluster, given where the prompts may go.

Week 3Pilot

Attack one target first

Point the attacker agents at a single chatbot or agent, read every finding with its owner, and agree what counts as a fail.

Month 2Prove

Turn findings into policy

Feed the findings to AI Guardrails if you hold it, switch on the policies in a staging app, and re-test to confirm the fix.

Month 3Commit

Make re-testing routine

Schedule repeat runs for each target after model or prompt changes, so new attack patterns are tried as the database grows.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
36+ reviews*
82% would recommend
Attack breadth4.4
Link to runtime fixes4.3
Deployment choice4.2
Report clarity3.9
Value for money3.7
5★
45%
4★
36%
3★
13%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“The attacker agents found a way to make our loan chatbot quote internal rate rules. A manual test last year had missed it.”
AI Security Lead
BFSI
Insurance
“We run it on our OpenShift cluster, so claim-handling prompts never left our data centre during testing. That settled compliance.”
Platform Engineering Manager
Insurance
Telecom
“Findings landed in Guardrails as policies we could switch on, rather than a spreadsheet the app team would ignore.”
Application Security Architect
Telecom
IT Services
“Our second run a quarter later caught two jailbreak styles the first one had not tried. Schedule it, do not do it once.”
Red Team Engineer
IT Services
Retail
“Ask early how licensing is counted. Our quote changed once we added the internal agents beside the customer chatbot.”
Head of IT Procurement
Retail
Healthcare
“Strong if you also buy AI Guardrails. On its own, someone still has to turn each finding into a fix in another tool.”
CISO
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the AI red-teaming market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag AI Red Teaming Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
F5 AI Red TeamThis page

Quote-only; findings flow to F5 AI Guardrails.

Grid 02 · The architecture

Deployment Choice × Attack Depth

The grid nobody publishes — how many places the tester can run, your own premises included, vs how deep and varied its automated attacks go.

Deep but hosted-onlyDeep and run-anywhereLight and hostedPortable toolkits
F5 AI Red TeamThis page

Three clouds or OpenShift; agent swarms and a growing database.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

F5 AI Red Team vs the AI red-teaming field

Against Palo Alto Prisma AIRS AI Red Teaming, Cisco AI Defense, Check Point AI Red Teaming, Promptfoo and Microsoft PyRIT — on attack method, coverage, fixes, price, support and India.

DimensionF5 AI Red TeamPalo Alto Prisma AIRS AI Red TeamingCisco AI Defense (AI Validation)Check Point AI Red TeamingPromptfooMicrosoft PyRIT
What it isAgent-swarm AI testingRed teaming in AIRSAI Validation moduleFormerly Lakera RedOpen-source red teamingMicrosoft OSS framework
Deployment3 clouds or OpenShiftSaaS via StrataCloud, VPC or AI PODHosted platformLocal, cloud or on-premYour own Python setup
Attack methodAttacker-agent swarmsLibrary, agent, customAlgorithmic promptsObjectives + strategiesPlugins, then gradingCrescendo, TAP and more
Attack coverage10,000+ new a month50+ techniques200+ subcategories23 default objectivesPlugin catalogueBuild your own
Frameworks mappedNot verifiedOWASP, ATLAS, NISTNIST, ATLAS, OWASPOwn three categoriesOWASP, NIST, EU AI ActNot documented
Scoring and reportsFormat unpublished0–100 risk scorePer-model resultsSeverity per findingGraded vulnerabilitiesScorers + memory
Finding to runtime fixInto AI GuardrailsInforms AIRS runtimeAuto-made guardrailsMapped to Guard levelsGate, then fixNo runtime layer
Pricing modelQuote; unit unpublishedNGFW creditsThree tiersEnterprise quoteFree tier, then customFree, MIT licence
Published entry priceNot publishedNo public rateNot publishedNo list price$0 Community tier$0 open source
Included vs add-onGuardrails sold apartNeeds SCM ProValidation in 2 tiersGuardrails sold apartSLA in EnterpriseBring your own models
India data locationYour OpenShift clusterNot in IndiaVPC optionNot publishedSelf-host anywhereRuns where you run it
SupportPer F5 contractPalo Alto portalWith subscriptionEnterprise contractCommunity or SLACommunity only
Lock-in and exitBest inside F5Strata platformCisco Security CloudCheck Point AI stackOpen-source exitMIT, no vendor tie
Best fitF5 shops securing AIPalo Alto AI estatesModel-registry checksCheck Point AI stacksDevelopers in CI/CDIn-house red teams
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose F5 AI Red Team if…

  • ✓You already run, or plan to buy, F5 AI Guardrails and want test findings to arrive there as policy, not as a report
  • ✓Prompts and model answers used in testing must stay on your own OpenShift cluster in an Indian data centre
  • ✓You want automated attacks that repeat as F5’s database grows, not a one-off consultant engagement

Compare alternatives if…

  • ✓Your runtime protection is Prisma AIRS, Cisco AI Defense or Check Point AI Guardrails — each vendor’s tester feeds its own
  • ✓You want to start free — Promptfoo’s Community tier and Microsoft PyRIT cost nothing to licence
  • ✓You need a published framework mapping today — Palo Alto, Cisco and Promptfoo document OWASP and NIST alignment

Do not expect…

  • ✓A published price or licensing unit for AI Red Team on f5.com
  • ✓Runtime blocking from this product alone; that is AI Guardrails, quoted on its own
  • ✓A Gartner Magic Quadrant placement — the 2026 Market Shaper label is from an Emerging Market Quadrant

TechBag has no AI red teaming guide yet, so F5 AI Red Team sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does testing your own AI by hand cost you?

Drag the sliders (AI apps, models and agents tested; security-engineer-hour cost). Estimates model in-house time spent writing attack prompts, running tests and turning findings into fixes at an assumed 1.5 hours per AI target a year, with 70% of it removed by automated attacker agents and findings sent to guardrails. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual AI-testing cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: f5.com shows no price for AI Red Team, it has no cloud-marketplace listing, and F5 does not say what the licence counts. The runtime fix, F5 AI Guardrails, is a separate product with its own quote. TechBag inventories your AI targets first, then gets both quoted in INR with GST.

F5 AI Red Team

Best for testing AI apps, models and agents

  • Quote only; licensing unit not published
  • AWS, Azure, Google Cloud or OpenShift
  • Findings flow to F5 AI Guardrails

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

With F5 AI Guardrails

Best for closing findings at runtime

  • Guardrails quoted as its own product
  • AI Remediate links findings to policy
  • Ask for both on one INR quote

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Targets

Which AI apps, models and agents will be tested first, and who owns the fix when one of them fails?

2
Licensing unit

What does F5 count in the quote: targets, scans, capacity or time? Ask before adding more agents.

3
Deployment

Will tests run in your AWS, Azure or Google Cloud account, or on an OpenShift cluster you operate?

4
India data

If prompts or answers are sensitive, can the OpenShift operator run in your Indian data centre?

5
Guardrails

Do you hold F5 AI Guardrails, or will someone translate findings into another runtime product by hand?

6
Frameworks

Ask F5 for a sample report: does it map findings to OWASP LLM Top 10, NIST AI RMF or MITRE ATLAS?

7
Cadence

How often will each target be re-tested, and who triggers a run after a model or system-prompt change?

8
Commercials

Is Guardrails quoted together with Red Team? Ask for INR with GST, the term and the support level.

FAQ

Questions buyers ask

It is F5’s automated adversarial testing product for AI. Swarms of attacker agents probe your models, AI apps and agents for weaknesses an attacker could exploit, using a database F5 says gains over 10,000 new attack patterns each month. Findings are pushed into F5 AI Guardrails, the runtime product.

Ready to evaluate F5 AI Red Team?

List the AI apps and agents worth attacking first, or let a TechBag advisor scope a pilot against one chatbot or agent on the deployment route you choose.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.