F5 Added AI Agent Detection to Bot Defense Platform

The update enables granular traffic management for automated workflows instead of binary blocking.

Updated on Sept. 21, 2026 in Artificial Intelligence

F5 Added AI Agent Detection to Bot Defense Platform

Live Poll

Do you trust automated AI agents to interact with your personal banking or shopping accounts?

F5 has updated its Distributed Cloud Bot Defense platform to identify and classify AI agents alongside human users and malicious bots. This new framework allows organizations to apply specific policies, such as rate-limiting or step-up challenges, to different traffic sources.

Why it matters

As AI agents perform complex, multi-step actions that mimic legitimate traffic, businesses must distinguish between productive automation and threats. This update allows for nuanced security decisions that maintain legitimate AI workflows while blocking malicious actors.

The updated platform employs persistent device intelligence to track sessions across accounts, analyzing client integrity signals to generate real-time risk scores. These scores enable the identification of emulators, spoofed devices, and tampered clients.

The players

F5

A provider of application security and delivery technologies specializing in multi-cloud networking and traffic management.

The details

The platform analyzes client integrity signals—data points verifying the authenticity and state of the connecting device—to determine if a request is generated by a legitimate browser or a scripted agent. By tracking persistent device context across sessions, F5 monitors behavioral patterns to classify actors rather than relying on static IP-based filtering. This allows security administrators to enforce risk-based policies that differentiate between an authorized AI integration and a malicious automation suite.

Timeline

  1. September 21, 2026: F5 announced the updated bot defense capabilities.

The Tech Race

This development shifts F5 away from the legacy binary-blocking bot defense model toward a risk-based architecture. It reflects a wider industry pivot to accommodate the surge in AI-driven traffic while maintaining strict security perimeters.

Organizations can immediately begin configuring their security policies to implement step-up challenges for unknown AI agents. This change shifts management workflows from simple blocking to more granular control, potentially reducing false-positive blocking of legitimate automated services.

The takeaway

The rise of intelligent agents necessitates a transition from broad traffic blocking to sophisticated identity-based risk management. Security teams should monitor how these new classification policies affect the latency of their automated API calls.

Further reading

For broader trends in bot detection, visit Artificial Intelligence.

Live Poll

Do you trust automated AI agents to interact with your personal banking or shopping accounts?

F5 Added AI Agent Detection to Bot Defense Platform