As AI evolves from pilot projects into business-critical systems, security becomes a defining factor in successful AI deployments. To help organizations address this challenge, WWT developed ARMOR (AI Readiness Model for Operational Resilience), a vendor-agnostic AI security framework. Built through collaboration with NVIDIA and strengthened by real-world engagement with the Texas A&M University System, ARMOR provides security leaders with a practical framework for assessing and managing AI risk. It organizes AI security into seven domains: Governance, Risk and Compliance (GRC); Model Protection; Secure AI Operations; Infrastructure Security; Identity Security; Data Security; and the Secure Software Development Lifecycle. Together, these domains help organizations build cyber-resilient AI environments 

Icon list of the seven ARMOR domains grouped around a central Cyber Resilience label.
The seven ARMOR domains that structure Akamai's AI security capabilities.

ARMOR's seven domains focus on key elements of securing AI systems and related processes, helping organizations understand security control points inside and between these systems, and ​​​​their interactions with the surrounding environment. This is key to understanding how AI security mechanisms mesh with traditional security solutions and is vital to identifying present gaps. ARMOR also accommodates organizations at different maturity levels. ARMOR is a real-world-tested AI security framework that was shaped through two-way collaboration ​​with a lighthouse customer, Texas A&M University, who served as the first testing ground. 

​​​​​​​​​Akamai brings a distinctive perspective to the ARMOR framework. As one of the world's largest distributed cloud and edge platforms, Akamai is operationalizing AI inference at scale through Akamai Inference Cloud, a purpose-built AI inference platform that combines ​NVIDIA RTX PRO™ 6000 Blackwell Server Edition GPUs​, NVIDIA AI Enterprise software and a global edge footprint of more than 4,400 points of presence. Akamai's security portfolio extends this same edge-native approach to AI security: protection is enforced where AI workloads, APIs and inference endpoints actually live. In the sections ahead, we'll show how Akamai's solutions map to the ARMOR domains, with particular strength in Infrastructure Security, Secure AI Operations and the cyber-resilience controls that keep AI services available under attack. 

Mapping Akamai's portfolio to ARMOR domains 

Akamai's security portfolio is organized around a layered architecture that protects the full lifecycle of AI systems: the infrastructure they run on, the APIs and microservices that expose them, the models and prompts at the inference layer and the user and machine interactions that drive them. This layered design aligns well to ARMOR's domain structure, and Akamai's strongest, most-cited coverage sits in Infrastructure Security (Guardicore Segmentation), Secure AI Operations (API Security, App & API Protector, Bot Manager) and the cyber-resilience controls embedded in GRC (Prolexic, Edge DNS). 

Table mapping Akamai security products to the seven ARMOR domains with primary and overlap indicators.
How Akamai's product portfolio maps to each ARMOR domain.

Across the seven ARMOR domains, Akamai's alignment can be summarized as follows: 

Snapshot cards summarizing how six Akamai products align to specific ARMOR domains.
A quick-reference snapshot of Akamai's ARMOR domain alignment by product.

With the portfolio mapped, the following sections describe how each Akamai solution contributes to the ARMOR domains it primarily supports and the domains it secondarily reinforces. 

Akamai Guardicore Segmentation 

ARMOR Domains: Infrastructure Security (Primary); GRC, Data Security (Overlap) 

When AI workloads span GPU clusters, containers and distributed services, lateral movement becomes the dominant infrastructure risk. Akamai Guardicore Segmentation establishes Zero Trust segmentation as the foundation of AI infrastructure security, enforcing least-privilege communication between workloads and giving security teams the visibility they need to govern east-west traffic across high-performance environments. Notable capabilities include: 

  • Zero Trust Workload Segmentation: Enforces least-privilege communication between AI workloads, GPU clusters, containers and infrastructure components, restricting lateral movement across distributed AI environments ​as well as other legacy, OT and/or cloud systems as required​.
  • Deep Application Dependency Visibility: Maps service-to-service communication and dependencies so data flows are controlled and exposure is reduced even before a control is enforced.
  • Hybrid and HPC Coverage: Extends Zero Trust segmentation across on-premises data centers, cloud platforms and high-performance AI environments where east-west traffic must be tightly controlled.
  • Continuous Validation for Compliance: Continuously validates Zero Trust enforcement in support of frameworks such as NIST AI RMF, contributing to provable, real-time compliance posture.
  • Semantic AI Labeling: Enriched asset information for context, speed and accuracy.

Akamai Firewall for AI 

ARMOR Domains: Model Protection (Primary); GRC, Data Security, Secure AI Operations (Overlap) 

Akamai Firewall for AI is the dedicated runtime control plane for inference endpoints. It inspects inbound prompts and outbound responses to defend models against misuse, leakage and adversarial manipulation, while generating the telemetry needed for governance and audit. Core capabilities include: 

  • Prompt Injection Detection: Identifies and blocks prompt-injection techniques targeting LLMs and inference services in real time.
  • Response Data Loss Prevention: Inspects outbound model responses to prevent sensitive data exposure through AI services. Policy-based data controls to meet AI governance and compliance standards.
  • Adversarial Activity Detection: Detects abusive or adversarial AI interaction patterns aimed at degrading or manipulating model behavior. Real-time AI monitoring continuously scans LLM interactions for emerging threats.
  • Policy-Based Enforcement: Provides monitor, modify or block enforcement modes so governance is enforced in real time rather than documented only on paper.
  • AI Interaction Logging & Analytics: Generates detailed logs and analytics for AI interactions that feed centralized audit, compliance and incident-response workflows.

Akamai API Security 

ARMOR Domains: Secure AI Operations (Primary); GRC, Secure Software Development Lifecycle, Data Security (Overlap) 

Modern AI applications are API-first, and the API layer is now one of the highest-value attack surfaces in any AI deployment. Akamai API Security gives security and platform teams continuous discovery, behavioral monitoring and pre-production testing of the APIs that front AI services. Highlighted features include: 

  • API Discovery and Inventory: Continuously discovers APIs and shadow endpoints exposing AI services, providing the foundation for governance and runtime protection. Detect APIs connected to MCP servers to identify shadow integrations and make sure agent adoption is safe.
  • Behavioral Monitoring & Abuse Detection: Monitors API usage and authentication patterns to detect business logic abuse, automated attacks and data exfiltration attempts.
  • Pre-Production Vulnerability Testing: Identifies vulnerabilities and misconfigurations in APIs before deployment, integrating with development workflows. Understand with visualizations of business logical, network infrastructure and API traffic flows.
  • CI/CD Pipeline Integration: Plugs into development workflows and CI/CD pipelines to deliver automated testing and vulnerability detection prior to production release.
  • Visibility for Governance & Audit: Provides detailed visibility into API usage, authentication and data access patterns to support governance and audit requirements.

Akamai App & API Protector 

ARMOR Domains: Secure AI Operations (Primary); GRC (Overlap) 

Akamai App & API Protector provides adaptive, policy-driven runtime protection for the web applications and APIs that front AI services. Paired with API Security, it is one of the primary ways Akamai delivers governance and runtime defense across AI service interactions. Capabilities include: 

  • Adaptive Policy Enforcement: Uses machine learning and real-time telemetry to apply policy decisions across web apps and APIs as traffic and threat patterns shift.
  • Consistent Governance Across Surfaces: Helps apply governance policies consistently across web applications and APIs that expose AI services.
  • Protection Against API Attacks and Logic Abuse: Defends AI-facing APIs against business logic abuse, common application attacks and data exfiltration attempts.
  • Comprehensive: Solution includes WAF, L7 DDoS defense, API discovery, sensitive data protection and bot controls.
  • Centralized Dashboards and Reporting: Provides centralized dashboards and reporting for ongoing governance validation and audit response.

Akamai Bot Manager (bot & abuse protection) 

ARMOR Domains: Secure AI Operations (Primary); GRC, Identity Security (Overlap) 

AI endpoints are uniquely attractive targets for automated abuse: scraping of model outputs, account takeover against AI-enabled services and sophisticated bot-driven attacks designed to extract value from inference endpoints. Akamai Bot Manager hardens these surfaces against the automated-abuse threat model. Highlighted features include: 

  • Anti-Scraping for AI Outputs: Detects and mitigates automated scraping that targets AI services and inference endpoints.
  • Account Takeover Defense: Protects AI-enabled services against credential-based attacks and sophisticated bot-driven account takeover.
  • Sophisticated Bot Detection: Defends against advanced bot techniques aimed at extracting or abusing AI capabilities. Continuous updates to known bot directory, and detailed analysis of bot traffic.
  • Governance for Automated Interactions: Provides a control point for governing automated interactions with AI systems, complementing Firewall for AI and App & API Protector.

Akamai Prolexic 

ARMOR Domains: Infrastructure Security (Primary); GRC (Overlap) 

ARMOR treats cyber resilience as a through-line across the framework, and availability is non-negotiable for AI services that customers and revenue depend on. Akamai Prolexic provides industry-leading DDoS protection for the data centers and infrastructure that host AI workloads. Core capabilities include: 

  • Volumetric DDoS Protection: Defends against high-volume DDoS attacks targeting AI data centers, networks and supporting infrastructure.
  • Infrastructure-Level Attack Defense: Mitigates network- and infrastructure-level attacks aimed at degrading the availability of AI services.
  • Cloud, On-Prem and Hybrid Deployment: Delivered as cloud, on-premises or hybrid protection so coverage matches how AI workloads are actually deployed.
  • Operational Resilience for AI Workloads: Supports operational-availability KPIs for AI infrastructure under sustained volumetric pressure.

Akamai Edge DNS (with Shield NS53) 

ARMOR Domains: Infrastructure Security (Primary) 

If DNS goes down, AI endpoints become unreachable regardless of how well the inference layer is protected. Akamai Edge DNS, paired with Shield NS53, provides highly available, secure authoritative DNS designed to keep AI application endpoints reachable under attack. Highlighted capabilities include: 

  • Authoritative DNS for AI Endpoints: A highly available, secure authoritative DNS service that resolves AI application endpoints reliably.
  • DNS-Layer DDoS Protection: Defends AI application endpoints and infrastructure against DNS-focused DDoS attacks.
  • Resilient Edge Distribution: Backed by Akamai's global edge footprint, providing geographically distributed DNS resilience for AI services.

Akamai ASPM (Apiiro) 

ARMOR Domains: Secure Software Development Lifecycle (Primary) 

Secure development for AI software is broader than runtime: it requires visibility into the code, the components and the development workflows that produce AI services. Akamai ASPM (Apiiro) is the application-security-posture-management capability in Akamai's SDLC mapping, paired with API Security to support secure development of AI applications and services. Core capabilities include: 

  • Application Security Posture Management: Provides posture visibility across application development to support secure-by-design practices for AI services.
  • Earlier Risk Identification: Helps development teams identify security risks earlier in the lifecycle, before they reach production AI deployments.
  • Complementary to API Security: Works alongside Akamai API Security so that API-layer and broader application-layer risks are managed coherently across the SDLC.

NVIDIA BlueField DPU integration on Akamai 

ARMOR Domains: Infrastructure Security (Primary) 

In high-performance AI environments, security cannot become the bottleneck. ​Akamai's work with NVIDIA includes​ hardware-accelerated segmentation powered by ​NVIDIA BlueField® DPUs,​ helping customers extend hardware-accelerated segmentation across AI infrastructure. Capabilities include: 

  • Hardware-Accelerated Segmentation: Offloads segmentation and security enforcement to NVIDIA BlueField DPUs for performance at scale.
  • Independent Deployment Model: ​​Extends​​ hardware-accelerated AI security to customer's own infrastructure.
  • Performance-First Security for AI Workloads: Designed for the ​stringent​ ​​throughput requirements of GPU-bound, high-performance AI environments.

Ready to get started? 

At WWT, we're helping organizations operationalize ARMOR with the partners who can deliver against it. Akamai's portfolio brings particular strength in Infrastructure Security, Secure AI Operations and the cyber-resilience controls that keep AI services available under attack; anchored by Guardicore Segmentation for Zero Trust enforcement across AI workloads, Firewall for AI runtime model protection and Prolexic and Edge DNS for the resilience layer that underpins everything else. 

Whether you're standing up a new AI inference platform or ​​​​bolstering the security posture of an existing one, the path forward starts with visibility and prioritization. Access the ARMOR dashboard, connect with WWT for an ARMOR briefing and take the next step toward secure, resilient AI built on Akamai's edge-native platform. 

Access the ARMOR dashboard, connect with us for an ARMOR briefing and take the next step toward secure, resilient AI.Explore the ARMOR dashboard 

Technologies