As AI shifts from a pilot to a business-critical system, security becomes a defining factor in an AI deployment's success. That is exactly why WWT built ARMOR, our AI Readiness Model for Operational Resilience. ARMOR is a vendor-agnostic​ AI security framework delivered by WWT, developed with input from ​NVIDIA, and strengthened through real-world collaboration with the Texas A&M University System. ARMOR gives security leaders a clear and practical way to organize AI risk through expert guidance across seven security domains: governance, risk and compliance, model protection, secure AI operations, infrastructure security, identity security, data protection, and  secure software development lifecycle which results in a cyber-resilient architecture.  

ARMOR's seven domains focus on key elements of securing AI systems and related processes, helping organizations understand security control points inside and between these systems, and in their interactions with the surrounding environment. This is key to understanding how AI security mechanisms mesh with traditional security solutions and is vital to identifying present gaps. ARMOR also accommodates organizations at different maturity levels. ARMOR is a ​ ​​real-world-tested AI security framework​ that was shaped through two-way collaboration with a lighthouse customer who served as the first testing ground. 

F5 delivers AI security at the runtime enforcement layer through its Application Delivery and Security Platform (ADSP), an integrated portfolio that operates where governance intent becomes technical control: the AI boundary. F5's approach is built on a clear separation of responsibility: governance defines intent, engineering builds models, and F5 enforces policies at runtime and produces audit-ready evidence. ​​Based on WWT's control review​, F5's portfolio aligns to five of ARMOR's seven domains; Identity Security, Model Protection, Infrastructure Security, Secure AI Operations, and Data Protection. In the sections ahead, we'll show exactly how F5's portfolio maps to each of those domains. 

Mapping F5's Portfolio to ARMOR Domains 

F5's ADSP concentrates security at the AI boundary, delivering consistent enforcement and observability across on-premises, hybrid, private cloud, and multi-cloud AI deployments. The approach emphasizes identity-anchored access, runtime model protection, hardened AI infrastructure, audit-ready operations, and protected data flows. The mapping below illustrates the high-level coverage of F5's portfolio across the five ARMOR domains where F5 operates: 

 

 

Focusing a bit closer, F5's flagship AI security and application delivery products demonstrate a focused approach in alignment with ARMOR: 

With the entire portfolio mapped, now let's look at how each solution within F5's ADSP drives security across the ARMOR domains. 

F5 AI Guardrails 

ARMOR Domains: Model Protection, Secure AI Operations 

F5 AI Guardrails is the runtime AI policy enforcement layer within F5's ADSP, sitting between users, applications, and models. It inspects every prompt and response, enforces natural-language governance policies, and produces explainable, audit-grade evidence for every allow/block decision. Some key capabilities and alignment areas are: 

  • Runtime AI Policy Enforcement: Inspects prompts and responses to prevent data leakage, prompt injection, jailbreaks, and other OWASP Top 10 for LLM classes of risk across any model in any environment, including on-prem, air-gapped, private cloud, and hybrid deployments. 
  • Natural Language Policy Controls: Allows security and compliance teams to define and enforce AI usage policies without requiring deep AI expertise, broadening responsible AI oversight beyond data science teams. 
  • AI Observability and Explainability: Provides operators with detailed explanations of why prompts are allowed or blocked, surfacing attack-pattern trends and unanticipated model behavior in real time. 
  • Agentic Fingerprints and Outcome Logs: Generates traceable, audit-ready records that feed SDLC validation gates, threat hunting, and compliance workflows. 
  • ​​​Embedded at the Inference Edge: Pairs with NVIDIA-accelerated inference infrastructure to provide a traffic inspection point at the AI inference edge. 

F5 AI Red Team 

ARMOR Domains: Model Protection, Secure AI Operations 

F5 AI Red Team automates adversarial testing against AI systems, identifying and remediating model vulnerabilities before attackers exploit them. The platform supports both pre-production validation and continuous production monitoring, aligning with the NIST AI RMF's Govern–Map–Measure–Manage approach. Notable features include: 

  • Automated Adversarial Testing: Tests AI models for prompt injection, jailbreaks, data exfiltration, model misbehavior, and other adversarial techniques without manual red-team effort. 
  • Risk Benchmarking: Quantifies model-specific vulnerabilities to support risk benchmarking and remediation prioritization. 
  • Test-to-Defense Feedback Loop: Findings can be converted with F5 AI Remediate to create AI Guardrails policies, closing the loop between adversarial testing and enforcement. 
  • Continuous Production Validation: Operates in production environments to surface vulnerabilities introduced by model updates, drift, or new attack techniques. 

F5 BIG-IP Next for Kubernetes on ​​​NVIDIA BlueField® DPUs​ 

ARMOR Domains: Infrastructure Security, Model Protection, Secure AI Operations 

F5 BIG-IP Next for Kubernetes on NVIDIA BlueField DPUs places traffic control, security enforcement, and telemetry on the DPU itself, ​     ​​offloading infrastructure services from host CPUs​ in AI factory environments. By anchoring enforcement and observability at the DPU layer, BIG-IP Next for Kubernetes aligns directly with ARMOR's guidance on chip-to-cloud AI infrastructure security. Core capabilities include: 

  • DPU-Offloaded Security and Networking: Delivers firewalling, encryption, segmentation, and load balancing on ​     ​​BlueField DPUs​, ​     ​​helping free host CPU resources for application workloads​ while isolating the security control plane from the application compute plane. 
  • Per-Tenant Programmable Segmentation: Supports full VRF, API-driven dynamic routing, and per-tenant ingress and egress access control lists for programmable L3 segmentation in multi-tenant Kubernetes environments. 
  • ​​​Tenant-Aware Telemetry: Streams L4–L7 telemetry into total-telemetry architectures, providing telemetry that can support broader detection and investigation workflows. 
  • AI Inference Edge Enforcement: Pairs with F5 AI Guardrails on NVIDIA GPUs to deliver protections near GPUs at the AI inference edge. 
  • ​​​​​Scalable Multi-Cluster Operations: BIG-IP Next for Kubernetes management supports hundreds of namespaces, TMM instances per DPU, endpoints with Gateway API compatibility, faster convergence. BIG-IP Next for Kubernetes has been tested ​​on​​​​     ​​ BlueField-3​ DP​Us​​.​     ​ 

F5 BIG-IP for AI Data Delivery (LTM with S3-Optimized Profiles and MCP Routing) 

ARMOR Domains: Infrastructure Security, Data Protection 

F5 BIG-IP for AI Data Delivery secures and optimizes the data path that feeds AI training, fine-tuning, RAG, and inference workloads. Using BIG-IP LTM with S3-optimized profiles and MCP/JSON-RPC routing, F5 provides reliable, encrypted, high-throughput access to AI storage backends and agent-to-model traffic. Key capabilities are: 

  • Smart Load Balancing for S3 Storage: Distributes load across S3 endpoints and regions to prevent hotspots, throttling, and rate-limit issues that bottleneck training and inference. 
  • Integrated SSL/TLS Offload and Re-Encryption: Provides secure, optimized encrypted traffic to S3 backends without breaking compliance or performance. 
  • Centralized Programmability: Enables dynamic optimization based on traffic patterns and streamlined hybrid and multi-cloud S3 connectivity without extensive manual tuning. 
  • MCP Hub Pattern: Centralizes routing and load balancing for JSON-RPC traffic across MCP endpoints, providing high availability and predictable performance between AI agents and backend services. 
  • Storage Backend Abstraction: Decouples applications from specific storage providers, supporting data residency, automated failover, and retention policy enforcement. 

F5 BIG-IP Advanced WAF 

ARMOR Domains: Model Protection, Secure AI Operations 

F5 BIG-IP Advanced WAF inspects application and API traffic for AI-targeted Layer 7 attacks, providing structured SecOps with reduced false positives. Positioned at the AI data center border, it produces actionable alerts and feeds telemetry into broader SecOps workflows. Feature highlights cover: 

  • Layer 7 Inspection for AI-Facing APIs: Detects and blocks malformed requests and known malicious traffic patterns targeting AI-facing applications and APIs, while F5 AI Guardrails provides semantic prompt and response protection.. 
  • Reduced False Positives: AI-driven analytics provide predictive insights and rapid triage, moving teams from reactive alerts to structured SecOps. 
  • Telemetry Streaming to SIEM and SOAR: Feeds normalized telemetry to customer SIEM and SOAR platforms (e.g., Splunk, Microsoft Sentinel) for correlated threat detection. 
  • Automation and iRules Translation: Simplifies iRules creation and translation to suppport repeatable traffic-management automation. 

F5 NGINX (NGINX One, Plus, Ingress Controller, Gateway Fabric) 

ARMOR Domains: Model Protection, Infrastructure Security, Identity Security 

The NGINX family provides cloud-native security, traffic management, and policy enforcement for containerized AI workloads, with security-by-default configurations that reduce misconfiguration risk in Kubernetes deployments. Key alignments include: 

  • Kubernetes Ingress and Gateway Security: NGINX Ingress Controller and Gateway Fabric provide cloud-native L7 traffic control, mTLS, and policy enforcement for AI microservices. 
  • App and API Protection at the Cluster Boundary: NGINX App Protect WAF and NIGINX App Protect DoS inspect API traffic to AI applications inside the cluster, blocking abuse and Layer 7 attacks. 
  • mTLS and Machine Identity: Enforces mutual TLS between AI microservices and validates JWTs and OAuth tokens at the ingress, anchoring service-to-service identity inside the cluster. 
  • GitOps and Declarative Security: NGINX supports GitOps-based deployment workflows, enabling declarative security policy management alongside application code. 
  • Service-to-Service Access Controls: Uses mTLS, ingress and Gateway API policy, and access controls to help govern service-to-service communication within Kubernetes clusters. 
  • Bridge Between Legacy and Cloud-Native: Connects cloud-native Kubernetes deployments with legacy application tiers under a single security posture. 

F5  Application Delivery and Security Platform (ADSP) 

ARMOR Domains: Model Protection, Infrastructure Security, Secure AI Operations, Identity Security 

 Application Delivery and Security Platform (ADSP) provides a SaaS-delivered control plane that unifies WAF, API security, bot defense, DDoS mitigation, client-side defense, web app scanning, and identity-aware access policy across on-premises, private cloud, and multi-cloud environments. It functions as the multi-tenant enforcement layer for AI-exposed surfaces. Some core capabilities include: 

  • Distributed Cloud WAF and API Security: Protects AI APIs and applications against OWASP Top 10 and OWASP API Top 10 risks at scale across hybrid environments. 
  • Identity-Aware Policy at the Edge: mTLS and JWT authorization at the global edge, applying consistent access policy to AI APIs regardless of where they run. 
  • Bot Defense and Client-Side Defense: Mitigates credential stuffing, scraping, account takeover, and supply-chain script injection attacks (Magecart-style) targeting AI-driven web properties. 
  • DDoS Mitigation Service: Protects AI service availability against volumetric and application-layer DDoS attacks. 
  • Distributed Cloud Web App Scanning: Identifies vulnerabilities in web applications and APIs to support pre-production remediation and continuous attack-surface monitoring. 
  • Unified SaaS Control Plane: Delivers consistent policy enforcement, telemetry, and visibility across all environments, exportable to customer SIEM and SOAR for unified compliance reporting. 
  • AI-Powered WAF- Reduces operational complexity, resulting in fewer false positives, less manual tuning, and faster response. 

F5 BIG-IP SSL Orchestrator with Post-Quantum Cryptography Readiness 

ARMOR Domains: Secure AI Operations, Data Protection 

F5 BIG-IP SSL Orchestrator decrypts, inspects, and re-encrypts traffic at scale, enabling zero-trust visibility into encrypted AI API and storage flows. Combined with F5's Post-Quantum Cryptography (PQC) Readiness capability, SSL Orchestrator helps organizations prepare for the transition to post-quantum cryptography: 

  • Decryption for Inspection: Enables zero-trust visibility into all encrypted AI traffic, including AI API calls and S3 storage traffic, without sacrificing performance. 
  • Hybrid Inspection Chains: Steers traffic through inspection chains of WAF, DLP, IDS, and other tools while maintaining a single decrypt-and-re-encrypt point. 
  • Post-Quantum Cryptography Readiness: Helps organizations prepare for the transition to post-quantum cryptography as standards and migration guidance evolve. 
  • Future-Resilient Data Protection: Protects long-lived sensitive data, including training data, model weights, and transaction records, from retroactive decryption as quantum capabilities advance. 

F5 Zero Trust Access (BIG-IP Access Policy Manager/APM) 

ARMOR Domains: Identity Security, Model Protection, Infrastructure Security 

F5 Zero Trust Access is F5's identity-anchored access enforcement layer for AI. APM authenticates users, devices, and service accounts and authorizes them against scope and posture before they ever reach AI applications, APIs, or management planes. WWT's controls review notes that ZTA enforces identity at the boundary rather than owning the identity lifecycle (e.g., identity stores, governance) — so ZTA is best paired with an enterprise IdP. A few highlighted features include: 

  • Identity-Based Access Enforcement: Authenticates users, devices, and service accounts before granting access to AI applications, APIs, and management planes. 
  • Zero Trust Access for AI: Enforces least-privilege access based on identity and posture, with continuous validation across AI systems and management interfaces. 
  • Scope-Based Authorization: Supports OAuth 2.0, API keys, JWT, and RBAC per user, token, or application context, aligned to model and API zoning. 
  • SSO and Federation: Provides single sign-on and federation for AI management interfaces, reducing identity sprawl across hybrid environments. 
  • Continuous Validation: Reassesses identity and device posture throughout a session, supporting NIST AI RMF identity assurance and zero-trust assumptions. 

F5 ADSP with AS3, Declarative Onboarding, Telemetry Streaming, and Native Kubernetes 

ARMOR Domains: Infrastructure Security, Secure AI Operations 

The F5 Application Delivery and Security Platform (ADSP) is the unified foundation that standardizes delivery and security controls across the F5 portfolio. Together with Application Services 3 (AS3) and Declarative Onboarding (DO), BIG-IP configurations can be managed declariatively, supporting version-controlled, auditable, and repeatable deployment. Telemetry Streaming integrates F5 operational and security data into customer SIEM and observability platforms. Core capabilities include: 

  • Configuration-as-Code: AS3 and Declarative Onboarding enable BIG-IP configuration to be managed as code, supporting controlled changes, audit trails, and repeatable deployment. 
  • Repeatable Cyber Recovery: AS3 and DO support rapid redeployment of policy and control during DR and cyber recovery, supporting NIST CSF Detect, Respond, and Recover outcomes. 
  • Telemetry Streaming to SIEM: Streams operational and security telemetry into SIEM and observability platforms (e.g., Splunk, Sentinel) for continuous monitoring and recovery validation. 
  • Consistent Operations Across Environments: Supports a more consistent operating model across on-prem, private cloud, and multi-cloud environments, helping reduce operational fragmentation across AI deployments. 
  • Isolated Recovery Environment (IRE) Support: Aligns with ARMOR's IRE guidance by including the policy and control plane in cyber recovery scope and validating restored services via telemetry. 

Ready to get started? 

F5's ADSP delivers a focused, ARMOR-aligned approach to AI security at the runtime enforcement layer, where governance intent becomes auditable technical control. F5's roadmap continues to advance AI Guardrails and AI Red Team capabilities against emerging attack vectors (prompt injection through RAG data sources, model supply-chain risks, agentic AI), and to expand post-quantum cryptography readiness as standards and migration guidance evolve. Because F5 operates at the AI boundary and not at the GRC policy authorship or secure development lifecycle layers, and because identity enforcement at the boundary still depends on an enterprise identity store and governance program, F5 is most powerful when paired with complementary partner solutions in those domains, giving customers a complete ARMOR-aligned stack. 

Whether you're beginning your AI security journey or looking to mature your program, the path starts with visibility and prioritization. 

Access the ARMOR dashboard, connect with us for an ARMOR briefing, and take the next step toward secure, resilient AI. Explore the ARMOR Dashboard

Technologies