F5 expands WAAP stack with AI risk scoring, air‑gapped API discovery and virtual patching
F5 is augmenting its application and API security portfolio with a set of AI-driven capabilities intended to reduce the time between vulnerability discovery and exploitation, a period industry sources say has been compressed by advances in generative models. The vendor said the updates include enhancements to its distributed cloud web application firewall, a new on‑premises API Security Local Edition for air‑gapped and highly regulated environments, and a virtual patching workflow that aims to protect applications at runtime while code fixes are deployed.
What F5 is announcing
The company said its Distributed Cloud Web Application Firewall now applies a continuously trained model to score the risk of individual HTTP requests, rather than relying solely on signature matching. The numerical risk score is intended to provide SecOps teams with a graded assessment of potential attacks so they can take context‑aware actions and reduce false positives.
Separately, F5 introduced an API Security Local Edition designed to operate entirely on premises without cloud connectivity. The product promises automatic API discovery, schema mapping, local risk scoring and enforcement that integrates with F5’s BIG‑IP Advanced WAF for immediate blocking where required. The on‑prem capability is pitched to organizations that must meet digital sovereignty or air‑gap requirements.
Finally, F5 detailed a virtual patching mechanism that combines BIG‑IP Advanced WAF with Distributed Cloud Web App Scanning to apply defensive rules at the application delivery layer when a vulnerability is detected, buying time for development teams to produce and test permanent fixes.
Why the company is positioning the changes now
F5 frames the timing around what it calls “frontier AI” — large, capable models that can accelerate vulnerability research and automated exploitation. In its announcement, F5 cited a company report showing most organisations face AI‑related operational or security challenges, and argued vendors must adapt defenses to a faster threat cycle.
“Attackers no longer need a CVE. They need a model and a target,” Kunal Anand, F5’s chief product officer, said in the company statement. He described the risk engine as one that “learns continuously and scores every request dynamically, catching attack patterns before a signature exists to stop them.”
Evidence and vendor testing
F5 referenced SecureIQLab testing that it said resulted in a 97.09% total security score for its WAAP and AI Guardrails, including full accuracy against OWASP WAF Top 10 and API Top 10 categories and top marks for bot mitigation and Layer‑7 denial‑of‑service protection. The company also points to operational benefits such as fewer false positives and reduced tuning effort for SecOps teams.
Industry buyers commonly evaluate such claims against independent testing, integration requirements and operational tradeoffs, particularly when products move from detection into automated enforcement in production environments.
Implications for enterprises and regulated sectors
For organisations in finance, healthcare, defense and government, the appeal of an air‑gapped API discovery and enforcement capability is clear: regulatory or contractual obligations can limit cloud telemetry and third‑party processing, making on‑prem visibility a must. By locating discovery, scoring and enforcement inside a local environment, vendors seek to reconcile security analytics with data residency and sovereignty constraints.
At the same time, enterprises will need to weigh the operational burden of running locally managed security stacks against the convenience and telemetry advantages of cloud services. On‑prem deployments can impose staffing and lifecycle management costs and may reduce the speed at which shared intelligence is propagated unless architectures include safe, policy‑controlled telemetry exchange.
Virtual patching is an established mitigation pattern that can reduce risk exposure in the days or weeks before a code fix reaches production. Combining runtime defenses with scanning is a reasonable extension of that approach, but organisations must ensure virtual rules are tested and monitored to avoid disrupting legitimate traffic.
Market context and next steps
Vendors across the WAAP and API security market have been adding machine learning and behavioral analytics to address automated probing and credential‑stuffing attacks. What distinguishes offerings will be model transparency, ease of tuning, integration with existing WAF and API gateways, and the ability to operate under strict compliance regimes.
Enterprises evaluating the new F5 capabilities should consider proof‑of‑concepts that measure detection and false‑positive rates against their own traffic, test the operational process for virtual patch rollout and rollback, and validate the local edition’s discovery accuracy against known API inventories.
F5’s announcement underscores a broader trend: as generative AI changes both defensive and offensive tooling, organisations are prioritising layered controls, faster detection, and options that respect regulatory boundaries. Whether that will blunt the accelerating window to exploit depends on how quickly detection models adapt to new attack patterns and how effectively security teams operationalise risk‑based controls.
Disclosure: This article is based on an F5 product announcement and company‑cited testing. Independent verification is recommended where indicated.







