F5 enhances its bot mitigation platform to secure machine-speed APIs against autonomous AI agents while defending against credential stuffing and automated fraud.
F5 has introduced a series of advanced enhancements to F5 Distributed Cloud Bot Defense, integrating new device intelligence features and specialized agentic AI protections. Announced on September 15, 2026, the updated security capabilities deliver persistent device context and continuous risk decisioning directly into the active application data path.
The platform updates arrive as enterprise environments encounter a surge in autonomous AI agents interacting directly with websites, mobile applications, and customer portals at machine speed. Unlike traditional static web crawlers or simple scripts, these modern AI agents perform multi-step workflows like transactional commerce, travel bookings, and banking operations. Legacy bot management tools relying on rigid, single-request inspection often struggle to separate authorized automation from malicious traffic, forcing many security teams to rely on disruptive IP blocking or CAPTCHAs.
Integrated directly within F5’s web application and API protection (WAAP) portfolio and the F5 Application Delivery and Security Platform (ADSP), the updated bot defense system correlates behavioral, device, and client-integrity telemetry. This multi-signal framework establishes trust across critical login and API touchpoints without interrupting legitimate users or approved automated workflows.
Key feature updates in the release include persistent device identification to track sessions across multiple accounts and expose credential stuffing, real-time device risk scoring to detect tampering or emulators, risk-based workflow enforcement for dynamic policy adjustments, and an agent-aware policy framework capable of categorizing human traffic, verified AI agents, and malicious scripts under one unified rule set.
Agentic AI is breaking the old security model, where automated traffic was treated as inherently malicious, said Kunal Anand, Chief Product Officer at F5. The answer is not to block AI. It is to understand which agents and devices can be trusted, what they are trying to do, and how risk changes across every interaction. By bringing persistent device intelligence and real-time risk decisioning into the active data path, F5 helps organizations stop fraud and account abuse without closing the door on legitimate users, trusted AI agents, or new digital business models.