F5 Adds Device Intelligence and Agentic AI Detection to Bot Defense

New tools aim to separate trusted AI agents from malicious bots

Application security company F5 has announced enhancements to its F5 Distributed Cloud Bot Defense, adding device intelligence and specialized protections for agentic AI. The upgrades are designed to help enterprises prevent automated fraud and account abuse without blocking legitimate customers or authorized AI agents.

Why Old Bot Tools Fall Short

AI agents are becoming a common way to interact with websites, mobile apps and customer portals. Unlike basic crawlers or scripts, they carry out multi-step tasks on behalf of users, such as making purchases, booking travel or handling banking operations. They also talk directly to APIs at machine speed.

F5 says first-generation bot management, built on rigid “bot or not” rules, struggles in this setting. Static, request-level controls cannot tell an authorized AI agent from a malicious bot, and blunt measures like IP blocking or CAPTCHAs risk shutting down revenue-generating AI channels.

A Multi-Signal Approach

Instead of inspecting single requests, F5 correlates behavioral, device, and client-integrity data across interactions. This builds trust at critical login, web and API connections. The capability is part of F5’s web application and API protection (WAAP) offerings, integrated with the F5 Application Delivery and Security Platform (ADSP).

“The answer is not to block AI,” said Kunal Anand, Chief Product Officer at F5. He added that organizations need to understand which agents and devices can be trusted and what they are trying to do.

Key Enhancements

  • Persistent device identification: Tracks devices across sessions and accounts, exposing multi-account access, credential stuffing and account takeover.
  • Real-time device risk scoring: Checks client integrity signals to spot emulators, device spoofing and tampering.
  • Risk-based enforcement: Lets customers choose to allow, challenge, rate-limit or block, reducing CAPTCHA friction and false positives.
  • Agent-aware policy framework: Manages humans, trusted AI agents and malicious bots under one policy on F5 ADSP.

Availability

The new agentic AI protections are available now. Device intelligence is expected to become available to a limited number of F5 Distributed Cloud customers in the fourth quarter of calendar year 2026, with broader availability to follow over the coming months.

Source: F5 announcement, September 21, 2026

Author