Securing and Governing Agentic AI Orchestration System with F5 AI Guardrails
By F5 DevCentral Community
Key Concepts
- Agentic AI: AI systems where multiple autonomous agents collaborate, use tools, and execute complex workflows via supervisor-driven orchestration.
- Multi-Agent Orchestration: A framework where a supervisor agent delegates tasks to specialized agents (e.g., document extractors, credit checkers).
- MCP (Model Context Protocol): A standard for connecting AI agents to external data sources, tools, and backend systems.
- AI Guardrails: Runtime security mechanisms that inspect prompts, agent context, and tool usage for malicious intent.
- Prompt Injection: An attack technique where hidden or malicious instructions are embedded in data (like PDFs) to manipulate AI decision-making.
- Shadow AI: Unauthorized or unmanaged AI usage within an organization that bypasses security protocols.
- Trust Zone Model: A security architecture that applies varying levels of inspection and control based on the risk profile of specific agents or tools.
1. The Evolution and Risks of Agentic AI
Organizations are shifting from simple chatbots to Agentic AI systems to act as "workforce multipliers." These systems automate end-to-end business processes by autonomously invoking services and making decisions. However, this autonomy expands the attack surface significantly.
- Security Challenges: Increased interactions between users, agents, tools, and APIs create vulnerabilities such as unauthorized tool usage, sensitive data exposure, and loss of operational control.
- The F5 Approach: F5’s Application Delivery and Security Platform (ADSP) moves beyond LLM-only protection to secure the entire end-to-end workflow through:
- Detection: Autonomous AI red teaming and continuous threat intelligence.
- Remediation: Risk-score-based guardrails and actionable security recommendations.
- Governance: Model-agnostic runtime guardrails that secure prompts, agents, and tools.
2. Case Study: Secure Loan Evaluation Workflow
F5 demonstrated a loan evaluation platform to illustrate the difference between unprotected and secured multi-agent workflows.
The Workflow Process:
- Supervisor Agent: Receives the request and delegates tasks to specialized agents.
- Document Collector: Extracts data from the loan application PDF.
- Credit Checker: Uses MCP tools to retrieve external credit bureau data.
- Eligible/Risk Scorer: Evaluates the application against lending policies.
- Decision Writer & Audit Logger: Finalizes the outcome and records the transaction for compliance.
Key Findings from the Demo:
- Unprotected Workflow: When a manipulated PDF containing hidden malicious instructions (prompt injection) was submitted, the agent was tricked into approving a loan that should have been rejected.
- F5-Protected Workflow: The system utilized runtime guardrails to inspect the prompt and agent context. It successfully blocked the malicious PDF, identifying the hidden instructions (embedded as tiny white text) and preventing unauthorized approval.
- Policy Enforcement: F5 ADSP provides a centralized console that logs triggered policies, providing visibility into why a request was blocked (e.g., built-in security vs. custom policy violations).
3. Security Frameworks and Methodologies
F5 employs a Trust Zone Model to balance security with performance:
- Risk-Based Enforcement: Not all agents are treated equally. High-risk agents (e.g., supervisors, external tool connectors) undergo stricter, deeper inspection. Trusted agents operate with lighter controls to ensure the security layer does not become a performance bottleneck.
- AI Gateway: Acts as the central enforcement point for protecting prompts, APIs, and sensitive data across the entire multi-agent ecosystem.
4. Synthesis and Conclusion
The transition to multi-agent AI systems offers immense operational benefits but introduces critical security risks that traditional perimeter defenses cannot address. The core takeaway is that securing agentic AI requires a holistic, runtime-focused approach. By implementing model-agnostic guardrails, utilizing a trust-zone-based inspection model, and maintaining centralized visibility, organizations can safely harness the power of autonomous agents while mitigating risks like prompt injection and unauthorized tool manipulation. F5’s ADSP provides the necessary governance to ensure that AI workflows remain compliant, explainable, and secure.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Connecting the unconnected | Secretary-General of the ITU Doreen Bogdan-Martin
Microsoft

GPT 5.6 Mythos Level Intelligence
Prompt Engineering

GPT 5.6, Mythos ban lifted, realtime avatars, Seedance 2.5, brain ultrasound: AI NEWS
AI Search

Anthropic Just Replaced Claude Code With New Claude Tag
AI Revolution

Google Just Dropped a Masterclass on Agentic Engineering (It's SO Good)
Cole Medin

What's new in Google Cloud's agent platform
Google Cloud Tech

What's new in Looker: Empowering business users in the governed agentic era
Google Cloud Tech