Securing Enterprise AI-powered Apps with F5 AI Guardrails
By F5 DevCentral Community
Key Concepts
- F5 AI Security Platform: A comprehensive solution designed to secure AI-powered applications.
- F5 AI Guardrails: A core component enabling centralized definition, protection, and observation of AI model and agent interactions with users and data.
- Observability: The ability to monitor and gain insights into the performance and security posture of AI systems over time.
- Compliance Scanners: Configurable policies within F5 AI Guardrails (e.g., custom, financial, medical) to enforce specific rules and prevent out-of-scope or risky AI responses.
- Prompt Injection/Jailbreaking: A malicious technique to override an AI model's system prompts, forcing it to reveal sensitive information or perform unauthorized actions.
- RAG Chatbot (Retrieval Augmented Generation): An AI chatbot that retrieves information from an internal knowledge base before generating a response.
- Data Redaction: The process of automatically obscuring or removing sensitive personal information from AI responses to prevent data leakage.
- Explainability & Traceability: Features that allow users to understand why an AI system made a particular decision (e.g., blocking a request, redacting data) and trace it back to the specific policy triggered.
- NGINX Data Plane: In the demo setup, it acts as the policy control point for F5 AI Guardrails.
- OWASP Top 10 for LLM Applications: A list of the most critical security risks for large language model applications.
Securing Enterprise AI-Powered Applications with F5 AI Security Platform
This demonstration showcases how the F5 AI Security Platform, specifically F5 AI Guardrails, integrates with observability to ensure AI systems remain secure, compliant, and aligned with organizational policies. As organizations scale their AI initiatives, visibility and governance become paramount. F5 AI Guardrails provide a centralized mechanism to define, protect, and observe how AI models and agents interact with users and data, fostering trust, compliance, and resilience against emerging AI threats.
The F5 AI Guardrails can be self-hosted or delivered as a service. In the presented demo, the NGINX data plane functions as the policy control point. Guardrails can also be directly embedded into AI applications to apply policies before any backend calls, thereby reducing latency and cost.
Demo Scenarios and Risk Mitigation
The demonstration walks through three key scenarios, comparing an unprotected AI chatbot with one secured by F5 AI Guardrails. The fictitious financial institution, "Aadia Financial," is used as the context for the chatbot.
1. Preventing Out-of-Scope and Non-Compliant Responses
Problem (Unprotected Chatbot): An unprotected AI chatbot, designed to retrieve information for Aadia Financial, readily provides detailed comparisons with other banks (e.g., "HSPC") and offers financial or medical advice when prompted.
- Specific Risk: Commenting on another bank introduces serious compliance risks, potentially being seen as unauthorized financial advice. If incorrect, this could lead to legal, regulatory, and reputational damage. Similarly, offering financial or medical advice crosses compliant boundaries, exposing the organization to significant liability.
Solution (F5 AI Guardrails Protected Chatbot): When the same out-of-scope questions are posed to the F5 AI Guardrails protected chatbot:
- For normal, in-scope questions about Aadia, the chatbot responds accurately and professionally.
- When asked about HSBC or for financial/medical advice, the chatbot responds with "request blocked by F5 AI gutrails."
- Mechanism: F5 AI Guardrails act as an intelligent control layer, automatically blocking any questions or prompts that fall outside defined policy or the Aadalia domain.
Policy Configuration and Explainability:
- Compliance Scanners: Multiple compliance scanners are enabled to enforce policy control.
- A custom scanner ensures discussions remain focused on Aadia and do not involve other banks.
- Financial and medical scanners prevent the chatbot from offering advice in these sensitive areas.
- Logging and Explainability: The F5 AI Guardrails portal provides an "explainability and logging view." This view clearly shows that requests were flagged by the custom scanner policy (preventing discussions about other banks) and matched with financial and medical scanners, blocking further conversations on those topics.
2. Mitigating Prompt Injection and Jailbreaking Attacks
Problem (Unprotected Chatbot): A malicious identity is injected to override the system prompt, attempting to force the model to reveal internal sensitive information.
- Specific Risk: On the unprotected chatbot, sensitive business logic and core payment system details are exposed. This information could be leveraged by an attacker to target the systems, representing a critical risk highlighted in the OWASP Top 10 for LLM applications.
Solution (F5 AI Guardrails Protected Chatbot): When the same prompt injection attack is executed on the protected chatbot:
- Detection and Blocking: F5 AI Guardrails consistently detect and block the malicious intent, preventing any sensitive data exposure.
- Logging: The F5 AI Guardrails logs show that both the "jailbreaks" and "system prompt scanner" were triggered, immediately blocking the malicious injections and preventing unauthorized actions.
3. Protecting Sensitive Data in Internal RAG Chatbots
Scenario: An internal employee accesses a RAG chatbot containing sensitive personal information. This system is protected by F5 AI Guardrails.
Demonstration:
- When asked for general information (e.g., "Who is the chairman of the board for Aadia?"), the chatbot retrieves correct information from the internal database.
- When asked for details about a specific individual (e.g., "Tonymart"), all sensitive information is carefully redacted from the response, preventing any data leakage.
Explainability, Traceability, and Compliance:
- F5 AI Guardrails Portal: The portal allows easy review of each prompt's status and clearly shows which attributes were redacted.
- Data Handling: F5 does not store or record any sensitive information; only the redacted data is logged for compliance.
- Visibility: The portal enables tracing each event back to the specific policy that triggered the redaction. This level of visibility is crucial for compliance verification, audit readiness, and maintaining trust in AI operations.
Observability Dashboard
Beyond detailed logs, F5 AI Guardrails offer an intuitive observability dashboard. This dashboard provides clear metrics and insights into the AI security posture, allowing organizations to easily visualize trends and monitor the performance of their AI systems over time.
Conclusion
F5 AI Guardrails, as part of the F5 AI Security Platform, provide a robust solution for safely deploying AI systems in enterprise environments. By offering centralized policy definition, proactive threat mitigation against risks like prompt injection, intelligent compliance enforcement, sensitive data redaction, and comprehensive observability, F5 enables organizations to leverage AI while ensuring security, compliance, and resilience. This platform empowers organizations to maintain trust and control over their AI initiatives, safeguarding against legal, regulatory, and reputational damages.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Why Does This Guy Appear In Kids Videos?
sphynx

TIC en las Organizaciones - Electiva Complementaria II Unisimon
Julieth Güell S

How to Tame Your Advice Monster | Michael Bungay Stanier | TED
TED

Margaret Heffernan: Why it's time to forget the pecking order at work
TED

The importance of psychological safety: Amy Edmondson
The King's Fund

What Is Psychological Safety?
Harvard Business Review

13-Conflict Management: Listening in Conflict
Deliberate Development