AWS Partner Network (APN) Blog
Continuous AI security with F5 AI Guardrails and AWS Bedrock
By: Vlad Tyshkov, Partner Solutions Architect – AWS
By: Mark Toler, Product Marketing Manager – F5
By: Daniel Salzedo, Sr. Solutions Architect – AWS
![]() |
| F5 |
![]() |
Threats to AI applications evolve faster than manual defenses can match. According to Gartner®, enterprise generative AI application infrastructure experienced security events at 29 percent of organizations in the last 12 months. Together, pre-deployment evaluation, continuous testing, and adaptive protection compress the gap-to-fix cycle from weeks to minutes.
Encoded inputs, rephrased queries, and multi-turn prompt chaining bypass static rules and keyword filters. To defend AI applications, you need protection that understands intent, not patterns alone.
F5 AI Guardrails and F5 AI Red Team run with AWS Bedrock and deliver continuous adaptive security for AI applications in production. In this post, we introduce three capabilities your enterprise AI security program needs and explain how F5 addresses them on AWS Bedrock: pre-deployment model evaluation, adversarial testing at scale, and adaptive runtime protection that stays ahead of emerging threats.
Three capabilities for your AI security program
AI application security requires more than content filtering. You need a continuous cycle of evaluation, testing, and adaptation. Here’s why each capability matters.
Evaluate foundation models before deployment
Before you commit to a foundation model (FM), you need visibility into its security profile. Different models respond differently to adversarial inputs. A model that resists prompt injection in one category might be vulnerable in another. Without pre-deployment assessment, you’re committing to guardrail configurations based on assumptions rather than data.
The F5 Comprehensive AI Security Index (CASI) Leaderboard ranks leading AI models based on their resistance to real-world attacks. You can use the leaderboards to compare foundation models available through AWS Bedrock. CASI evaluates models against a database of more than 100,000 test patterns, with more than 10,000 new prompts added monthly. It provides security scores and detailed profiles so you can make model selection decisions based on each model’s actual response to specific test types. Results pinpoint which runtime guardrails to enforce before deployment.
Test at adversarial scale
Manual security reviews cover dozens of scenarios. Automated adversarial testing generates thousands of test variations in hours. The gap matters because sophisticated prompt techniques (encoded inputs, multi-turn chaining, rephrased queries) bypass pattern-matching filters that catch obvious threats. You need testing that adapts like a real threat actor: revising prompts based on responses, backtracking when blocked, and strategizing dynamically.
F5 AI Red Team complements AWS Bedrock by testing your AI applications at this scale. It generates more than 10,000 test variations in 48 hours, conducting multi-turn tests that adapt strategies based on your application’s responses. According to F5, this approach discovers 3–5 times more security gaps than manual reviews. You can trace how each gap was discovered using Agentic Fingerprints, a visualization that maps the full prompt-and-response sequence across every turn of the test. You can use the visualization to understand precisely how security gaps manifest in multistep scenarios.
Evolve defenses faster than threats
Static guardrails degrade over time. New bypass techniques emerge daily. You need runtime protection that blocks known patterns in real time and a mechanism to discover and deploy defenses for new patterns faster than threats evolve. The critical metric is the time from gap discovery to rule deployment in production.
F5 AI Guardrails operates as an inspection layer between your applications and AWS Bedrock, evaluating prompts before they reach the foundation model and responses before they return to your application. Input and output policies operate as separate rule sets, so you can enforce different criteria for each direction. F5 AI Guardrails runs within your own AWS account, so your data doesn’t leave your environment.
When F5 AI Red Team discovers a new gap, its companion capability, AI Remediate, generates a guardrail configuration for your team to review and apply in a single step. You can tailor defenses through a natural language interface without writing code. Production monitoring feeds findings back into red teaming campaigns, creating a continuous improvement cycle.
How F5 and AWS Bedrock Guardrails work together
Both AWS Bedrock Guardrails and F5 AI Guardrails enforce content policies at runtime. AWS Bedrock Guardrails provides strong foundational protection, with capabilities that include content filters, denied topics, word filters, sensitive information filters for personal identifiable information (PII) detection and masking, contextual grounding checks, and Automated Reasoning checks. These address a broad range of known risks and form a solid security baseline for your AI deployments.
Together, AWS Bedrock Guardrails and F5 deliver layered protection: foundational enforcement plus continuous discovery and adaptation. F5 AI Guardrails evaluates prompts and responses in context of the full interaction history, maintaining awareness across the entire conversation. F5 AI Red Team probes your application to surface scenarios that emerge as threats evolve. You set the testing objective in natural language, such as “extract restricted financial data.” The AI agent then determines how to reach that goal across multiple conversation turns. The agent revises its approach when blocked and backtracks to try new paths. You can trace each decision the agent made to reach its goal, giving you the context to evaluate what to change in your defenses. Each test cycle feeds the next, so your protection improves continuously rather than eroding between reviews.
An illustrative scenario in a regulated industry
An organization in a regulated industry, such as financial services or healthcare, might deploy AI models that process sensitive domain-specific information. These organizations need to prevent their AI systems from generating or disclosing restricted content while still providing useful responses to legitimate queries.A common initial approach is keyword filtering to block specific query terms before they reach the model. However, adversarial testing quickly reveals edge cases where rephrased queries bypass these filters. Security teams need protection that understands query intent rather than matching specific prompt terms.
Your AI governance team can create custom guardrails through F5’s natural language interface, blocking both inputs and outputs related to restricted content without AI engineering resources or custom code. According to key findings from F5, F5 AI Guardrails achieved 99.3 percent efficacy against direct prompt injection, 98.7 percent against excessive agency, and 99.0 percent against sensitive data leakage across approximately 20,000 adversarial test cases.
What this means for your organization
When you combine pre-deployment evaluation, adversarial testing at scale, and adaptive runtime protection, you create a security posture that evolves continuously. Data informs your model selection decisions. Security gaps are discovered proactively and defenses updated before they reach production. This lifecycle runs within your existing AWS infrastructure, keeping your security team in control at every step.
Conclusion
AI security requires three continuous capabilities: pre-deployment model evaluation, adversarial testing at scale, and adaptive runtime protection that evolves faster than threats. Organizations that implement all three can reduce the gap between a threat being discovered and deploying a defense from weeks to minutes.To get started:
- Review foundation model security profiles using the CASI Leaderboard before you make procurement decisions.
- Adopt automated adversarial testing to identify multistep threat sequences that manual reviews miss.
- Configure runtime guardrails that block known patterns in real time. When Red Team discovers a new gap, apply updated rules in a single step.
To get started with F5 AI Guardrails and AI Red Team for your AWS Bedrock deployments, contact F5 or explore F5 in AWS Marketplace.
Gartner Press Release, Gartner Survey Reveals GenAI Attacks Are on the Rise, September 22, 2025 GARTNER is a trademark of Gartner, Inc. and/or its affiliates.
F5 – AWS Partner Spotlight
F5 is an AWS Advanced Technology Partner and AWS Security Partner that gives the world’s largest businesses, service providers, governments, and consumer brands the freedom to securely deliver every app, anywhere, with confidence. F5 delivers cloud and security application services that help organizations embrace the infrastructure they choose without sacrificing speed and control. For more information, go to f5.com.
The F5 Application Delivery and Security Platform (ADSP) delivers adaptive security for AI applications, APIs, and data across hybrid multi-cloud environments. F5 AI Red Team, F5 AI Guardrails, and F5 AI Remediate together provide a comprehensive AI security lifecycle, from pre-deployment model evaluation through runtime protection.


