IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
F5 launches AI security to monitor worker tool use

F5 launches AI security to monitor worker tool use

Fri, 11th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

F5 has launched Workforce AI Security, extending its AI Security Platform to monitor employee use of artificial intelligence tools and the actions of AI agents acting on users' behalf.

The offering is designed to give organisations visibility into which AI services staff are using, while allowing security teams to set rules around those services. Those controls can cover licence tiers, file uploads and data policies.

The launch comes as companies give AI systems a wider role in their operations. Employees are increasingly using AI assistants and coding agents that can access internal systems, call software tools, handle data and carry out tasks with permissions granted by staff.

According to F5's State of Application Strategy Report, 66 per cent of organisations already allow AI to adjust policies and configurations automatically. That trend has raised questions for security teams about how to govern not only access to AI tools, but also the actions those tools can take once employees delegate work to them.

Borrowed authority

Workforce AI Security focuses on what F5 describes as AI acting with borrowed authority, where an agent carries out actions using a user's credentials or permissions. In practice, that means firms may need an audit trail showing who initiated an AI task, which agent executed it, what the system attempted to do and whether the action was allowed or blocked.

One part of the service is intended to identify AI interactions by user and by agent. It records context including intent, risk and policy decisions for enforcement and audit purposes.

Another feature inspects actions before they are executed. The system can check tool calls across MCP servers and supported agent tools, then allow, block or modify those actions based on identity, access risk and exposure of sensitive data.

F5 says the controls are applied in the interaction path rather than through a separate endpoint installation. That means the service is intended to work across browsers, command-line interfaces, coding agents, MCP clients and internally built tools that connect to public model APIs, while fitting into existing SASE environments.

Platform expansion

The release builds on a broader push by F5 to expand its AI security portfolio. Earlier this year, it introduced its AI Security Platform to provide visibility, governance, testing and runtime protection across enterprise AI deployments.

It later added AI Gateway functions, including MCP Gateway, to manage traffic and enforce policy across AI applications, models, agents and tools. Workforce AI Security is the latest addition, shifting part of that focus to employee activity and delegated agent behaviour.

By placing controls where prompts and responses move across networks, F5 aims to offer a single policy layer that is not tied to one model, application or vendor stack. The approach is intended to help organisations discover AI use, test for vulnerabilities, protect live interactions and govern what users and agents can access without changing existing systems.

F5 is targeting enterprises trying to bring order to a growing mix of consumer AI services, coding assistants and agent-based tools entering the workplace. These systems can improve productivity, but they also expand the number of services and workflows security teams must track.

That challenge is becoming more acute as AI tools move beyond generating text and into direct action inside enterprise environments. Once an employee allows an agent to retrieve data, interact with software tools or change settings, oversight shifts from simple content monitoring to control of machine-led activity inside business systems.

For companies, the issue is no longer only whether staff are entering sensitive information into AI tools. It is also whether an agent can trigger a change, access an internal resource or carry out a workflow step without sufficient review.

F5 says Workforce AI Security is intended to address that gap by combining discovery of AI tool usage with policy checks on agent behaviour. The aim is to give security teams one place to manage both employee AI activity and actions performed on employees' behalf.

"Employees aren't just asking AI questions anymore. They're handing work to AI agents that can reach into enterprise systems, call tools, and change data on their behalf," said Kunal Anand, Chief Product Officer, F5.

"Workforce AI Security applies intent-based guardrails in the network path to understand the context of AI interactions and enforce policy before risky actions occur. With this addition, the F5 AI Security Platform gives organisations one set of controls across how their workforce uses AI and how they build and deploy AI, wherever it runs," Anand said.