F5 has announced new capabilities for Distributed Cloud Bot Defense aimed at more accurately distinguishing between users, authorized automations, and malicious bots. The update adds persistent device identification, real-time risk scoring, and specific protections against artificial intelligence (AI) agents capable of taking autonomous actions on websites, applications, and APIs.
F5’s bot defense update in 30 seconds
- F5 adds device intelligence and specific protection against AI agents.
- The system correlates behavioral, device, and client-integrity signals.
- Persistent identification aims to detect patterns such as credential stuffing, multi-account abuse, and account takeover.
- Policies can allow, throttle, require additional verification, or block an interaction based on its risk level.
- Agentic AI protection is available now; device intelligence arrives with limited availability in Q4 2026.
The move responds to a shift in automated traffic that complicates traditional protection models. AI agents can interact with a website or an API, complete several steps autonomously, and carry out operations on a person’s behalf. Examples F5 cites include agent-driven purchases, travel bookings, and certain banking operations.
That behavior differs from a conventional web crawler or a script designed to repeat a single request. An agent can maintain a sequence of interactions and make decisions along the way, while a protection system based solely on each individual request can struggle to determine whether that automation belongs to a legitimate customer or is part of a fraud attempt.
From blocking bots to assessing the risk of each interaction
F5 frames its new strategy around several combined signals. Distributed Cloud Bot Defense can correlate information about behavior, device, and client integrity across different interactions, instead of limiting the analysis to a single, isolated request.
One of the announced elements is persistent device identification. The company says this capability will make it possible to recognize and track a device across different sessions and accounts. The goal is to uncover relationships that can stay hidden when each access attempt is analyzed separately.
That context can help identify patterns tied to certain forms of abuse, such as automated access across multiple accounts, credential stuffing — testing credentials previously obtained from other services — or account takeover attempts.
The update also includes real-time device risk scoring. According to F5, the system will analyze signals related to client integrity to detect potentially suspicious environments, including emulators, spoofed devices, or tampered devices.
The company combines these capabilities with risk-based policies. Instead of necessarily applying the same response to all automated traffic, organizations will be able to define different actions depending on the detected risk level: allow the interaction, request additional verification, throttle request frequency, or block it.
This approach aims to reduce reliance on mechanisms like CAPTCHAs when they aren’t necessary. It also aims to prevent anti-bot measures from ending up affecting real users or automations that a company actually wants to allow.
AI agents change the security problem
The rise of agents capable of acting autonomously adds a new challenge for protection systems. Automation no longer comes solely from bots designed to crawl information, generate artificial traffic, or attempt to access accounts. An AI agent can carry out an entire task through multiple calls to services and APIs.
To address that, F5 is adding an agent-aware policy framework that classifies traffic among people, AI agents considered trustworthy, and malicious bots within a single management structure on its F5 Application Delivery and Security Platform (ADSP).
The company says this model allows automated interactions to be managed differently instead of treating all non-human activity as a threat. The distinction matters for companies that want to enable new agent-based services without giving up security controls over their applications and APIs.
The proposal is also integrated into F5’s WAAP protection for web applications and APIs, short for Web Application and API Protection. This approach combines bot defense with other controls sitting within the infrastructure that manages traffic to applications and services.
Kunal Anand, F5’s chief product officer, said the company considers the traditional model — where automated traffic is treated as malicious by default — insufficient. Under this approach, the analysis has to take into account which agent or device is involved, what action it’s trying to perform, and how the risk evolves during the interaction.
The announced features don’t all have the same availability. The new agentic AI protections are available as of the announcement, while device intelligence capabilities are set for an initial phase of limited availability for F5 Distributed Cloud customers during the fourth quarter of 2026. F5 expects to broaden that availability later.
The difference between the two timelines also shows that not every feature described in the announcement has the same degree of commercial availability. Device intelligence follows a rollout schedule set by the company, so its characteristics and scope should be understood within that plan.
For companies, the value of this evolution lies in being able to better distinguish between legitimate automation and abuse without necessarily resorting to identical controls for every user. As AI agents move from querying information to executing operations through APIs, that distinction will also need to become part of applications’ access and security policies.
Frequently asked questions
What is F5 adding to Distributed Cloud Bot Defense?
The update adds persistent device identification, real-time risk scoring, risk-based policies, and specific capabilities for handling traffic from AI agents.
What is F5’s device intelligence?
It’s a capability designed to identify and track devices across different sessions and accounts, as well as analyze integrity signals to detect potentially suspicious environments.
When will device intelligence be available?
F5 expects limited availability for Distributed Cloud customers during the fourth quarter of 2026, followed by a broader rollout later.
Are the AI agent protections already available?
Yes. F5 says the new agentic AI protections are available as of the announcement, while device intelligence features follow a later availability schedule.

