For most of the past decade, the companies that keep the internet’s plumbing running have sold much the same thing to much the same buyers: gear and software that moves application traffic around quickly and keeps the bad actors out. The generative AI wave is now scrambling that settled picture, and the vendors who sit between users and applications believe they are staring at one of the largest new markets in enterprise technology. F5, the Seattle-based application delivery and security firm best known in corporate data centres for its BIG-IP kit, is one of the loudest voices making that case.
In an interview with CRN Australia, F5 chief executive Francois Locoh-Donou framed the arrival of AI applications as a structural shift rather than a passing trend, arguing that the same forces driving companies to adopt AI at speed are also creating a security problem that existing tools were never designed to handle. His pitch, in short, is that every new AI application is a new front door that has to be defended, and that defending those front doors is a business opportunity measured in the billions.
Why AI breaks the old security model
The logic behind the argument is not hard to follow. Traditional web applications behave in fairly predictable ways. A large language model does not. It takes free-form instructions, calls out to other systems and data sources, and can be coaxed into behaviour its builders never intended through prompt injection, data leakage or manipulation of the model’s outputs. Layer on top of that the explosion of application programming interfaces, the connectors that let AI models talk to other software, and the attack surface widens dramatically. F5’s contention is that the volume of AI-driven traffic flowing through corporate networks is set to balloon, and that this traffic needs to be inspected, governed and secured in ways that legacy firewalls and web gateways simply cannot manage on their own.
That is the commercial thesis. F5 has spent the past two years repositioning itself around it, folding AI-specific security controls into its product line and talking up the idea of an “AI gateway” that sits between users, models and data. The company is far from alone. Rivals across the networking and security world, from the incumbents in application delivery to a wave of well-funded startups, are chasing the same buyers with broadly similar promises. The result is a crowded and fast-moving corner of the market where the winners are yet to be decided.
A more sceptical read
Not everyone is convinced the opportunity is as clean as the vendors suggest. Security analysts have pointed out that much of what is being sold as “AI security” is a repackaging of controls that already exist, and that the genuinely novel risks, such as prompt injection, remain poorly understood and hard to defend against with any single product. There is also the awkward reality that many organisations are still working out where their AI is even running. The rise of so-called shadow AI, where staff quietly feed corporate data into consumer chatbots without approval, is a governance failure that no gateway can fully solve. A firm that has not mapped its own AI usage is in a weak position to secure it, whatever the vendor’s roadmap promises.
There is a further tension worth naming. The same companies selling AI security are often selling the AI infrastructure that creates the risk in the first place. That does not make the risk imaginary, but it does mean buyers should treat bullish vendor framing with the usual caution and ask hard questions about what a product actually inspects, what it cannot see, and how it behaves when a model misbehaves rather than when it works as intended.
What it means for Australia
For Australian enterprises, this is not an abstract overseas debate. The country’s larger organisations, from the big four banks to government agencies and the major retailers, are among the more enthusiastic adopters of generative AI, and they are deploying it against a backdrop of tightening regulatory and board-level scrutiny. The Australian Signals Directorate and its Australian Cyber Security Centre have been steadily lifting expectations on how critical infrastructure operators manage digital risk, and AI systems are increasingly caught in that net. A bank or health insurer that stands up a customer-facing AI assistant is now expected to be able to explain how it is secured, not merely that it exists.
The local evidence suggests the gap between ambition and readiness is real. Recent industry research covered on FluentSea has found Australian firms racing ahead on AI adoption while governance and security controls lag behind, and separate survey work has flagged a rise in AI-related security incidents and vulnerabilities as deployments scale. That is precisely the environment in which a pitch like F5’s lands well, because it speaks directly to the anxiety of executives who have been told to embrace AI quickly and to keep it safe at the same time, with those two instructions frequently in tension.
There is a channel dimension too. In Australia, most enterprise security is not bought directly from vendors but through resellers, integrators and managed service providers, the audience CRN Australia serves. If the AI security market grows the way F5 expects, it will flow through those partners, who will need to build the skills to advise clients on securing AI workloads rather than simply reselling boxes. For a local channel still recovering its footing after years of cloud-driven disruption, a fresh and fast-growing category is a welcome prospect, provided the demand proves as durable as the marketing suggests.
What happens next
The near-term test is whether AI security becomes a genuine line item in Australian technology budgets or stays a talking point in vendor keynotes. That will hinge on a few things: how quickly AI applications move from pilots into production, whether a high-profile AI-related breach forces the issue, and how regulators choose to interpret existing cyber and privacy obligations as they apply to models. The Albanese government’s broader push to give Australia a coherent AI policy framework, including its new national office of AI, adds another variable, because clearer rules tend to accelerate enterprise spending on compliance and security.
What is not in doubt is that the vendors have decided AI security is the next big thing, and they are investing accordingly. Whether F5 in particular captures the opportunity it is describing will depend on execution and on fending off a long list of competitors making the same promise. For Australian buyers, the more useful takeaway is simpler. The AI applications now being rushed into service carry risks their existing defences were never built to handle, and working out who is accountable for closing that gap is a decision that cannot be deferred much longer.
Sources: CRN Australia.



















































