F5 Hardened Release 1 is available. Staying current is one of the most important steps you can take to protect your environment.Learn more

The authority trap: What F5 Labs AI threat intelligence reveals about AI’s expanding attack surface

Industry Trends | August 13, 2026

The AI attack surface is expanding as models gain access to tools, credentials, code, and production systems. Across F5 Labs research published from April through July 2026, the clearest finding is that enterprise AI risk is not defined only by whether a model can be manipulated, but also by what the surrounding system allows it to access and do when manipulation or errors occur.

The F5 research reveals that similarly capable models can have radically different security profiles, those profiles can shift after deployment, useful features can create new attack paths, and excessive authority can turn a model-level weakness into a business incident. That risk is no longer theoretical. In incidents examined by F5 Labs, attackers manipulated an AI-supported account-recovery process to change access details, while a coding agent deleted a production database and its backups.

For CISOs, the value of the research is not in a leaderboard recap, but in the practical lessons it provides for model selection, procurement, continuous assurance and control over what AI systems are permitted to access and do.

F5 Labs uses two complementary measures to evaluate these risks. The F5 Comprehensive AI Security Index (F5 CASI), scores resistance to prompt injection and jailbreak attacks, while the F5 Agentic Resistance Score (F5 ARS), scores resistance to sustained, multi-step attacks in agentic scenarios. Both run from 0 to 100, with higher scores indicating stronger resistance.

F5 research reveals that similarly capable models can have radically different security profiles, those profiles can shift after deployment, useful features can create new attack paths, and excessive authority can turn a model-level weakness into a business incident.

Authority turns model risk into business impact

A model-level weakness becomes a business incident when the surrounding system permits consequential action. A model that produces an unsafe response creates risk. A model connected to code, credentials, account-recovery workflows or production data can create an incident.

In one case examined by F5 Labs, a coding agent deleted a production database and its backups. In another, attackers manipulated an AI-supported account-recovery process to change access details for prominent social media accounts. The critical failure was not only that the AI reached the wrong conclusion. The surrounding system allowed that conclusion to trigger a high-impact action.

The JadePuffer ransomware operation reinforced the point from the attacker’s perspective. A human selected the victim, supplied credentials and established infrastructure, but the agent automated meaningful parts of reconnaissance, exploitation, lateral movement, and encryption. Full autonomy was unnecessary; partial automation already reduced the time, skill, and effort required.

For CISOs, the immediate risk is not autonomy alone, but also authority. AI agents should be governed as privileged identities, with tightly scoped credentials, restricted tool access, continuous monitoring, and independent approval for high-impact actions. The next question is how attackers exploit the behaviors that make these systems useful in the first place.

Useful features create attack paths

F5 Labs research found that attackers repeatedly exploited behaviors enterprises actively want from AI systems. Developer Role Attack targeted how models interpret privileged instructions. BiasJailbreak used demographic framing to expose inconsistencies in refusal behavior, while Topic Bridge used conversational continuity to move models gradually from legitimate subject matter toward harmful requests.

Adversarial Tales extended the same pattern by embedding harmful procedures inside fictional narratives and asking models to analyze the story rather than respond to an overtly malicious request. Across 26 frontier models from nine providers, the technique achieved an average attack success rate of 71.3%.

These attacks targeted instruction following, contextual reasoning, role awareness and content analysis, capabilities that underpin legitimate enterprise use cases. They show how useful features can expand the AI attack surface. Static filters and known jailbreak libraries will struggle when attackers can preserve malicious intent while changing how it is presented.

Useful behaviors can therefore create the path to manipulation, while authority and access determine the potential business impact. The likelihood of manipulation also depends on the model’s underlying resilience, and capability is a poor proxy for it.

Capability does not predict resilience

F5 Labs testing found that models with similar capabilities can sit at opposite ends of the security rankings, while models within the same family can behave very differently.

The clearest example came from Qwen3.5. Its 2-billion-parameter model scored 1.28 on F5 CASI, while the 4-billion-parameter version scored 80 - a gap of almost 79 points between two models carrying the same family name.

The latest testing reinforced the pattern. Flagship models with relatively similar capabilities ranged from 93.08 to 16.25 on F5 CASI. F5 ARS data added another dimension: Qwen3.5-4B scored 91.04 on F5 ARS, but 58 on F5 CASI, with average performance of 16 percent. The contrast shows why F5 CASI, F5 ARS and performance should be interpreted as distinct, complementary signals.

For CISOs, capability benchmarks indicate whether a model can complete a task, not whether it can do so securely. Every model and version must be assessed independently during procurement and throughout deployment. Model selection, however, is only the first decision; security teams must also account for how resilience changes over time.

AI security posture can shift after deployment

Model resilience is not fixed. F5 Labs observed one model decline by more than 29 F5 CASI points in a month, while another moved by more than 55 points across the period examined. Other releases remained comparatively stable, making consistency itself part of the risk picture.

Providers can update system prompts, classifiers and safety controls without changing the customer-facing model name. A model may therefore appear unchanged while its security posture has shifted materially.

This is not a traditional patching problem. Point-in-time approval is insufficient when a model’s security posture can change without a new model name or visible deployment event. Security teams should reassess models after provider updates, configuration changes and material changes to the application, and continuously verify that surrounding controls remain effective.

That volatility makes continuous assurance essential, but evaluation alone is not enough. CISOs must also control what AI systems are permitted to access and do.

What CISOs should do now

The clearest takeaway from the research is that authority determines impact. CISOs should govern AI systems according to what they are permitted to access and do, while continuously evaluating the models, controls and systems around them.

  • Treat AI agents as privileged identities. Inventory and restrict access to credentials, tools, data and production systems; require independent approval for high-impact actions; and log every consequential step.
  • Continuously evaluate the complete AI system. Assess every model and version independently during procurement and throughout deployment, reassess after provider or configuration changes, and test gateways, packages, plugins, workflows, identities and integrations - not only the model.

How F5 Labs measures AI resilience

F5 CASI and F5 ARS are comparative measures, not permanent safety certifications. Results should be interpreted alongside the exact model version, assessment date, intended use and surrounding controls.

Taken together, the research reveals a connected chain of risk: capability does not predict resilience, resilience can shift after deployment, useful features can expand the AI attack surface, and excessive authority can turn a model weakness into a business incident.

The question for CISOs is no longer only whether an AI model can be manipulated. It is what the surrounding system will allow that model to do when manipulation succeeds.

Learn more

Share

About the Authors

Malcolm Heath
Malcolm HeathPrincipal Threat Researcher | F5

Malcolm Heath is the Principal Threat Researcher with F5 Labs. His career has included incident response, program management, penetration testing, code auditing, vulnerability research, and exploit development at companies both very large and very small. Prior to joining F5 Labs, he was a Senior Security Engineer with the F5 SIRT.

More blogs by Malcolm Heath
Louise Scully
Louise ScullySr. Mgr., PMM, AI Security & Threat Intelligence | F5

Louise Scully is a Senior Manager in Product Marketing for AI Security and Threat Intelligence at F5. Her career has spanned product marketing, product management, go-to-market strategy, communications, thought leadership, and category development across AI security and enterprise technology. Prior to joining F5, Louise led marketing at both CalypsoAI and Artomatix, helping bring AI technology and research to market.

More blogs by Louise Scully

Related Blog Posts

Securing the new control points in the AI journey
Industry Trends | 07/01/2026

Securing the new control points in the AI journey

AI architecture is fundamentally different than traditional IT environments and requires a different security strategy to protect critical AI workloads.

The patch window has closed. Here is how F5 is built for what comes next.
Industry Trends | 04/27/2026

The patch window has closed. Here is how F5 is built for what comes next.

As AI models have changed software security, the industry needs to adapt.

Best practices for optimizing AI infrastructure at scale
Industry Trends | 01/21/2026

Best practices for optimizing AI infrastructure at scale

Optimizing AI infrastructure isn’t about chasing peak performance benchmarks. It’s about designing for stability, resiliency, security, and operational clarity

Datos Insights: Securing APIs and multicloud in financial services
Industry Trends | 12/23/2025

Datos Insights: Securing APIs and multicloud in financial services

New threat analysis from Datos Insights highlights actionable recommendations for API and web application security in the financial services sector

Secrets to scaling AI-ready, secure SaaS
Industry Trends | 12/12/2025

Secrets to scaling AI-ready, secure SaaS

Learn how secure SaaS scales with application delivery, security, observability, and XOps.

How AI inference changes application delivery
Industry Trends | 11/19/2025

How AI inference changes application delivery

Learn how AI inference reshapes application delivery by redefining performance, availability, and reliability, and why traditional approaches no longer suffice.