Stay current to protect your environment with F5 Hardened Releases.Learn more

Security at AI speed: Defending the enterprise against autonomous threats

Industry Trends | September 08, 2026

AI is significantly compressing the time between when security vulnerabilities are discovered and exploited. To understand what that means in practice for security leaders, we recently sat down with F5's Chief Technology Operations Officer Michael Montoya, who’s responsible for F5’s enterprise-wide security and resiliency strategy. Read on to learn Montoya’s perspective on what the post-Mythos threat landscape looks like and what organizations must do to survive.

Q: Mythos threat landscape actually look like?

Montoya: Honestly, it looks faster. That's the headline. What we're seeing is AI accelerating vulnerability discovery and compressing the window between disclosure and exploitation. That window used to be measured in weeks or months. Security teams built their entire operating rhythm around that assumption— you'd get a disclosure, triage it, schedule a patch, work it through change control. That cadence doesn't hold up anymore.

And I want to be clear about what the real challenge is here. It isn't simply that there are more threats. It's the speed and the scale at which they emerge. Velocity is a different problem entirely because organizations no longer have weeks or months to respond.

So what does that mean for security leaders? It’s important they shift from patch-first thinking to protection-first thinking. Patching still matters enormously, but it can't be your only line of defense when the clock is running that fast. Second, they need to respond at AI speed. That means leaning on runtime protection and virtual patching to reduce exposure while permanent fixes are working their way through. And in a world where applications, APIs, and AI workloads are distributed across clouds, data centers, and the edge, it means adopting a platform approach that enables security to be applied consistently across your entire environment.

Q: What is the biggest risk you see organizations underestimating right now?

Montoya: Without hesitation, it’s complexity. I think many organizations haven’t fully internalized that complexity itself has become one of their most significant security risks.

Think about where the average enterprise actually operates today: hybrid environments, multiple clouds, the edge, and now a growing set of AI environments layered on top. Every one of those creates the potential for disconnected tools, policies, and workflows—and the opportunity for a gap or a blind spot. Nobody sets out to build it that way. Yet it happens over time.

The work here is unglamorous but high leverage. Reduce operational complexity wherever you can. Move away from disparate point solutions toward a unified platform strategy. And establish consistent visibility, policy enforcement, and protection across every environment you operate in. If you can't answer, “What's protecting this app, and by what policy?’ the same way regardless of where the app lives, that's your starting point.

Q: Trust in the software supply chain is under pressure. How are you evolving F5's security practices to keep customers safe?

Montoya: Our customers measure trust in F5 by how quickly we help them identify and respond to emerging threats. It’s a fair assessment, and one we apply to ourselves.

The hard truth is that traditional release cycles struggle to keep pace with machine-speed vulnerability discovery. If your security improvements move on a quarterly rhythm and threats move on a daily one, you're structurally behind. So security has to be continuous, and it has to be built into the platform itself.

Practically, that means automating security testing, validation, and hardening wherever we possibly can, and accelerating how fast security improvements and updates actually reach customers.

And I'd extend that expectation outward. Hold your technology partners accountable for securing and hardening their products at the pace of emerging threats. Ask them what their cycle time looks like. Ask what's automated. Those are fair questions now, and the answers tell you a lot.

Q: With app teams pushing new code and AI features at lightspeed, how do you protect innovation without slowing down the business?

Montoya: This is a question I get asked a lot. AI-driven innovation is fueling an explosion of applications, APIs, and services. That's not a problem to be contained; it's the business. But here's the dynamic security leaders have to watch: when security becomes a bottleneck, development doesn't stop. It routes around you. You end up with less visibility and less control than you had before, which is the opposite of what you were trying to achieve.

So the goal isn’t choosing between speed and security. You can’t make that tradeoff. Instead, you need to enable both. There isn’t a CISO out there who’s looking to slow down the business or stop innovation.

A few ways to achieve the balance needed: Embed security into the application delivery process itself. Automate protection wherever you can instead of relying on manual reviews that don't scale. Use controls that can reduce risk immediately when new threats emerge, extending protection while the code catches up. And then give developers real freedom to innovate, with governance and security holding steady underneath.

Get that right and security stops being the team that says no. It becomes the team that makes innovation safe.

Q: Bottom line: what's the single most important thing a security leader needs to do today to survive this new reality?

Montoya: Build for resilience and organize around it. It’s important to understand that boards are no longer only asking whether their organization is secure, but also whether they can adapt, respond, and recover quickly in the face of constant change. And that means resilience is now a business requirement.

As I said earlier, eliminating complexity is a big part of that equation. You need to converge application delivery, security, and operations around a common operating model. You need to invest in platforms that improve visibility, consistency, and resilience. And you need to maintain control over where all your applications, data, and security policies reside, as geopolitical and AI-driven pressures continue to evolve.

Security leaders have to move at the same speed, if not faster than AI. And that means we have to use AI in every part of our defense. It’s not a quick lift. But it’s ultimately what will separate the organizations that thrive in the AI era.

To learn more, visit our F5 Application Delivery and Security Platform (ADSP) webpage. Also, be sure to register for F5’s virtual, on-demand Post-Mythos Security Summit, which starts September 10.

Share

Related Blog Posts

Securing the new control points in the AI journey
Industry Trends | 07/01/2026

Securing the new control points in the AI journey

AI architecture is fundamentally different than traditional IT environments and requires a different security strategy to protect critical AI workloads.

The patch window has closed. Here is how F5 is built for what comes next.
Industry Trends | 04/27/2026

The patch window has closed. Here is how F5 is built for what comes next.

As AI models have changed software security, the industry needs to adapt.

Best practices for optimizing AI infrastructure at scale
Industry Trends | 01/21/2026

Best practices for optimizing AI infrastructure at scale

Optimizing AI infrastructure isn’t about chasing peak performance benchmarks. It’s about designing for stability, resiliency, security, and operational clarity

Datos Insights: Securing APIs and multicloud in financial services
Industry Trends | 12/23/2025

Datos Insights: Securing APIs and multicloud in financial services

New threat analysis from Datos Insights highlights actionable recommendations for API and web application security in the financial services sector

Secrets to scaling AI-ready, secure SaaS
Industry Trends | 12/12/2025

Secrets to scaling AI-ready, secure SaaS

Learn how secure SaaS scales with application delivery, security, observability, and XOps.

How AI inference changes application delivery
Industry Trends | 11/19/2025

How AI inference changes application delivery

Learn how AI inference reshapes application delivery by redefining performance, availability, and reliability, and why traditional approaches no longer suffice.