Recently, I was in London again, attending the analyst summit F5 held alongside its AppWorld event. Since this is also F5’s 30th anniversary year, there was the expected amount of reflection on how much application delivery, security, cloud, and enterprise infrastructure have changed over the past three decades. There was also, inevitably, a lot of AI.
In this case, however, the AI story was connected to a real enterprise problem: complexity. Enterprises are not standardizing on one cloud, one application architecture, or one AI model. They operate across data centers, public clouds, edge locations, SaaS services, APIs, Kubernetes clusters, and AI inference environments. F5’s message at AppWorld was that this complexity is not a temporary phase on the way to something cleaner but, in fact, the new operating model.
The company is repositioning application delivery as a strategic control point for the AI-era enterprise. In the roadmap session, F5 described the infrastructure shift as moving “from packets to tokens,” which may be the most precise framing. Traditional application delivery was about traffic, protocols, and availability. The next-generation application delivery stack must also understand APIs, models, agents, data flows, runtime policy, token costs, and AI-specific risks.
Application Delivery Is Relevant Again
The central story is F5’s Application Delivery and Security Platform, or ADSP. This is the umbrella under which F5 is bringing together BIG-IP, NGINX, and Distributed Cloud Services capabilities like WAF, API security, bot defense, observability, and AI security. The ambition is obvious: make it the platform that delivers, secures, observes, and increasingly governs applications wherever they run.
Of course, every technology vendor wants to be a platform because “platform” has become the default claim of any company assembling more than two products. F5's claim is harder to dismiss than most. Large organizations already rely on F5 in the data path for critical application delivery, resilience, and security. The company is trying to extend an existing infrastructure position into a world where application traffic increasingly includes APIs, AI models, and autonomous agents.
This also fits a broader point I made recently in Why API Security Is Becoming the Core of Enterprise Cyber Defense: APIs are no longer just developer plumbing. They are the channels through which business logic, data access, automation, and increasingly AI agents operate. Application delivery and API security are therefore no longer adjacent topics. They are becoming part of the same control problem.
Hybrid Multicloud Is the New Baseline
F5’s event narrative was built around the idea that hybrid multicloud is no longer a transitional mess. It is the baseline. According to F5's own research, 93% of organizations now operate in hybrid multicloud environments, with F5 customers running applications across an average of more than 19 environments.
That complexity is precisely the problem F5 Insight for ADSP is designed to address. The company acknowledged that customers value the technology, but that understanding what it does, managing it across environments, and transferring knowledge between teams can be difficult. Insight is intended to change that by turning telemetry into natural-language explanations, root-cause analysis, application health views, and prioritized remediation guidance.
APIs, AI, and Runtime Control
F5 is extending API discovery and protection deeper into enterprise environments, including BIG-IP deployments and air-gapped local editions. API security is often discussed as if the main issue were public-facing APIs exposed through modern cloud gateways. In reality, many important APIs are internal, hybrid, undocumented, or connected to legacy systems.
Every time an AI application calls a model, every time an agent calls a tool, and every time a workflow stitches together services, APIs are doing the work. This is why F5’s AI security story is strongest when framed around runtime control and remediation, not just detection. The combination of F5 AI Red Team, F5 AI Guardrails, and AI Remediate is meant to identify weaknesses, translate them into runtime protections, and let the customer decide when these protections go live.
That human-in-the-loop element is important. Agentic AI is not just an authentication problem or a prompt security problem. MCP servers, tool definitions, agents, and downstream integrations create a dependency graph that must be inventoried, reviewed, and monitored at runtime. A valid token does not mean safe behavior. It only means someone or something was allowed to connect.
AI agents are changing the nature of data access because they chain operations, combine data sources, and adapt behavior based on intermediate results. F5 does not own the data layer, but its position in the traffic path gives it a relevant enforcement and observation point for these new flows.
Sovereignty and Resilience
Digital sovereignty was another important theme, especially in the European context. F5 framed it as autonomy over data, technology stack, and operations, including where data lives, how quickly organizations recover from disruption, which infrastructure providers they depend on, and how much they rely on any single provider. That is the right direction, because digital sovereignty is often reduced to data residency, which is far too narrow.
For F5, sovereignty can be a tailwind. In the analyst Q&A session, the company’s leadership argued that many customers are moving away from overreliance on U.S. hyperscalers toward on-premises deployments, local cloud alternatives, and customer-controlled infrastructure. At the same time, F5 remains a US vendor, so the sovereignty message must be handled carefully. The stronger argument is not “buy from us instead of hyperscalers” but one centered on deployment choice, operational autonomy, and customer control over where critical functions run.
This also echoes the argument I made in Platform Dependence and the Growing Fragility of the Internet: resilience cannot be outsourced entirely. Platform consolidation creates efficiency, but it also creates dependency. Sovereignty without resilience is just a different form of fragility.
Cryptographic agility is a case in point. F5 BIG-IP v21, highlighted at the event, adds support for hybrid ciphers combining classical ECC with ML-KEM - incremental and non-disruptive by design, which is precisely how infrastructure adapts before it is forced to.
The Caveats: Convergence, Developers, and Agents
There are still areas where F5 needs to prove execution. The first is platform convergence. ADSP is a compelling umbrella, but F5 must bring together several product families with different histories, deployment models, and operating assumptions. A genuinely converged platform would deliver common policies, shared telemetry, simpler operations, clearer packaging, and a realistic migration path.
The second is developer relevance. F5 was clear that its enterprise engagement model remains centered on NetOps and SecOps, not developers. And yet, agentic AI, MCP usage, and AI-assisted application development often start in development and test environments before reaching production. F5 does not need to become a developer tools company, but it will need a credible way to influence platform engineering and application design earlier in the lifecycle.
The third is agent identity. The industry has not yet established how to authorize agents continuously and in context, and F5 has no answer here either, at least not yet.
Bottom Line
F5 is addressing real enterprise conditions: hybrid multicloud complexity, expanding API surfaces, AI-driven traffic, digital sovereignty demands, and a persistent shortage of specialist expertise.
The opportunity is significant because F5 already sits where many of these problems converge: in the data path, close to applications, APIs, users, bots, models, and agents. The risk is that convergence becomes too complicated before it becomes useful. F5’s job now is not to prove that it has enough products but to demonstrate that ADSP can become a coherent operating model for customers.
If F5 can make delivery, security, observability, and AI governance simpler across hybrid environments, the move from packets to tokens may give application delivery renewed strategic relevance.