From one app to a fleet of agents: A 90-day AI security framework

Industry Trends | July 27, 2026

Most organizations didn't plan their generative AI rollouts. A team stood up a chatbot, another connected a model to internal data, and now there's an agent quietly calling tools in production. Somewhere in that sprint from pilot to deployment, security was left to catch up.

That's the gap F5’s white paper, Securing GenAI: A 30-60-90 Day Framework, is built to close. Instead of treating AI security as a procurement checkbox or a one-time audit, our framework lays out a sequenced, 90-day path that takes teams from securing a single application to running a fleet-wide program to defending autonomous agents.

So what does this framework look like?

Day 0-30 is about discipline, not deployment speed

The temptation with any new GenAI application is to ship it. Yet our AI security framework calls for a different first move: treat model selection, red teaming, and guardrail design as the real work of the first 30 days, not friction to push through.

That means red-teaming the bare model to establish a security baseline, building the application on top of it, and then red-teaming the combined system to see whether the application made things more secure or less. It also means building guardrails across four distinct categories—existing regulations, AI-specific regulations, use-case threats, and red-team findings—so nothing gets missed because it didn't fit neatly into one bucket.

The output of this first phase is a repeatable loop: when a new zero-day threat surfaces, red team again, patch the guardrails, validate, and redeploy.

30-60-90 chart
F5’s three-phase AI security framework moves teams from securing a single application to scaling across the estate to defending autonomous agents.

Day 30-60 turns one secured app into a program

Securing one application well is a good outcome. Securing 20 applications the same way, on the same cadence, with the same auditability, is a different problem entirely. This is where most organizations stall.

Our framework includes four pillars that turn ad-hoc security work into a scalable program:

  1. Defined red-team cadences tied to risk tier
  2. Establish a guardrail patch pipeline that can roll updates out (and back) across many applications at once
  3. Create a fleet-wide zero-day response process with real SLAs
  4. Provide SOC enablement so security operators can investigate AI incidents with the same fluency they bring to any other threat

This second phase is complete when an organization can answer, for every AI application, who owns it and when it was last tested.

Day 60-90 confronts a fundamentally different risk

Autonomous agents don't just respond to questions. They run continuously, reason through multi-step plans, and take real actions through tools. This means the security model built for request-and-response applications doesn't transfer cleanly.

Our framework's answer centers on two ideas. First, observability has to extend beyond logging outcomes to logging reasoning: every thought, tool call, and decision an agent makes, tied together so a post-incident review can reconstruct not just what happened, but how. Second, when an agent's reasoning veers somewhere risky, simply blocking that thought tends to break the agent mid-task. The framework instead points to thought injection—replacing a risky thought with a safer one that keeps the agent productive—paired with action-level controls like tool permissions and approval gates for high-impact moves. GenAI security isn't a single milestone you hit and move past. It's an operating rhythm that this framework is built to help security teams establish before the gaps in their AI deployments turn into incidents.

Read our white paper for the complete 30-60-90 day framework, including the Phase 1-3 checklists your team can put to work right away. Also, be sure to register for our upcoming webinar.

Share

About the Authors

James White
James WhiteCTO, AI Security | F5

James White is an accomplished engineer and business leader with nearly two decades of experience in the enterprise software industry.

More blogs by James White
Jessica Brennan
Jessica BrennanSenior Product Marketing Manager, AI Security | F5

More blogs by Jessica Brennan

Related Blog Posts

Securing the new control points in the AI journey
Industry Trends | 07/01/2026

Securing the new control points in the AI journey

AI architecture is fundamentally different than traditional IT environments and requires a different security strategy to protect critical AI workloads.

The patch window has closed. Here is how F5 is built for what comes next.
Industry Trends | 04/27/2026

The patch window has closed. Here is how F5 is built for what comes next.

As AI models have changed software security, the industry needs to adapt.

Best practices for optimizing AI infrastructure at scale
Industry Trends | 01/21/2026

Best practices for optimizing AI infrastructure at scale

Optimizing AI infrastructure isn’t about chasing peak performance benchmarks. It’s about designing for stability, resiliency, security, and operational clarity

Datos Insights: Securing APIs and multicloud in financial services
Industry Trends | 12/23/2025

Datos Insights: Securing APIs and multicloud in financial services

New threat analysis from Datos Insights highlights actionable recommendations for API and web application security in the financial services sector

Secrets to scaling AI-ready, secure SaaS
Industry Trends | 12/12/2025

Secrets to scaling AI-ready, secure SaaS

Learn how secure SaaS scales with application delivery, security, observability, and XOps.

How AI inference changes application delivery
Industry Trends | 11/19/2025

How AI inference changes application delivery

Learn how AI inference reshapes application delivery by redefining performance, availability, and reliability, and why traditional approaches no longer suffice.