Technology2026-10-074 min read

F5 Workforce AI Security maps AI risk before agents act

F5’s new agentless security product is aimed at a growing business problem: employees and AI agents using company data, tools and permissions without a clear control point. Here is what UAE owners should do with the announcement.

F5 Workforce AI Security maps AI risk before agents act

F5 Workforce AI Security: agentless AI traffic monitoring

F5 announced Workforce AI Security on 9 September 2026. The product is part of its wider AI Security Platform and is expected to become generally available during October 2026. Its purpose is to show how employees use AI, identify the AI services in use, and control what agents do on a user’s behalf. (f5.com)

The important detail is that it is agentless. F5 says it works by analysing network traffic, rather than requiring another endpoint client, browser extension or software installation on every device. It is designed to cover browsers, command-line tools, coding agents, MCP clients and agent harnesses. (f5.com)

The business question is no longer only which AI tool employees use. It is what that tool can see, change or send on their behalf.

A transparent security gate separates company data cards from the tools waiting to access them.
A transparent security gate separates company data cards from the tools waiting to access them.

How F5 Workforce AI Security controls AI agents and data

Workforce AI Security is designed to create an inventory of AI services, models and agent tools appearing in company traffic. F5 also says it can record prompts, responses, user intent and data flows, then apply policies based on the service, user group, file upload or data involved. (f5.com)

For agent activity, the proposed control point is before execution. F5 says the product can inspect and classify tool calls across MCP servers and supported agent tools, then allow, block or modify an action according to identity, access risk and sensitive-data exposure. That is different from finding a problem after an agent has already changed a record or sent information. (f5.com)

F5 also describes inline redaction for sensitive information and integration with identity providers such as Azure AD and Okta. These are product claims from F5, not a guarantee that every UAE company’s existing setup will work without configuration or testing. (f5.com)

What F5 Workforce AI Security means for UAE businesses

The announcement does not create a new UAE filing, licence or fee. It changes the practical discussion around AI access. If an employee is using a public model to summarise customer information, or an agent is connected to an ERP, CRM or shared drive, the owner needs to know the permissions involved and the action that could follow.

A small company may not need an enterprise security platform. It may first need a written AI register and a short list of prohibited actions. For example:

That work is useful even if the business never buys F5. If your AI project touches stock, accounts or customer records, document the workflow before automating it. Paknology’s ERP and automation service may be relevant to the workflow design, but it is not a replacement for specialist cybersecurity advice.

The F5 announcement is also a reminder that endpoint controls alone may not show the full picture. F5’s position is that a network-level view can identify approved and unapproved AI use, including private models and shadow AI, without installing agents or extensions. Whether that approach fits depends on your network design, identity controls, existing SASE tools and the level of audit detail you need. (f5.com)

  • —Which AI services are approved
  • —Which information cannot be pasted into them
  • —Which systems an agent may read
  • —Which actions need human approval
  • —Who reviews logs and exceptions

How UAE owners can review AI agent permissions

Start with one worked example rather than a company-wide technology purchase. Take an agent that drafts supplier emails or updates an internal system. Write down its user identity, data sources, tools, permissions, approval point and possible failure. Then decide whether a simple access rule is enough or whether you need traffic inspection and pre-action policy enforcement.

If the answer is “we do not know what AI is being used”, begin with discovery. If the answer is “we know the tools, but agents can act without review”, prioritise permissions and approval gates. If AI use is limited to low-risk drafting with no company data or system access, a policy and staff training may be the cheaper and simpler answer.

F5 says Workforce AI Security will be generally available beginning in October 2026. Read the official announcement for the stated capabilities, then ask a security specialist to test the design against your own network and data flows. (f5.com)

Paknology has a commercial interest where this discussion leads to ERP workflows, automation or a website and app project, including through its ERP and automation service. It does not sell F5 or specialist cyber-security products. If your requirement is only an AI-use policy, a permissions review or independent security testing, a cheaper specialist or an internal IT review may serve you better. If none of the listed services fits, talk to us and we will keep the answer within scope.

Ready to launch, automate and scale?

Book a free consultation and get a clear roadmap — from company formation to a fully automated digital operation.