Back to News
SecurityAI Understanding briefing

Fastly launches AI firewall and runtime control tools

Fastly has introduced AI Runtime Control, AI Firewall, and enhanced API security features to help organizations manage AI model access, costs, and security risks in production environments.

4 min readRead the linked source
Source-provided image accompanying Fastly launches AI firewall and runtime control tools
Source referenceSource recorded
Publisher
securitybrief.co.nz
Source link
securitybrief.co.nzhttps://securitybrief.co.nz/story/fastly-launches-ai-firewall-runtime-control-tools
Source type
Linked source โ€” primary-source status has not been established.
Also cited

Story last revised

ContextUnderstand this in 60 seconds

Start here

Key terms

API (Application Programming Interface)
A structured way for one software system to send requests to and receive responses from another system.
Prompt Injection
An attack pattern where malicious instructions are inserted into model inputs or retrieved content.
Prompt
The input instructions and context provided to a generative model.
Test yourselfAI Agents Quiz

What changed since publication

  1. First published
  2. This source provides additional context regarding the motivation for the launch, specifically citing internal network data showing machine-generated traffic exceeding 50% in July and August, and references McKinsey research on AI budget overruns to justify the need for the new cost-management and security features.

What happened

Fastly has expanded its product portfolio with the launch of AI Runtime Control, AI Firewall, and new API security capabilities. These tools are designed to provide real-time visibility and governance for organizations transitioning AI deployments from experimental phases to production environments.

Fastly's new AI Runtime Control sits between applications and AI models, acting as a central routing endpoint for both public and self-hosted providers. It includes features for token spending visibility, rate limiting, and budget controls, while using virtual keys to protect provider credentials. This allows organizations to switch between different model providers while maintaining consistent policy enforcement.

The AI Firewall is specifically designed to protect AI applications by evaluating prompts in the request path before they reach the model, aiming to mitigate risks such as . Additionally, the new API Security features are intended to govern how AI agents interact with enterprise APIs, allowing organizations to enforce API contracts and block non-compliant requests from agentic or agent-assisted traffic.

The company stated that these tools are a response to the rapid growth of machine-generated traffic, which it claims rose above 50% on its network during July and August. Fastly cited McKinsey research indicating that 93% of organizations are currently exceeding their AI budgets, highlighting the need for the cost-management features included in the new release.

Source details: securitybrief.co.nz โ†—

Why it matters

As organizations increasingly integrate AI models and autonomous agents into their infrastructure, they face significant challenges regarding cost management, security, and operational reliability. Fastly's new suite addresses these by centralizing policy enforcement and security controls directly in the request path. By providing a unified layer for model routing, token budget management, and mitigation, the company aims to help enterprises scale AI adoption without sacrificing security or exceeding operational budgets.

The shift toward multi-model architectures means enterprises are increasingly reliant on a complex web of external and internal services. Fastly's approach attempts to consolidate security and governance on the same edge platform used for content delivery and DDoS protection, potentially simplifying the security stack for IT teams.

By moving security and control to the edge, Fastly aims to provide the 'real-time' governance that Kelly Shortridge, Chief Product Officer, argues is necessary to maintain business resilience. The ability to observe or block traffic on a service-by-service basis provides a granular level of control that is critical as AI agents begin to automate more complex software development and operational tasks.

Interactive Mechanism

Interactive Mechanism: How It Actually Works

Explore the underlying technology behind this development interactively.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:๐Ÿ›ก๏ธ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language modelโ€”it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Interactive Concept Check+10 Points
AI Agents Quiz

What is the most accurate way to describe what AI Agents can do today?

What to watch next

The effectiveness of these tools in mitigating sophisticated attacks and their ability to handle diverse, multi-vendor AI architectures will be key indicators of their utility. Observers should monitor how well these edge-based controls integrate with existing enterprise workflows and whether they successfully reduce the operational friction associated with managing heterogeneous AI model deployments.

Pricing and specific availability details for these new features were not disclosed in the announcement. Potential users should verify whether these tools are currently generally available or if they are being rolled out in phases.

The long-term impact of these tools will depend on their compatibility with the rapidly evolving landscape of AI frameworks and the specific types of attacks they can effectively neutralize. As AI agents become more autonomous, the ability of these tools to enforce strict API contracts will be a critical test of their efficacy in preventing unauthorized or malformed operations.

Related guides & quizzes

AI AgentsAI Models ExplainedAI EthicsTest what you know โ€” try a free AI quizLook up an AI term in our glossary

Updates and corrections

This canonical story is updated in place when the developing event materially changes. Its URL and original publication date never change.

  • This source provides additional context regarding the motivation for the launch, specifically citing internal network data showing machine-generated traffic exceeding 50% in July and August, and references McKinsey research on AI budget overruns to justify the need for the new cost-management and security features.
See the public corrections log
Found this useful?