Platform summary
F5 SurePath AI is a network-level governance platform for safe, compliant adoption of Generative AI (GenAI) across the enterprise. Rather than blocking public AI outright or relying only on coarse SASE controls, SurePath AI intercepts GenAI traffic, applies fine-grained policy (access control, content controls, and PII detection), and produces an auditable record of workforce AI use. This reduces the risk of data exposure, policy violations, and shadow AI.
SurePath AI integrates with an organization's existing security stack — preferably via SASE vendor-specific forward proxy chaining (often referred to as "forward-to-proxy"), or through proxy PAC, DNS reflection, destination NAT, and secure web gateways — so organizations can adopt public and private AI without changing user workflows. SurePath AI adds GenAI-aware governance and visibility on top of an existing SASE investment rather than replacing it.
Gain visibility
User Activity centralizes governed sessions, detections, and outcomes. Admins can export events automatically to a customer-managed S3 bucket for long-term retention, SIEM correlation, and reporting. Dashboards surface adoption trends and risk events for IT and business stakeholders.
Mitigate risk
SurePath AI helps organizations meet compliance obligations by limiting personal and confidential data sent to external AI services and producing auditable records of usage. This support is relevant to GDPR and CCPA/CPRA, HIPAA, PCI DSS, GLBA, and FERPA, as well as programs aligned to ISO 27001, NIST 800-53/171, DORA, and AI Act readiness.
Organizations can reduce exposure by applying guardrails that identify risky or sensitive content and take actions such as monitoring, alerting, redaction, or blocking. Consistent handling of personal data and other sensitive categories, paired with user coaching and policy enforcement, aligns day-to-day AI use with security and compliance requirements.
Increase safe adoption
SurePath AI helps organizations move from pilots to organization-wide GenAI adoption without sacrificing control. Detecting and mitigating sensitive data in prompts reduces the likelihood and cost of data exposure. Observing adoption across teams and tools lets admins prioritize licenses and focus on the highest-value use cases. Policies default to coaching — warning users and guiding safe behavior — while allowing stronger redaction, synthesis, or blocking where needed. Because SurePath AI integrates through SASE and PAC, organizations reach value without deploying new agents for web traffic, and retain audit-ready records in their own systems for investigations and analytics.
SurePath AI governs how the workforce engages with both public and private GenAI. For public tools, SurePath AI intercepts requests and applies access and sensitive-data controls before prompts leave the organization's environment, while recording a complete, searchable audit trail. For private AI, SurePath AI provides a portal that routes to models the organization operates in its own cloud, protected by RBAC and policy. A unified policy engine ties this together: admins decide who can use which services, what data must be protected, and how violations are handled. Integrations steer only GenAI traffic for inspection, leaving normal browsing untouched.
How it works
Policy model
SurePath AI applies least-privilege. The Default Policy sets the baseline for everyone. Group Policies are additive, granting access to additional public services, private models, data sources, or exceptions to sensitive-data handling for specific user populations. Within policy, admins configure public service access using the Public Service Catalog (a curated list of GenAI destinations); sensitive-data handling through Content Controls (rules that detect risky content such as harmful content, code, prompt injection, and confidential data) and PII Detection (entity-based detection for personal data) with actions such as Monitor, Warn, Tag, Mask, Delete, Synthesize, or Block. Policies also control access to private portal resources including models, Data Sources, and Assistants.
Controls and end-user experience
Content Controls detect high-risk requests, confidential data, harmful content, prompt injection, and code. Depending on policy, users may see a contextual warning, have elements redacted or synthesized, or be blocked where allowed. PII Detection applies a global action to enabled entities for consistent handling of personal data. Most organizations begin with non-blocking warnings and progress to stronger actions for higher-risk groups.
How traffic reaches SurePath AI
Only GenAI destinations are diverted to SurePath AI; all other web traffic follows its normal path. In the preferred model, the organization's SASE platform performs TLS interception and forwards GenAI traffic to SurePath AI using a vendor-specific forward proxy chaining concept (often called forward-to-proxy), optionally adding an X-Authenticated-User header for identity. Alternatively, endpoints can use a Proxy PAC URL (a browser/network auto-config file) to send only GenAI domains to the SurePath AI TLS proxy, or SASE can forward without upstream TLS interception when endpoints trust the SurePath AI Root CA (the SurePath AI certificate authority). The private portal is always accessed directly and is governed by portal policy and RBAC.
Ways to deploy
SurePath AI integrates with leading SASE providers such as Zscaler, Netskope, and Cloudflare via a vendor-specific forward proxy chaining concept (often called forward-to-proxy). For PAC-based steering, configuration can be distributed through Google Admin, Microsoft Intune, Jamf, or Rippling. Network options like DNS reflection, destination NAT, and secure web gateways are also supported. When SurePath AI performs TLS inspection, endpoints or upstream devices must trust the SurePath AI Root CA.
Beyond SASE
The table below highlights how SurePath AI complements a SASE-only approach.
Capability | SASE-only controls | SurePath AI added value |
GenAI-specific allow/deny | URL category allow/block | Per-service governance with Public Service Catalog |
Prompt and response awareness | Limited or none | Intercept prompts; apply Content Controls and PII actions |
Sensitive data handling | Generic DLP (varies) | Entity-based detection; Tag/Mask/Delete/Synthesize |
Coaching vs blocking | Coarse policy | User-friendly warnings; least-friction workflows |
Shadow AI mitigation | Block drives bypass | Govern and monitor to keep users on approved paths |
Visibility & audit | Web logs | AI-focused activity events; exportable to S3 |
Private AI enablement | Not applicable | Portal with private models, data sources, assistants |
For a description of platform components and traffic flows, see SurePath AI architecture.
Ready to deploy? See Initial configuration steps for a guided setup walkthrough.
