
Most conversations about introducing enterprise AI gloss over a simple fact: the vast majority of organisations didn’t plan their generative AI rollouts. A team stood up a chatbot, another connected a model to internal data, and now there’s an agent quietly calling tools in production. Somewhere in that sprint from pilot to deployment, security was left to catch up.Â
https://www.f5.com/go/white-paper/securing-generative-ai-a-30-60-90-day-framework Instead of treating AI security as a procurement checkbox or a one-time audit—or, worse still, ignoring it altogether—organisations should adopt a framework which lays out a clearly sequenced, 90-day path that takes teams from securing a single application to running a fleet-wide program to defending autonomous agents.Â
So what does this framework look like?Â
Building a repeatable security foundationÂ
Of course the temptation with any new application is to ship it quickly; with GenAI apps, which are relatively easier to build than traditional software, the temptation is particularly acute. Yet adopting an AI security framework calls for a different first move: treat model selection, red teaming, and guardrail design as the real work of the first 30 days, not simply awkward friction to push through.Â
That means red-teaming the bare model to establish a security baseline, building the application on top of it, and then red-teaming the combined system to see whether the application made things more secure or less. After that, it also means building guardrails across four distinct categories—existing regulations, AI-specific regulations, use-case threats, and red-team findings—so nothing gets missed just because it didn’t fit neatly into one bucket.Â
The output of this first phase is a repeatable loop: when a new zero-day threat surfaces, red team again, patch the guardrails, validate, and redeploy.Â
Taking inventory of every AI application Â
Securing one application well is a good outcome. Securing 20 applications the same way, on the same cadence, with the same auditability, is an entirely different challenge. This is where most organisations stall.Â
A solid framework includes four pillars that turn ad-hoc security work into a scalable program:Â
- Define red-team cadences tied to risk tierÂ
- Establish a guardrail patch pipeline that can roll updates out (and back) across many applications at onceÂ
- Create a fleet-wide zero-day response process with real service level agreements (SLAs)Â
- Provide Security Operations Centre (SOC) enablement so security operators can investigate AI incidents with the same fluency they bring to any other threatÂ
This second phase is complete when an organisation can answer, for every AI application, who owns it and when it was last tested.Â
Securing a fundamentally different type of riskÂ
AI agents run continuously, reason through multi-step plans, and take real autonomous actions through tools, which may give them access to sensitive or proprietary data. This means the security model built for request-and-response applications doesn’t transfer cleanly to agents.Â
Robust frameworks centre on two ideas. First, observability has to extend beyond logging outcomes to logging reasoning: having every thought, tool call, and decision an agent makes tied together, so a post-incident review can reconstruct not just what happened, but how. Â
Second, when an agent’s reasoning veers somewhere risky, simply blocking that thought tends to break the agent mid-task. The framework must instead point to thought injection—replacing a risky thought with a safer one that keeps the agent productive—paired with action-level controls like tool permissions and approval gates for high-impact moves. Â
Scaling AI security for future threatsÂ
GenAI security isn’t a single milestone you hit and move past. Instead, it must be treated as an operating rhythm built with a framework that helps security teams establish security before the gaps in their AI deployments turn into incidents.Â
Establishing a repeatable approach to mitigating zero-day threats, tracing every AI agent and preparing for fundamentally new risks will be critical to scaling security alongside agent adoption, creating the optimal conditions for return on investment. Breaking this down into a measurable, 90-day path helps organisations establish a robust security framework that works for a fleet of agents, not just one or two. Â



