Agentshield vs CalypsoAI - Independent Control Plane or F5 AI Security
CalypsoAI built a well-regarded inference security and red-teaming product, and it is no longer an independent company. F5 acquired it in September 2025, and the technology now ships as F5 AI Guardrails and F5 AI Red Team inside the F5 Application Delivery and Security Platform. That changes what you are actually buying, so here is an honest comparison against Agentshield, which stays independent and self-serve.
| Capability | Agentshield | CalypsoAI |
|---|---|---|
| Runtime prompt-injection and jailbreak defense | Core strength | |
| Automated adversarial red teaming at scale | Partial | Core strength |
| Per-agent tool and data permissions | Partial Model and inference centric | |
| Human-approval gates on irreversible actions | × | |
| Immutable action audit trail | Compliance audit logs | |
| Vendor-neutral and standalone | × Part of F5 ADSP | |
| Self-serve with pricing on the page | × Enterprise sales | |
| On-prem and hybrid deployment | SaaS, on-prem, hybrid |
The verdict
Choose F5 AI Guardrails and AI Red Team if you already run F5 for application delivery and security, want AI controls consolidated into that platform, and value their continuous adversarial testing depth. Choose Agentshield if you want a vendor-neutral control plane for agents that take actions, deployable today without adopting a platform, with per-agent tool permissions, approval gates, and an immutable audit trail priced on the page.
This comparison is meant to be fair and reflects publicly available information. Both products evolve; verify the latest before deciding.
What the F5 acquisition actually changed
Get the facts straight first, because most pages covering this repeat one number without checking it. F5 announced the acquisition in mid September 2025 at roughly 180 million dollars in purchase consideration. F5's own annual report on Form 10-K states the transaction closed on September 26, 2025 for 145.2 million dollars in cash, with CalypsoAI becoming a wholly owned subsidiary. Both figures are real and they describe different things, and we are not going to speculate about the reconciliation. If you see 180 million quoted as the closing price, that is the announcement figure, not the number in the filing.
On September 29, 2025, F5 announced completion and introduced two products built from the CalypsoAI technology: F5 AI Guardrails, which does runtime security for models and agents including injection and jailbreak defense, sensitive data leakage prevention, and centralized policy with audit logs, and F5 AI Red Team, which runs autonomous agent swarms to simulate attack patterns against your deployment and turns findings into active guardrails. Both sit inside the F5 Application Delivery and Security Platform.
For an F5 customer this is a good outcome: AI controls arrive in a platform you already operate, next to your existing traffic and security telemetry. For everyone else the calculus shifts. Roadmap priorities follow the platform, evaluation runs through F5 enterprise sales, and the natural gravity is toward consolidation. That is what platform acquisitions are for and it is not a criticism. It does mean that if what you wanted was an independent control you could put in front of any agent without adopting a platform, that product is now in a different category.
Testing the model versus governing the action
The deeper difference is not the acquisition, it is the center of gravity. CalypsoAI grew up around the inference path: what goes into the model, what comes out, and how hard you can push it before it breaks. F5 AI Red Team is a genuinely strong expression of that, backed by a continuously updated vulnerability database, and we will say plainly that automated adversarial testing at that scale is not our strongest surface.
Agentshield's center of gravity is the action path. An agent that has already been jailbroken is only dangerous because of what it can then do: which tools it can call, which records it can read, which transfers it can execute. Our controls assume the model will eventually be fooled and constrain the blast radius anyway.
| Question | F5 AI Guardrails and AI Red Team | Agentshield |
|---|---|---|
| Can this model be jailbroken? | Core strength, automated at scale | Covered, not our depth |
| Is sensitive data leaking in responses? | Core strength | Core strength |
| Should this agent be allowed to call this tool? | Partial, platform policy | Core strength, per-agent permissions |
| Should a human approve this transfer? | Not a surface | Built in |
| Can I reconstruct what the agent did and why? | Audit logs and per-interaction reasoning | Immutable attributed action trail |
| Can I deploy it without adopting a platform? | No | Yes, self-serve |
Those are complementary, not competing, claims. Testing tells you where an agent breaks; enforcement decides what happens when it does. We make the same argument on AI penetration testing and in AI penetration testing vs red teaming. Neither of us publishes pricing for the other, and F5 does not list AI Guardrails pricing publicly, so verify it with them.
FAQ
Common questions about this comparison.
Was CalypsoAI acquired by F5?
Yes. F5 announced the acquisition in mid September 2025 at roughly 180 million dollars in purchase consideration, and F5's Form 10-K reports the deal closed on September 26, 2025 for 145.2 million dollars in cash, making CalypsoAI a wholly owned subsidiary. F5 announced completion on September 29, 2025 and folded the technology into its Application Delivery and Security Platform.
What is CalypsoAI called now?
The technology ships as two F5 products. F5 AI Guardrails provides runtime security for models and agents, covering prompt injection and jailbreak defense, sensitive data leakage prevention, policy enforcement, and audit logging, deployable as SaaS, on-prem, or hybrid. F5 AI Red Team runs autonomous agent swarms to simulate attack patterns and converts findings into active guardrails. CalypsoAI's earlier flagship was the Inference Platform.
What is the difference between Agentshield and CalypsoAI?
Scope and independence. The F5 products center on the inference path, securing what goes into and out of the model and testing how hard it can be pushed, inside the F5 platform. Agentshield centers on the action path of agents that call tools: per-agent tool and data permissions, human-approval gates on irreversible actions, and an immutable audit trail, vendor-neutral and self-serve with pricing published.
Is F5 AI Guardrails good for AI agents?
For runtime input and output protection, yes, and the red-teaming depth behind it is a real advantage if continuous adversarial testing is your priority. The gap for agentic deployments is action governance: deciding per agent which tools and records are in scope and holding irreversible actions for a person. If your agents mostly generate text, the F5 pairing covers a lot. If they move money or change records, you need action-level controls as well.
Do I need to be an F5 customer to buy AI Guardrails?
The products sit within the F5 Application Delivery and Security Platform and are sold through F5 enterprise sales, so expect a platform-shaped engagement even if you are not an existing customer. Verify current packaging with F5 directly, since it has changed since the acquisition. Agentshield is the alternative when you want the controls without taking on a platform relationship.