
AI API Security: Same toolbox, new scale and new risks
AI API security is having a moment, complete with new tools and a shiny new market label. This episode asks the uncomfortable question: is it actually a new domain, or is it classic API security under more pressure? F5's Lori MacVittie is joined by Principal Product Manager, Vinnie Mazza, for a grounded conversation about what’s genuinely changing and what’s the same problem wearing a new badge. Vinnie’s take is that it’s a collision: old weaknesses like broken access control and deferred security maintenance are now being hit at agent scale. Organizations that never fully adopted modern authentication, strong identity practices, or zero-trust-style assumptions are feeling it harder because agents can generate huge volumes of API calls, rapidly, from inside and outside the environment. The fundamentals still apply—clients make requests, you inspect, and you decide—but the economics and timing are different. They dig into what changes when transports evolve toward streaming and async patterns, including MCP shifting toward a streaming protocol. Faster, bidirectional flows reduce the time you have to make security decisions, while overall volume increases the likelihood that sampling-based detection misses what matters. They also revisit the split between positive and negative security models, why most organizations default to “everything is allowed unless it’s known bad,” and why that becomes more fragile as AI produces more novel behaviors. The key theme is defense in depth with new priorities. Data loss prevention and IP protection move from “later” to front-and-center when agents can unintentionally leak sensitive internal data to external model providers. The takeaway is practical: you don’t need to panic or replace your toolbox, but you do need to adapt it for higher volume, faster change, and stronger data controls.
- Transcript
- Chapters