Skip to main content
Favicon of CalypsoAI

CalypsoAI

What is CalypsoAI?

CalypsoAI is an AI security platform for security, AI platform, compliance, and MLOps teams that tests, monitors, and constrains models, apps, and agents before production. It combines Combat adversarial attacks, Secure AI data, Govern responsible AI usage, Simplify AI observability, AI risk assessment, and low-latency runtime security. The platform is model-agnostic and supports distributed data protection and insights into actions.

Last verifiedHow we evaluate

Screenshot of CalypsoAI website

At a glance

Best for
CalypsoAI is best for security teams who need to test and control AI behavior before production.

What you are actually buying in 2026

CalypsoAI is not a purchasable product under that name. F5 announced the acquisition on 15 September 2025 and closed it on 26 September 2025 (F5's FY2026 Q1 10-Q: "On September 26, 2025, the Company closed on a transaction for the acquisition of CalypsoAI Corp."). The brand has since been fully retired: as of today, https://calypsoai.com/ returns a 301 to https://www.f5.com/products/ai-guardrails, and https://docs.calypsoai.com/ returns a 308 to https://docs.aisecurity.f5.com/. Neither the F5 AI Guardrails nor the F5 AI Red Team product page mentions CalypsoAI at all.

The technology now ships as two products, both declared generally available on 14 January 2026:

  • F5 AI Guardrails — runtime security for AI models, apps and agents: prompt-injection and jailbreak defence, semantic detection of PII/PCI/PHI leakage, content moderation, blocking of unauthorised agent tool calls, compliance templates (GDPR, HIPAA, EU AI Act), and audit logging of every enforcement action.
  • F5 AI Red Team — automated adversarial testing that "unleash[es] swarms of autonomous agents to simulate thousands of attack patterns," with findings feeding back into Guardrails for remediation.

One residual detail worth knowing: F5's own documentation still points at an app hosted on us1.calypsoai.app, so the rebrand is complete in marketing but not yet in the product surface.

What the technology is genuinely good at

Three things stand out, and they are the reason F5 paid for it.

It secures the right layer. CalypsoAI's bet was on the inference layer — where requests actually hit the model — rather than on model training or supply-chain scanning. Independent analyst PAC framed this as the deal's core logic: "attacks that worry CISOs: prompt injection, cross-model data leakage, and model exfiltration, happen during inference." It is model-agnostic by design and works with public or proprietary models.

The test-then-fix loop is unusually clean. Most vendors sell either a runtime filter or a red-teaming service. Here the same attack corpus drives both: AI Red Team finds the vulnerability, and "AI remediate" pushes the corresponding control into AI Guardrails. F5 claims this turns a threat assessment into a two-hour exercise rather than a four-week consultancy engagement. That is a vendor claim, but the architecture behind it is real and it is the part competitors do not straightforwardly match.

Deployment flexibility is a real differentiator. Public cloud (AWS, Azure, GCP), private cloud, on-premises, and air-gapped environments; AI Red Team ships an on-prem certified Red Hat OpenShift operator, and the AWS Marketplace listing delivers Guardrails as a container image for Amazon EKS and EKS Anywhere. Very few AI-security startups can serve a genuinely air-gapped defence or regulated buyer, and this one was built for that market from the start — it began in national-security use cases.

On efficacy: F5 published results from SecureIQLab showing AI Guardrails blocking 19,356 of 19,679 adversarial payloads across ten threat categories (98.36% overall; 99.33% prompt injection, 99.01% sensitive data leakage, 98.68% excessive agency). SecureIQLab is an independent lab, but the test was published by F5 and the funding arrangement is not disclosed, so treat it as a well-specified vendor-published benchmark rather than a neutral bake-off. It is still more than most vendors in this category publish.

How it is sold, and what that implies about deal size

There is no public price list and no self-serve purchase path. The AWS Marketplace listing for F5 AI Guardrails is the closest thing to a public number, and it is explicit about what it is: a single contract dimension, F5_GuardrailsAI, at $100,000.00 for 12 months, with the note "Pricing must be configured by F5 and transacted as a Private Offer. Pricing on the listing is a placeholder until a customer configuration is completed." The listing bills in "units" that it does not publicly define, so what one unit covers for your deployment is a sales conversation.

Two practical consequences. First, the placeholder is not a quote, but marketplace placeholders are generally set in the neighbourhood of a realistic entry contract — treat six figures per year as the plausible starting order of magnitude and verify it, rather than assuming a smaller pilot tier exists. Second, everything is a commitment: you buy a set quantity of units for the term rather than paying per interaction, and the listing states there are no refunds. If your use case is bursty or you want to prove value on one application before committing, that model works against you.

The F5 AI Red Team product page does offer a "Start a free trial" call to action, which is the only no-commitment entry point we could find. We could not establish what the trial includes or whether it requires a sales conversation.

How much independent evidence exists

Not much yet, and this is normal for a product that reached general availability in January 2026 — but it is worth knowing before you rely on peer signal.

The Gartner Peer Insights page for F5 AI Guardrails currently carries no reviews at all ("Be the First to Write a Review"). A separate legacy page for the old "CalypsoAI Inference Platform" still exists with a handful of reviews written before the acquisition; the recurring themes there are positive on real-time visibility into model behaviour and negative on customisation being "not always as flexible as expected." Those reviews describe a product that has since been re-platformed under F5, so weight them accordingly. We could not retrieve G2's CalypsoAI page (403) to verify its review count or rating, so we are not quoting numbers from it.

KuppingerCole published an inaugural Generative AI Defense Leadership Compass (dated 2 December 2025, analyst Jonathan Care). F5 states it was named an Innovation, Product and Market Leader in it, with Innovation Leader its strongest placement. We could not extract the report's own text to verify the placements or read the analyst's stated challenges for F5, so this is currently a vendor-reported analyst claim.

The most substantive independent-ish evidence remains the SecureIQLab efficacy test described above.

Company, funding, and what the acquisition maths tell you

CalypsoAI was founded in 2018, with major operations in Dublin, Ireland, and raised over $40 million in venture funding from investors including Paladin Capital Group, Lockheed Martin Ventures and Hakluyt Capital. It was a top-two finalist in the 2025 RSAC Innovation Sandbox and named one of Fast Company's Most Innovative Companies in AI for 2025 — genuine third-party recognition of the technology.

Two numbers are worth putting side by side. F5's press release announced "$180 million in purchase consideration financed primarily with cash." F5's 10-Q reports the transaction closed for "$145.2 million in cash." The gap is most likely retention and earn-out consideration accounted for separately rather than as purchase price, but we have not established the reason, so we state both figures rather than picking one.

The same filing contains the most candid available signal about the business's scale: "The pro forma financial information, as well as the revenue and earnings generated by CalypsoAI, were not material to the Company's operations for the periods presented." That is not a criticism of the technology — F5 bought capability, not revenue — but a buyer should read it as confirmation that this was a small-installed-base product being scaled up by a large vendor, not a widely-deployed platform. F5's own customer claim, that CalypsoAI was "trusted by global enterprises including Palantir and SGK," is a vendor claim we have not independently corroborated.

The market this sits in, and what it means for lock-in

CalypsoAI is the fourth independent AI-security vendor absorbed by a large security or networking platform in under two years: Protect AI went to Palo Alto Networks, Robust Intelligence to Cisco, Lakera to Check Point (completed 11 November 2025), and CalypsoAI to F5. F5 has kept buying in the space, adding SurePath AI — AI discovery and shadow-AI detection — on 26 June 2026, with CEO François Locoh-Donou framing the strategy explicitly: "Having four, five, six different tools to discover, test and secure your AI is a nightmare."

For a buyer this cuts both ways, and honestly. In favour: the capability is now backed by a large vendor with global support, and it plugs into the F5 Application Delivery and Security Platform, so if you already run F5 for WAF or API security you can extend existing policy to AI traffic without onboarding another vendor. Against: you are buying into a platform, not a point tool, and PAC's independent take flagged the obvious open question — "Some customers may watch for clearer pricing and roadmaps as products converge." That was written at announcement; general availability has since landed, but pricing is still not public.

If a platform commitment is the wrong shape for you, the functional alternatives at the runtime-guardrail layer include open-source options (LLM Guard, NVIDIA NeMo Guardrails) and remaining independents. We have not evaluated those here and are not ranking them — they are named only so you know the category still has non-platform choices.

Who this suits, and who it does not

A good fit if: you are an enterprise deploying generative or agentic AI at scale; you need runtime enforcement with an audit trail for GDPR, HIPAA or EU AI Act obligations; you have on-premises or air-gapped requirements that rule out SaaS-only guardrail vendors; or you already run F5 ADSP and want AI traffic under the same policy layer. The combination of air-gapped deployment and automated red-teaming is genuinely hard to source elsewhere.

A poor fit if: you want to trial something on one application this week without a sales cycle — the only self-serve entry point we found is an unspecified AI Red Team trial; you need a published price before you can get internal approval; your budget is below the low six figures per year; or you specifically wanted an independent vendor rather than a module of a large platform.

Not established: latency overhead of inline Guardrails enforcement, throughput limits, the definition of a billing "unit", what the AI Red Team trial includes, and whether legacy CalypsoAI contracts were migrated on their original terms.

Frequently asked questions

What is CalypsoAI?

CalypsoAI is an AI security platform for security, AI platform, compliance, and MLOps teams that tests, monitors, and constrains models, apps, and agents before production. It combines Combat adversarial attacks, Secure AI data, Govern responsible AI usage, Simplify AI observability, and low-latency runtime security. The platform is model-agnostic and supports distributed data protection and insights into actions.

What is CalypsoAI used for? Who is it for?

CalypsoAI is used for Combat adversarial attacks, Secure AI data, and Govern responsible AI usage. It's built for Security leaders, AI platform teams, and Compliance teams.

Share:

Sponsored
Favicon

 

  
 

Explore other Security AI Agents

Favicon

 

  
  
Favicon

 

  
  
Favicon