Pull to refresh
Logo
Fastly launches AI firewall and runtime control as machine traffic tops half its network

Fastly launches AI firewall and runtime control as machine traffic tops half its network

New Capabilities

Edge cloud vendor adds governance layer for model access, prompt injection, and agent API calls

Yesterday: Fastly launches AI Runtime Control, AI Firewall, and API Security

Overview

Updated 55 minutes ago

Half the traffic on Fastly's network in July and August was generated by machines, not people. On September 21, the edge cloud company launched the governance layer it sells to the owners of that traffic: AI Runtime Control, AI Firewall, and API Security.

The products route every AI model call through a single Fastly-managed endpoint. Companies get virtual keys per application, real-time token spend tracking, budget limits, automatic failover between model providers, and inline blocking of prompt injection attacks. A third capability validates that AI agents stick to published API contracts.

Fastly reports AI traffic grew 6.5 times faster than human traffic from January through May 2026. McKinsey found 93% of organizations are exceeding their AI budgets. The launch is Fastly's bet that enterprises need a control point at the network edge rather than inside each model provider or application.

Why it matters

Enterprises now have one place to govern AI spend, block prompt injection attacks, and control what AI agents touch inside their APIs.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

>50%
Machine-generated traffic share on Fastly's network
Automated traffic crossed the halfway mark on Fastly's network during July and August 2026.
6.5x
AI traffic growth vs. human traffic growth
From January through May 2026, AI traffic on Fastly's network grew 6.5 times faster than human traffic.
93%
Organizations exceeding AI budgets
A McKinsey survey found 93% of organizations are spending more on AI than they planned.
5 trillion+
Daily requests handled by Fastly's network
Fastly's global edge network processes more than five trillion requests per day as of March 2026.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Organizations Involved

Timeline

August 2026 September 2026

2 events Latest: Yesterday
  1. Fastly launches AI Runtime Control, AI Firewall, and API Security

    Latest Product launch

    Fastly introduced three products to govern AI model access, block prompt injection attacks, and control agent access to enterprise APIs.

  2. Machine-generated traffic tops 50% of Fastly's network

    Market data

    Across July and August, automated traffic beat human traffic for share of Fastly's network volume for the first time.

Scenarios

1

Fastly reports AI products as a material revenue contributor

Possible Resolves by Feb 28, 2027

Discussed by: Investors and analysts tracking Fastly's transition from CDN to AI infrastructure

If ARC and AI Firewall gain traction with enterprises consolidating AI governance, Fastly's next earnings calls will name AI products as a growth driver. The company's shift from content delivery to AI security could re-rate the stock if adoption shows in usage metrics.

2

Cloudflare or Akamai ships equivalent AI security products

Likely Resolves by Q2 2027

Discussed by: Industry observers watching edge platform competition

Fastly's edge competitors already operate networks at similar scale, and both have security product lines close to this territory. If Cloudflare or Akamai announces AI firewall and runtime control features within months, Fastly's first-mover advantage narrows to pricing and integration quality.

3

Enterprises build in-house AI governance, third-party adoption stalls

Possible Resolves by Q3 2027

Discussed by: Security analysts who note many large firms prefer internal control over external platforms

Enterprises with mature security stacks may build their own governance layers for AI traffic, treating Fastly's tools as point solutions rather than platforms. Adoption stays limited to mid-size firms without the engineering staff to build internally.

Historical Context

2 moments from history that rhyme with this story — and how they unfolded.

2007–2010

Web application firewall adoption (late 2000s)

As e-commerce and web applications became business-critical, SQL injection and cross-site scripting attacks grew sharply. Web application firewalls emerged to inspect and filter malicious requests before they reached application servers.

Then

Imperva, F5, and Akamai built large WAF businesses serving enterprises that needed front-line defense for public web apps.

Now

WAFs became standard infrastructure for any organization running public web applications, and inline security inspection at the network edge became an industry norm.

Why this matters now

Fastly's AI Firewall adapts the WAF concept to large language models: it inspects prompts at the edge for injection attacks before they reach the model.

2012–2015

Cloud Access Security Broker market emergence (2012–2015)

As enterprises migrated to Salesforce, Office 365, and other cloud apps, security teams lost visibility into data flows that bypassed the corporate network. A new product category, the cloud access security broker, emerged to sit between users and cloud services and enforce policy on traffic outside the firewall.

Then

Vendors including Netskope, Skyhigh Networks, and McAfee built substantial businesses on the category. Gartner called CASB the fastest-growing security market in 2015.

Now

The pattern became a template for enterprise security: new architecture adopted first, governance layer built second.

Why this matters now

AI traffic is creating the same visibility gap now. Enterprises deploying LLM calls and agents cannot see what they control, and Fastly is positioning its edge as the governance layer.

Sources

(7)