AI Security

Fastly’s AI Firewall is live. Edge WAF logic just met the LLM path.

Sep 21 GA: AI Runtime Control + AI Firewall + agent API Security. Machine traffic >50% Jul/Aug (Fastly). AI traffic 6.5× human Jan–May (Fastly). McKinsey 93% over AI budget (via Fastly). Edge control — or CDN add-on?

Sep 21, 2026 · 4 min read

The edge already sees the traffic. Fastly is betting it should also govern the model call.

On September 21 Fastly (NASDAQ: FSLY) announced AI Runtime Control, AI Firewall, and new API Security capabilities — and said all three are now available (company press release). The framing: real-time visibility and control across AI systems on the same platform Fastly already uses for delivery and security. No valuation or ARR attach in the release. This read rests on the product launch and the disclosed network metrics; monetization is Undisclosed.

Three paths Fastly says it covers: applications calling models; users and systems interacting with AI applications; agents calling enterprise APIs. AI Runtime Control (ARC) routes model calls through a single endpoint across public and self-hosted providers; virtual keys protect underlying provider credentials; token spend visibility, rate limits, budgets, and failover keep policy central while preserving model choice. AI Firewall mitigates LLM-based attacks including prompt injection by evaluating prompts in the request path before they reach targeted models. API Security enforces API contracts on agentic, agent-assisted, and conventional traffic — observe or block non-conforming requests service by service.

Fastly’s own docs sharpen the SKU relationship: AI Firewall is a security module for ARC that inspects LLM requests and responses flowing through the ARC gateway; it is an add-on purchased with ARC, billed on AI requests processed, separate from ARC and from LLM provider token charges (docs.fastly.com). That matters for buyers comparing “AI firewall” marketing to what actually sits in the path.

Network and market claims in the PR (Fastly / cited sources): across Fastly’s network, machine-generated traffic crossed 50% in July and August this year; AI traffic grew 6.5 times faster than human traffic from January through May this year. Fastly cites McKinsey finding that 93% of organizations are exceeding their AI budgets — that is McKinsey via Fastly, not a CyberMerge primary read of McKinsey. Capacity: 622 Tbps of global edge network capacity as of June 30, 2026; more than five trillion requests daily as of March 31, 2026 (company).

CPO Kelly Shortridge, via the PR: enterprises need control in production, at runtime, without delay — Fastly is extending real-time control customers trust for content delivery and software security to models, applications, and agents. Platforms named in the Fastly for AI stack alongside the new products: Bot Management, ContentGuard, DDoS Protection, API Discovery, and Next-Gen WAF.

POV: CDN and edge WAF vendors will all ship an “AI firewall” this cycle. The underwrite question is whether putting model routing, prompt-injection inspection, and agent API contracts on the same edge that already carries the traffic changes production RFPs — or whether ARC+Firewall stays a Fastly-attached control plane for customers already on the network. GA is real (Fastly Sep 21). Machine-traffic and AI-growth figures are Fastly network claims. The 93% budget overrun is McKinsey as cited by Fastly. Sources: Fastly Sep 21 press release and Fastly ARC / AI Firewall docs.

Underwrite sheet — sourced only: AI Runtime Control + AI Firewall + API Security now available (Fastly Sep 21); ARC single endpoint + virtual keys + spend/rate/budget/failover; AI Firewall prompt injection in-path; API Security contract enforcement for agents; AI Firewall is ARC add-on (docs); machine traffic >50% Jul/Aug (Fastly); AI traffic 6.5× human Jan–May (Fastly); McKinsey 93% over AI budget (via Fastly); 622 Tbps as of Jun 30, 2026; >5T requests/day as of Mar 31, 2026. Edge LLM control — durable platform or CDN SKU? Underwrite the GA.

Sources