Your Company Has a Shadow AI Problem You Don’t Know About
Jimmy White, VP of AI at F5, joins Alan Shimel on Techstrong.TV to discuss the rise of “shadow AI” — the AI equivalent of shadow IT, where employees adopt AI tools and agents that IT and security teams never approved and can’t see.
Jimmy traces his path from Mandiant to Qualtrics to founding CalypsoAI (acquired by F5 last year), and explains how F5 is approaching AI security from every angle: guardrails to defend against attacks, red teaming to find new vulnerabilities, and auto-remediation capabilities unveiled at RSA this year. He also details F5’s recent acquisition of SurePath for next-generation AI discovery — closing the “unknown unknowns” gap that most enterprises face.
The conversation also covers a costly but common mistake: using the most powerful (and expensive) AI models for simple tasks, driving up token costs unnecessarily. Jimmy closes with practical advice for organizations just starting their AI security journey — start with a focused pilot before scaling.
Transcript
Hi, everyone. " My next guest is Jimmy White. Jimmy is the VP of AI at F5.
I first became involved with F5 back in the dot-com days. I helped put together a company called Interliant. It was an early ASP infrastructure provider.
And we were using big iron load balancers and stuff like that. So to give you an idea, this was 2000 maybe, 1999, 2000. I guess 2001 I left, so in there too.
" It's great to have you on here. It's great to be here. Thank you for having me, and looking forward to the conversation.
Absolutely. Hey, as I mentioned, you're VP of AI at F5, but I'm sure that's not a role you've had for 10 years, right? They didn't have a VP of AI.
But so give people a sense of what you've done in your career and how you got here. Yeah. So I guess, worked in every type of tech from, started off in legislative software, back in the early days, changing out mainframes for XML screen scraping technology into Java web apps.
Then into a great company, Dun & Bradstreet, 180-year-old company that had many ex-US presidents working for it at one stage. But that was all around risk management and credit checks. Then into Mandiant.
So spent many years in Mandiant. That was my first entrance into security. Caught the bug there.
We got acquired by FireEye a couple of years later. Then worked for Qualtrics, which is employee engagement and customer experience. Sure.
Acquired by SAP, and then started a company called Calypso AI, focused on AI security nearly seven years ago now. And last year, acquired by F5. And so, VP doesn't stand for "very popular" as I was hoping it did, but that's how I got here today.
Absolutely. Hey, you know what? That's a tremendous track record.
It seems wherever you go, there's an acquisition. Yeah. Maybe you want to come over here next.
Yeah. Well, it's certainly exciting. I think if you try to be in interesting tech in your career, it's going to be closer to an acquisition rather than not.
So that was- Yeah, that is the easier path than sort of an IPO or something like that. Yeah. But hey, that's great.
Congratulations. So it sounds like you were early to this whole AI security thing with Calypso. Came into F5 last year.
And now, I was mentioning big iron and load balancing. Well, that's where F5 sort of started maybe, but F5 has been involved in the security, especially in the data center security business for many, many years. My friend Laurie McVeety has been documenting and writing and talking about it for as long as I've been around, or maybe longer.
But that being said, VP of AI at F5. We're all doing something with AI, but it begs the question of what is F5 doing with AI? Yeah, so F5, it's a 30-year-old company, globally known.
It's super famous for its big IP, ARANGE. It's kind of the franchise business of the company, and it also has XC distributed cloud and NGINX, of course, a very well-known brand. Sure.
A couple of years ago, the company recognized that AI was going to be the biggest new growth area, and the timing of when to jump into that market was something I think they got right. They acquired us just when AI security was really heating up, and of course, this year, it's all anyone's talking about. And so it's an exciting position to be in, in F5, where we're building out this AI security platform.
We recently just acquired, of course, SurePath, to round out that platform. And F5 is one of the biggest security vendors in the world. And now we're covering the whole gamut from all your networking, so every data that goes across it.
As we all know, over half the internet traffic is now AI-generated. And then that has to be secured bidirectionally, so outside in, inside out, left to right, right to left. There is a growing use case every day.
There's some new something claw tool coming out that we talked about a little bit beforehand. And so it's one of these exciting periods to be at the intersection of data and AI, and right in the middle of all that, sits security. Absolutely.
It is, and you know what? The thing about AI and security is there's this... So I've been in security 25 years myself, right?
Did a few startups around security. There's sort of this love-hate relationship with AI and security, right? We love it because maybe it'll wind up having more secure code, right?
Mythos is going to make it too easy to find vulnerabilities. But in the same token, the bad guys get to use it, too, and they're not dumb. And it's just what it's done to phishing.
I mean, it's so much harder right now to ferret out phishing attempts and stuff like that, educate people around it. Mm-hmm. It cuts both ways is the bottom line.
And then probably the biggest thing, and I think that's what we're going to talk here to you about ... is the rise of shadow AI, right? We saw this with shadow IT in the cloud, right?
Any developer could whip out their credit card, start up an instance or two at Amazon. Never shut them off when they're done, of course, bill the company back. But, before we knew it, we had all these cloud instances with data, sometimes proprietary or regulated data, that the IT department knew nothing about, and therefore, it was invisible to us.
We're seeing the same thing with AI. Do we know what agents are running around? Do we know what they have access to?
Do we know what they're pushing up, maybe to big models that are now available? What's F5 doing around that, Jimmy? Well, I'm a big movie and car fan, and the wheel man's the name for the guy who drives the getaway car.
Mm-hmm. And so they got faster cars, so the police had to get faster cars, and so on that cat and mouse game goes. What's super interesting and different about shadow AI versus shadow IT is you could be doing the right thing for the right reason, and you can drum up a huge bill or accidentally make a massive mistake without knowing it and without setting out to do so.
And so we see a lot of cases, I'll pick the top three, where folks are using a Porsche 911 Turbo to go one mile down the street to pick up milk, right? They're using the biggest model for the simplest task, and that drums up a huge bill. It's all token costs.
We also have the opposite. People are using simple models because they're cheaper or maybe not as important the task to do really complex work, and it just doesn't do a good job. So if you're scanning for vulnerabilities in source code, you don't want to use a cheap model.
You want to use the best in class. You want to use Fable, or you want to use GPT Cyber. One of those models are best in class for that.
And when people are building, of course, products with AI, the source code has been generated by AI. The outcome is often an agent now doing the work. And so how do you test this?
We already had issues with testing regular software, just having enough tests around the software to make sure it's not doing anything it shouldn't. And for regression testing, right, when you're fixing an issue, how do you make sure it hasn't caused an unknown different execution path you weren't expecting? So all of these problems add up to this insurmountable feeling for engineers and security professionals.
People feel overwhelmed in our industry. And at F5, we believe our job is to make sure that we rebalance everything. We bring back the asymmetric attack to defense.
We want to reverse that and bring that asymmetric defense in, right? So we're bringing in the tools that allow you to do a whole lot more on the defensive side to bring the professionals back in balance with the attackers. I love it.
Now, everybody wants to be a platform when they grow up. No one wants to be just a product or, even worse, a feature. Yeah.
Right? We all want to be a platform. But what makes this truly a platform?
So, the definition of a platform really has to be more than one thing. Otherwise, it's just a thing. And so, day one of Calypso, we called ourselves a platform when we had zero things.
So I definitely- Mm-hmm ... get the question. So when we look at what we had in F5 a few months ago, we had the ability to create guardrails to defend, with the ability to red team to find new vulnerabilities.
And then we introduced the ability at RSA this year to auto remediate. So take new attacks, figure out good guardrails with high efficacy to automatically deploy with a human in the loop. And that gave you that cycle, right?
And that is, I think, the minimal definition of a platform. But then when you bring it to your customer, they're the ones who actually tell you what they mean by a platform. And when we brought this to our customers, they still had a gap, and they said, "Hey, we need discovery.
" Right? The known knowns we have, the known unknowns, we're figuring out. It's the unknown unknowns that are a big problem for us.
" And that's why we went out, we met a huge amount of companies, and we eventually found SurePath, who had the ability to do really next-gen discovery and find things that no other solution would find. And then when you show that to your customers and they say, "Okay, now I know of all these new things I need to protect," you need to have that protection in place, which is what we started with. So that's, for me, what constitutes a platform, something that your customers believe is a platform and does all the things they expect it to do, from finding to securing and then to finding threats with those known things that they've discovered.
Got it. So Jimmy, you guys just launched this. Yep.
Correct? Is it a standalone piece of hardware that sits in there? Does it run as a service on a cloud?
Software? Is it a SaaS kind of thing? What exactly is it under the covers there?
" And that, for me- Absolutely ... is the definition, right? And so, when we speak to our customers, it's super wild what's happening right now in the industry, in the Global 500s.
It's not one thing. " And so we realized early on that we needed to meet them where they're at. So either of these three scenarios, we needed to support them.
And so our platform runs across SaaS, hybrid, and on-prem, and including air-gapped on-prem for government. And so that's the deployment vehicle you need to have in the AI race, is to be able to meet your customers where they're at, because they've invested heavily before they come to you, and you need to be able to secure that investment wherever it may lay. Excellent.
So you've got all the bases covered, is what it sounds like. Touch wood. Yeah.
And I'd love to say that we sat down for five minutes and prepared the perfect plan. In reality, it's meeting hundreds of customers, meeting CISOs, understanding their pain points, understanding what they're trying to achieve with AI, because it's wild out there, what people are doing with AI. And then every time you want to do that, you're also faced with, where do they operate?
Is it in Europe? Is there sovereignty expectations? And all of these things come together.
So, the old days of being able to-- I started my career where every release of Norton came in a box with a CD and a manual, and you had to have all of the vulnerabilities printed on a piece of paper. Those days are gone, and now it's wild use cases deploying anywhere and everywhere, and you need to be able to do the whole gamut of solutions. And so it is exciting.
I'm not complaining, but it's certainly different. Yes, it is. Jimmy, we've got a little bit of time left.
For people who want to maybe dig in deeper, see if this is something for them, what's the on-ramp? What should they do? So for me, it really depends.
There's two options that I like to advocate. So one is, you can start with the AI you have, figuring out how it's vulnerable by running red team. So it's a very simple process.
Just get a cloud instance, SaaS. Within five minutes, you're up and running, point it at your AI, and find vulnerabilities. If you've got some, then you need to then go deeper and start putting in guardrails, but at least you know you've got a problem, and you know how to solve it.
The other option is to do a full POC. So, hey, we know we're going into AI. We need to cover that whole platform from discovery all the way to remediation.
And the simplest way for that is to do a POC, get everything set up, installed, operating, configured, and then you'll have all of the bases covered. And then you can start adding and implementing policy on top of that, use case by use case. I always advocate crawl, walk, run.
So start with the smallest, simplest project, get your sea legs and be ready to understand what you're doing and how you've implemented it, and then take on the more technical and complex products or projects. So that's my two pieces of advice, from dipping your toe in the water to making sure you've got a seaworthy raft to continue your journey. com.
com and F5 Labs, they're the two places we have all our information. If you're curious about the latest threats, hit up F5 Labs and see our threat intel reports, et cetera. com.
Love it. All right. Jimmy, thank you so much for coming out here on Techstrong TV.
We appreciate it. Keep up the great work. We'll speak to you soon.
My pleasure. Thanks, Alan. All righty.
Jimmy White, VP of AI from F5, here on Techstrong TV. We're going to take a break. We've got more Techstrong TV coming at you, so stay tuned.