Fastly launches AI controls for the traffic already crossing its edge
AI Runtime Control routes model calls, tracks spend and fails over providers, while AI Firewall inspects prompts before they reach a model.
By RuntimeWire Staff · Published
Primary source: Financial Times company announcements
Why it matters
Fastly is converting its position in the web request path into an AI governance business. Existing customers could consolidate routing, spending controls and security, while Fastly gains a route into higher-growth security and compute revenue.

Fastly, the edge-infrastructure provider Artur Bergman co-founded in 2011, launched AI Runtime Control, AI Firewall and expanded API security, putting model access, prompt inspection and agent permissions into the same request path Fastly already uses to deliver and protect web applications.
The products were made immediately available, according to a Fastly announcement republished by the Financial Times. The original Business Wire announcement does not include product-specific customer figures. Fastly publishes pricing separately, including rates for some AI products on its pricing page. The commercial test will be whether existing customers pay Fastly to consolidate AI routing and security rather than add another specialist vendor.
The launch is being led on the product side by Kelly Shortridge, Fastly's chief product officer and a former cybersecurity founder whose startup was acquired by CrowdStrike. Shortridge previously ran Fastly's security business and worked in its Office of the CTO, experience that maps closely to the problem Fastly is pursuing: developers want to ship AI features quickly, while security and finance teams want control over what those features can access and spend.
"Organizations need control in production, at runtime, without delay, friction, or disruption," Shortridge said in the announcement.
The founder's edge bet gets an AI workload
Bergman founded Fastly after engineering and technology leadership roles at Wikia, Six Apart and Fotango. He served as Fastly's CEO until February 2020 and is now founder and chief technology officer. His original wager was that application logic, security decisions and content delivery should happen closer to users, with developers retaining direct control over the infrastructure.
Fastly co-founder Simon Wistow, who previously worked in search engineering at Yahoo Europe and in engineering roles at LiveJournal, Scribd and Zendesk, has described the original target as the slow and inflexible architecture of legacy content-delivery networks. Fastly's latest release extends that founding argument in the opposite direction: the edge can also govern requests leaving an application on their way to models and enterprise APIs.
That position gives Fastly a credible distribution path. Fastly says its network serves over five trillion requests per day as of March 31st, 2026, and had 622 Tbps of capacity as of June 30th, 2026. The new AI products can sit inside infrastructure that Fastly customers already use for delivery, web application security, bot management, DDoS protection and observability.
Three controls in the request path
AI Runtime Control places a Fastly-managed endpoint between applications and public or self-hosted model providers. Customers keep their provider accounts and negotiated rates, while Fastly supplies virtual keys that can be issued to individual applications, developers or teams. Fastly's documentation describes how those requests are routed and logged.
Fastly says administrators can use those keys to measure token consumption, set dollar budgets and rate limits, revoke access, and search request and response logs. A key can also point to an ordered list of models, allowing Fastly to retry a request with a backup provider when the first provider returns an error.
AI Firewall adds prompt inspection to that flow. Fastly says the product uses an updated version of its SmartParse detection engine and custom guardrails to identify prompt injection and other attacks before a request reaches the selected model. Fastly has not supplied an independent efficacy benchmark, false-positive rate or latency measurement for the firewall, leaving buyers to evaluate how much inspection Fastly can add without slowing production applications or blocking legitimate prompts.
The third piece applies Fastly's API security controls to agents. Organizations can define API contracts and observe or block requests that use unsupported operations, contain malformed data or fall outside an established service boundary. That matters as coding assistants and autonomous agents create and call endpoints faster than many security teams can document them.
Security is already Fastly's faster-growing business
The product strategy follows Fastly's financial direction. In the quarter ended June 30th, 2026, Fastly reported $183.3 million in revenue, up 23% from a year earlier. Security revenue grew 43% to $41.7 million, compared with 17% growth in network-services revenue. Compute and observability revenue, grouped under Fastly's "other" category, grew 69% to $7.7 million.
Those figures give Fastly a direct incentive to package AI traffic as a security, compute and governance sale rather than treat it only as additional network volume. Its existing customer base also gives the company a ready-made distribution channel for that cross-sell.
Fastly's own traffic measurements supply the urgency, with an important caveat: the figures come from Fastly's network rather than an independent internet-wide study. Fastly says AI requests grew roughly 30% from January through May 2026, a rate 6.5 times faster than human traffic growth during the same period. Fastly also says machine-generated requests accounted for over half of its network traffic in both July and August. Fastly's traffic analysis explains the methodology behind those figures.
The AI gateway market is already crowded
Fastly is arriving after several infrastructure and security providers established similar positions. Cloudflare AI Gateway supports model routing, token and cost analytics, caching, rate limits and provider fallback, while Cloudflare's application-security tools inspect prompts for injection attempts and sensitive information.
Palo Alto Networks completed its acquisition of Portkey on May 29th, 2026, adding an AI gateway to Prisma AIRS. F5 launched an AI security platform in June after announcing its acquisition of SurePath AI, covering AI discovery, governance and runtime protection. Dedicated vendors such as Lakera also focus on prompt attacks and model-facing security controls.
Fastly's pitch rests on consolidation and placement. A control point operating at the edge can see model calls, incoming prompts and agent requests as they happen, and Fastly can sell it beside infrastructure already deployed by large customers. That advantage only holds if Fastly demonstrates low latency, dependable failover and detection quality comparable to dedicated AI-security products.
Bergman's original edge thesis gave Fastly a durable place in the web request path. AI Runtime Control is the latest attempt to make that position carry a larger share of each customer's infrastructure budget, this time by governing the machines that are increasingly generating the requests.