The idea is that if there is a need to enable the Malicious Users feature to check with Javascript or Captcha to be able to bypass the checks for example for google good bots etc. with a predefined ip prefix set.
The F5 XC Bot Defense already has such a feature.
https://docs.cloud.f5.com/docs/how-to/advanced-security/malicious-users
https://docs.cloud.f5.com/docs/how-to/advanced-security/js-challenge
https://developers.google.com/search/docs/crawling-indexing/verifying-googlebot