Basically something to extract boatloads of money from enterprise customers by annoying THEIR customers so they can't write "<script>" in texts in their application.
Or, less tongue-in-cheek, a way to harden web applications against known attack patterns like sql injections or xss-attacks. As they work on pattern recognition and don't know anything about your application they sometimes get in the way. But they'll probably check some box for some security audit so they're used.
Cloudflare for example offers one at https://www.cloudflare.com/waf/
A WAF is useful for when a zero-day is found for that legacy application you just can't get patches for anymore because the team has "moved on".