Normal view

Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5

21 August 2026 at 19:21

Frontier AI has compressed attack timelines from weeks to minutes. 

For defenders to gain the upper hand, they need to fight back at machine speed. That’s why Palo Alto Networks Unit 42 launched Frontier AI Defense, our comprehensive service that pairs advanced frontier AI models with leading threat intelligence to uncover hidden risks, validate real attack paths, and accelerate remediation before adversaries strike. 

Today, in a major milestone for organizations to defend themselves against AI-powered attacks, Unit 42 is expanding its Frontier AI Exposure Analysis capabilities with Anthropic’s Claude Mythos 5, giving organizations access to its advanced cyber capabilities.

Unlocking High-Fidelity Security with the Right Models, Harness and Expertise

While incredibly powerful, achieving high-fidelity results with frontier AI requires three things: the right models, an advanced harness, and the expertise to run it. With Unit 42 Frontier AI Exposure Analysis, guided and reviewed by Unit 42 experts, Claude Mythos 5 goes beyond identifying exposures. It tests whether those exposures can actually be exploited, connects weaknesses into attack paths, and helps prioritize the most urgently needed fixes. That answers the questions conventional scanners alone cannot: Is this exploitable? What can an attacker reach from here? And what should we fix first?

Further, our research shows models have different strengths. Unit 42’s multi-model approach applies the model best suited for the task, improving coverage and results while allowing us to continuously incorporate the strongest new capabilities as models advance. 

Human expertise remains at the center. Unit 42 combines these models with our offensive security experts, global Palo Alto Networks telemetry, and Unit 42 Threat Intelligence to turn model output into validated attack paths, prioritized remediation, and clear defensive action.

How It Works

Our Frontier AI Defense service uses the most advanced AI models to discover exposures, test whether they are exploitable, validate attack paths and help customers prioritize what to fix first, including: 

  • Leading Cyber Models: Advanced AI applied to discovery, testing, and validation.
  • Multi-Model Harness: Dynamic routing for stronger results, wider coverage, and managed costs.
  • Exposure Discovery: Identification of vulnerabilities, misconfigurations, exposed credentials, and unmanaged attack surfaces across apps and networks.
  • Advanced Adversary Simulation: Live exploitability testing and end-to-end attack path validation.
  • Custom Remediation Plans: Prioritized fixes delivered directly into existing IT, development, and security workflows.

Security teams do not need more findings. They need to know which weaknesses lead to a viable attack path. Attackers do not think about applications, identity, cloud, and infrastructure in isolation. They look for ways to move across them to reach their objective.

By putting frontier models to work with Unit 42 experts, we can identify and validate those attack paths before attackers do, and help organizations close them first.

Visit Palo Alto Networks Frontier AI Defense to learn more.

The post Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5 appeared first on Palo Alto Networks Blog.

Prisma AIRS - Unified Data Protection for Claude

As AI adoption shifts from experimental tools to the business core, enterprises are deploying AI agents and assistants across every department. Developers are accelerating software delivery with Claude Code and business functions are collaborating in Claude.ai, Claude Cowork, and Claude Design, using Anthropic's Claude to fundamentally rewire how they operate and drive complex, autonomous workflows across their most critical tasks.

Broad AI adoption has forced enterprise security into a difficult paradox: secure the business without stalling innovation. Today, security teams must answer three critical questions: How do we prevent sensitive data from leaking into AI models? How do we intercept runtime attacks, like prompt injection, before they execute? And how do we enforce these guardrails consistently across every AI interaction, in real-time?

We are thrilled to announce that Palo Alto Networks Prisma AIRS API now directly integrates with Claude Enterprise via inference hooks.

Key Takeaways:

  • Synchronous Governance at the Speed of AI: Enforce critical runtime policy guardrails instantly before model inference occurs. By evaluating every Claude interaction in real-time, security teams can confidently enable high-speed AI innovation without introducing unacceptable risk or operational bottlenecks.
  • Extending Proven DLP to AI Workflows: Safeguard PII, intellectual property, and proprietary code across all Claude environments (Claude Code, Claude.ai, Claude Cowork) seamlessly. By directly leveraging your organization’s existing enterprise DLP policies, you get consistent, unified data protection without the friction of managing disparate rule sets.
  • Neutralizing AI-Specific Threats Proactively: Deploy enterprise AI with confidence by intercepting malicious activity before it executes. Proactively block sophisticated runtime threats, including prompt injections, jailbreaks, and toxic inputs, enabling your AI workflows to remain secure and your business operations uninterrupted.

How It Works

Setting up zero-trust governance for your Claude Enterprise environment takes just a few clicks:

  • Configure Claude Enterprise: In your Claude Enterprise organization settings, navigate to inference hooks, set the hook endpoint URL to your designated Prisma AIRS webhook URL, and include your custom Prisma AIRS API key in the custom headers (x-pan-token).
  • Activate Cryptographic Verification in Prisma AIRS: Claude generates a unique, one-time signing secret. You simply drop this signing secret into the Prisma AIRS UI.

Prisma AIRS securely stores the signing secret in an encrypted edge Key-Value Map (KVM) to cryptographically verify the authenticity of every incoming request before processing.

Unified Governance Across All Claude Surfaces

Before Claude reads a prompt, Claude POSTs the payload to Prisma AIRS, which evaluates the input against the configured security profile and returns a synchronous allow or deny verdict back to Claude.

Removing the Data Inspection Blind Spot

This Prisma AIRS integration natively leverages the Palo Alto Networks Enterprise DLP engine your organization already runs. Your current policies, custom definitions of "confidential," and compliance dashboards now instantly govern Claude. No redundant rule creation, and no new management overhead. Every prompt is classified in real-time, before anything reaches the model. Data Policy updates reach Claude the moment they reach everything else, and Claude events land in the same dashboards and audit reporting as every other channel. AI stops being the exception to your data protection strategy and becomes just another channel that is covered.

In practice, this helps prevent:

  • Accidental exposure of PII and regulated data: a Social Security number, card number, or patient record pasted into a prompt is detected  on the spot by advanced RegEx patterns and ML classifiers,  with Exact Data Matching (EDM) recognizing your actual customer records.   When policy requires, Prisma AIRS enforces a deny policy to help keep Claude usage stays aligned with GDPR, HIPAA, and PCI-DSS requirements.
  • Misuse of credentials in code: Developers working in Claude Code can't inadvertently submit hardcoded API keys, private tokens, or environment credentials into prompt context.
  • Disclosure of confidential business matters. Document classifiers flag prompts touching M&A, legal, or HR material — even when they contain no identifier a pattern could match.

AI Safety & Runtime Threat Protection

Simultaneously, Prisma AIRS inspects payloads for operational risks specific to large language models:

  • Prompt Injection & Jailbreak Attacks: Intercepts malicious attempts to manipulate model context or bypass system instructions.
  • Malicious Code & Malicious URLs: Prevents execution or processing of untrusted scripts and risky links embedded within prompts.
  • Toxic Content & Topic Guardrails: Enforces compliance with corporate policies and custom business topics.

If a prompt violates your security policy, Prisma AIRS issues a deny verdict. Claude immediately blocks the prompt, optionally presenting a user-facing explanation while returning a unique audit correlation code to your security telemetry dashboards.

Deploy Claude Without the Risk

The Prisma AIRS integration with Claude transforms security from a deployment bottleneck into a business enabler. You no longer have to choose between the operational control of Palo Alto Networks and the cognitive velocity of Claude.

Choose Your Path Forward:

 


Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.  All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

The post Prisma AIRS - Unified Data Protection for Claude appeared first on Palo Alto Networks Blog.

Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out.

13 August 2026 at 15:00

Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it.  Key takeaways  Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% […]

The post Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out. appeared first on Check Point Blog.

Native AI Security Comes to Claude: Why Anthropic’s Inference Hooks Matter

10 August 2026 at 15:00

Anthropic’s new inference hooks give enterprises a native enforcement point before prompts ever reach the model. Combined with Check Point Workforce AI Security, organizations get a real-time allow-or-deny decision on every prompt, with no proxy in the path. Why This Matters Enterprise AI adoption has moved well past experimentation. Employees draft documents, write code, summarize meetings, and query enterprise knowledge through large language models every day. The challenge was never understanding that AI introduces risk. It was finding a practical enforcement point. Web gateways and Data Loss Prevention (DLP) tools were designed for websites and SaaS applications, not conversations with […]

The post Native AI Security Comes to Claude: Why Anthropic’s Inference Hooks Matter appeared first on Check Point Blog.

Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security

6 August 2026 at 21:01

Check Point brings open research, objective benchmarks and customer-controlled runtime protection to the industry initiative introduced by NVIDIA.  AI is rapidly changing how organizations build, operate, and protect their digital environments. As a leader in the global cyber community, we believe in the power of collective intelligence. We are proud to join the Open Secure AI Alliance as an inaugural member, working alongside leaders from across cyber security, cloud computing, enterprise software, AI, and the open-source community.  Introduced by NVIDIA, the alliance is creating a collaborative foundation for developing and sharing open technologies that advance AI safety and security, and will help organizations identify, remediate, and responsibly disclose […]

The post Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security appeared first on Check Point Blog.

Three AI security disclosures, fourteen days: what the warnings signs are telling us

5 August 2026 at 21:44

This week, the UK’s AI Security Institute (AISI) published an incident report most organizations would have quietly buried. During a routine cyber evaluation, an AI agent researched the real human maintainers of an open-source project, invented multiple fake online identities, and used them to pressure a real person into approving malicious code. Nobody instructed it to deceive anyone, and deception simply became a route to finishing the task. A human maintainer caught it and refused. The facts AISI ran a cybersecurity challenge 122 times across seven models. In 10 runs, an agent acted outside the scope of the test, producing […]

The post Three AI security disclosures, fourteen days: what the warnings signs are telling us appeared first on Check Point Blog.

When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context

4 August 2026 at 11:00
When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context

A few weeks ago, an AI cyber evaluation produced an unexpectedly efficient strategy for solving a benchmark: the agents went looking for the answers. According to OpenAI’s preliminary disclosure, models being tested for advanced cyber capabilities found ways to obtain secret information that could help them complete a benchmark. They chained vulnerabilities, stolen credentials, internet access, and inferences about where benchmark material might be hosted. The route eventually reached Hugging Face infrastructure, where the activity was detected and contained. Hugging Face has since published a technical reconstruction of 17,600 actions. Its investigators found a coherent intrusion that rebuilt tooling, tested […]

The post When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context appeared first on Check Point Blog.

AI Escaped a Sandbox. That is Not What Should Worry You

31 July 2026 at 03:27

What OpenAI’s and Anthropic’s testing incidents really teach defenders  In the past two weeks, two of the world’s leading AI labs have disclosed the same unsettling result. During their own safety testing, their most capable models reached real companies’ systems. First OpenAI, whose models broke into Hugging Face. Then Anthropic, whose models reached three more organizations.  Read the disclosures closely. Two facts carry the weight.  First, the safeguards were not defeated. They were switched off by design. OpenAI ran the models with reduced cyber refusals and safety classifiers disabled, to measure raw capability on a cyber benchmark. A model doing […]

The post AI Escaped a Sandbox. That is Not What Should Worry You appeared first on Check Point Blog.

Introducing the Industry’s First AI Network Firewall

30 July 2026 at 12:33

AI has introduced a new class of network traffic. Prompts, file uploads, model calls, and agent actions carrying sensitive business context now traverse the network as organizations race to adopt AI and achieve their business goals. Traditional firewalls were never built to understand these connections, AI activity often looks like ordinary web traffic, leaving the firewall unable to determine whether a prompt contains sensitive data, an agent is calling a tool it should never access, or an application’s AI model is subjected to a malicious prompt. These challenges demand comprehensive protection, which is why Check Point created the AI Defense […]

The post Introducing the Industry’s First AI Network Firewall appeared first on Check Point Blog.

AI Agent Security Just Had Its Catalyst Moment

28 July 2026 at 22:09

Update: Hugging Face has since published a detailed technical timeline of the incident. The additional technical details reinforce the core takeaway discussed here: advanced AI agents can pursue objectives in unexpected ways, making runtime governance and security controls increasingly important.  There are certain moments in technology where you realize the conversation is about to change. I remember the first time I launched an EC2 instance. I remember trying Uber when there were only a handful of cars on the road. I remember riding in a Waymo before autonomous driving felt normal. Each one was an early glimpse of a future […]

The post AI Agent Security Just Had Its Catalyst Moment appeared first on Check Point Blog.

Your AI Governance Policy Should Survive Your Next Model Change

28 July 2026 at 11:00
AI Governance

The model migration is ready for approval. Tests show better performance and lower costs. The application will serve the same users, process the same data, and support the same business workflow. The product team expects a straightforward technical sign-off. Then security asks the question that changes the review: which controls will survive the switch? Access rules, data protection, logging, and human approval may depend on settings provided by the current model platform. A migration can alter the organization’s effective policy even when the business use stays exactly the same. Models and providers will keep changing. The requirements attached to business […]

The post Your AI Governance Policy Should Survive Your Next Model Change appeared first on Check Point Blog.

Announcing the General Availability of Prisma AIRS AI Gateway

16 July 2026 at 16:50

Every modern enterprise is moving from an organization run by software to one orchestrated by AI, creating a tension between velocity and control. To resolve this tension, organizations require a unified architecture. Today, we are announcing the general availability of the Prisma AIRS AI Gateway, the AI control plane for the enterprise. 

Driven by the absolute conviction that an AI Gateway is foundational to the modern AI infrastructure stack, we are bringing AI innovations from the Portkey acquisition to Prisma AIRS just six weeks after closing. You can now scale AI at machine speed without compromising on enterprise-grade security and control.

Your AI Footprint is Outpacing Controls

Our next-generation firewall telemetry reveals that MCP activity climbed from 11% late last year to 41.4% by mid-2026. Monthly AI transaction volume grew twelve-fold over the same six months; some individual sessions moved hundreds of megabytes of enterprise data outbound. The AI footprint you can govern today is the smallest it will ever be.

Some of the most rapid AI adoption is happening with – coding assistants, enterprise agents and copilots.

  • Coding agents access code repositories, file systems, configurations, and credentials. When this context, including source code and secrets, is sent to a frontier model, it risks exposing sensitive data, and a runaway loop could burn a fortune in tokens overnight.
  • Enterprise agents run with broad access and standing privileges sharing context with each other. A single agent stretched beyond its scope can massively increase the risk of data breach, impact business reputation and customer trust.
  • Copilots now sit inside the SaaS and productivity tools employees already use. Copilots with broad access can surface data an employee was never meant to see.

As this enterprise data leaves when an AI request goes out, it creates a security and governance challenge at an unprecedented scale and speed.

What breaks when every team adopts AI 

AI adoption rapidly outpaces the security and governance infrastructure meant to secure it:

  • Shadow AI (Cost and usage are both hidden): You can't see the AI your teams already use or what it costs. 
  • Data Exposure (Sensitive data leaves without a trace): AI interactions can expose sensitive data, bypass policy and trigger unsafe outputs.
  • Agents Overstep (Actions run without accountability): Agents act across systems without clear identity, permission, or accountability. Keys get shared and agents run with broad, standing privileges, so no one can say which identity authorized a specific action or reverse it when an agent takes a wrong turn at machine speed.

Faced with this, most leaders either block traffic entirely or stay permissive and promise to govern later. Both approaches fail because they skip the critical step: seeing what agents do at runtime and controlling their actions while they happen.

Accelerate AI Adoption with Control

To scale AI adoption safely, you need a single control plane sitting between every AI interaction and the backend models. Prisma AIRS AI Gateway brings AI governance, identity and runtime controls together in one place. With the AI Gateway, you can:

  • Discover AI usage: Know exactly which apps, models, users, teams and agents are active, what they are accessing, and what they cost in a single unified view.
  • Govern AI interactions: Enforce central rules for model access, tool use and budgets while inspecting prompts and responses inline to prevent data leaks.
  • Secure every agent: Verify agent identities and enforce just-in-time, least-privilege access so autonomous systems only touch what they need, when they need it.

How the AI Gateway works 

Prisma AIRS AI Gateway sits inline between every AI interaction, model provider, and agentic interaction (Agent/AI App to LLMs, MCP Tool Calls, and A2A). It acts as a unified LLM, MCP, and A2A Gateway with a single enforcement point for all operational and security controls. Your teams keep using their existing coding assistants, enterprise agents, and copilots, while enforcement moves to the infrastructure layer where the platform team can own it.

Capabilities delivered through this unified control plane are:

Observability

Every request maps to a single unified view: tracking usage, users, projects, token counts, latency and cost so you can retire shadow AI infrastructure immediately.

Governance

Centrally define approved models, tools, and access without touching developer configurations. To drive FinOps and usage management, track every request's cost, tokens, and latency by team or project. Answer cost questions instantly, shut down unsanctioned AI usage, and proactively enforce budgets and rate limits before access is granted.

Coding Assistant Security

Protect credentials, proprietary code and development systems from risky AI actions. The gateway replaces raw provider keys with scoped credentials per user and team.

Operational Controls

Apply data protection, usage limits and policy checks as AI interactions happen. Traffic distributes via a Universal API across providers ensuring quotas are enforced and outages never stall your pipeline.

Agent Identity Security

Establish trusted identities by binding a verifiable, ephemeral identity to agents at execution. The AI Gateway acts as an enforcement point to enable only authenticated agents to make approved calls.

Runtime Security 

Powered by Prisma AIRS AI Runtime Security, the gateway inspects every prompt and response inline, stopping source code, secrets and customer data from leaving the network while neutralizing prompt injection attempts aligned with the OWASP LLM Top 10 and OWASP Top 10 for Agentic Applications.

Watch Anand Oswal break down why an AI gateway is foundational to this architecture.

the ai control plane of every enterprise

The AI Control Plane for the Enterprise

Prisma AIRS AI Gateway brings AI governance, identity and runtime controls together in one place. Point products filter text strings or route a single API call and they buckle under real enterprise volume.
Most products fail at scale. Prisma AIRS AI Gateway is built on an architecture tested in the most demanding enterprises for their ever evolving AI workloads: 

  • 68 Trillion+ tokens processed in the last month alone.
  • Sub-millisecond routing latency and inline inspection secures AI interactions without degrading user experience.
  • 99.999% availability helps ensure your AI operational pipeline does not experience a single point of failure.

Learn about Prisma AIRS AI Gateway and register for our webinar to see the AI Gateway in action. 

Your developers have already adopted their agents. The agentic enterprise is a reality. As the recently named "company to beat" in AI Security Platforms by Gartner, Palo Alto Networks is uniquely positioned to help you. Let’s build it securely, together.

The post Announcing the General Availability of Prisma AIRS AI Gateway appeared first on Palo Alto Networks Blog.

AI Appreciation Day: Let’s Be Honest About What We’re Appreciating

16 July 2026 at 16:46

Today is AI Appreciation Day, and honestly, we mean it. AI has changed how we write code, analyze threats, and get work done faster than anyone thought possible a few years ago. It deserves a moment of gratitude. But at Check Point, we spend most of our year studying the other side of that coin and our newly released AI Security Report 2026 makes one thing very clear: the same qualities we’re celebrating today are exactly what’s made AI such a powerful tool for attackers too. So in the spirit of appreciating AI honestly, not just enthusiastically, here’s what a […]

The post AI Appreciation Day: Let’s Be Honest About What We’re Appreciating appeared first on Check Point Blog.

AI Security Is Never Finished: Building the Continuous Red Teaming Loop 

15 July 2026 at 15:00
Continuous Red Teaming Loop

Security programs are built around moments of closure: the finding is closed, the control passed, and the release can move forward.  AI security refuses to cooperate with that model.  A passing test is useful evidence, but only for a specific system, configuration, and moment.  Production AI keeps moving. Models change behavior, prompts are revised, retrieval sources are added, agents gain tools, and users introduce unexpected context. Attackers adapt just as quickly. Yesterday’s clean result may not describe tomorrow’s risk.  That has been the practical case for continuous AI red teaming. Now, research from the National Institute of Standards and Technology […]

The post AI Security Is Never Finished: Building the Continuous Red Teaming Loop  appeared first on Check Point Blog.

AI Security Threats in 2026: Annual Insights from Check Point Research

14 July 2026 at 03:00

Key Takeaways Vulnerability response times have collapsed from days to hours. AI can reason about code well enough to generate working exploits at scale, so defenders now face patch windows of 12 to 72 hours instead of the traditional timeframe Your exposed AI infrastructure is being actively probed right now. Model servers, inference endpoints, and agent control panels are facing the internet, and most security teams don’t know they’re there Data leakage through approved AI use doubled in one year. Employees sharing context with generative AI to get useful answers are exposing credentials and source code in ordinary workflows, no […]

The post AI Security Threats in 2026: Annual Insights from Check Point Research appeared first on Check Point Blog.

AI Agents are Only As Effective as Their Harness

13 July 2026 at 15:00

Every AI vendor is talking about agents – autonomous systems that handle complex tasks without constant human input. The promise is real. But one question gets asked too rarely: what makes an agent reliable enough to trust with your network security?  The answer isn’t the model. It’s the harness.  Agents Run on LLMs. Reliability Runs on Something Else AI agents get their reasoning power from large language models (LLMs). LLMs are impressive. They understand context, reason through complex problems, and plan across a wide range of tasks.  But on its own, an LLM is a generalist. It knows a little about everything and not enough about your […]

The post AI Agents are Only As Effective as Their Harness appeared first on Check Point Blog.

Redefining the CISO Contract: From Securing the Business to Securely Doing Business

10 July 2026 at 11:05
Redefining CISO Contract Blog Banner

Walk into almost any executive leadership meeting right now and you’ll find the same dynamic playing out. The CEO is asking how the company can do more with AI, faster. Engineering teams are already three sprints deep into building something new. And when the CISO walks into the room, the energy subtly shifts. The unspoken question is always the same: is this person here to help us move, or to slow us down? That dynamic is an issue, and I think it’s one the security community has to own. The CISO has long carried the label of the “Office of […]

The post Redefining the CISO Contract: From Securing the Business to Securely Doing Business appeared first on Check Point Blog.

What It Takes to Secure Claude Cowork Across the AI Enterprise

You've watched the demos. Whether it's Claude Cowork, ChatGPT Enterprise, GitHub Copilot, Cursor, or internally developed agents, AI systems are no longer answering questions. They are connecting to enterprise data, invoking tools, making decisions, and executing multi-step workflows across applications without human intervention. The capability is real, and organizations are rapidly moving from experimentation to deployment.

Teams are no longer asking if they should use this, they have accepted agentic tools as the reality. But the board and the infosec team are asking a different question: can this capability be secured and controlled at enterprise scale? Can security teams prevent sensitive company data from being exchanged without oversight?

Anthropic built meaningful access controls into Cowork — role-based permissions, group spend limits, usage analytics and connector restrictions — so the answer is a qualified yes. Those controls handle who can use the tool and what they can connect to, but they don't answer whether a specific action inside a given session is safe. That gap is the one standing between a successful pilot and a successful org-wide rollout.

The Gap That a Demo Doesn’t Expose

The organization’s admin assigns roles, sets spend ceilings per user group and restricts which connectors have access to write to your database. Anthropic's OpenTelemetry support even lets your team pipe session events into your SIEM. These controls cover real ground, but they operate at the permissions level — answering whether a person is authorized to use the tool rather than whether what's happening inside a session is safe.

Consider what that gap looks like in practice. Let’s consider two scenarios. Your finance analyst has full Cowork access and uploads a quarterly forecast containing unannounced acquisition figures. The access controls confirm she is authorized to use the tool, but nothing evaluates whether that information should be exposed to a model. That's an AI data loss prevention risk, and access controls are blind to it.

The risk becomes greater when agents move beyond information retrieval and begin taking actions. Let’s say a scheduled Cowork automation is set up to pull weekly competitor pricing from the web. A target site embeds hidden instructions in its page content. The agent, running unattended, reads them as legitimate commands and begins modifying local files and triggering actions your team never authorized. By the time anyone notices, the agent has already acted.

The first scenario exposes a governance problem because your security team has no visibility into what data is flowing through AI tools across the organization. The second is a runtime security problem as there is nothing evaluating whether an action in progress is safe, regardless of whether the user was authorized to start it. Neither gap is addressed with the predefined controls in Cowork; both need to be solved before you can say yes to Cowork adoption in the whole organization.

Why Traditional Controls Break Down

Traditional enterprise software behaves predictably. Access controls work because administrators can reasonably anticipate what an authorized user or application will do once access is granted. 

AI systems operate differently. Agents combine models, tools, data sources, and reasoning paths dynamically at runtime. An authorized user may start with a simple request, but the resulting chain of actions may evolve in ways that were never explicitly programmed or anticipated. The challenge is no longer controlling who can access a system. The challenge is securing and governing what happens after access has been granted.

The Missing Layer is Runtime Security 

Anthropic's access controls establish who can use Cowork and what they can connect to. But as the examples above show, they don't protect against what happens inside a session: a finance analyst uploading sensitive acquisition data to the model, or a scheduled automation being hijacked by a malicious instruction embedded in a webpage it was directed to visit. What organizations working with Cowork need is a layer that enforces data and security controls and gives complete visibility at runtime across all Cowork agents in the enterprise every interaction boundary.

An AI runtime security layer that sits between your teams and the model providers such as  Anthropic, AWS Bedrock, Google Vertex or any combination, and evaluates risk in every interaction. It inspects every request, every tool call and detects sensitive data like client names, financial projections, internal pricing and contract terms.  It enforces agent identity controls, so every automated action is traceable to a specific workflow and owner. 

Your CISO gets the audit trail and your Infosec team gets the evidence.

The AI Enterprise Needs a Control Plane

The CIO needs the observability for all Cowork activity and costs. An AI control plane allows the CIO to set spending limits per team and use case across every AI tool from a single console. Procurement asks for a quarterly forecast across all AI spend, and you pull it from one place instead of aggregating reports from four different vendor dashboards. If you need to move providers for cost or compliance, the gateway reroutes traffic without disrupting your teams or breaking your workflows.

Claude Cowork may be where organizations begin scaling their AI journey, but it won't be the only AI tool your teams use. Developers will use coding assistants,  business teams will leverage the AI built into SaaS applications and data science teams will deploy custom agents for their workflows. New models, new providers and new workflows will continue to appear.

The challenge isn't just governing one AI application; it’s governing AI activity across the entire AI enterprise.

Everyone looks to secure each tool individually: configure Cowork's controls, configure your coding assistant's controls, configure your internal agents separately. But this approach doesn't scale. This is the sole purpose of the control plane. It sits above individual tools, applications and models and enforces  security policies,  across every AI interaction. 

Prisma AIRS AI Gateway provides that centralised control plane. Organizations that deploy Cowork behind our gateway get runtime security, data protection, agent identity controls, and full visibility, applied consistently, without changing how teams use the tool. The same gateway secures every other AI tool in your environment on the same terms.

Cowork may be where the journey begins, the gateway is what allows it to scale and secure the AI Enterprise.

The post What It Takes to Secure Claude Cowork Across the AI Enterprise appeared first on Palo Alto Networks Blog.

It Might Feel Like We’ve Been Here Before, But We Haven’t

6 July 2026 at 13:09

As artificial intelligence (AI) adoption surges and organisations move from the ‘should we?’ phase to the ‘how do we?’ phase, it’s natural to evaluate the likelihood of positive returns on AI investments. That’s always been the case with the onset of each new technology paradigm: C-suite executives, guided by their boards and aided by technical and business teams, remain keenly focused on traditional metrics such as return on investment, shareholder equity, developing and extending competitive advantage, and ensuring superior customer relationships.

This time is different, however. I recently experienced that firsthand when I went to visit a major customer. My contact, a senior decision maker, gave me a pointed piece of advice about how to talk about AI with his boss, the CEO: “Please don’t say anything negative about AI.” The subtext was clear: The company was fully committed to AI and didn’t want any cognitive dissonance to dissuade them from their mission.

It's hard to imagine a CEO taking such an absolutist stance on previous technology waves, such as cloud, bring your own device, or the internet of things. CEOs, board members, and technical leaders would be pragmatic in evaluating the benefits of investments and put mileposts in place to gauge progress – and to determine if and how to proceed.

AI is certainly a different kind of paradigm, though. While no one is casting aside careful evaluation and monitoring of AI investments, the underlying assumption is that we’re stepping on the accelerator. We’re all enthused not only by its potential for transformation and innovation, but also by how this technology can be leveraged for remarkable societal good.

However, while the accelerating momentum toward AI and agentic systems is undeniable, it is vitally important to set aside the fervour around AI and take a sober look at how to deliver safe, secure, and tightly governed systems at enterprise scale. 

Many organisations are underestimating the challenges of AI governance, in large part because they think they’ve been here before. They already have many experiences of ensuring robust cybersecurity and strict governance for new technologies, as they’ve done for remote systems, cloud computing, the internet of things, and more. They already have a corporate commitment to doing governance correctly and a sound governance model. 

But this new era of AI and agentic systems is different. New challenges abound, and AI strategy, build-out, and governance must be in alignment from the start to ensure proper operational, ethical, and regulatory outcomes. 

Our intention with this Peer Insights guide is to raise what we believe are existential issues around governance for this powerful, complex, and unprecedented technology wave. Few technologies have merited the often overused phrase ‘inflection point’ more than AI. The speed of AI adoption is nothing short of breathtaking; however, today’s runaway embrace of AI is far stronger than our current ability to govern it. That’s because AI represents a fundamental shift in how organisations do their business, interact with customers, make vital decisions, and execute their plans. This isn’t just a technology play: It’s a strategy for success and survival for entire industries and our global economy. The stakes have never been higher.

CEOs care so passionately about AI because they see it changing nearly everything we’ve learned and believed to be true about organisational success and failure. CEOs are in their positions for one purpose: to grow the business. AI can do that by transforming their processes and sparking new ideas. When that customer representative forewarned me, I really wasn’t surprised to hear his CEO felt so strongly about AI: Research from BCG indicates that more than 94% of CEOs say they still plan to deploy AI irrespective of demonstrated business value, even if there is a lack of tangible ROI or financial benefits from the start. 

Which brings us to the central role of AI governance. As we all know, there are many fundamental elements to any governance strategy, starting with robust, scalable, and intelligent cybersecurity. Cybersecurity - the foundation of governance - also includes the twin imperatives of accountability (‘rogue AI’ being a real thing, after all) and regulatory compliance.

But good AI governance has to go even further. Operational integrity is key to good governance because so much sensitive and even proprietary data is poured into AI models and accessed through powerful agentic AI systems. Now more than ever, organisations have to be transparent with customers and trading partners about how their AI systems operate, what kind of data is accessed, and how it is protected. And that doesn’t just mean being upfront with customers by telling them when they are interacting with an AI agent. Let’s take a typical retail use case: Imagine you’re on a website looking at clothing, and the agent recommends specific styles of clothing in specific colours. True operational integrity would allow you to discover why and when the agent made those recommendations. Was it based on your prior purchasing history, or on your browsing patterns on a recent web session? AI and agentic governance take the guesswork out of the equation for those interacting with the system and help breed greater confidence and trust.

It's critically important for decision makers to view AI governance holistically, rather than through a series of narrow lenses. For instance, even though cybersecurity is the foundation of good AI governance, it’s a mistake to treat AI governance primarily as a cybersecurity problem. If asked about ownership of AI governance, CEOs cannot and should not reply, “Oh yeah, the CISO has that covered.”

AI governance is fundamentally an enterprise risk problem, which means everyone must be involved in creating, deploying, managing, evaluating, and adjusting AI governance guardrails on a real-time basis. Again, AI is a different kind of risk environment than any we’ve previously encountered. For the most part, organisations are simply not adequately prepared to apply the right level and right type of governance to AI and agentic systems. I’ve spent much of the past 15 years of my career building governance frameworks, and while it has never been easy, we have had the advantage of being able to control many of the variables – such as infrastructure and network access – impacting governance decisions. With AI and agentic, we no longer have that advantage.

To explore the critical and complex issues of AI governance, we’ve enlisted five leading voices to bring their real-world experience to the discussion. Together, our five authors help lay out the new rules of the road for governing AI and agentic systems at scale.

Just as my customer gave me a heads up about the realities of speaking with his boss about AI, I’d like to offer you a heads up about the realities of AI governance challenges before you read this Peer Insights guide

  1. Visibility is paramount for successful AI governance. As we learned during the growth of trends such as cloud, bring your own device, and remote work, our employees will push the envelope with a do-it-yourself mindset. These tech-savvy and resourceful users are already making rogue AI a reality, so organisations need more visibility than ever into where AI ‘science projects’ and sandboxes are operating without anyone’s knowledge.
  2. AI governance must reflect the stunning velocity of change in AI development and deployment. Not only does AI have its own never-imagined rate of change, but the technology is changing everything else faster – product development, supply chains, marketing programmes, and more. AI governance has to evolve just as rapidly. Governance in the AI world must be a living system, constantly evolving with new technology use cases.
  3. Trust boundaries are incredibly different and difficult to manage in AI governance. AI represents a new class of identity that simply didn’t exist before. That means AI doesn’t fit neatly into your existing identity management framework, making things like application whitelists and zero trust network access less effective.

Unfortunately, many CEOs, board members, and business executives simply don’t understand the profound importance and complexity of these issues. They may have been heartened by how they integrated generative AI into their technology frameworks and their business processes, but GenAI was pretty familiar territory for CIOs, CTOs, and CISOs. Agentic AI is different for several reasons, including its automation and self-learning capabilities. Don’t be lulled into a false sense of security: Agentic AI is not simply a refresh of GenAI.

As you get ready to dive into the following chapters, rethink how you define governance when applying it to AI systems and agentic AI. Most traditional governance models are imagined, constructed, and deployed as gates, preventing people from doing things or going places they shouldn’t. Instead, think of AI governance as a guardrail to guide and direct people to get the most out of AI without creating problems. With so much excitement and investment around AI, organisations – and their employees – want to get the most out of their AI and agentic systems. We all know people don’t want to hear “no, you can’t do that”, so an effective governance system should use guardrails to drive proper, responsible, and safe usage of the technology.

Finally, as complex as AI and agentic governance are and will continue to be, don’t overthink things in hopes of creating the perfect model – it doesn’t exist. My advice is to start now, even if the model and framework are imperfect, and then bring the business along with you.

We at Palo Alto Networks are excited to give you insights, ideas, and actions you can take away from the chapters of this guide. We encourage you to share what you learn with your colleagues, peers, and team members – and to take prudent steps to build an AI governance model that rewards innovation without allowing your organisation to drift into dangerous waters.

 

Click here to download the guide today. Visit Executive Edge, our C-level thought leadership platform, for more insights for EMEA CXOs.

Haider Pasha is VP & Chief Security Officer, EMEA, Palo Alto Networks

The post It Might Feel Like We’ve Been Here Before, But We Haven’t appeared first on Palo Alto Networks Blog.

Built to Last: What Stonehenge Teaches us About IT Architecture & Cyber Resilience

23 June 2026 at 17:55

Anyone who has seen the impressive frame of Stonehenge against the morning’s sunrise cannot help but be struck by its resilience, how it has withstood time and the unpredictable impact of nature and humans. And partly because of this, a recent conversation I had with the CIO of a large healthcare technology company made me realize that it was a fitting metaphor for cybersecurity.

As our conversation wove through familiar topics — the challenges and breakthroughs in enterprise IT architecture — we recognised and discussed a recurring pattern throughout most EMEA and multinational enterprises. Those organisations have gradually but surely evolved into a mosaic of vendor fragmentation, ‘micro-platforms’ across vendor-specific technologies, and rapidly developing data silos that no single IT architecture can solve on its own. 

The increased heterogeneity of hardware, operating systems, and cloud architectures now comes with a dizzying mix of cybersecurity tools and services, often optimised for Vendor X’s platform. This has led to the situation that a large organisation typically has more than 30 cybersecurity point solutions in place to protect their digital assets. And now that we have thrown AI into that mix, designing the right cybersecurity solution is as confusing as it is imperative.

That’s when I was reminded of Stonehenge. Its lintel-and-joinery design is strikingly simple and elegant, and it stands as a brilliant monument to long-term resilience. Just as Stonehenge has endured against natural and human threats, so organisations must build a cybersecurity architecture that endures a revolutionary rate of change and threat diversity, including geopolitical turbulence and AI entering the value chain. 

For CISOs, CIOs, board members, C-suite executives and line-of-business leaders concerned with operational resilience, cybersecurity architecture matters—deeply. 

And we should not forget that cybersecurity is a data problem. The more telemetry data you have, the more effectively you can execute security algorithms and protect your digital essentials across all your enterprise IT pillars, i.e., IT, OT, Clouds, Networks, Workplace, Endpoints, etc. We at Palo Alto Networks are able to combine relevant telemetry data from networks, firewalls, clouds, browsers, endpoints and the internet. 

Stonehenge was built from massive, self-reinforcing pillars and platforms of stone. The lintels and joinery help hold together the overall structure as a cohesive unit, and they have striking similarities to how IT architects are now thinking about cybersecurity. In today’s technology architecture, Stonehenge’s vertical pillars are an IT organisation’s specialised, vendor-specific IT domains—sometimes with its own security tools and capabilities rather than as a strategically integrated zero-trust cybersecurity framework across your enterprise IT pillars.

Now, Stonehenge’s with its unique resilience, can also serve in its own construction as a model for modern cybersecurity architecture. Like our evolution towards modular platformisation evolved deliberately and assuredly over time and it spans all key domains of cybersecurity, ie network, cloud, AI,  identity security and all key building blocks for an AI-driven SOC, the last line of defense that has to be real-time. In other words, it is the linchpin of our strategy for enterprise security built upon such key areas as Identity, the Autonomous SOC, and Network Security. 

Stonehenge’s lintel is analogous to cybersecurity platformization, a growing trend rapidly replacing the now-outdated best-of-breed point solution mindset. This employs a modular approach that gives flexibility and control to the security architect looking to add security domain capabilities as needs evolve. The mortise-and-tenon joinery of Stonehenge works because the parts fit together rather than being stacked as an afterthought, in much the same way modern cybersecurity frameworks are built upon the concept of embedded functionality rather than being bolted on. 

An important example here is Palo Alto Networks’ decision to power the cybersecurity platform core with Precision AI, rather than its technology being added as a separate tool. This approach enables Precision AI to power data, analytics, and workflows, making it an omnipresent resource for smarter and faster prevention, detection and response.

Another important element of any enduring architecture is its ability to provide stability to the overall framework. In cybersecurity architecture, this is the all-important cyber data layer across an integrated zero trust framework. As organisations continue to struggle with data silos across networks, cloud environments, security operations centres, and edge systems, the cybersecurity data lake takes on a heightened role of importance for the resilience of the entire cyber framework. Again, let’s not forget, cybersecurity is a data problem, a domain in its own right across all vertical IT pillars.

Now, Stonehenge with its unique resilience, can also serve in its own construction as a model for modern cybersecurity architecture. Like our evolution towards modular platformization evolved deliberately and assuredly over time and it spans all key domains of cybersecurity, i.e.  network, cloud, AI, endpoints, identity security and all key building blocks for an AI-driven SOC, the last line of defense that has to be real-time. In other words, it is the linchpin of our strategy for enterprise security built upon such key areas as Identity, the Autonomous SOC, and Network Security/SASE. 

Another critical element of the cyber platform is something even Stonehenge hasn't had to face: securing AI itself, especially the opportunity and threat represented by agentic AI. AI security must become part of the platform design and implementation, as we have done with our Prisma AIRS (AI Runtime Security) platform for enabling an organisation's growing AI portfolio to remain a vital asset and not an inviting attack vector. Agents now are not just another non-human identity; they are an entirely new class of identity, with a striking mismatch in speed between agent decision-making and human governance. The inside-out attack paths taken by hackers' ill-intentioned agents represent a major threat to under-protected AI supply chains. The same pressure now also comes from geopolitics and from AI moving into the value chain itself, such as in the case of the Factory of the Future.

Similarly, our recent acquisition of CyberArk gives us what we believe is the industry’s strongest identity security platform, Idira, positioning it as yet another vertical pillar connected to the overall cybersecurity platform lintel. Cortex XSIAM and its security data lake are deliberately open — ingesting and correlating third-party telemetry alongside our own, over 17 petabytes of telemetry data each day — to form a secure data layer that is accessible to users based on policy management and credentials validation. Palo Alto Networks leverages this mountain of data, along with around-the-clock scanning of more than 5 billion daily security events, to feed Precision AI in order to detect and block potentially devastating attacks. Currently, we detect about 9,6m new attacks per day that have not been there the day before. The use of automated AI in attack vectors has been accelerating the time of exfiltration of data from the compromise of an organization. This delay was 9 days about 3 years ago, now data is exfiltrated in most cases in less than a day, sometimes already within less than one hour!

In this context, it's also important to highlight the importance of an Autonomous SOC pillar, particularly since compliance reporting windows are continuously contracting from days to mere hours calling for real-time, highly automated defence. Today, mean-time-to-detect and mean-time-to-respond are board-level imperatives commanding more conversation and attention at an organisation’s highest levels. The Autonomous SOC pillar is a vital element in helping enterprises achieve even faster detection and remediation, ideally down into single minutes. If it also integrates the historic enterprise SIEM you can further simplify your SOC operations and gain solid financial benefits by platformization of your security relevant data.

Finally, keep in mind the use of supply chains to build the actual platform. For Stonehenge, that was an impressive physical supply chain: The bluestones used in the structure were hauled about 250 kilometers from Wales without the benefit of air, rail, or truck transport. For Palo Alto Networks’ cybersecurity platform, the supply chain was no less impressive, but more virtual than physical, often faced with attacks on third-party interdependencies such as SaaS applications, APIs and in times of Frontier AI models, the Open Source components. 

Like the pyramids, the Great Wall of China, and the Roman road system, the most remarkable aspect to Stonehenge isn’t just its engineering elegance, but its ability to withstand changing conditions and threats over time. Whether you’re a CEO, board member, CIO, CISO or security engineer, the decisions you make about cybersecurity carry significant impact and implications. In order to achieve Stonehenge-like resiliency, technical and business leaders should commit to an architectural model designed not only for today’s needs, but for what those needs are likely to be over the long term. 

Therefore, cybersecurity should be architected as a horizontal, dedicated platform across all your IT domains and businesses. With this you are able to provide real-time and platformized cybersecurity for tomorrow. And tomorrow is going to be a more and more AI-driven business world. 

 

Helmut Reisinger is CEO for Europe, Middle East, and Africa at Palo Alto Networks.

The post Built to Last: What Stonehenge Teaches us About IT Architecture & Cyber Resilience appeared first on Palo Alto Networks Blog.

❌