Overview of Content Published in August


Unit 42 is putting the latest frontier cyber models to work across customer environments to find, validate and help remediate the attack paths that matter most.
In May, we introduced Frontier AI Defense with a warning: the window to get ahead of AI-enabled attacks was shorter than most people realized. Since then, we have briefed more than 1,000 security teams around the world and introduced our Frontier AI Defense service to hundreds of customers.
Today, through our partnership with OpenAI, we are expanding Unit 42 Frontier AI Exposure Analysis to put advanced frontier cyber models directly to work in customer environments. Under Unit 42 direction, these models can find exposures, test whether they are exploitable, validate attack paths and help customers prioritize what to fix first.
Our early work shows why this approach matters: 36% of the exposures we identified map to no known CVE, often because they involve multiple gaps that have to be discovered, chained and tested together.
Palo Alto Networks has been among a limited group of organizations with early access to advanced cyber capabilities from the leading frontier AI labs. Through our partnership with OpenAI, Unit 42 can now bring its latest advanced cyber capabilities, including GPT-5.6 Daybreak, to security testing and validation for our customers. Until now, GPT-5.6 Daybreak has not been available for commercial use.
Frontier models have helped inform the work of our experts. Now they can increasingly perform complex offensive security tasks directly, at machine speed and under Unit 42 direction. That allows us to go deeper than traditional vulnerability discovery by testing exploitability, reasoning across multiple weaknesses and determining how an attacker could use them to achieve an objective.
There is no single best model for every cyber task. Our research has shown that different models have different strengths and find vulnerabilities others miss. A multi-model harness routes work to the model best suited for the task, improving efficacy and coverage while managing the cost of frontier AI at scale. As stronger models emerge, we can incorporate them without rebuilding the offering around a single model or provider.
Unit 42 experts remain central to the process. We combine frontier models with our offensive security expertise, Palo Alto Networks telemetry and Unit 42 Threat Intelligence to validate findings, connect exposures into attack paths and understand what an attacker could ultimately achieve.
The expanded service brings five capabilities together:
Most security teams already have more findings than they can act on. The harder problem is knowing which ones create a real path to compromise. Attackers look across applications, infrastructure, identity and cloud for weaknesses they can combine to achieve an objective. Frontier AI Exposure Analysis applies that same adversarial perspective, helping defenders understand which paths matter and what to fix first.
For the past several months, frontier AI has been a story about what is coming for defenders: vulnerability discovery at scale, exploit chaining that sees full-stack logic no scanner catches, and attack cycles compressed to seconds from initial access to exfiltration.
All of that is still true. Our answer has been to put everything we learn testing these frontier models into the hands of defenders. Today, that gets more direct: not just what frontier models have taught us, but the models themselves, working in your environment for your defenders before those same capabilities are working for the attacker.
The window is still closing. We intend to spend it building on the side of the defenders.
Visit Palo Alto Networks Frontier AI Defense to learn more.
The post Putting OpenAI Cyber Models to Work for Defenders appeared first on Palo Alto Networks Blog.


As organizations race to deploy agentic AI, legacy network security solutions are ill-equipped to keep up, forcing productivity tradeoffs while exposing coverage gaps. At the same time, Frontier AI is proving capable of discovering vulnerabilities and creating exploits in real-time. Navigating this shift requires more than incremental feature enhancements; it requires a bold, market-defining vision backed by relentless customer focused execution.
Today, we’re proud to announce that Gartner® has once again recognized Palo Alto Networks as a Leader in the 2026 Magic Quadrant™ reports for both Security Service Edge and SASE Platforms. This marks the fourth consecutive year that Palo Alto Networks has been recognized, making us the only security vendor to be recognized as a Leader in both reports for four years in a row.
![]()
In this year’s Magic Quadrant for SSE, Palo Alto Networks was placed highest in ability to execute and furthest in completeness of vision for Prisma Access.
Every day we focus relentlessly on understanding the needs of our customers and channeling that back into products and services that create real value for them. Our product strategy centers on where our customers' environments and security needs are heading, not just where it sits today.
The AI landscape is changing daily - in this new reality, we strive to be the visionary leaders to serve our customers. GenAI and Agentic AI are exposing enterprises to novel categories of risks like prompt injection, over-privileged agents, and poisoned models. At the same time, Frontier AI is accelerating vulnerability discovery and attack speed resulting in attack timelines being compressed by over 95%.
Gartner projects that by the end of this year, 40% of enterprise applications will feature embedded agents, up from less than 5% today. And by 2028, 60% of brands will use agentic AI to facilitate streamlined one-to-one interactions. Operating a business in this new reality requires security architecture engineered to anticipate threats that haven't yet emerged. Success cannot be achieved by retrofitting legacy products with support for AI infrastructure. It demands a unified future-ready foundation that natively secures users, applications, sensitive data, and non-human identities across every touchpoint. The platform enterprises use today determines whether they'll be prepared for tomorrow's threats.
As the cybersecurity landscape undergoes its biggest shift in decades, to us, the Gartner recognition as a Leader on vision and execution across both reports means more than ever before. In our opinion, it not only validates Palo Alto Network’s ability to serve the world’s largest enterprises but also celebrates our strategic product capabilities as shaping the future of cybersecurity through industry leading innovation such as securing AI traffic flows and agents that simplify manageability of SASE operations.
We believe being placed highest in execution and furthest in vision is only as valuable as the ability to execute on it, and Palo Alto Networks has a proven record of creating value for our customers. Our recent milestone of crossing the $1.6 billion ARR mark while growing 40% year over year for Prisma SASE reflects the trust customers have placed in us. Over 6,800 organizations, including over one third of the fortune 500, trust us because we consistently turn market-defining innovation into enterprise-grade reality. Our execution leadership is built on a strong foundation:
As the rules of cybersecurity are rewritten in real time, leading the market requires more than following past trends, it requires setting the trajectory. Our aim is to continuously be at the forefront of defining the future of cybersecurity to power the agentic enterprise of tomorrow.
Palo Alto Networks continues to innovate to keep enterprises safe at the speed of AI. Our Precision AI security service blocks over 30B threats every single day defeating sophisticated and highly evasive tactics. When combined with our virtual patching and IP defense security services, organizations receive proactive defense that secures at the speed of Frontier AI with flexible enforcement that provides consistent protection everywhere. We are delivering comprehensive security across network, edge, and cloud infrastructure to stop hidden threats that are invisible to traditional networks security solutions.
This AI-powered defense in depth strategy operates across the entire attack lifecycle to enable proactive protection that shifts enterprise security postures from reactive incident response to preemptive defense.
Safely enabling employee adoption of AI tools and agents requires special considerations to mitigate risks around data leaks, intellectual property exposure, and compliance. Prisma SASE and Prisma Access solve these challenges by discovering all AI usage and agentic actions, enforcing granular least privilege access for human and non-human identities, and preventing exposure of risky data to AI and agents. Through AI Access Security™, Prisma SASE provides unified data security across the AI lifecycle by integrating GenAI app visibility and control, real-time prompt analysis, shadow data discovery, and protection on endpoint. Prisma Browser provides a secure AI workspace that safeguards both human and autonomous agent workflows across any LLM by defending against data leaks, prompt injections, and agent hijacking.
To secure the rapid adoption of AI agents by enterprises, Prisma Access will natively integrate with Prisma AIRS AI Gateway to provide a unified LLM, MCP, and A2A gateway giving security teams a single pane of glass for AI observability, cost governance, and runtime inspection.
This innovative approach represents an evolution away from traditional device and user centric fabrics towards an agent-aware platform capable of securing AI for the enterprise of tomorrow, today.
We continue to invest in capabilities that make our platforms proactive, efficient and easier to use. Our new deployment agents enable customers to onboard their SSE or SASE environment more efficiently, reducing their time to value while increasing productivity. Once onboarded, autonomous AI agents within Strata Cloud Manager continuously evaluate network and security posture to proactively identify configuration drift, performance degradation, and security policy gaps. By uncovering potential disruptions before they impact users or expose the organization to risk we’ve created automated systems capable of finding issues and automatically remediating them, with human-in-the-loop oversight calibrated to the administrator's comfort level, from guided recommendations to full autonomy.
The practical outcome is a dramatic reduction in mean time to resolution (MTTR) and a measurable reduction in total cost of ownership (TCO) while significantly reducing administrative burdens and making Palo Alto Networks products easier to maintain and operate.
Download your complimentary copies of the 2026 Gartner® Magic Quadrant™ reports to learn why Palo Alto Networks has been recognized as a Leader in both SASE and SSE for the fourth consecutive year.
Gartner, Magic Quadrant for Security Service Edge, 29 July 2026, John Watts Et Al.
Gartner, Magic Quadrant for SASE Platforms, 28 July 2026, By Jonathan Forest Et Al.
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
Gartner and Magic Quadrant are a trademark of Gartner, Inc., and/or its affiliates.
This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Palo Alto Networks.
The post Palo Alto Networks Recognized as the Only Vendor to be Named a 4X Leader in SASE and SSE Gartner Magic Quadrant Reports appeared first on Palo Alto Networks Blog.

Palo Alto Networks works closely with OpenAI across our product platform and Unit 42, leveraging advanced frontier model capabilities. Furthermore, we are a partner in the OpenAI Daybreak Cyber Partner Program, working with OpenAI to bring trusted, AI-powered cyber defense to more organizations. Today, we’re announcing native integration of Prisma AIRS Runtime API with OpenAI Codex. This milestone deepens our partnership and drives our shared mission forward: equipping defenders with the industry's most advanced tools.
AI coding assistants have transformed software development, accelerating shipping velocity and changing how engineers solve problems. But as integration of AI coding assistants deepens across development teams, security and compliance teams constantly struggle with enabling developer productivity while helping protect proprietary source code and credentials, and reducing the risk of runtime threats entering the codebase.
We designed this integration to eliminate complex traffic steering and heavy client-side hooks. Securing your entire developer organization takes just a few clicks inside Codex Enterprise Management UI. Here is how you can enable it:
By connecting the Codex in ChatGPT for Enterprise workspace to the Prisma AIRS Runtime API, security teams gain comprehensive, automated security controls across two critical vectors:
Developers frequently paste context – logs, config snippets, or functions – into AI coding assistants. Prisma AIRS scans inputs to help identify sensitive data before it is submitted.
AI prompts and contextual inputs can contain content that introduces security risks into development workflows. Prisma AIRS Runtime API inspects incoming developer inputs for:
Security controls only work if developers actually use them. Because the inspection happens at the platform administrative level via API, developers continue working natively in Codex without changing their IDE setup or downloading local hooks. SecOps gain centralized visibility, consistent policy enforcement, and audit-ready logging capabilities across the entire engineering organization, while developers keep the speed and experience they expect.
The Prisma AIRS integration helps organizations maintain consistent security controls while preserving the speed and productivity gains of Codex. Organizations can combine Palo Alto Networks’ security capabilities with OpenAI Codex to maintain centralized security and governance controls.
Choose your path forward:
Forward-Looking Statements
This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov. All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.
The post Strengthening Security of AI Coding: Prisma AIRS API Integration with OpenAI Codex appeared first on Palo Alto Networks Blog.

Modern enterprise security is at a pivotal moment where CIOs and CISOs have a clear opportunity to build a cybersecurity architecture for both today’s environment, and for the future. Doing so requires redefining enterprise resilience across three critical dimensions.
First, Frontier AI driven threat velocity and novelty. Frontier AI models have automated the entire attack lifecycle. Adversaries aren’t just compressing exploit windows to near-zero timelines, they are also generating novel, highly evasive threats at machine speed, bypassing traditional signatures and often before patches are generated.
Second, surging network traffic is overwhelming traditional defenses. Driven by AI workloads, inter-datacenter traffic will nearly triple1 over the next decade dramatically expanding the volume of data teams must inspect and secure.
Finally, major shifts are forcing a “cryptographic reset.” Shrinking certificate lifecycles, internet-scale distrust events, and quantum computers powerful enough to crack public key cryptography are combining to shake the foundation of all digital communications.
Meeting these challenges requires more than incremental fixes. Today, we are proud to introduce PAN-OS 12.2 Ceres, a landmark release representing a major leap forward in network security.
Ceres brings to market 55+ innovations, including three flagship, core capabilities, designed to shift the balance of power back to defenders.
Today, Palo Alto Networks is giving defenders the ultimate advantage with the launch of Frontier Virtual Patching. By harnessing Frontier AI to discover unknown vulnerabilities, and deploying protections in hours, we are collapsing the exposure window from the industry-average 55 days2 it takes to deploy a traditional patch down into a near-zero window of exposure. This isn’t just about faster patching; it’s about eliminating the attacker’s chance by neutralizing exploits before they ever reach your network.
![]()
The new reality: Exploitation far outpaces patch deployment
We’ve built this capability as a collaborative, force-multiplying ecosystem, with our industry partnerships across the enterprise software and OT vendor landscape to accelerate vulnerability disclosure, remediation and customer protection. This includes our collaboration with Project Lightwell, which combines our rapid network-level protection with software remediation to help organizations reduce exposure to emerging threats. We’re also partnering with vulnerability clearinghouses, software maintainers, and industry initiatives to continuously expand a real-time pool of protected vulnerabilities.
This approach builds on recent Unit 42 research, where the autonomous AI system NOVA identified more than 14,000 previously unknown vulnerabilities in just two months – a clear signal that defenders must pair AI-powered discovery with equally fast, coordinated protection. We have built an all-new detection engine, “vaulted protection," that enables us to deliver these rapid protections in a safe and responsible manner. When one participant identifies a threat, the entire ecosystem is protected instantly. Individual discovery becomes global protection.
This is especially valuable for operational technology (OT), critical infrastructure, healthcare, and IoT: environments where systems can’t be taken offline to patch, where patch cycles can stretch for months, and where a single unpatched device can expose an entire network. Frontier Virtual Patching closes that gap in the network, blocking the exploit without applying a patch, rebooting a system, or causing any downtime to critical operations.
Bad actors will lean into Frontier AI to reduce the attack lifecycle from months to minutes. To keep pace, organizations require security partners to match that machine speed. To this end, Palo Alto Networks is raising the bar with its Frontier Virtual Patching, moving beyond compensating controls. By safely and efficiently discovering undisclosed vulnerabilities and deploying protection long before traditional patches can be rolled out, Palo Alto Networks deep security capabilities are flipping network defense from a reactive to proactive operational model.
Will Townsend
Chief Analyst, LoneStar Advisory & Research
And for existing Palo Alto Networks network security customers, getting started is effortless. Frontier Virtual Patching is available as a PAN-OS software upgrade with persistent, automatic content updates, so protections keep arriving as new threats emerge, with no new hardware and no manual intervention.
Clearly, Network Security is evolving quickly. Frontier Virtual Patching is part of a huge set of innovations that the team at Palo Alto Networks is delivering in PAN-OS Ceres 12.2 to enable you to stay protected.
Modern threat actors continuously work to hide their attacks and evade existing controls. Adversaries are increasingly evading traditional perimeter detection of their command-and-control traffic by leveraging direct-to-IP connection techniques that bypass DNS and URL inspection entirely. Attackers are also weaponizing massive proxy networks and hundreds of thousands of residential IP addresses to conduct stealthy, large-scale scanning, brute-force attacks, and exploitation that bypass traditional defenses such as IP reputation and blocklists.
To counter this, Palo Alto Networks is introducing a new preventative solution, Advanced IP Defense, with three powerful new capabilities:
The transition to the Frontier AI era isn't a distant future. It’s happening right now. The organizations that thrive won't be those trying to run old, reactive playbooks faster; they have to scale their defenses to match a whole new velocity of risk. When threats occur at machine speed, relying on human-scale operations is no longer an option. That is why AI and automation are becoming essential tools to meet these challenges head-on.
Varinder Singh
CIO, NXP Semiconductors
When threats execute in minutes, human-only operations become a bottleneck. To reduce fatigue and accelerate response, we’re launching an elite suite of AI agents for every major role a network administrator performs.
These six specialized AI-powered Network Security Agents, available through Strata Cloud Manager, are trained on your enterprise context and operational workflows. From onboarding and configuration to threat assessment and troubleshooting, they automate the hundreds of routine, repetitive tasks that consume an admin’s day. And you stay in control: for each workflow, you choose the level of oversight that matches your risk tolerance — human-in-the-loop, human-on-the-loop, or human-out-of-the-loop.
Securing the modern enterprise means extending these AI-powered capabilities across every surface, from data center cores to remote industrial sites, and from custom AI applications to the web browser.
Today we’re introducing PAN-OS Ceres 12.2, which, in addition to the innovations above, expands our platform across five more areas:
![]()
We are investing heavily in the innovations you need to defeat today’s threats while future-proofing your enterprise for tomorrow.
The transition to the Frontier AI era demands a bold strategy. The winners will be the organizations that adopt a prevention-first architecture capable of stopping threats long before weaponization occurs. With PAN-OS Ceres 12.2, Palo Alto Networks is giving defenders the speed, scale, and platform foundation to turn the tables on modern adversaries.
Forward-Looking Statements
This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. Any unreleased services or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.
Sources:
1 https://www.nokia.com/artificial-intelligence/explainer-network-traffic-is-fundamentally-changing-in-the-ai-supercycle/
2 According to the Verizon 2024 Data Breach Investigations Report
Join Palo Alto Networks virtual InterSECt 2026 event on Aug. 19–20
to see PAN-OS 12.2 Ceres and learn how to preempt AI-driven network attacks.
Secure your spot
Explore our leading Frontier AI Ecosystem and essential resources
Learn more
4,000 projects. 14,000 previously unknown vulnerabilities. Two months. Read Unit 42's latest research on why defenders must prepare for a dramatically faster threat landscape.
Read the report
The post Redefining Network Security for the Frontier AI Era appeared first on Palo Alto Networks Blog.

Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. Fulfilling that mission demands that we continually ensure our customers’ trust and instill confidence in our commitments.
In continuing to elevate global data trust, we have obtained both the Global Cross-Border Privacy Rules (CBPR) Certification and the Global Privacy Recognition for Processors (PRP) Certification.
These systems were originally established under the Asia-Pacific Economic Cooperation (APEC) Privacy Framework and expanded by the Global CBPR Forum. Through independent third-party audits, these globally recognized credentials validate that our data privacy practices meet rigorous international privacy standards.
These milestones join our existing portfolio of privacy and security certifications, reinforcing our ongoing commitment to responsible, accountable cross-border data protection.
To learn more, see the following resources:
The post Palo Alto Networks Achieves Global CBPR and PRP Certifications appeared first on Palo Alto Networks Blog.

This month, we celebrate 36 years of EFF and a mission that is bigger than any one of us. Thanks to EFF, communities around the world are demanding that technology protects their freedom, advances justice, and opens doors to opportunity. That's not a small thing—it's a life's work worth continuing.
If you are committed to staying on the cutting edge of digital rights issues, I'd like to invite you to consider taking that commitment one step further by joining EFF’s Lighthouse Society, our way to acknowledge and thank the community of supporters who are including EFF in their legacy plans.
Learn About the Lighthouse Society
By including EFF in your will or estate plans, you can ensure that EFF’s work and values don't just live beyond you; they thrive because of you. A legacy gift is one of the most powerful ways to say: This matters, and I want it to matter long after I'm gone.
Your gift will fuel our mission for generations by protecting freedom, advancing justice, and driving innovation for communities who need it most. There is still so much more to do, so much more to fight for. With your foresight, it can go so much further.
Planned giving is also more flexible than you might realize. A bequest in your will, a simple beneficiary designation, or another estate planning option can all make a profound difference, often without affecting your finances today.
Get in touch and learn more about what's possible with the Lighthouse Society. Reach out to Jocelyn Wicker at majorgifts@eff.org or fill out our online form to share your intention to give. Thank you for considering a legacy that will carry this work forward for years to come.

Every modern enterprise is moving from an organization run by software to one orchestrated by AI, creating a tension between velocity and control. To resolve this tension, organizations require a unified architecture. Today, we are announcing the general availability of the Prisma AIRS AI Gateway, the AI control plane for the enterprise.
Driven by the absolute conviction that an AI Gateway is foundational to the modern AI infrastructure stack, we are bringing AI innovations from the Portkey acquisition to Prisma AIRS just six weeks after closing. You can now scale AI at machine speed without compromising on enterprise-grade security and control.
Our next-generation firewall telemetry reveals that MCP activity climbed from 11% late last year to 41.4% by mid-2026. Monthly AI transaction volume grew twelve-fold over the same six months; some individual sessions moved hundreds of megabytes of enterprise data outbound. The AI footprint you can govern today is the smallest it will ever be.
Some of the most rapid AI adoption is happening with – coding assistants, enterprise agents and copilots.
As this enterprise data leaves when an AI request goes out, it creates a security and governance challenge at an unprecedented scale and speed.
AI adoption rapidly outpaces the security and governance infrastructure meant to secure it:
Faced with this, most leaders either block traffic entirely or stay permissive and promise to govern later. Both approaches fail because they skip the critical step: seeing what agents do at runtime and controlling their actions while they happen.
To scale AI adoption safely, you need a single control plane sitting between every AI interaction and the backend models. Prisma AIRS AI Gateway brings AI governance, identity and runtime controls together in one place. With the AI Gateway, you can:
Prisma AIRS AI Gateway sits inline between every AI interaction, model provider, and agentic interaction (Agent/AI App to LLMs, MCP Tool Calls, and A2A). It acts as a unified LLM, MCP, and A2A Gateway with a single enforcement point for all operational and security controls. Your teams keep using their existing coding assistants, enterprise agents, and copilots, while enforcement moves to the infrastructure layer where the platform team can own it.
Capabilities delivered through this unified control plane are:
Observability
Every request maps to a single unified view: tracking usage, users, projects, token counts, latency and cost so you can retire shadow AI infrastructure immediately.
Governance
Centrally define approved models, tools, and access without touching developer configurations. To drive FinOps and usage management, track every request's cost, tokens, and latency by team or project. Answer cost questions instantly, shut down unsanctioned AI usage, and proactively enforce budgets and rate limits before access is granted.
Coding Assistant Security
Protect credentials, proprietary code and development systems from risky AI actions. The gateway replaces raw provider keys with scoped credentials per user and team.
Operational Controls
Apply data protection, usage limits and policy checks as AI interactions happen. Traffic distributes via a Universal API across providers ensuring quotas are enforced and outages never stall your pipeline.
Agent Identity Security
Establish trusted identities by binding a verifiable, ephemeral identity to agents at execution. The AI Gateway acts as an enforcement point to enable only authenticated agents to make approved calls.
Runtime Security
Powered by Prisma AIRS AI Runtime Security, the gateway inspects every prompt and response inline, stopping source code, secrets and customer data from leaving the network while neutralizing prompt injection attempts aligned with the OWASP LLM Top 10 and OWASP Top 10 for Agentic Applications.
Watch Anand Oswal break down why an AI gateway is foundational to this architecture.
![]()
Prisma AIRS AI Gateway brings AI governance, identity and runtime controls together in one place. Point products filter text strings or route a single API call and they buckle under real enterprise volume.
Most products fail at scale. Prisma AIRS AI Gateway is built on an architecture tested in the most demanding enterprises for their ever evolving AI workloads:
Learn about Prisma AIRS AI Gateway and register for our webinar to see the AI Gateway in action.
Your developers have already adopted their agents. The agentic enterprise is a reality. As the recently named "company to beat" in AI Security Platforms by Gartner, Palo Alto Networks is uniquely positioned to help you. Let’s build it securely, together.
The post Announcing the General Availability of Prisma AIRS AI Gateway appeared first on Palo Alto Networks Blog.

By Yogesh Ranade from Palo Alto Networks, and Senthil Ramakrishnan from AT&T
The digital world is currently navigating a dual-speed revolution. Acceleration of AI and hyperconnectivity is unlocking unprecedented economic value. The silent but rapid progress of quantum computing is fundamentally threatening the cryptographic foundation upon which that value is built.
As leaders in global networking and cybersecurity, Palo Alto Networks and AT&T Business launched Secure Connectivity solutions for Business Customers. We recognize that quantum-readiness is no longer a distant milestone; it is now a strategic imperative. With threatening data longevity and Trust Now, Forge Later targeting digital identities, the risks are already looming.
By integrating Prisma SD-WAN’s cryptographic innovation with AT&T’s global network, Palo Alto Networks and AT&T Business are proud to deliver the Quantum-Resilient SASE Fabric.
For over 30 years, the difficulty of mathematics has been our primary defense. Classical algorithms, like RSA and Diffie-Hellman, provided the shield for our global economy because they were computationally impossible for classical machines to solve. However, quantum computing fundamentally changes this landscape by providing an exponential speed-up. By leveraging Shor’s Algorithm, quantum computers can break these classical cryptographic foundations, turning a decryption process that would take a classic supercomputer millennia into a task of mere hours.
Palo Alto Networks is embedding Post-Quantum Cryptography (PQC) as a native pillar of the Prisma SASE fabric. We are moving beyond the forklift-upgrade model to a software-defined, standards-based foundation, which is built on strict separation of management and data plane components:
From the perspective of a global leader like AT&T, PQC is an operational mandate. Providing connectivity to the world’s most regulated industries means that security cannot be bolted on. Security must be an inherent property of the transport layer and the connectivity infrastructure itself.
Managing a global footprint that spans across 5G, fiber, and legacy underlays requires an institutional expertise that few can match. For AT&T, the move to a more secure quantum-ready fabric with Dynamic Defense is about providing security where it matters most: the network. Our customers shouldn't have to worry about whether their data is traveling over an MPLS circuit or the public internet.
Through this collaboration, AT&T expands the delivery of Dynamic Defense:
The true value of this relationship lies in the synergy between the network and the security stack. By combining our strengths, we have built a solution that is significantly more resilient than the sum of its parts.
Through Service Provider Interconnect (SPI), Palo Alto Networks' security platforms natively integrate with AT&T’s private network core to deliver a seamless quantum-safe on-ramp. This means business traffic can connect directly to a secure AT&T network without having to build slow, complex software tunnels over the public internet, preserving high performance while delivering next-generation encryption. Historically, high-level encryption meant a "performance tax" on latency and throughput. Our combined architecture allows quantum-safe traffic to flow over AT&T’s network backbone, enabling organizations to modernize their security without sacrificing the user experience.
In today’s highly distributed business landscape, the traditional corporate "headquarters" is no longer the center of gravity. The network perimeter has shifted to the branch (decentralized edge locations like retail storefronts, remote clinics, regional bank offices, and warehouse hubs) and the individual 5G-connected devices employees use. Securing these remote, local edge points is critical because they represent the primary gateway where sensitive company data first enters the network.
By utilizing AT&T’s leadership in WAN, 5G and cellular technologies, we leverage Hybrid Public Key Infrastructure (PKI) to secure these edge locations. Hybrid PKI is a digital identity framework that issues dual security credentials to every device: one "classical" identity to ensure compatibility with existing networks today, and one "quantum-resistant" identity. This double-verification guarantees that a cellular-connected remote branch or a mobile site is just as immune to quantum decryption or identity spoofing as a fortified corporate data center.
The transition to a quantum-ready future is a marathon, not a sprint, and the first steps must be taken now. Palo Alto Networks and AT&T Business are offering a clear, practical path to quantum resilience.
We are delivering more than a simple software update as we prepare customers for the next generation of digital commerce. Together, we are designing our network to help ensure the data of today remains protected against the threats of tomorrow, securing the digital integrity of every enterprise we serve.
As we redefine the boundaries of security in connectivity, we invite you to join us in helping secure your organization’s digital future. Contact your or Palo Alto Networks account representative today to begin a strategic Quantum-Readiness Assessment and experience the power of the Quantum-Resilient SASE Fabric.
The post Palo Alto Networks and AT&T - Delivering Quantum-Resilient SASE Fabric appeared first on Palo Alto Networks Blog.



The White House Executive Order on securing the nation against advanced cryptographic attacks accelerates the mandatory timeline for post-quantum readiness.
For years, post-quantum cryptography has been discussed as an important, yet abstract future technical migration. Because of the uncertain timeline for quantum computing, it has been difficult for most organizations to prioritize quantum readiness against more immediate security demands.
That is changing.
Signed on June 22, 2026, the Executive Order mandates the transition of federal information systems to post-quantum cryptography and establishes a national policy to migrate them to NIST-approved standards. It also extends the urgency beyond government by directing support for critical infrastructure owners and operators, advancing requirements for federal contractors, and calling for cryptographic bill of materials guidance.
The order directly addresses harvest now, decrypt later risk and sets transition milestones for federal high-value assets and high-impact systems: 2030 for key establishment and 2031 for digital signatures.
While the order directly applies to U.S. Federal civilian agencies, it should be seen as a signal of broader policy and procurement momentum. Organizations that do business with the government, support critical infrastructure, or operate in regulated industries such as energy, financial services, and healthcare should expect post-quantum readiness expectations to accelerate.
Quantum risk has shifted from a long-term research concern to a national cybersecurity priority tied to sensitive data, critical infrastructure, federal systems, procurement, and the broader digital economy. For security teams, the challenge now is turning that urgency into an operational plan.
As quantum computing advances, widely used public-key cryptography will become vulnerable to future attacks. Even before a cryptographically relevant quantum computer exists, adversaries can capture encrypted data now with the goal of decrypting it later.
This “harvest now, decrypt later” risk is especially concerning for organizations that protect sensitive information with a long shelf life. The response cannot wait until the threat fully materializes.
The broader ripple effect matters because compliance alone will not equal readiness. As requirements flow into federal acquisition rules and contractor obligations, the vendor ecosystem will be pushed to support quantum-safe capabilities in the products and services that enterprises, critical infrastructure organizations, and regulated industries rely on.
Adding support for post-quantum algorithms is not the same as safely migrating to them. Support means a system can use new algorithms. Readiness means the organization knows where cryptography exists, which systems are exposed, which dependencies matter most, and how to execute changes without creating disruption or new risk.
That matters because post-quantum migration can affect more than cryptographic libraries. Larger cryptographic objects, new protocol behaviors, hybrid modes, hardware acceleration requirements, interoperability constraints, and legacy system limitations can create real performance, availability, and compatibility challenges if changes are made blindly.
This is why cryptographic visibility must lead to actionable migration planning.
Security teams cannot migrate what they cannot see. But visibility by itself is not enough. They also need to classify exposure, prioritize high-value systems and long-lived data, understand operational dependencies, and plan changes in a way that avoids disruption, downgrade risk, or incomplete migration.
Cryptographic bill of materials guidance will be an important step toward mapping cryptographic assets. But a CBOM should be the starting point, not the finish line. An inventory can show where cryptography exists, but readiness requires understanding business impact, migration complexity, interoperability risk, ownership, and the order in which changes should happen.
Post-quantum readiness is not just an algorithm swap. It is an operating model for managing cryptographic change at scale.
The path forward starts with five practical actions.
These actions help security leaders move from awareness to readiness.
The Cryptographic Reset is already underway, driven by post-quantum risk, shorter certificate lifecycles, machine identity growth, fragmented cryptographic ownership, CA distrust events, and expanding digital infrastructure.
The organizations that move first will not simply be the ones that adopt new algorithms the fastest. They will be the ones that build the visibility, operating model, and governance needed to manage cryptographic change continuously.
Read the guide: The Post-Quantum Readiness Race Is On: Five Actions Security Leaders Can Take to Accelerate Crypto Agility.
The post New Executive Order Accelerates Post-Quantum Readiness Amid the Cryptographic Reset appeared first on Palo Alto Networks Blog.

Securing the Future of Japan’s AI Landscape
The shift from static LLMs to autonomous agents has fundamentally changed the global threat surface. Frontier models like Anthropic's Mythos can now autonomously discover hundreds of zero-day vulnerabilities, rapidly shrinking the gap between discovery to exploitation from days to minutes. With the rise of autonomous offensive AI, multi-agent systems like the 'Zealot' proof-of-concept can independently perform reconnaissance, escalate privileges, and exfiltrate cloud data.
Prisma AIRS 3.0 is a comprehensive AI security platform that secures the new AI estate end-to-end: scanning models, agents, and artifacts before deployment, protecting runtime behavior, and enforcing unified control through posture management.To secure this new AI estate against these advanced global threats, Palo Alto Networks is pleased to announce a strategic investment designed to enhance cyber resilience: the establishment of our new local cloud location for Prisma® AIRS™ in Japan. This localized presence simplifies complex operations, enabling local data residency and low-latency processing to accelerate the secure adoption of Generative AI and Agentic Workflows.
Comprehensive Agent Security Platform The new regional expansion in Japan hosting Prisma AIRS provides Japanese organizations with domestic, high-performance access to critical AI security capabilities. As we progressively roll out our full suite of features in the region, Prisma Airs is designed to be a comprehensive AI security platform that secures an organization's entire AI ecosystem including AI applications, models, agents, and datasets, from the development phase all the way through active deployment.
Please visit the regional cloud locations of Palo Alto Networks for more information. This infrastructure optimizes operational efficiency and provides the essential security foundation for large-scale Digital Transformation (DX) projects, empowering Japanese enterprises to innovate with confidence and Deploy Bravely.
![]()
The post Expanding Our Footprint: Local Cloud Availability for Prisma AIRS in Japan appeared first on Palo Alto Networks Blog.


The rise of Agentic AI is rapidly reshaping the enterprise, yet its deployment opens a complex new frontier for cyber threats. As organizations race to harness the power of enterprise agents, the "Data Estate" has become the new perimeter. CISOs today face a high-stakes trade-off: enabling developers to build at the speed of AI while keeping proprietary data visible, governed, and secure across the entire AI lifecycle. This requires meticulously checking user inputs, agent outputs, and tool calls for threats like prompt injections, sensitive data loss, and malicious code, while simultaneously preventing autonomous agents from performing destructive actions.
Securing the AI-driven enterprise requires a fundamental shift from reactive measures to proactive runtime protection. Palo Alto Networks and Databricks are delivering on that vision. Our partnership will integrate the Prisma AIRS API with Databricks Unity AI Gateway, embedding seamless security at runtime. This collaboration will enable organizations to innovate with AI agents, applications, models and MCP Servers at scale while maintaining a robust, policy-driven security posture. By combining the centralized AI governance and control capabilities of the Databricks platform with the runtime security protections of Palo Alto Networks, organizations can scale AI innovation without sacrificing visibility, compliance, or security.
AI security represents a fundamental departure from traditional defense. Legacy tools are designed for structured threats, leaving them incapable of parsing the intent behind complex, conversational attacks. Furthermore, the integration of Retrieval-Augmented Generation (RAG) and autonomous workflows creates a dynamic attack surface that goes far beyond traditional data loss. Without AI-native oversight, organizations can face severe risks from prompt injections, custom topics, and toxic content manipulating model logic, to tool misuse, malware execution, and malicious URLs hijacking agent actions.
Modern AI development requires more than just a perimeter; it requires contextual intelligence. By integrating Prisma AIRS directly into Databricks Unity AI Gateway, we will evolve security from a reactive layer into a native pillar of the AI architecture.
The most effective way to secure an entire AI environment is at the governance layer. Our integration focuses on Databricks Unity AI Gateway, which serves as the centralized interface for all AI activity within the Databricks environment. Unity AI Gateway is designed for managing, governing, and monitoring access to all models, agents and MCP Servers—whether they are open-source models deployed within Databricks or external proprietary models. As organizations deploy more agents, applications, and models, centralized governance becomes critical. Unity AI Gateway provides a single control plane for AI usage, enabling teams to apply consistent policies, monitor activity, and manage access across AI workloads.
Through this integration, Unity AI Gateway will make real-time calls to the Prisma AIRS Runtime Security API for security inspection. Instead of managing fragmented security policies across dozens of individual applications, SecOps teams will be able to enforce consistent guardrails across the entire Agentic AI estate from one location, providing a single, unified enforcement point for all AI workloads.
![]()
Prisma AIRS operates as an advanced inspection layer, leveraging its API Intercept capability to provide real-time security embedded directly into the application flow. By embedding Prisma AIRS directly into the workflow, we offer a seamless 'Security-as-Code' experience that unifies development and defense. Prisma AIRS intercepts AI prompts, responses, and MCP calls—inspecting them in real time to enforce security policies with an immediate Go/No-Go verdict or by sanitizing the data in transit. Prisma AIRS uses deep learning classifiers to detect data exfiltration risks, such as the presence of PII (Personally Identifiable Information), PHI, or PCI data. If sensitive data is found, it can be dynamically redacted or blocked based on corporate policy.
This integration isn't just about blocking threats—it’s about accelerating your AI roadmap. By removing the "security friction" that often slows down production deployments, we enable teams to move faster with confidence. Key benefits include:
As agentic workflows and multi-step model interactions become the standard, a 'fail-closed' runtime security posture is no longer optional; it is foundational. The integration of Prisma AIRS API and Databricks Unity AI Gateway marks a definitive shift toward a future where enterprise AI is secure by default. By integrating Prisma AIRS API with the Databricks platform through Unity AI Gateway, organizations can centrally govern AI across models, agents, applications, and MCP servers while enforcing consistent runtime security policies. Together, Databricks and Palo Alto Networks are helping customers scale AI innovation with the control, visibility, and protection required for the agentic era.
Are you ready to secure your AI workloads and agentic applications?
check out the latest Databricks blog and stay tuned for technical deep-dive sessions coming soon.
Forward-Looking Statements
This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov. All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.
The post Securing the Agentic AI Frontier: Palo Alto Networks and Databricks Deliver a New Standard for AI Security appeared first on Palo Alto Networks Blog.

After 26 years, today is my last day at EFF. It's been a terrific and wild ride — the organization has grown from a tiny band of fighty people trying to plant a flag for freedom and justice in the coming digital world into a large, established band of fighty people doing, well, much the same. The world around us has changed enormously. Our core values haven't budged.
![]()
I'm proud of what we've achieved: freeing encryption, defending coders, pushing to rein in government and corporate surveillance and ensure the right to have a private conversation online, standing up for free speech and anonymous speech, fighting for network neutrality and safe voting machines, busting stupid patents, and making sure copyright didn't become the one law that rules the internet. That's only the start. We've stopped more bad legislative, regulatory, and legal ideas than I can count, built tools that millions rely on to protect their privacy, and helped encrypt the web. I've long said EFF is the plumber of the internet — finding the clogs and barriers that prevent technology from serving freedom, justice, and innovation for everyone.
In addition to presenting cases in courts across the land, testifying in Congress and in California, in the European Parliament and at the United Nations, I went onto the internet with Stephen Colbert and engaged in a healthy disagreement with Jon Stewart. I wrote a lot of it down in a book, hoping to recruit others to the cause. The work has been hard and often frustrating at times. But looking back, the fun parts are what I remember most.
None of it would have been possible without EFF’s stalwart members. More than 30,000 people, some with big wallets and some with small ones, give us what we need to stand up to bullies and fight for the long haul. EFF has always served as a beacon for people who know that for technology to support freedom, justice, and innovation for all the people of the world, we need a dedicated band of folks working overtime on behalf of users, innovators, and creators.
There's still plenty left to do. We haven't killed the third-party doctrine, tamed the surveillance business model, or gotten metadata the constitutional protection it deserves. Stupid patents persist as does the overreach of DMCA section 1201 and the Computer Fraud and Abuse Act. The government is now the largest purchaser of data from shady brokers, communities everywhere are fighting license plate readers and other street-level surveillance, and we haven't reined in NSA and FBI spying nearly enough. Meanwhile, the rise of AI is supercharging problems we've fought against for years.
But I'm proud of what we've built together. I'm grateful to every EFFer — past, present, and future — who threw in with us when the odds were long and the pay was much better elsewhere. I'm grateful to the EFF Board and especially to my mentors and friends Pam Samuelson and Shari Steele, along with my longtime partner in justice, Lee Tien, who has been working with me since the Bernstein case. Fighting for justice is easier when you have a posse: coworkers, co-counsel, coalitions, interns, volunteers, and the heroic clients who trusted us to steward their cases in ways that bent the law toward everyone's benefit. Twenty-six years later, EFF is part of a global diaspora of organizations defending internet freedom — and I'm proud of that too.
I'm stepping down because good leaders should make way for new ones, and the time feels right. EFF is strong and full of fight. My successor Nicole Ozer — a longtime friend and collaborator — is exactly the right person for this moment. She understands EFF's role and values at a deep level and will protect them while helping the organization rise to meet what's coming.
As for me, I'm not going far. After a few months off to reflect and walk dogs, I plan to get back into the fight for justice — likely heading back into the courtroom. And I'll be watching, cheering, donating, and wearing the merch from EFF, just like the rest of you.
![]()

Palo Alto Networks is pleased to announce the successful completion of a new Cloud Medium security assessment conducted by the Canadian Centre for Cyber Security (Cyber Centre), significantly expanding the number of Palo Alto Networks cloud services assessed for Protected B / Medium Integrity / Medium Availability (PBMM) environments. This assessment includes a broad range of capabilities across our Cortex®, Cortex Cloud and Strata™ platforms. By achieving this milestone, Palo Alto Networks enables organizations handling Canada’s most sensitive data to leverage a unified, AI-driven security architecture without compromising on compliance or operational resilience.
For years, many organizations viewed PBMM as something that only mattered to the Canadian federal government. It was often seen as a procurement requirement—a framework tied to public sector cloud adoption, relevant for departments handling Protected B information, but not necessarily for the private sector.
That assumption is changing.
The reality is that the challenges driving PBMM are no longer unique to government environments. Banks, energy providers, transportation networks, healthcare organizations, crown corporations, and other critical infrastructure operators are now facing many of the same pressures:
That is why PBMM matters far beyond Ottawa. At its core, PBMM represents a rigorous approach to validating whether enterprise-grade security platforms can operate securely in environments where trust, resilience, and operational continuity are critical.
Increasingly, that level of assurance matters to everyone.
PBMM, a rigorous cybersecurity and data classification standard used by the Canadian Centre for Cyber Security, stands for Protected B / Medium Integrity / Medium Availability. While often associated with federal cloud security requirements, PBMM is not simply a checkbox exercise. It is a comprehensive assessment framework aligned to Canadian cybersecurity guidance and operational security expectations.
What makes PBMM important is that it evaluates whether platforms and services can securely support sensitive and mission-critical workloads in real-world environments.
Palo Alto Networks meeting these rigorous PBMM requirements through three core pillars:
These are not theoretical requirements. They are practical operational expectations designed for environments where downtime, visibility gaps, or security failures can have significant consequences.
Organizations today are no longer evaluating cybersecurity solely based on features. They are evaluating whether platforms can be trusted to support critical operations at scale.
The cybersecurity landscape has evolved dramatically. Infrastructure is distributed across cloud providers, SaaS applications, remote users, third-party integrations, operational technology (OT), AI platforms, and interconnected supply chains. At the same time, attacks have become faster, more automated, and more disruptive.
In this environment, security can no longer be treated as a compliance exercise. Organizations need confidence that their platforms, operational processes, and security controls can function effectively under pressure.
This is why Palo Alto Networks has undertaken independent PBMM assessments across its portfolio, providing customers with greater assurance and trust. By meeting these rigorous standards into Strata and Cortex, we enable non-government entities—like financial institutions and utility providers—to deploy the same defensive rigor used to protect national security systems.
To effectively manage risk, critical infrastructure operators require a platform approach that helps eliminate security silos, reduce manual intervention, and accelerate threat mitigation.
One of the most significant shifts occurring across industries today is the growing focus on operational resilience. Organizations are increasingly asking questions that extend beyond traditional cybersecurity controls:
As organizations adopt cloud-native architectures, AI-driven technologies, and interconnected digital ecosystems, resilience has become a board-level concern. The ability to prevent incidents remains important, but organizations are equally focused on their ability to withstand, respond to, and recover from them.
This is where frameworks like PBMM provide value. Beyond evaluating security controls, PBMM assesses the governance, operational processes, monitoring capabilities, and risk management practices that help organizations operate securely.
For critical infrastructure operators, resilience is no longer simply an IT objective—it is a business imperative. Increasingly, the organizations that earn trust are those that can demonstrate they are prepared to operate effectively when disruption occurs.
PBMM may have started solely as a government assessment framework, but its relevance now extends far beyond federal environments. It represents something universal: the ability to operate securely, reliably, and transparently in environments where trust matters most.
By expanding our PBMM-assessed offerings across Cortex and Strata, Palo Alto Networks underscores its commitment to securing Canada's digital future. We provide the validated foundation organizations need to innovate with confidence, protect sensitive data, and maintain operational continuity under any circumstance.
To learn more about the Palo Alto Networks Cloud Medium security assessment, review the publicly available assessment summary report issued by the Canadian Centre for Cyber Security.
Ready to modernize your defenses with PBMM-assessed solutions? Schedule a demo with our team or contact Unit 42 to learn how we can help elevate your organization's resilience against emerging cyber threats.
The post Securing Canada’s Digital Future: Why PBMM Matters Beyond Government appeared first on Palo Alto Networks Blog.


The release of OMB Memo M-26-14 ("Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats") marks a historic turning point in federal cybersecurity. By officially rescinding the M-21-31 directive, the White House has delivered a clear message to federal IT leaders: the era of compliance-driven data hoarding is officially over.
While the previous framework was a well-intentioned response to the SolarWinds breach, its mandate to collect and retain vast oceans of unstructured logging data created unintended, unsustainable operational burdens. For the past several years, federal agencies have faced skyrocketing cloud storage bills and overwhelmed Security Operations Centers (SOCs). Crucially, they have been left with vast quantities of cold data that lacked clear operational utility.
As OMB noted, retaining endless data without operational focus is neither cost-effective nor operationally feasible. With M-26-14, the federal government is pivoting to a smarter, sleeker, and far more decisive strategy: a risk-based, prioritized logging framework driven by AI and machine-speed defense.
M-26-14 strips away administrative "red tape" to focus on how modern cybersecurity risks have evolved. Nation-state threat actors are actively leveraging advanced automation and Artificial Intelligence (AI) to orchestrate attacks at unprecedented speeds. They move laterally across agencies in minutes, hiding behind legitimate corporate credentials.
To beat machine-speed threats, your data layer must operate at machine-scale. The new memo reorganizes federal visibility around two foundational pillars:
Continuous Event Monitoring demands that logging infrastructure shift from a passive archiving tool to a live-streaming asset. Agencies are now required to monitor network and asset activity in real time, rapidly flag anomalous behavior via behavioral analytics, and initiate immediate mitigation actions directly through their SOCs.
When a compromise is suspected, agencies can no longer spend days running slow database queries or pulling disconnected csv files. M-26-14 mandates that agencies keep 6 months of logs "hot and searchable" and 1 year fully "retrievable." This allows defenders to immediately stitch together cross-domain attack patterns, perform rapid root-cause forensics, and share threat intelligence seamlessly with CISA and the FBI.
Perhaps the most significant structural change is the explicit inclusion of Internet of Things (IoT) and Operational Technology (OT) systems. Adversaries do not respect the boundary between your corporate IT network and your physical infrastructure. Under M-26-14, your logging and threat-hunting capabilities must aggressively cover the entire enterprise—from public cloud workloads to the physical facility controls and critical infrastructure grids running on an agency's behalf.
Agencies cannot afford a passive approach. The timeline established by OMB M-26-14 moves quickly:
Trying to retrofit a legacy SIEM architecture to meet the advanced or optimal effectiveness tiers of M-26-14 is an engineering and budgetary dead end. Legacy SIEMs scale costs linearly with ingestion and rely on static, human-written correlation rules that fail against AI-fueled threats.
The FedRAMP Certified Palo Alto Networks Cortex platform—anchored by Cortex XSIAM (Extended Security Intelligence and Automation Management)—was engineered from the ground up to solve the exact problems this new memo addresses.
Legacy logging stores data in isolated silos. An analyst trying to track an adversary has to manually look at an identity log, cross-reference it with a network firewall alert, and match it to an endpoint execution.
Cortex XSIAM features a revolutionary Analytics Engine that automatically stitches multi-vendor logs across cloud, network, endpoint, and identity at the moment of ingestion. It transforms raw text into a single, cohesive, context-rich story, instantly aligning incidents with the MITRE ATT&CK framework. Cortex XSIAM doesn’t just ingest data, it understands the data which enables stitching of multiple data elements into a single, multi-context construct which accelerates analysis via AI and machine learning.
Adversaries use AI to evade signature detection. Cortex XSIAM fights fire with fire, applying out-of-the-box, unsupervised machine learning models to baseline normal behavioral patterns across your entire federal enterprise. When an anomalous lateral movement, data exfiltration attempt, or credential abuse event occurs, XSIAM flags the threat instantly—without requiring your team to spend weeks writing custom correlation code.
There is more to CEM than just monitoring network activity. Activity on endpoints, within your identity management solution(s) and in the cloud are just as important. Understanding the data, knowing which log records are related to each other across multiple log sources, which events are relevant and the context they provide is required.
Understanding these events and their contextual relationships is fundamental to providing THIRF in an efficient manner. Cortex XSIAM provides over 2,900 machine learning models out of the box, models that are trained on the data in your environment so they detect anomalous activity based on what is “normal” in your environment, not trained on generic data from other customers or a lab. These models can identify threats based on data stitched together from multiple sources to provide a more complete context yielding more accurate and consistent results while decreasing time to value.
You cannot install an EDR logging agent on a smart building HVAC system or an industrial programmable logic controller (PLC). Palo Alto Networks utilizes non-disruptive, passive network analysis to continuously discover, profile, and generate high-fidelity security logs for IoT and OT infrastructure. These logs stream directly into XSIAM, eliminating critical federal blind spots and protecting your High Value Assets (HVAs) from cross-boundary pivot attacks.
Keeping six months of high-velocity event logs fully "hot and searchable" under a traditional database indexing model creates a crushing financial burden. Cortex XSIAM fundamentally resets the Total Cost of Ownership (TCO) equation by leveraging an index-free, cloud-native data lake architecture that decouples storage costs from analytical performance. By eliminating legacy ingestion taxes and infrastructure overhead, federal defenders can search petabytes of data in seconds—effortlessly meeting the 6-month searchable and 1-year retrievable thresholds. Furthermore, integrated data masking rules strip away sensitive PII or low-value data noise before it hits the SOC, ensuring agencies only pay for operationally vital intelligence.
OMB M-26-14 is a massive step forward for federal cybersecurity. It frees CISOs from the operational gridlock of untargeted data archiving and empowers them to build faster, modern, and highly responsive security operations.
Meeting the strict 120-to-320-day maturity milestones requires moving past the tools of the last decade. By partnering with Palo Alto Networks and deploying the Cortex suite, federal agencies can seamlessly transition into a risk-aligned, AI-driven SOC. They can confidently check the box on OMB compliance while achieving what the directive actually intends: protecting the resilience and integrity of the federal mission at machine speed.
Palo Alto Networks’ Cortex XSIAM is FedRAMP certified at both the moderate and high levels.
Want to learn more about how to structure your upcoming Agency Logging Plan to meet CISA's upcoming Logging Reference Architecture?
Contact the Palo Alto Networks Federal Team today to schedule an architectural deep-dive.
The post Shifting from Data Hoarding to Active Defense: Navigating the New Era of OMB M-26-14 appeared first on Palo Alto Networks Blog.

Sovereignty has become the driving principle of Europe's technology conversation. Every policy discussion, every emerging legislative development, every procurement process, every boardroom debate comes back to which platforms and partners to trust.
Trust goes beyond compliance. It demands integrity, accountability, and transparency about the limits of what any provider can guarantee – rather than making commitments that sound reassuring but cannot be verified.
We have spent considerable time listening to public sector organizations, critical national infrastructure operators, and regulators across Europe. This is not a new concern. Over the years, what organizations are asking for has become increasingly specific. They want their data to remain in Europe. They want to know precisely who can access it and who holds the encryption keys. And they want every access event logged and visible. They want operations managed locally, under local jurisdictions and subject to local laws.
These are governance requirements as much as technical ones. And what they add up to is a demand for verifiable control, not more contractual promises. The distinction matters enormously. Telling an organization you will protect their data is one thing; giving them the architecture and the visibility to verify that protection themselves is another.
It is worth being clear about who is driving this conversation. These requirements are not universal. A large enterprise running productivity tools has different needs from a government ministry managing sensitive national data or a critical infrastructure operator running systems that society depends on for clear drinking water. What we are describing here is what we hear from the most demanding end of the spectrum: public sector and critical national infrastructure. And that is where we focus, because getting it right there matters most.
The announcement of the Sovereign Cortex with T Security, together with Deutsche Telekom and Google Cloud, is our direct response to these demands and the next step in our long-standing commitment to Europe. It is not a marketing position – it is a framework that provides customers actual controls. It is built on the five elements that reflect how we fundamentally think about sovereignty. One that will set the standard across every solution we build for the region.
![]()
Each element of this framework was designed from the outside in, with the input of every European organization we collaborated with.
Here is what I believe, having spent years in this conversation across Europe. Trust is not something a provider can simply assert. It is something that has to be earned, over time, through consistent and verifiable action.
For technology companies operating in Europe, that means placing meaningful control with a trusted local European partner, being transparent about what we can and cannot guarantee, and treating sovereignty not as a compliance exercise but as a design principle.
It also means being honest about the journey. We have done significant work, yet we have further to go. The organizations we serve deserve partners who acknowledge that openly rather than presenting a finished picture.
What drives this work is straightforward: we believe in Europe’s digital future. We believe in the missions of the organizations we work with every day, whether they are protecting critical public services, securing national infrastructure, or safeguarding the data that citizens and institutions depend on. Being a committed partner to those organizations is not a product decision. It is a values decision.
And that is precisely why trust is the measure we hold ourselves to. The direction is clear, the commitment is real. But commitment means nothing without trust – and trust, like everything worth having, has to be earned every day.
Forward-Looking Statements
This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov. All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.
The post Trust is the Foundation of Sovereignty appeared first on Palo Alto Networks Blog.

EFF is on the front lines of the fight against tech-enabled tyranny, but we aren't alone. Our team depends on your help to fight back against the surveillance state.
People around the world are pushing back against the mass surveillance that undermines privacy and free expression for everyone. You can help during EFF's spring membership drive.
One of the people who joined the fight for digital rights is EFF client Will Freeman. Will created the website DeFlock.me to reveal the dangers of automated license plate readers (ALPRs)—cameras that collect location data on every vehicle they see and upload that to a massive nationwide police database. Deflock.me turns the tables by enlisting ordinary people to track the locations of tens of thousands of ALPR cameras.
But when the police spy-tech company Flock Safety went after Will's website with legal threats citing trademark law, he saw it for what it was: an attempt to silence critics and dim the light on mass surveillance.
The company will try everything it can to downplay the criticism, but EFF will be right there demanding accountability.
"I was totally unprepared to receive a cease & desist letter. I can see how most people would be bullied into submission by a threat like that. That's when I remembered Dave Maass from the EFF introduced himself via email several weeks before, so I reached out for help," Freeman says.
And that's when EFF stepped in. Recognizing DeFlock.me as a quintessential expression of grassroots advocacy and a form of criticism protected by the U.S. First Amendment, EFF's lawyers helped Will fight back. And the Big Surveillance Tech flinched.
But these battles against Flock's Spying tools rage on. In cities around the country, privacy advocates are pressuring officials to block or end contracts for ALPRs—and winning. The company will try everything it can to downplay the criticism, but EFF will be right there demanding accountability.
"I'm really grateful the EFF was able to step in and help. Without them, free speech would be only for those wealthy enough to defend themselves against billion dollar companies. We've grown a lot since then and are expanding our efforts to expose and push back against mass surveillance on our streets," Freeman says.
stop mass surveillance tech today when you join EFF
____________________
EFF is a member-supported U.S. 501(c)(3) organization. We've received top ratings from the nonprofit watchdog Charity Navigator since 2013! Your donation is tax-deductible as allowed by law.

Building on the momentum of NVIDIA GTC Taipei at COMPUTEX 2026, the conversation has moved beyond AI experimentation to the industrialization of intelligence. Organizations are rapidly deploying AI Factories – high-performance, purpose-built computing infrastructures designed to manufacture intelligence at an unprecedented scale. AI’s next phase is agentic. Autonomous AI agents are reshaping enterprise operations—and demand security architectures that can keep pace with the speed and scale of innovation. We are proud to announce the integration of Palo Alto Networks Cortex XSIAM with the NVIDIA DOCA Argus framework, a breakthrough that brings real-time, AI-powered security operations directly into the heart of the NVIDIA AI factory.
By operating on the NVIDIA BlueField data processor, DOCA Argus provides situational awareness through real-time memory analysis at the silicon level. This allows Cortex XSIAM to detect kernel-level rootkits and "living-off-the-land" attacks without installing security agents on the host system.
This innovation builds upon our proven foundation with Palo Alto Networks Prisma AIRS, where AI Runtime Security is deployed natively on NVIDIA BlueField, and powered by NVIDIA DOCA, bringing defense in depth. This integration enables offload , isolation and acceleration of security in AI factories.
Deployed consistently across the AI factory, DOCA Argus monitors and correlates AI application processes, network telemetry, and data access to detect sophisticated anomalies that traditional tools miss. With this integration, Cortex XSIAM recognizes the high-fidelity data from DOCA Argus as a native Palo Alto Networks sensor, allowing for better decisions with the new intelligence gathered directly from the host.
By integrating Cortex XSIAM with the NVIDIA DOCA Argus framework, we leverage the innovations of two industry leaders to deliver a seamless, high-performance SecOps ecosystem for your most valuable AI assets.
![]()
The inclusion of Prisma AIRS in NVIDIA AI Factory validated design delivers a unified security platform, providing proactive, defense-in-depth security across critical layers of the AI ecosystem.
Serving as the network enforcement engine for this architecture, Prisma AIRS secures the infrastructure of the modern AI Factory. By unifying protection and visibility into a single automated fabric, it eliminates the traditional trade-off between security and agility, allowing organizations to innovate at machine speed without compromising performance or governance.
Beyond enforcement, the broader Prisma AIRS platform acts as the security blueprint for the entire enterprise AI ecosystem—consolidating fragmented point-tools to slash total cost of ownership while providing end-to-end observability from the data plane to the model layer. The platform scales dynamically alongside your AI clusters to safeguard raw datasets, build Layer 7 micro-perimeters around autonomous agents, and protect proprietary model weights from external threats—all without throttling mission-critical performance.
By deploying the AI Runtime Firewall directly on NVIDIA BlueField, we establish a foundational network security layer that is fully offloaded, isolated, and accelerated. This provides pervasive protection across the Enterprise AI Factory without sacrificing critical compute resources.
Securing the NVIDIA AI factory requires the entire Prisma AIRS suite, which secures the AI lifecycle through five specialized pillars:
Looking ahead to the next frontier of enterprise-scale agentic AI, Palo Alto Networks is closely aligning its platform approach with the NVIDIA Vera BlueField-4 STX architecture, extending protections to AI data storage infrastructure. As AI data demands surge, high-throughput, large-scale environments require a move toward hardware-isolated, performance-neutral protection to support the rapid growth of critical AI applications.
Operating within an isolated trust domain on future BlueField-4 silicon, our inline security capabilities will maintain strict, policy-driven controls independently of the host operating system and storage systems. This co-design enables critical forward-looking innovations for data, agents, and context memory, ensuring security is offloaded, isolated and accelerated to support the next generation of the AI Factory.
![]()
Our ongoing collaboration with NVIDIA focuses on these essential pillars for reimagining AI security:
The Palo Alto Networks platform approach delivers a comprehensive solution to secure an enterprise's entire AI ecosystem. By integrating Cortex XSIAM with the NVIDIA DOCA Argus framework, we are extending this comprehensive, deep visibility and protection to the very heart of the AI Factory. With this integration, security teams can leverage an agentless approach via DOCA Argus to gain deep visibility into AI systems hosts by simply downloading the content pack from the Cortex Marketplace.
The Palo Alto Networks platform secures the entire AI journey, protecting the infrastructure, intelligent applications, agents and data it produces. With the inclusion of Prisma AIRS in NVIDIA Enterprise AI Factory Validated Design, we have delivered the blueprint for secure AI.
Palo Alto Networks and NVIDIA are redefining security for the AI factory. Together, we are ensuring your security architecture is as fast, scalable and innovative as the intelligence it protects, empowering you to scale AI production with reduced latency and stronger governance.
Discover more through the Palo Alto Networks partner directory, or read the official press release from NVIDIA for more details.
The post Reinventing Security for the Agentic NVIDIA AI Factory appeared first on Palo Alto Networks Blog.

