Normal view

Palo Alto Networks Achieves Global CBPR and PRP Certifications

28 July 2026 at 21:05

Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. Fulfilling that mission demands that we continually ensure our customers’ trust and instill confidence in our commitments.

In continuing to elevate global data trust, we have obtained both the Global Cross-Border Privacy Rules (CBPR) Certification and the Global Privacy Recognition for Processors (PRP) Certification.

These systems were originally established under the Asia-Pacific Economic Cooperation (APEC) Privacy Framework and expanded by the Global CBPR Forum. Through independent third-party audits, these globally recognized credentials validate that our data privacy practices meet rigorous international privacy standards.

These milestones join our existing portfolio of privacy and security certifications, reinforcing our ongoing commitment to responsible, accountable cross-border data protection.

To learn more, see the following resources:

The post Palo Alto Networks Achieves Global CBPR and PRP Certifications appeared first on Palo Alto Networks Blog.

Your Vision. Your Legacy. Your Future.

17 July 2026 at 18:44

This month, we celebrate 36 years of EFF and a mission that is bigger than any one of us. Thanks to EFF, communities around the world are demanding that technology protects their freedom, advances justice, and opens doors to opportunity. That's not a small thing—it's a life's work worth continuing.

If you are committed to staying on the cutting edge of digital rights issues, I'd like to invite you to consider taking that commitment one step further by joining EFF’s Lighthouse Society, our way to acknowledge and thank the community of supporters who are including EFF in their legacy plans.

Learn About the Lighthouse Society

By including EFF in your will or estate plans, you can ensure that EFF’s work and values don't just live beyond you; they thrive because of you. A legacy gift is one of the most powerful ways to say: This matters, and I want it to matter long after I'm gone.

Your gift will fuel our mission for generations by protecting freedom, advancing justice, and driving innovation for communities who need it most. There is still so much more to do, so much more to fight for. With your foresight, it can go so much further.

Planned giving is also more flexible than you might realize. A bequest in your will, a simple beneficiary designation, or another estate planning option can all make a profound difference, often without affecting your finances today.

Get in touch and learn more about what's possible with the Lighthouse Society. Reach out to Jocelyn Wicker at majorgifts@eff.org or fill out our online form to share your intention to give. Thank you for considering a legacy that will carry this work forward for years to come.

Announcing the General Availability of Prisma AIRS AI Gateway

16 July 2026 at 16:50

Every modern enterprise is moving from an organization run by software to one orchestrated by AI, creating a tension between velocity and control. To resolve this tension, organizations require a unified architecture. Today, we are announcing the general availability of the Prisma AIRS AI Gateway, the AI control plane for the enterprise. 

Driven by the absolute conviction that an AI Gateway is foundational to the modern AI infrastructure stack, we are bringing AI innovations from the Portkey acquisition to Prisma AIRS just six weeks after closing. You can now scale AI at machine speed without compromising on enterprise-grade security and control.

Your AI Footprint is Outpacing Controls

Our next-generation firewall telemetry reveals that MCP activity climbed from 11% late last year to 41.4% by mid-2026. Monthly AI transaction volume grew twelve-fold over the same six months; some individual sessions moved hundreds of megabytes of enterprise data outbound. The AI footprint you can govern today is the smallest it will ever be.

Some of the most rapid AI adoption is happening with – coding assistants, enterprise agents and copilots.

  • Coding agents access code repositories, file systems, configurations, and credentials. When this context, including source code and secrets, is sent to a frontier model, it risks exposing sensitive data, and a runaway loop could burn a fortune in tokens overnight.
  • Enterprise agents run with broad access and standing privileges sharing context with each other. A single agent stretched beyond its scope can massively increase the risk of data breach, impact business reputation and customer trust.
  • Copilots now sit inside the SaaS and productivity tools employees already use. Copilots with broad access can surface data an employee was never meant to see.

As this enterprise data leaves when an AI request goes out, it creates a security and governance challenge at an unprecedented scale and speed.

What breaks when every team adopts AI 

AI adoption rapidly outpaces the security and governance infrastructure meant to secure it:

  • Shadow AI (Cost and usage are both hidden): You can't see the AI your teams already use or what it costs. 
  • Data Exposure (Sensitive data leaves without a trace): AI interactions can expose sensitive data, bypass policy and trigger unsafe outputs.
  • Agents Overstep (Actions run without accountability): Agents act across systems without clear identity, permission, or accountability. Keys get shared and agents run with broad, standing privileges, so no one can say which identity authorized a specific action or reverse it when an agent takes a wrong turn at machine speed.

Faced with this, most leaders either block traffic entirely or stay permissive and promise to govern later. Both approaches fail because they skip the critical step: seeing what agents do at runtime and controlling their actions while they happen.

Accelerate AI Adoption with Control

To scale AI adoption safely, you need a single control plane sitting between every AI interaction and the backend models. Prisma AIRS AI Gateway brings AI governance, identity and runtime controls together in one place. With the AI Gateway, you can:

  • Discover AI usage: Know exactly which apps, models, users, teams and agents are active, what they are accessing, and what they cost in a single unified view.
  • Govern AI interactions: Enforce central rules for model access, tool use and budgets while inspecting prompts and responses inline to prevent data leaks.
  • Secure every agent: Verify agent identities and enforce just-in-time, least-privilege access so autonomous systems only touch what they need, when they need it.

How the AI Gateway works 

Prisma AIRS AI Gateway sits inline between every AI interaction, model provider, and agentic interaction (Agent/AI App to LLMs, MCP Tool Calls, and A2A). It acts as a unified LLM, MCP, and A2A Gateway with a single enforcement point for all operational and security controls. Your teams keep using their existing coding assistants, enterprise agents, and copilots, while enforcement moves to the infrastructure layer where the platform team can own it.

Capabilities delivered through this unified control plane are:

Observability

Every request maps to a single unified view: tracking usage, users, projects, token counts, latency and cost so you can retire shadow AI infrastructure immediately.

Governance

Centrally define approved models, tools, and access without touching developer configurations. To drive FinOps and usage management, track every request's cost, tokens, and latency by team or project. Answer cost questions instantly, shut down unsanctioned AI usage, and proactively enforce budgets and rate limits before access is granted.

Coding Assistant Security

Protect credentials, proprietary code and development systems from risky AI actions. The gateway replaces raw provider keys with scoped credentials per user and team.

Operational Controls

Apply data protection, usage limits and policy checks as AI interactions happen. Traffic distributes via a Universal API across providers ensuring quotas are enforced and outages never stall your pipeline.

Agent Identity Security

Establish trusted identities by binding a verifiable, ephemeral identity to agents at execution. The AI Gateway acts as an enforcement point to enable only authenticated agents to make approved calls.

Runtime Security 

Powered by Prisma AIRS AI Runtime Security, the gateway inspects every prompt and response inline, stopping source code, secrets and customer data from leaving the network while neutralizing prompt injection attempts aligned with the OWASP LLM Top 10 and OWASP Top 10 for Agentic Applications.

Watch Anand Oswal break down why an AI gateway is foundational to this architecture.

the ai control plane of every enterprise

The AI Control Plane for the Enterprise

Prisma AIRS AI Gateway brings AI governance, identity and runtime controls together in one place. Point products filter text strings or route a single API call and they buckle under real enterprise volume.
Most products fail at scale. Prisma AIRS AI Gateway is built on an architecture tested in the most demanding enterprises for their ever evolving AI workloads: 

  • 68 Trillion+ tokens processed in the last month alone.
  • Sub-millisecond routing latency and inline inspection secures AI interactions without degrading user experience.
  • 99.999% availability helps ensure your AI operational pipeline does not experience a single point of failure.

Learn about Prisma AIRS AI Gateway and register for our webinar to see the AI Gateway in action. 

Your developers have already adopted their agents. The agentic enterprise is a reality. As the recently named "company to beat" in AI Security Platforms by Gartner, Palo Alto Networks is uniquely positioned to help you. Let’s build it securely, together.

The post Announcing the General Availability of Prisma AIRS AI Gateway appeared first on Palo Alto Networks Blog.

Palo Alto Networks and AT&T - Delivering Quantum-Resilient SASE Fabric

16 July 2026 at 16:00

By Yogesh Ranade from Palo Alto Networks, and Senthil Ramakrishnan from AT&T

The digital world is currently navigating a dual-speed revolution. Acceleration of AI and hyperconnectivity is unlocking unprecedented economic value. The silent but rapid progress of quantum computing is fundamentally threatening the cryptographic foundation upon which that value is built.

As leaders in global networking and cybersecurity, Palo Alto Networks and AT&T Business launched Secure Connectivity solutions for Business Customers. We recognize that quantum-readiness is no longer a distant milestone; it is now a strategic imperative. With threatening data longevity and Trust Now, Forge Later targeting digital identities, the risks are already looming. 

By integrating Prisma SD-WAN’s cryptographic innovation with AT&T’s global network, Palo Alto Networks and AT&T Business are proud to deliver the Quantum-Resilient SASE Fabric.

The Quantum Shift Towards Building Resilience for Tomorrow’s Reality

For over 30 years, the difficulty of mathematics has been our primary defense. Classical algorithms, like RSA and Diffie-Hellman, provided the shield for our global economy because they were computationally impossible for classical machines to solve. However, quantum computing fundamentally changes this landscape by providing an exponential speed-up. By leveraging Shor’s Algorithm, quantum computers can break these classical cryptographic foundations, turning a decryption process that would take a classic supercomputer millennia into a task of mere hours.

Neutralizing the Quantum Crisis

Palo Alto Networks is embedding Post-Quantum Cryptography (PQC) as a native pillar of the Prisma SASE fabric. We are moving beyond the forklift-upgrade model to a software-defined, standards-based foundation, which is built on strict separation of management and data plane components:

  • Universal Control Plane Hardening (TLS 1.3): We have transitioned all control plane traffic to TLS 1.3 (Transport Layer Security 1.3), the global gold standard for Internet encryption. This secures the "brain" of the network (where routing configurations and security policies are managed), making it immune to quantum-enabled impersonation and credential theft.
  • PQC-Hardened Data Plane (IETF Standards): We are operationalizing PQC across the entire fabric by adopting official standards published by the Internet Engineering Task Force (IETF), specifically RFC 9370, 9242, and 8784. In plain terms, these standards allow us to use "hybrid key exchanges." This means we wrap your data in two layers of protection at once: a classical mathematical shield for immediate compatibility, and a quantum-resistant shield to protect against future decryption threats, all without causing packet fragmentation or network slowdowns.
  • Logs and Telemetry Plane: All network telemetry and metadata (the automated operational logs and traffic pattern data generated by the network, rather than the actual content of your business files) are encrypted in transit via TLS 1.3. This architecture guarantees that even this secondary network metadata is geofenced to your chosen region with no cross-region aggregation, satisfying the most stringent data residency mandates.
  • Crypto-Agility as a Standard: "Crypto-agility" is natively built into our systems, which means the software is designed to adopt new mathematical algorithms. As the National Institute of Standards and Technology (NIST) refines its guidelines, our systems can be upgraded seamlessly via simple, automated cloud updates without requiring expensive hardware replacements to ensure our customers’ security posture.
  • Secure Boot Support: Palo Alto Networks Prisma SD-WAN ION hardware supports Secure Boot to ensure that only cryptographically signed bootloaders, kernels, and trusted applications are executed during the boot process. This establishes a chain of trust from the BIOS firmware to the operating system, preventing the execution of unauthorized or tampered software. ION hardware appliances ship with an integrated, dedicated Trusted Platform Module (TPM), which provides hardware-level root-of-trust by securely storing cryptographic keys, certificates, and sensitive data to prevent unauthorized physical tampering and ensure secure device authentication. The OS/software layers use PQC algorithms to negotiate and secure the management, control plane and data plane tunnels. This ensures quantum readiness without requiring an immediate, widespread rip-and-replace of physical branch hardware.

The AT&T Perspective Views Security at Global Scale

From the perspective of a global leader like AT&T, PQC is an operational mandate. Providing connectivity to the world’s most regulated industries means that security cannot be bolted on. Security must be an inherent property of the transport layer and the connectivity infrastructure itself.

Turning Complexity into a Strategic Advantage

Managing a global footprint that spans across 5G, fiber, and legacy underlays requires an institutional expertise that few can match. For AT&T, the move to a more secure quantum-ready fabric with Dynamic Defense is about providing security where it matters most: the network. Our customers shouldn't have to worry about whether their data is traveling over an MPLS circuit or the public internet.

Through this collaboration, AT&T expands the delivery of Dynamic Defense:

  • Cross-Underlay Consistency: We enable PQC protection to be applied uniformly across all transport mediums, eliminating the "weak links" that often exist in hybrid environments where data moves between private and public circuits.
  • Automated PQC Policy Orchestration: New branch locations are seamlessly integrated into the quantum-ready fabric through automated policy distribution. The moment a device is activated via zero touch provisioning, the branch is enabled to be protected against HNDL threats from the first packet without requiring manual site-by-site intervention.
  • Compliance: With mandates like NIS2/DORA in Europe and NORA/CNSA 2.0 in the U.S., our clients face a closing window for compliance. AT&T provides the verifiable chain of trust required to prove "Quantum Readiness" across the entire circuit path, ensuring your fabric is audit-ready and compliant with global standards.

The Power of the Post-Quantum Secure Fabric

The true value of this relationship lies in the synergy between the network and the security stack. By combining our strengths, we have built a solution that is significantly more resilient than the sum of its parts.

The SPI Advantage Is Performance Without Compromise

Through Service Provider Interconnect (SPI), Palo Alto Networks' security platforms natively integrate with AT&T’s private network core to deliver a seamless quantum-safe on-ramp. This means business traffic can connect directly to a secure AT&T network without having to build slow, complex software tunnels over the public internet, preserving high performance while delivering next-generation encryption. Historically, high-level encryption meant a "performance tax" on latency and throughput. Our combined architecture allows quantum-safe traffic to flow over AT&T’s network backbone, enabling organizations to modernize their security without sacrificing the user experience.

Securing the Decentralized Perimeter (The Branch as the Edge)

In today’s highly distributed business landscape, the traditional corporate "headquarters" is no longer the center of gravity. The network perimeter has shifted to the branch (decentralized edge locations like retail storefronts, remote clinics, regional bank offices, and warehouse hubs) and the individual 5G-connected devices employees use. Securing these remote, local edge points is critical because they represent the primary gateway where sensitive company data first enters the network. 

By utilizing AT&T’s leadership in WAN, 5G and cellular technologies, we leverage Hybrid Public Key Infrastructure (PKI) to secure these edge locations. Hybrid PKI is a digital identity framework that issues dual security credentials to every device: one "classical" identity to ensure compatibility with existing networks today, and one "quantum-resistant" identity. This double-verification guarantees that a cellular-connected remote branch or a mobile site is just as immune to quantum decryption or identity spoofing as a fortified corporate data center.

The Path Forward Is a Vision for Long-Term Trust

The transition to a quantum-ready future is a marathon, not a sprint, and the first steps must be taken now. Palo Alto Networks and AT&T Business are offering a clear, practical path to quantum resilience.

We are delivering more than a simple software update as we prepare customers for the next generation of digital commerce. Together, we are designing our network to help ensure the data of today remains protected against the threats of tomorrow, securing the digital integrity of every enterprise we serve.

As we redefine the boundaries of security in connectivity, we invite you to join us in helping secure your organization’s digital future. Contact your or Palo Alto Networks account representative today to begin a strategic Quantum-Readiness Assessment and experience the power of the Quantum-Resilient SASE Fabric.

The post Palo Alto Networks and AT&T - Delivering Quantum-Resilient SASE Fabric appeared first on Palo Alto Networks Blog.

New Executive Order Accelerates Post-Quantum Readiness Amid the Cryptographic Reset

24 June 2026 at 01:30

The White House Executive Order on securing the nation against advanced cryptographic attacks accelerates the mandatory timeline for post-quantum readiness.

For years, post-quantum cryptography has been discussed as an important, yet abstract future technical migration. Because of the uncertain timeline for quantum computing, it has been difficult for most organizations to prioritize quantum readiness against more immediate security demands.

That is changing.

Signed on June 22, 2026, the Executive Order mandates the transition of federal information systems to post-quantum cryptography and establishes a national policy to migrate them to NIST-approved standards. It also extends the urgency beyond government by directing support for critical infrastructure owners and operators, advancing requirements for federal contractors, and calling for cryptographic bill of materials guidance.

The order directly addresses harvest now, decrypt later risk and sets transition milestones for federal high-value assets and high-impact systems: 2030 for key establishment and 2031 for digital signatures.

While the order directly applies to U.S. Federal civilian agencies, it should be seen as a signal of broader policy and procurement momentum. Organizations that do business with the government, support critical infrastructure, or operate in regulated industries such as energy, financial services, and healthcare should expect post-quantum readiness expectations to accelerate.

Quantum risk has shifted from a long-term research concern to a national cybersecurity priority tied to sensitive data, critical infrastructure, federal systems, procurement, and the broader digital economy. For security teams, the challenge now is turning that urgency into an operational plan.

Operationalizing the quantum mandate

As quantum computing advances, widely used public-key cryptography will become vulnerable to future attacks. Even before a cryptographically relevant quantum computer exists, adversaries can capture encrypted data now with the goal of decrypting it later.

This “harvest now, decrypt later” risk is especially concerning for organizations that protect sensitive information with a long shelf life. The response cannot wait until the threat fully materializes.

The broader ripple effect matters because compliance alone will not equal readiness. As requirements flow into federal acquisition rules and contractor obligations, the vendor ecosystem will be pushed to support quantum-safe capabilities in the products and services that enterprises, critical infrastructure organizations, and regulated industries rely on.

Adding support for post-quantum algorithms is not the same as safely migrating to them. Support means a system can use new algorithms. Readiness means the organization knows where cryptography exists, which systems are exposed, which dependencies matter most, and how to execute changes without creating disruption or new risk.

That matters because post-quantum migration can affect more than cryptographic libraries. Larger cryptographic objects, new protocol behaviors, hybrid modes, hardware acceleration requirements, interoperability constraints, and legacy system limitations can create real performance, availability, and compatibility challenges if changes are made blindly.

This is why cryptographic visibility must lead to actionable migration planning.

Security teams cannot migrate what they cannot see. But visibility by itself is not enough. They also need to classify exposure, prioritize high-value systems and long-lived data, understand operational dependencies, and plan changes in a way that avoids disruption, downgrade risk, or incomplete migration.

Cryptographic bill of materials guidance will be an important step toward mapping cryptographic assets. But a CBOM should be the starting point, not the finish line. An inventory can show where cryptography exists, but readiness requires understanding business impact, migration complexity, interoperability risk, ownership, and the order in which changes should happen.

Post-quantum readiness is not just an algorithm swap. It is an operating model for managing cryptographic change at scale.

Five actions for post-quantum readiness

The path forward starts with five practical actions.

  • First, see cryptographic exposure. Organizations must gain visibility into cryptographic usage across all environments to mitigate the risks associated with undocumented encryption.
  • Second, prioritize what matters most. Cryptographic exposure varies in urgency. Organizations should prioritize protecting authentication, high-value assets, and long-lived sensitive data based on risk and business impact.
  • Third, modernize trust infrastructure. Existing systems rely on fixed cryptographic assumptions. Post-quantum readiness demands flexible infrastructure and trust services that support evolving standards.
  • Fourth, automate cryptographic change. Manual tracking with spreadsheets provides an incomplete, point-in-time snapshot that quickly becomes outdated and is insufficient for the coming changes. Automation allows organizations to manage cryptographic updates and trust operations in a consistent, controlled manner.
  • Fifth, govern readiness over time. Post-quantum migration requires continuous governance to track progress, align ownership, and adapt to evolving threats and standards.

These actions help security leaders move from awareness to readiness.

What this means for cybersecurity now

The Cryptographic Reset is already underway, driven by post-quantum risk, shorter certificate lifecycles, machine identity growth, fragmented cryptographic ownership, CA distrust events, and expanding digital infrastructure.

The organizations that move first will not simply be the ones that adopt new algorithms the fastest. They will be the ones that build the visibility, operating model, and governance needed to manage cryptographic change continuously.

Take the next step

Read the guide: The Post-Quantum Readiness Race Is On: Five Actions Security Leaders Can Take to Accelerate Crypto Agility.

More resources

The post New Executive Order Accelerates Post-Quantum Readiness Amid the Cryptographic Reset appeared first on Palo Alto Networks Blog.

Expanding Our Footprint: Local Cloud Availability for Prisma AIRS in Japan

Securing the Future of Japan’s AI Landscape

The shift from static LLMs to autonomous agents has fundamentally changed the global threat surface. Frontier models like Anthropic's Mythos can now autonomously discover hundreds of zero-day vulnerabilities, rapidly shrinking the gap between discovery to exploitation from days to minutes. With the rise of autonomous offensive AI, multi-agent systems like the 'Zealot' proof-of-concept can independently perform reconnaissance, escalate privileges, and exfiltrate cloud data.

Prisma AIRS 3.0 is a comprehensive AI security platform that secures the new AI estate end-to-end: scanning models, agents, and artifacts before deployment, protecting runtime behavior, and enforcing unified control through posture management.To secure this new AI estate against these advanced global threats, Palo Alto Networks is pleased to announce a strategic investment designed to enhance cyber resilience: the establishment of our new local cloud location for Prisma® AIRS™ in Japan. This localized presence simplifies complex operations, enabling local data residency and low-latency processing to accelerate the secure adoption of Generative AI and Agentic Workflows.

 

Comprehensive Agent Security Platform The new regional expansion in Japan hosting Prisma AIRS provides Japanese organizations with domestic, high-performance access to critical AI security capabilities. As we progressively roll out our full suite of features in the region, Prisma Airs is designed to be a comprehensive AI security platform that secures an organization's entire AI ecosystem including AI applications, models, agents, and datasets, from the development phase all the way through active deployment.  

  • AI Model Security:
    Enables the safe adoption of third-party AI models by scanning them for vulnerabilities and secures the AI ecosystem against risks, such as model tampering, malicious scripts and deserialization attacks.
  • AI Red Teaming:
    Uncovers potential exposure before bad actors do. Performs automated penetration tests using our Red Teaming agent that learns and adapts like a real attacker to stress test AI deployments at machine speed.
  • AI Runtime Security™:
    Protects LLM-powered AI apps against runtime threats, such as prompt injection, sensitive data leaks, and Indirect Prompt Injection (IDPI) embedded in benign-looking websites.
  • AI Agent SSPM (SaaS Security Posture Management):
    Secures AI agents against new agentic threats, such as identity impersonation, memory manipulation and tool misuse. This governs autonomous connections and prevents attackers from weaponizing a company's internal AI assistants.

Please visit the regional cloud locations of Palo Alto Networks for more information. This infrastructure optimizes operational efficiency and provides the essential security foundation for large-scale Digital Transformation (DX) projects, empowering Japanese enterprises to innovate with confidence and Deploy Bravely

The post Expanding Our Footprint: Local Cloud Availability for Prisma AIRS in Japan appeared first on Palo Alto Networks Blog.

Securing the Agentic AI Frontier: Palo Alto Networks and Databricks Deliver a New Standard for AI Security

The rise of Agentic AI is rapidly reshaping the enterprise, yet its deployment opens a complex new frontier for cyber threats.  As organizations race to harness the power of enterprise agents, the "Data Estate" has become the new perimeter. CISOs today face a high-stakes trade-off: enabling developers to build at the speed of AI while keeping proprietary data visible, governed, and secure across the entire AI lifecycle. This requires meticulously checking user inputs, agent outputs, and tool calls for threats like prompt injections, sensitive data loss, and malicious code, while simultaneously preventing autonomous agents from performing destructive actions.

Securing the AI-driven enterprise requires a fundamental shift from reactive measures to proactive runtime protection. Palo Alto Networks and Databricks are delivering on that vision. Our partnership will integrate the Prisma AIRS API with Databricks Unity AI Gateway, embedding seamless security at runtime. This collaboration will enable organizations to innovate with AI agents, applications, models and MCP Servers at scale while maintaining a robust, policy-driven security posture. By combining the centralized AI governance and control capabilities of the Databricks platform with the runtime security protections of Palo Alto Networks, organizations can scale AI innovation without sacrificing visibility, compliance, or security.

 

The Context: Why AI Security is Different

AI security represents a fundamental departure from traditional defense. Legacy tools are designed for structured threats, leaving them incapable of parsing the intent behind complex, conversational attacks. Furthermore, the integration of Retrieval-Augmented Generation (RAG) and autonomous workflows creates a dynamic attack surface that goes far beyond traditional data loss. Without AI-native oversight, organizations can face severe risks from prompt injections, custom topics, and toxic content manipulating model logic, to tool misuse, malware execution, and malicious URLs hijacking agent actions.

Modern AI development requires more than just a perimeter; it requires contextual intelligence. By integrating Prisma AIRS directly into Databricks Unity AI Gateway, we will evolve security from a reactive layer into a native pillar of the AI architecture.

 

The Joint Solution: Centralized Security at the Gateway

The most effective way to secure an entire AI environment is at the governance layer. Our integration focuses on Databricks Unity AI Gateway, which serves as the centralized interface for all AI activity within the Databricks environment. Unity AI Gateway is designed for managing, governing, and monitoring access to all models, agents and MCP Servers—whether they are open-source models deployed within Databricks or external proprietary models. As organizations deploy more agents, applications, and models, centralized governance becomes critical. Unity AI Gateway provides a single control plane for AI usage, enabling teams to apply consistent policies, monitor activity, and manage access across AI workloads.

Through this integration, Unity AI Gateway will make real-time calls to the Prisma AIRS Runtime Security API for security inspection. Instead of managing fragmented security policies across dozens of individual applications, SecOps teams will be able to enforce consistent guardrails across the entire Agentic AI estate from one location, providing a single, unified enforcement point for all AI workloads.

Figure 1: Centralized AIRS guardrail configuration delivers instant protection across all applications, agents and MCP Servers without requiring client-side code refactoring

 

Mechanism: API Intercept for AI Runtime Security

Prisma AIRS operates as an advanced inspection layer, leveraging its API Intercept capability to provide real-time security embedded directly into the application flow. By embedding Prisma AIRS directly into the workflow, we offer a seamless 'Security-as-Code' experience that unifies development and defense. Prisma AIRS intercepts AI prompts, responses, and MCP calls—inspecting them in real time to enforce security policies with an immediate Go/No-Go verdict or by sanitizing the data in transit. Prisma AIRS uses deep learning classifiers to detect data exfiltration risks, such as the presence of PII (Personally Identifiable Information), PHI, or PCI data. If sensitive data is found, it can be dynamically redacted or blocked based on corporate policy.

 

Key Benefits for the Enterprise

This integration isn't just about blocking threats—it’s about accelerating your AI roadmap. By removing the "security friction" that often slows down production deployments, we enable teams to move faster with confidence. Key benefits include:

  • Zero-Friction Governance: Developers continue working within their familiar Databricks environment. Security is enforced via the Unity AI Gateway API, meaning there are no bulky agents to install and no complex architectural re-wiring required.
  • Prevention of Data Leakage: Leverage Prisma AIRS’s data classifiers to automatically protect sensitive intellectual property, preventing data leaks to public models and unauthorized users.
  • Resilience Against AI-Specific Attacks: Protect your Unity AI Gateway deployments from emerging threats that standard network security tools cannot see, including prompt injection, toxic content, custom topics, malware detection and malicious URL detection.

 

Key Takeaway

  • Ease of use and unified Policy Management: Enable runtime security through the Unity AI Gateway to gain centralized control over security enforcement.
  • Audit-Ready Compliance: Every transaction mediated by the Unity AI Gateway is logged with detailed security metadata, delivering enriched insights in Strata Cloud Manager. This provides the forensic trail required for regulatory compliance in highly governed industries like finance and healthcare.
  • Protection for Agentic Workflows: Future-proof your multi-step AI agents against sophisticated Agentic Threats by inspecting function and tool calls within the runtime.

 

Looking Ahead

As agentic workflows and multi-step model interactions become the standard, a 'fail-closed' runtime security posture is no longer optional; it is foundational. The integration of Prisma AIRS API and Databricks Unity AI Gateway marks a definitive shift toward a future where enterprise AI is secure by default.  By integrating Prisma AIRS API with the Databricks platform through Unity AI Gateway, organizations can centrally govern AI across models, agents, applications, and MCP servers while enforcing consistent runtime security policies. Together, Databricks and Palo Alto Networks are helping customers scale AI innovation with the control, visibility, and protection required for the agentic era.

Are you ready to secure your AI workloads and agentic applications?
check out the latest Databricks blog and stay tuned for technical deep-dive sessions coming soon.

 

Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.  All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

The post Securing the Agentic AI Frontier: Palo Alto Networks and Databricks Deliver a New Standard for AI Security appeared first on Palo Alto Networks Blog.

Onward, Friends

16 June 2026 at 20:56

After 26 years, today is my last day at EFF. It's been a terrific and wild ride — the organization has grown from a tiny band of fighty people trying to plant a flag for freedom and justice in the coming digital world into a large, established band of fighty people doing, well, much the same. The world around us has changed enormously. Our core values haven't budged.

cartoon of EFF as superheros

I'm proud of what we've achieved: freeing encryption, defending coders, pushing to rein in government and corporate surveillance and ensure the right to have a private conversation online, standing up for free speech and anonymous speech, fighting for network neutrality and safe voting machines, busting stupid patents, and making sure copyright didn't become the one law that rules the internet. That's only the start. We've stopped more bad legislative, regulatory, and legal ideas than I can count, built tools that millions rely on to protect their privacy, and helped encrypt the web. I've long said EFF is the plumber of the internet — finding the clogs and barriers that prevent technology from serving freedom, justice, and innovation for everyone.  

In addition to presenting cases in courts across the land, testifying in Congress and in California, in the European Parliament and at the United Nations, I went onto the internet with Stephen Colbert and engaged in a healthy disagreement with Jon Stewart.  I wrote a lot of it down in a book, hoping to recruit others to the cause.  The work has been hard and often frustrating at times.  But looking back, the fun parts are what I remember most.   

None of it would have been possible without EFF’s stalwart members. More than 30,000 people, some with big wallets and some with small ones, give us what we need to stand up to bullies and fight for the long haul. EFF has always served as a beacon for people who know that for technology to support freedom, justice, and innovation for all the people of the world, we need a dedicated band of folks working overtime on behalf of users, innovators, and creators. 

There's still plenty left to do. We haven't killed the third-party doctrine, tamed the surveillance business model, or gotten metadata the constitutional protection it deserves. Stupid patents persist as does the overreach of DMCA section 1201 and the Computer Fraud and Abuse Act. The government is now the largest purchaser of data from shady brokers, communities everywhere are fighting license plate readers and other street-level surveillance, and we haven't reined in NSA and FBI spying nearly enough. Meanwhile, the rise of AI is supercharging problems we've fought against for years. 

But I'm proud of what we've built together. I'm grateful to every EFFer — past, present, and future — who threw in with us when the odds were long and the pay was much better elsewhere. I'm grateful to the EFF Board and especially to my mentors and friends Pam Samuelson and Shari Steele, along with my longtime partner in justice, Lee Tien, who has been working with me since the Bernstein case. Fighting for justice is easier when you have a posse: coworkers, co-counsel, coalitions, interns, volunteers, and the heroic clients who trusted us to steward their cases in ways that bent the law toward everyone's benefit. Twenty-six years later, EFF is part of a global diaspora of organizations defending internet freedom — and I'm proud of that too. 

I'm stepping down because good leaders should make way for new ones, and the time feels right. EFF is strong and full of fight. My successor Nicole Ozer — a longtime friend and collaborator — is exactly the right person for this moment. She understands EFF's role and values at a deep level and will protect them while helping the organization rise to meet what's coming. 

As for me, I'm not going far. After a few months off to reflect and walk dogs, I plan to get back into the fight for justice — likely heading back into the courtroom. And I'll be watching, cheering, donating, and wearing the merch from EFF, just like the rest of you.

Cindy Cohn with her 2 Bernese Mountain Dogs at sunset

Securing Canada’s Digital Future: Why PBMM Matters Beyond Government

12 June 2026 at 17:09

Palo Alto Networks is pleased to announce the successful completion of a new Cloud Medium security assessment conducted by the Canadian Centre for Cyber Security (Cyber Centre), significantly expanding the number of Palo Alto Networks cloud services assessed for Protected B / Medium Integrity / Medium Availability (PBMM) environments. This assessment includes a broad range of capabilities across our Cortex®, Cortex Cloud and Strata™ platforms. By achieving this milestone, Palo Alto Networks enables  organizations handling Canada’s most sensitive data to leverage a unified, AI-driven security architecture without compromising on compliance or operational resilience.

For years, many organizations viewed PBMM as something that only mattered to the Canadian federal government. It was often seen as a procurement requirement—a framework tied to public sector cloud adoption, relevant for departments handling Protected B information, but not necessarily for the private sector.

That assumption is changing.

The reality is that the challenges driving PBMM are no longer unique to government environments. Banks, energy providers, transportation networks, healthcare organizations, crown corporations, and other critical infrastructure operators are now facing many of the same pressures:

  • Expanding attack surfaces across hybrid and multi-cloud environments.
  • Increased regulatory scrutiny and privacy obligations.
  • Greater operational dependence on cloud and AI technologies.
  • Increased reliance on third-party providers and software supply chains.
  • The need to maintain operational resilience during cyber incidents and disruptions.
  • A growing expectation that organizations can demonstrate—not just claim—security maturity.

That is why PBMM matters far beyond Ottawa. At its core, PBMM represents a rigorous approach to validating whether enterprise-grade security platforms can operate securely in environments where trust, resilience, and operational continuity are critical.

Increasingly, that level of assurance matters to everyone.

What PBMM Really Represents

PBMM, a rigorous cybersecurity and data classification standard used by the  Canadian Centre for Cyber Security, stands for Protected B / Medium Integrity / Medium Availability. While often associated with federal cloud security requirements, PBMM is not simply a checkbox exercise. It is a comprehensive assessment framework aligned to Canadian cybersecurity guidance and operational security expectations.

What makes PBMM important is that it evaluates whether platforms and services can securely support sensitive and mission-critical workloads in real-world environments.

Palo Alto Networks meeting these rigorous PBMM requirements through three core pillars:

  • Strata (Network Security): Secures data resiliency and zero trust connectivity, driving robust perimeter and cloud edge protection.
  • Cortex Cloud (Cloud Security): Provides complete visibility, security governance, and data protection across complex cloud-native architectures.
  • Cortex (Security Operations): Powers the agentic SOC, combining unified data, AI, and automation to detect and respond to threats in real time.

These are not theoretical requirements. They are practical operational expectations designed for environments where downtime, visibility gaps, or security failures can have significant consequences.

Organizations today are no longer evaluating cybersecurity solely based on features. They are evaluating whether platforms can be trusted to support critical operations at scale.

Why Security Expectations Are Changing

The cybersecurity landscape has evolved dramatically. Infrastructure is distributed across cloud providers, SaaS applications, remote users, third-party integrations, operational technology (OT), AI platforms, and interconnected supply chains. At the same time, attacks have become faster, more automated, and more disruptive.

In this environment, security can no longer be treated as a compliance exercise. Organizations need confidence that their platforms, operational processes, and security controls can function effectively under pressure.

This is why Palo Alto Networks has undertaken independent PBMM assessments across its portfolio, providing customers with greater assurance and trust. By meeting these rigorous standards into Strata and Cortex, we enable non-government entities—like financial institutions and utility providers—to deploy the same defensive rigor used to protect national security systems.

Transforming Critical Infrastructure with a Unified Platform

To effectively manage risk, critical infrastructure operators require a platform approach that helps eliminate security silos, reduce manual intervention, and accelerate threat mitigation.

Key Portfolio Advantages for Critical Infrastructure & Enterprise:

  • AI-Driven Threat Detection & Response: Cortex XSIAM® and Cortex XDR® unify telemetry across endpoints, network, and cloud to deliver unparalleled visibility and automated threat stitching, neutralizing advanced cyberthreats before they disrupt operations.
  • Comprehensive Cloud Native Protection: Cortex Cloud secures applications from code to cloud to SOC, offering posture security, data protection, and continuous compliance monitoring tailored to stringent Canadian data standards.
  • Zero Trust Network Security: Strata enables secure access and consistent policy enforcement across campus, branch, and data center environments, protecting critical OT and IT systems from lateral threat movement.
  • Elite Incident Response: Backed by Unit 42®, organizations gain access to threat intelligence and rapid incident response services to augment their teams and build long-term cyber resilience.

Operational Resilience Is Becoming a Strategic Requirement

One of the most significant shifts occurring across industries today is the growing focus on operational resilience. Organizations are increasingly asking questions that extend beyond traditional cybersecurity controls:

  • Can we maintain critical services during a cyber attack?
  • Do we have visibility across our cloud environments and supply chain dependencies?
  • Can we rapidly detect, respond to, and recover from disruptions?
  • Are our governance processes keeping pace with cloud adoption and AI innovation?

As organizations adopt cloud-native architectures, AI-driven technologies, and interconnected digital ecosystems, resilience has become a board-level concern. The ability to prevent incidents remains important, but organizations are equally focused on their ability to withstand, respond to, and recover from them.

This is where frameworks like PBMM provide value. Beyond evaluating security controls, PBMM assesses the governance, operational processes, monitoring capabilities, and risk management practices that help organizations operate securely.

For critical infrastructure operators, resilience is no longer simply an IT objective—it is a business imperative. Increasingly, the organizations that earn trust are those that can demonstrate they are prepared to operate effectively when disruption occurs.

Final Thoughts: PBMM Reflects the Future of Trust

PBMM may have started solely as a government assessment framework, but its relevance now extends far beyond federal environments. It represents something universal: the ability to operate securely, reliably, and transparently in environments where trust matters most.

By expanding our PBMM-assessed offerings across Cortex and Strata, Palo Alto Networks underscores its commitment to securing Canada's digital future. We provide the validated foundation organizations need to innovate with confidence, protect sensitive data, and maintain operational continuity under any circumstance.

Read the Assessment Summary Report

To learn more about the Palo Alto Networks Cloud Medium security assessment, review the publicly available assessment summary report issued by the Canadian Centre for Cyber Security.

Ready to modernize your defenses with PBMM-assessed solutions? Schedule a demo with our team or contact Unit 42 to learn how we can help elevate your organization's resilience against emerging cyber threats.

The post Securing Canada’s Digital Future: Why PBMM Matters Beyond Government appeared first on Palo Alto Networks Blog.

Shifting from Data Hoarding to Active Defense: Navigating the New Era of OMB M-26-14

10 June 2026 at 00:39

The release of OMB Memo M-26-14 ("Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats") marks a historic turning point in federal cybersecurity. By officially rescinding the M-21-31 directive, the White House has delivered a clear message to federal IT leaders: the era of compliance-driven data hoarding is officially over.

While the previous framework was a well-intentioned response to the SolarWinds breach, its mandate to collect and retain vast oceans of unstructured logging data created unintended, unsustainable operational burdens. For the past several years, federal agencies have faced skyrocketing cloud storage bills and overwhelmed Security Operations Centers (SOCs). Crucially, they have been left with vast quantities of cold data that lacked clear operational utility.

As OMB noted, retaining endless data without operational focus is neither cost-effective nor operationally feasible. With M-26-14, the federal government is pivoting to a smarter, sleeker, and far more decisive strategy: a risk-based, prioritized logging framework driven by AI and machine-speed defense.

The Core Shifts: What Federal Leaders Must Understand

M-26-14 strips away administrative "red tape" to focus on how modern cybersecurity risks have evolved. Nation-state threat actors are actively leveraging advanced automation and Artificial Intelligence (AI) to orchestrate attacks at unprecedented speeds. They move laterally across agencies in minutes, hiding behind legitimate corporate credentials.

To beat machine-speed threats, your data layer must operate at machine-scale. The new memo reorganizes federal visibility around two foundational pillars:

1. Continuous Event Monitoring — Owning the Present

Continuous Event Monitoring demands that logging infrastructure shift from a passive archiving tool to a live-streaming asset. Agencies are now required to monitor network and asset activity in real time, rapidly flag anomalous behavior via behavioral analytics, and initiate immediate mitigation actions directly through their SOCs.

2. Threat Hunting, Investigation, Response, and Forensics — Dominating the Post-Compromise

When a compromise is suspected, agencies can no longer spend days running slow database queries or pulling disconnected csv files. M-26-14 mandates that agencies keep 6 months of logs "hot and searchable" and 1 year fully "retrievable." This allows defenders to immediately stitch together cross-domain attack patterns, perform rapid root-cause forensics, and share threat intelligence seamlessly with CISA and the FBI.

3. Expanding the Blast Radius: Entering IoT and OT

Perhaps the most significant structural change is the explicit inclusion of Internet of Things (IoT) and Operational Technology (OT) systems. Adversaries do not respect the boundary between your corporate IT network and your physical infrastructure. Under M-26-14, your logging and threat-hunting capabilities must aggressively cover the entire enterprise—from public cloud workloads to the physical facility controls and critical infrastructure grids running on an agency's behalf.

The Clock is Ticking: The Aggressive Maturity Deadlines

Agencies cannot afford a passive approach. The timeline established by OMB M-26-14 moves quickly:

  • T+90 Days: CISA will publish the new Logging Reference Architecture (LRA) codifying hybrid/centralized deployments, Zero Trust Maturity Model (ZTMM) integration, and AI-driven monitoring guidelines.
  • LRA +90 Days: Agencies must submit their comprehensive Agency Logging Plans.
  • LRA +120 Days: Achieve Basic Level 1 Maturity.
  • LRA +180 Days: Achieve Intermediate Level 2 Maturity.
  • LRA +320 Days: Achieve Advanced Level 3 Maturity (Advanced/Optimal Effectiveness).

Activating OMB M-26-14 with Palo Alto Networks Cortex

Trying to retrofit a legacy SIEM architecture to meet the advanced or optimal effectiveness tiers of M-26-14 is an engineering and budgetary dead end. Legacy SIEMs scale costs linearly with ingestion and rely on static, human-written correlation rules that fail against AI-fueled threats.

The FedRAMP Certified Palo Alto Networks Cortex platform—anchored by Cortex XSIAM (Extended Security Intelligence and Automation Management)—was engineered from the ground up to solve the exact problems this new memo addresses.

From Disconnected Columns to Cross-Domain "Stitching"

Legacy logging stores data in isolated silos. An analyst trying to track an adversary has to manually look at an identity log, cross-reference it with a network firewall alert, and match it to an endpoint execution.

Cortex XSIAM features a revolutionary Analytics Engine that automatically stitches multi-vendor logs across cloud, network, endpoint, and identity at the moment of ingestion. It transforms raw text into a single, cohesive, context-rich story, instantly aligning incidents with the MITRE ATT&CK framework.  Cortex XSIAM doesn’t just ingest data, it understands the data which enables stitching of multiple data elements into a single, multi-context construct which accelerates analysis via AI and machine learning.

Replacing Static Rules with Cloud-Scale AI

Adversaries use AI to evade signature detection. Cortex XSIAM fights fire with fire, applying out-of-the-box, unsupervised machine learning models to baseline normal behavioral patterns across your entire federal enterprise. When an anomalous lateral movement, data exfiltration attempt, or credential abuse event occurs, XSIAM flags the threat instantly—without requiring your team to spend weeks writing custom correlation code.

Accelerating Continuous Event Monitoring (CEM) and Threat Hunting, Investigation, Response and Forensics (THIRF)

There is more to CEM than just monitoring network activity.  Activity on endpoints, within your identity management solution(s) and in the cloud are just as important.  Understanding the data, knowing which log records are related to each other across multiple log sources, which events are relevant and the context they provide is required.  

Understanding these events and their contextual relationships is fundamental to providing THIRF in an efficient manner.  Cortex XSIAM provides over 2,900 machine learning models out of the box, models that are trained on the data in your environment so they detect anomalous activity based on what is “normal” in your environment, not trained on generic data from other customers or a lab.  These models can identify threats based on data stitched together from multiple sources to provide a more complete context yielding more accurate and consistent results while decreasing time to value.

Securing the Unmanageable: Agentless IoT/OT Defense

You cannot install an EDR logging agent on a smart building HVAC system or an industrial programmable logic controller (PLC). Palo Alto Networks utilizes non-disruptive, passive network analysis to continuously discover, profile, and generate high-fidelity security logs for IoT and OT infrastructure. These logs stream directly into XSIAM, eliminating critical federal blind spots and protecting your High Value Assets (HVAs) from cross-boundary pivot attacks.

Solving the Storage Conundrum Safely

Keeping six months of high-velocity event logs fully "hot and searchable" under a traditional database indexing model creates a crushing financial burden. Cortex XSIAM fundamentally resets the Total Cost of Ownership (TCO) equation by leveraging an index-free, cloud-native data lake architecture that decouples storage costs from analytical performance. By eliminating legacy ingestion taxes and infrastructure overhead, federal defenders can search petabytes of data in seconds—effortlessly meeting the 6-month searchable and 1-year retrievable thresholds. Furthermore, integrated data masking rules strip away sensitive PII or low-value data noise before it hits the SOC, ensuring agencies only pay for operationally vital intelligence.

 

The Bottom Line for Federal Leaders

OMB M-26-14 is a massive step forward for federal cybersecurity. It frees CISOs from the operational gridlock of untargeted data archiving and empowers them to build faster, modern, and highly responsive security operations.

Meeting the strict 120-to-320-day maturity milestones requires moving past the tools of the last decade. By partnering with Palo Alto Networks and deploying the Cortex suite, federal agencies can seamlessly transition into a risk-aligned, AI-driven SOC. They can confidently check the box on OMB compliance while achieving what the directive actually intends: protecting the resilience and integrity of the federal mission at machine speed.

Palo Alto Networks’ Cortex XSIAM is FedRAMP certified at both the moderate and high levels.

Want to learn more about how to structure your upcoming Agency Logging Plan to meet CISA's upcoming Logging Reference Architecture? 

Contact the Palo Alto Networks Federal Team today to schedule an architectural deep-dive.

The post Shifting from Data Hoarding to Active Defense: Navigating the New Era of OMB M-26-14 appeared first on Palo Alto Networks Blog.

Trust is the Foundation of Sovereignty

9 June 2026 at 09:01

Sovereignty has become the driving principle of Europe's technology conversation. Every policy discussion, every emerging legislative development, every procurement process, every boardroom debate comes back to which platforms and partners to trust.

Trust goes beyond compliance. It demands integrity, accountability, and transparency about the limits of what any provider can guarantee – rather than making commitments that sound reassuring but cannot be verified.

We have spent considerable time listening to public sector organizations, critical national infrastructure operators, and regulators across Europe. This is not a new concern. Over the years,  what organizations are asking for has become increasingly specific. They want their data to remain in Europe. They want to know precisely who can access it and who holds the encryption keys. And they want every access event logged and visible. They want operations managed locally, under local jurisdictions and subject to local laws.

These are governance requirements as much as technical ones. And what they add up to is a demand for verifiable control, not more contractual promises. The distinction matters enormously. Telling an organization you will protect their data is one thing; giving them the architecture and the visibility to verify that protection themselves is another.

It is worth being clear about who is driving this conversation. These requirements are not universal. A large enterprise running productivity tools has different needs from a government ministry managing sensitive national data or a critical infrastructure operator running systems that society depends on for clear drinking water. What we are describing here is what we hear from the most demanding end of the spectrum: public sector and critical national infrastructure. And that is where we focus, because getting it right there matters most.

What We Have Built

The announcement of the Sovereign Cortex with T Security, together with Deutsche Telekom and Google Cloud, is our direct response to these demands and the next step in our long-standing commitment to Europe. It is not a marketing position – it is a framework that provides customers actual controls. It is built on the five elements that reflect how we fundamentally think about sovereignty. One that will set the standard across every solution we build for the region.

  1. Customer data and systems data (telemetry) are stored and processed in Europe and accessed only by personnel in-region.
  2. The encryption keys are held externally under control by the customer. 
  3. Data access events are independently reviewed, logged, visible, and auditable. 
  4. Site reliability engineers and support personnel based in Europe manage and support the service. 
  5. Contracts are signed by a European legal entity, governed by European law.

Each element of this framework was designed from the outside in, with the input of every European organization we collaborated with. 

Why Trust Has to Be Earned, Not Claimed

Here is what I believe, having spent years in this conversation across Europe. Trust is not something a provider can simply assert. It is something that has to be earned, over time, through consistent and verifiable action.

For technology companies operating in Europe, that means placing meaningful control with a trusted local European partner, being transparent about what we can and cannot guarantee, and treating sovereignty not as a compliance exercise but as a design principle.

It also means being honest about the journey. We have done significant work, yet we have further to go. The organizations we serve deserve partners who acknowledge that openly rather than presenting a finished picture.

What drives this work is straightforward: we believe in Europe’s digital future. We believe in the missions of the organizations we work with every day, whether they are protecting critical public services, securing national infrastructure, or safeguarding the data that citizens and institutions depend on. Being a committed partner to those organizations is not a product decision. It is a values decision.

And that is precisely why trust is the measure we hold ourselves to. The direction is clear, the commitment is real. But commitment means nothing without trust – and trust, like everything worth having, has to be earned every day.


Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.  All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

The post Trust is the Foundation of Sovereignty appeared first on Palo Alto Networks Blog.

We're Fighting Mass Surveillance Tech—and Winning

2 June 2026 at 18:41

EFF is on the front lines of the fight against tech-enabled tyranny, but we aren't alone. Our team depends on your help to fight back against the surveillance state.

JOIN EFF

People around the world are pushing back against the mass surveillance that undermines privacy and free expression for everyone. You can help during EFF's spring membership drive.

One of the people who joined the fight for digital rights is EFF client Will Freeman. Will created the website DeFlock.me to reveal the dangers of automated license plate readers (ALPRs)—cameras that collect location data on every vehicle they see and upload that to a massive nationwide police database. Deflock.me turns the tables by enlisting ordinary people to track the locations of tens of thousands of ALPR cameras.

But when the police spy-tech company Flock Safety went after Will's website with legal threats citing trademark law, he saw it for what it was: an attempt to silence critics and dim the light on mass surveillance.

The company will try everything it can to downplay the criticism, but EFF will be right there demanding accountability.

"I was totally unprepared to receive a cease & desist letter. I can see how most people would be bullied into submission by a threat like that. That's when I remembered Dave Maass from the EFF introduced himself via email several weeks before, so I reached out for help," Freeman says.

And that's when EFF stepped in. Recognizing DeFlock.me as a quintessential expression of grassroots advocacy and a form of criticism protected by the U.S. First Amendment, EFF's lawyers helped Will fight back. And the Big Surveillance Tech flinched.

But these battles against Flock's Spying tools rage on. In cities around the country, privacy advocates are pressuring officials to block or end contracts for ALPRs—and winning. The company will try everything it can to downplay the criticism, but EFF will be right there demanding accountability.

Two people wear EFF Claw Back member t-shirts. The front shows a cat swatting at spy cameras and the back says “Mass Surveillance” with red claw marks through it

Get the new Claw Back member t-shirt featuring a fierce feline swatting at community surveillance. You might empathize with him, but there’s a better way. Let’s end the law enforcement contracts, harmful practices, and twisted logic that enable mass spying in the first place.

"I'm really grateful the EFF was able to step in and help. Without them, free speech would be only for those wealthy enough to defend themselves against billion dollar companies. We've grown a lot since then and are expanding our efforts to expose and push back against mass surveillance on our streets," Freeman says.

Support the movement

stop mass surveillance tech today when you join EFF

____________________

EFF is a member-supported U.S. 501(c)(3) organization. We've received top ratings from the nonprofit watchdog Charity Navigator since 2013! Your donation is tax-deductible as allowed by law.

Reinventing Security for the Agentic NVIDIA AI Factory

Building on the momentum of NVIDIA GTC Taipei at COMPUTEX  2026, the conversation has moved beyond AI experimentation to the industrialization of intelligence. Organizations are rapidly deploying AI Factories – high-performance, purpose-built computing infrastructures designed to manufacture intelligence at an unprecedented scale. AI’s next phase is agentic. Autonomous AI agents are reshaping enterprise operations—and demand security architectures that can keep pace with the speed and scale of innovation.  We are proud to announce the integration of Palo Alto Networks Cortex XSIAM with the NVIDIA DOCA Argus framework, a breakthrough that brings real-time, AI-powered security operations directly into the heart of the NVIDIA AI factory. 

By operating on the NVIDIA BlueField data processor, DOCA Argus provides situational awareness through real-time memory analysis at the silicon level. This allows Cortex XSIAM to detect kernel-level rootkits and "living-off-the-land" attacks without installing security agents on the host system.

This innovation builds upon our proven foundation with Palo Alto Networks Prisma AIRS, where AI Runtime Security is deployed natively on NVIDIA BlueField, and powered by NVIDIA DOCA, bringing defense in depth. This integration enables offload , isolation and acceleration of security in AI factories.  

Purpose-Built Observability for the AI Factory

Deployed consistently across the AI factory, DOCA Argus monitors and correlates AI application processes, network telemetry, and data access to detect sophisticated anomalies that traditional tools miss. With this integration, Cortex XSIAM recognizes the high-fidelity data from DOCA Argus as a native Palo Alto Networks sensor, allowing for better decisions with the new intelligence gathered directly from the host.

By integrating Cortex XSIAM with the NVIDIA DOCA Argus framework, we leverage the innovations of two industry leaders to deliver a seamless, high-performance SecOps ecosystem for your most valuable AI assets.

Why This Integration Is a Game-Changer for SecOps

  • Process Introspection: Residing on NVIDIA BlueField, DOCA Argus has the unique ability to correlate network telemetry with deep process inspection.
  • Anomaly Detection: By analyzing traffic and host behavior simultaneously, XSIAM can detect sophisticated anomalies (e.g., lateral movement or data exfiltration) that traditional tools miss.
  • Unified Intelligence: Cortex XSIAM recognizes the security and alert information in this high-fidelity data, providing security teams with end-to-end visibility and dedicated security dashboards specifically for their AI infrastructure.

 

Native integration of DOCA Argus with XSIAM

 

Palo Alto Networks Prisma AIRS Across the NVIDIA AI Factory

The inclusion of Prisma AIRS in NVIDIA AI Factory validated design delivers a unified security platform, providing proactive, defense-in-depth security across critical layers of the AI ecosystem. 

Serving as the network enforcement engine for this architecture, Prisma AIRS secures the infrastructure of the modern AI Factory. By unifying protection and visibility into a single automated fabric, it eliminates the traditional trade-off between security and agility, allowing organizations to innovate at machine speed without compromising performance or governance. 

Beyond enforcement, the broader Prisma AIRS platform acts as the security blueprint for the entire enterprise AI ecosystem—consolidating fragmented point-tools to slash total cost of ownership while providing end-to-end observability from the data plane to the model layer. The platform scales dynamically alongside your AI clusters to safeguard raw datasets, build Layer 7 micro-perimeters around autonomous agents, and protect proprietary model weights from external threats—all without throttling mission-critical performance.

By deploying the AI Runtime Firewall directly on NVIDIA BlueField, we establish a foundational network security layer that is fully offloaded, isolated, and accelerated. This provides pervasive protection across the Enterprise AI Factory without sacrificing critical compute resources.

Securing the NVIDIA AI factory requires the entire Prisma AIRS suite, which secures the AI lifecycle through five specialized pillars:

  • AI Model Security: Protects against model tampering, malicious scripts and data exfiltration attacks before deployment.
  • AI Red Teaming: Advanced threat simulation and vulnerability discovery to enable the safety, security and integrity of your AI and Agents deployments.
  • AI Runtime Security Firewall: Protects against prompt injection, data leakage, abuse and AI-specific runtime threats across distributed inference flows.
  • AI Agent Gateway acts as the control plane for the AI enterprise – governing tool calls, model access and external connections. Every agent interaction is enforced through centralized policies.
  • Agent Identity Security assigns each agent a governed identity with precise permissions and full traceability, ensuring actions are attributable and enforceable.

 

A Forward-Looking Architecture: Embracing Vera NVIDIA BlueField-4 STX

Looking ahead to the next frontier of enterprise-scale agentic AI, Palo Alto Networks is closely aligning its platform approach with the NVIDIA Vera BlueField-4 STX architecture, extending protections to AI data storage infrastructure. As AI data demands surge, high-throughput, large-scale environments require a move toward hardware-isolated, performance-neutral protection to support the rapid growth of critical AI applications.

Operating within an isolated trust domain on future BlueField-4 silicon, our inline security capabilities will maintain strict, policy-driven controls independently of the host operating system and storage systems. This co-design enables critical forward-looking innovations for data, agents, and context memory, ensuring security is offloaded, isolated and accelerated to support the next generation of the AI Factory.

                        

NVIDIA BlueField-4

 

Key Takeaways

Our ongoing collaboration with NVIDIA focuses on these essential pillars for reimagining AI security:

  • Deliver the industry-leading security platform reinvented for the unique demands of the AI factory. High-throughput, large-scale environments require a move toward hardware-isolated and performance-neutral protection to support the rapid growth of critical AI applications. By offloading AI Runtime Firewall directly to the NVIDIA BlueField, we enable zero-latency protection and strict data governance that neutralizes threats (like model theft) while maintaining peak performance and the integrity of your proprietary models.This architecture embeds security directly into the infrastructure, out of the way of app developers.
  • Transform the SOC and achieve deep visibility across AI environments by leveraging Cortex XSIAM to provide real-time detections and automated response. By connecting infrastructure protection with this centralized intelligence, you can secure the AI journey, from development in the factory to operations at the secure industrial edge.
  • Zero-Trust for AI Infrastructure: This helps ensure that as your operations scale toward multi-agent architectures, your security footprint is fully offloaded, isolated, and accelerated to protect advanced inference flows, autonomous agents, and data pipelines without throttling performance.
  • Unified Platform Architecture: Beyond standalone point tools, the Prisma AIRS platform serves as a unified security fabric that spans the entire AI lifecycle—from safeguarding raw data to autonomous agents.

Deploy Bravely

The Palo Alto Networks platform approach delivers a comprehensive solution to secure an enterprise's entire AI ecosystem. By integrating Cortex XSIAM with the NVIDIA DOCA Argus framework, we are extending this comprehensive, deep visibility and protection to the very heart of the AI Factory. With this integration, security teams can leverage an agentless approach via DOCA Argus to gain deep visibility into AI systems hosts by simply downloading the content pack from the Cortex Marketplace.

The Palo Alto Networks platform secures the entire AI journey, protecting the infrastructure, intelligent applications, agents and data it produces. With the inclusion of Prisma AIRS in NVIDIA Enterprise AI Factory Validated Design, we have delivered the blueprint for secure AI. 

Palo Alto Networks and NVIDIA are redefining security for the AI factory. Together, we are ensuring your security architecture is as fast, scalable and innovative as the intelligence it protects, empowering you to scale AI production with reduced latency and stronger governance.

Discover more through the Palo Alto Networks partner directory, or read the official press release from NVIDIA for more details.

The post Reinventing Security for the Agentic NVIDIA AI Factory appeared first on Palo Alto Networks Blog.

A 4X Gartner Magic Quadrant for EPP Leader. Built for the Agentic Era.

29 May 2026 at 15:16

I am incredibly proud to share that Palo Alto Networks has been named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection Platforms for the fourth consecutive year. For us, this recognition is a testament to our team's relentless vision as we continue to define endpoint defense—from the pioneer days of XDR to the new frontier of agentic AI.

We believe our repeated recognition as a Leader is built on a single, uncompromising commitment to our customers and partners: empowering organizations with reduced overhead, rapid threat response, a strengthened security posture, and the resilient protection required to close the most critical security gaps. We are now leading the shift into the agentic era. While AI agents significantly boost enterprise productivity, they also introduce novel attack surfaces that legacy EDR tools are unable to protect. As the pioneer of XDR, we are committed to defining the next generation of cybersecurity by securing this new frontier.

Cortex® XDR is helping customers:

  • Secure Agentic AI with Koi: Gain unprecedented visibility, guardrails, and control over AI agents and agentic tools before they become a liability.
  • Stop the Unseen: Leverage battle-tested prevention powered by behavioral analytics, and industry-leading automation and response.
  • Unify Your Defense: Consolidate your endpoint and workspace security with a proven, four-time industry Leader.

We are incredibly proud to be recognized as a Leader once again, an acknowledgement that belongs just as much to our customers and partners as it does to us. Your trust, feedback, and real-world challenges keep us sharp and dictate our roadmap. At the end of the day, our continued leadership is built on one core promise: make each day more secure than the day before.

To get the full story and a comprehensive analysis of the endpoint security market, I invite you to read the 2026 Gartner Magic Quadrant report.

Get Your Complimentary Copy of the Report

Gartner, Magic Quadrant for Endpoint Protection Platforms, By Deepak Mishra, Evgeny Mirolyubov, Nikul Patel, May 29, 2026

Gartner and Magic Quadrant are trademarks of Gartner, Inc. and/or its affiliates. Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

The post A 4X Gartner Magic Quadrant for EPP Leader. Built for the Agentic Era. appeared first on Palo Alto Networks Blog.

Age Verification is a Privacy Nightmare

28 May 2026 at 18:37

In the rush to block young people from certain parts of the internet, lawmakers are creating a privacy and security nightmare for everyone. This scenario is already playing out globally. Help us stop it and keep the web open and accessible for all.

JOIN EFF

Protect the web for everyone

Even with the best intentions, every online age verification scheme has the same result: users are forced to reveal sensitive personal information to third parties simply to access the web. Once that valuable data is centralized, it becomes an immediate target for leaks, hacks, and misuse. This isn’t hypothetical: it has already happened several times.

By age gating the web, we serve up a honeypot of private info ripe for bad actors. But you can help us stop this when you join EFF.

A person wears an EFF Claw Back member t-shirt on the left. A person on the right wears a black sweatshirt with the Privacy Badger mascot on the chest.

Support digital rights in EFF's new Claw Back member t-shirt and Privacy Badger Crewneck.

Thanks to our members, EFF is on the front lines fighting against online age gating and identity verification online. We’re working with lawmakers to pass better policies, educating the public, and fighting the wildfire of age verification proposals around the world. Now all we need is you.

🐝 No, It’s Not a Bug

We all want young people to be safe online, but we don’t need to trade everyone's digital rights to achieve it. These new restrictive mandates are used to justify government-led censorship and expanded surveillance. That's no accident.

Whether you trust today’s lawmakers or not, handing anyone keys to new forms of censorship and surveillance is a serious risk. Because history shows us that these powers are always abused. It’s time to demand better.

Join EFF today

Help us claw back your privacy

____________________

EFF is a member-supported U.S. 501(c)(3) organization. We've received top ratings from the nonprofit watchdog Charity Navigator since 2013! Your donation is tax-deductible as allowed by law.

We Updated Our Privacy Policy. Here's What Changed and Why.

18 May 2026 at 20:03

We recently updated our privacy policy for the first time since 2022. Most of the changes are clarifications, reorganizations, and improvements in transparency, particularly around how third-party tools that run parts of our site operate. But one change is substantive enough that we want to address it directly.

The Change You Should Know About: Opt-In Email Tracking

We want to know how we’re doing with our advocacy: which campaigns get your attention and which do not, which topics you are very interested in, which less so, and which not at all. It helps us to do our work better and to prioritize or rethink our strategies as we push to build support for freedom, justice and innovation around the world.

So, to give us a rough picture of how we’re doing, we are introducing the option for you to provide explicit, opt-in consent for us to see how you interact with the emails we send you. That includes whether you open emails, and whether you click on the links inside them.

We know what you’re thinking: Doesn’t EFF strongly oppose nonconsensual tracking? You bet we do. Sneaky email tracking is ubiquitous on the web and EFF’s opposition to it remains unchanged. We have never used email tracking pixels and we’re not changing that. We’re not building profiles and we’re not sharing the data and we’re definitely not selling it.

But we do want to give you the option of allowing us to learn about how our communications are landing with you. Here’s how consent will work. We will ask, and if you say yes, we’ll be able to see whether you opened an email or not, and whether you clicked on any links. That's it.

If you say no, or ignore the ask entirely, nothing will change and we’ll do no tracking.

If you say yes, you can change your mind and opt out at any time by clicking an opt-out link in any future email or by contacting membership@eff.org.

We have heard many EFF members say that EFF is one of the only organizations that they trust with consent to track their emails. That trust is important, and we do not take it lightly. But it led us to think that if we ask, enough of you would agree that we could have a better picture of how our campaigns and other emails to you are landing and that, in turn, could help us decide what to double down on and what to change.

By giving you a real ability to consent, EFF is taking a very different path than most of the web. Asking isn’t the norm; it’s more or less never an option to say no and dark patterns often make it hard even if it looks like you can. Unfortunately, estimates have shown that 2/3s of emails received by users contain tracking, regardless of whether the senders received explicit consent at the time when a recipient signs up to receive their mailings. Automatic, nonconsensual tracking doesn’t have to be the default, and it shouldn’t be.

We hope our approach works and it inspires others. It shouldn’t be an abnormality that users are not tracked by default, and that only users who feel comfortable doing so choose to consent to tracking. We hope that our example will show mailing platforms, organizations, and users that a privacy-protective approach is better and worth doing and can still give an email sender a solid understanding what campaigns and other messages resonate with recipients. We weighed this decision carefully. We know that email tracking is something we've criticized when used covertly or without meaningful consent and that many people don’t like at all. For EFF, an opt-in requirement isn't a formality. It's the key distinction between a sneaky strategy and an aboveboard relationship with you. And to us, it’s just a common sense approach based on respect.

It’s also consistent with our advocacy and approach to technology. We have said for many years that strong consumer privacy laws must require real opt-in consent before data is collected. And we have walked our talk in other ways as well, including in pushing for Do Not Track policies and in Privacy Badger, which protects you from ads and trackers that violate the principle of user consent.

Again, this behavior has been our suggestion for privacy policies, and privacy laws. In 2022 we released a guide for nonprofits that recommended the following:

Not tracking email open rates can, unfortunately, sometimes cause list “hygiene” problems, because it becomes difficult to know whether email subscribers on your list are still interested. You can send occasional emails to ensure subscribers want to receive emails, either using open or click tracking, and informing people that the purpose of that specific email is to determine active subscribers. The essential point is to let users know when you are using tracking, and to do it in a limited way when possible....

The Internet Archive found that while they preferred to use no open tracking in their emails to subscribers, too many unreachable email addresses had been added to their list over the years, and some email addresses had even become spam traps. To continue working with their email service provider, they needed to activate some tracking. They needed email open data to know whether an email address was still active or not; but they didn’t need or want gender, age, or demographic data. They settled on informing users that their email open rates are being tracked, and offering the alternate option to sign up for plain-text versions of their emails, which won't transmit any data at all.

In 2019, we recommended that all strong consumer privacy laws must include opt-in consent for data collection. We wrote:

Right to opt-in consent

New legislation should require the operators of online services to obtain opt-in consent to collect, use, or share personal data, particularly where that collection, use, or transfer is not necessary to provide the service.

Any request for opt-in consent should be easy to understand and clearly advise the user what data the operator seeks to gather, how they will use it, how long they will keep it, and with whom they will share it. This opt-in consent should also be ongoing—that is, the request should be renewed any time the operator wishes to use or share data in a new way, or gather a new kind of data. And the user should be able to withdraw consent, including for particular purposes, at any time.

Opt-in consent is better than opt-out consent. The default should be against collecting, using, and sharing personal information. Many consumers cannot or will not alter the defaults in the technologies they use, even if they prefer that companies do not collect their information.

We are sticking to those recommendations, which unfortunately are not yet the law, and following our principles.

We hope that you will feel comfortable opting in, but we also respect that you need to make that decision for yourself, and that you may need to change it as you go. We’ll do our part to make that as clear and easy as possible. And if you do agree, we’ll be grateful for getting a chance to learn a little more about how we’re doing, hopefully in ways that can make us even more effective at ensuring that technology supports freedom, justice and innovation for all the people of the world.

Other Changes: Clarity and Stronger Protections

The rest of the update is largely about being more precise and provide more transparency into our practices.

Cookies on eff.org: The new policy tightens our cookie practices. Previously, we carved out exceptions for "remember me" and logged-in users; now we don't use persistent ID cookies on the eff.org domain at all. We also clarified that other EFF-operated sites‚ like acteff.org and shopeff.org‚ have their own cookie policies and that our policies aren’t the ones that apply there. We’re not happy that you have to navigate multiple policies like this, but it’s one of the ways that the cookie ecosystem has gotten unfortunately complex. We want to be sure you know that and know where to look for all the information.

Third-party tool transparency: Similarly, while the vast majority of EFF’s public-facing websites, online tools and tech projects are created internally, self-hosted, and self-maintained, some of them are not. In this new policy, we are working to be more detailed and explicit in the new policy about those third-party services, and how they operate under their own privacy policies, not solely ours.

To help you understand exactly what choices you have when using these tools, we're publishing dedicated Privacy Guides for each of them. The first is live now for our shop, which runs on Shopify: EFF Shopify Privacy Guide. Guides for our other third-party tools are coming soon. As always, we recommend installing Privacy Badger to limit exposure from third-party tracking.

Overall, EFF believes that when a project like the Atlas of Surveillance doesn't exist, and we think it should, we build it and maintain it. But what matters most to us is protecting your digital rights. So the time required to maintain and upgrade the tools we have built has to be weighed against our need to build new projects to fight new fights. And sometimes, a tool that was needed when we built it, like EFF’s Action Center, can be replaced by something that can take some of the weight off our internal staff.

To help make space for new projects, we carefully investigate services we rely on—like our campaign tools, payment processors, and online shop—and look for third party options that are the best in the industry and offer a level of privacy our users deserve. In this new privacy policy we try to give you as much information about those third-party services as we can.

GDPR data management: We added a clear, dedicated process for users in the EU and elsewhere to request deletion of their personal data. Email info@eff.org with the subject line "GDPR Data Deletion Request" and we'll respond within the legally required timeframe.

Data retention: We reorganized and clarified how long we keep different types of records (communications, financial records, donation paperwork) into a cleaner list. The substance is unchanged, but the structure should make it easier to find what's relevant to you.

Action Center: You may notice that the previous policy included a dedicated section on our Action Center - how we handled your campaign participation data, what we retained, and so on. That section is gone because we're transitioning our campaign tools to a third-party provider. This is the kind of situation the new third-party transparency language addresses: that provider operates under its own privacy policy, which we'll link to in its dedicated Privacy Guide. Our commitment to your privacy in those contexts doesn't change‚ it just lives in a different place now.

What Hasn't Changed

The fundamentals remain what they've always been: we don't sell your information, we don't share it with third parties without your real (not manufactured or dark-patterned) consent, outside of legal requirements we cannot change. We actively push back on legal demands we believe are improper. EFF's mission is to protect your digital rights, and our own practices will continue to reflect that. The changes we’ve described above will help us in that mission.

support EFF

You can read the full updated policy at eff.org/policy. If you have questions, we're always reachable at info@eff.org.

The “Why” Behind NextWave’s New Requirements

14 May 2026 at 15:00

Helping Partners Stay Competitive for the Future

Key Takeaways

  • The evolved NextWave Partner Program raises expectations while strengthening enablement, incentives and the Partner Development Fund to support partner growth and reinvestment.
  • Levels and specializations are more closely aligned to next-generation security priorities, helping partners deepen expertise and making partner distinctions more meaningful for customers.
  • These changes help create a more capable partner ecosystem, with deeper capabilities, greater alignment with customer needs, and a stronger foundation to support the future of security.

Cybersecurity partnerships are operating in a more demanding environment. As customers consolidate vendors, modernize security architectures and adopt artificial intelligence (AI) across the enterprise, they’re placing greater expectations on partners to help guide decisions across network, cloud and security operations. They also want clearer evidence that their selected partners have invested in growing the skills and expertise needed to support more integrated and fast-changing security priorities.

The Palo Alto Networks NextWave Partner Program has evolved to help partners meet these heightened expectations. As security delivery becomes broader and more strategic, customers are placing more weight on what a partner’s credentials actually represent. That’s why stronger performance and enablement requirements are part of our reimagined program. The new requirements help partners better understand what they need to build real capability and advance within our program. They also give more substance to the designations customers see when choosing a partner.

Our objective was never simply to raise the standards for engagement in our program. It was to inspire partners at all levels – Registered, Innovator, Platinum and Diamond – to invest deliberately and continuously in learning, so they can deepen their proficiency and earn specializations that will help them stay competitive and build and deliver the future of security.

Why Requirements and Incentives Had to Evolve Together

Raising performance expectations was only part of the work in evolving the NextWave program. We also wanted to give our partners compelling reasons to invest in the capabilities Palo Alto Networks wants to see scale. That meant looking more closely at how standards, specializations and incentives fit together, and how we can help accelerate mutual success.

We are providing our partners with better access, better visibility and better support for learning and enablement. In turn, we are recognizing and rewarding partners for their efforts to develop and maintain the competency, capability and capacity needed to go to market successfully with Palo Alto Networks.

This approach, shaped largely by partner feedback, is designed to make incentives easier to access while still directing partner investment toward deeper specialization and next-gen security capabilities. Program levels and product specializations help define what partners need to do to grow within our program and to excel at selling, supporting or delivering Palo Alto Networks products and services.

The program’s Partner Development Fund adds another dimension to this evolved model. It gives all partners a more deliberate way to reinvest a portion of their earned incentives into the capabilities they need to stay competitive and innovate, including training, certification, workshops, demos and other strategic activities that help strengthen their team’s overall readiness over time. In that sense, the program is both rewarding current performance and driving mutual growth.

Training and Enablement that Move with the Market

As we continue to strengthen our partner program, Palo Alto Networks is refreshing courses, updating certification paths and redesigning training to better reflect the customer needs that partners are helping to address today, including emerging areas like AI security.

Notable improvements:

  • Introduced more online, on-demand learning experiences across all products and across all roles, including sales, technical presales and post-sales professionals.
  • Expanded access to lab environments for hands-on experiences, as well as access to perform demos for customers.
  • Injected AI roleplay into learning experiences to help sales and presales teams improve their ability to educate customers about our products and services while addressing questions or concerns.
  • Instituted a continuous education component that encourages partners to stay current with certifications and other program requirements, so they don’t need to be tested annually.

Our aim with these changes is to keep learning options relevant, practical and easier to engage in and apply in practice. We believe product and services training should help partners deepen expertise, validate skills and stay current as technologies, customer expectations and threats shift. It should also recognize the experience many professionals already bring to the table, with learning paths that are rigorous without being repetitive or unnecessarily burdensome.

Ultimately, the impact of providing more effective enablement for our partners (and outlining clear requirements for advanced specializations and total certified staff for specific partner paths) positively impacts the customer experience through more informed conversations, stronger design guidance and more consistent support across the entire security lifecycle.

A More Focused Program to Help Accelerate Next-Generation Security

Part of what makes the current evolution of the NextWave program so significant is its focus on helping partners build the bench strength they will need to stay competitive as security becomes more platform-driven, AI-influenced and interconnected across domains. The program also encourages bookings tied to next-generation security priorities, helping direct partner investment toward the areas customers are prioritizing most. That focus is especially visible in areas such as Idira®Prisma® SASE, Cortex® Cloud™ and Cortex, where customer demand and program priorities are increasingly aligned.

The benefits of that alignment extend beyond the partner organization. Customers gain access to partners that are better prepared to support more connected security strategies without adding unnecessary complexity. They can work with partners that are building expertise around the technologies and use cases becoming more central to modern enterprise security programs.

This kind of alignment also strengthens the broader ecosystem. It creates a clearer connection between customer needs, partner capabilities and Palo Alto Networks platform strategy. It’s the value exchange in cybersecurity in action: Ongoing investment in knowledge, skills and services that helps partners grow while giving customers faster time-to-value realization.

What Stronger Program Requirements Mean for Customers

For customers, stronger requirements for our Nextwave program can make partner distinctions more meaningful. A specialization or program level should point to something real, such as training completed, certifications maintained and expertise developed. While those accomplishments don’t guarantee security outcomes, they do provide evidence that a partner has built the depth needed to support more complex environments.

Partner distinctions are also reinforced through an active compliance framework rather than treated as a one-time achievement. Partners have ongoing visibility into their progress and can be recognized immediately throughout the year as they meet requirements. Reviews take place on a defined cycle, and status changes are subject to oversight. Taken together, these elements add credibility to the designations customers see and give them more weight in the partner selection process.

This becomes increasingly important as customers look for security partners that can do more than support a single transaction or product decision. Many are seeking guidance at the architecture stage and during implementation, and expecting continuity as IT environments evolve and new risks emerge. It also raises the level of scrutiny that partner selection deserves:

  • Is a partner specialized in the areas most relevant to the customer’s priorities?
  • Do they have the certifications and technical expertise required to support the solutions being considered?
  • Can they provide the level of guidance, implementation support and ongoing engagement the relationship will require over time?

In a fast-moving security market, questions like these can help customers make more informed decisions about which partners are best equipped to deliver long-term value.

What Partners Should Do Now

Now that we’ve introduced our new program requirements, partners should take stock of whether their certifications, specializations and go-to-market priorities are aligned to where customer demand and the future of security are headed. Steps partners can take:

  • Evaluate your current book of business: Consider where you may be missing growth opportunities because the right specializations aren’t yet in place. Those gaps can affect both business momentum and the ability to earn incentives.
  • Reflect on the current direction of your practice: Which customer conversations are signaling the need for deeper expertise? Which areas of next-generation security are becoming more central to your future? These questions can help guide your next investments by clarifying where your practice needs to build more depth sooner rather than later.
  • Review certifications and specializations with growth in mind: Look at where new specializations could open the door to additional incentives and stronger alignment with customer demand, while ensuring your team’s existing certifications and specializations remain on track for the next compliance cycle.

Partners that take the time now to assess our new requirements and create a plan to meet them will be better positioned to advance within and benefit from our partner program, while developing the capabilities needed to help build the future of security.

Partners with a designated Palo Alto Networks Channel Business Manager can get detailed data and analysis now on their progress and performance in the Nextwave program, including the status of their certifications and which team members have engaged in training, demos and more. In the second half of 2026, we plan to make the same dashboard capabilities and insights directly available to all partners, so they can understand exactly what they need to do to excel in our program. These red-yellow-green dashboards are simple but powerful tools, and we are eager to put them in our partners’ hands soon.

Visit the NextWave Partner Portal to learn more.

The post The “Why” Behind NextWave’s New Requirements appeared first on Palo Alto Networks Blog.

Beyond the Frontier — Expanding the Ecosystem for Autonomous Defense

13 May 2026 at 21:00

Over the past few weeks, we have reached a critical turning point in cybersecurity. Following the launch of our Frontier AI Defense initiative, we’ve continued testing the latest frontier models (including Anthropic’s Mythos and Claude Opus 4.7, as well as OpenAI’s GPT-5.5-Cyber) as part of the Trusted Access for Cyber program.

The urgency to innovate continues to ramp up. As Lee Klarich recently detailed in his Defender's Guide to the Frontier AI Impact on Cybersecurity, our current landscape is defined by a brief three-to-five-month window to gain a strategic advantage over attackers. To outsmart AI-based exploits, enterprises must decisively address vulnerabilities across their code and stand up the right security stack to enable real-time, automated defenses.

With such a ticking clock in front of us, acting rapidly and at-scale to support our customers is paramount. Today, we exponentially grow our scale of delivery by expanding our Frontier AI Alliance.

Since introducing this initiative, our collaboration with initial partners – Accenture, Deloitte, IBM, NTT DATA, and PwC – has already begun changing the defensive math for our customers. This is a moment that calls for radical collaboration across the entire security ecosystem, so today we are proud to welcome a new cohort of strategic partners – Cognizant, HCLTech, Kyndryl, TCS, Infosys, McKinsey & Company, Orange Cyberdefense, and Wipro – who will join us in delivering AI readiness at scale.

Frontier AI Alliance

While this expansion significantly increases our reach, this is only the beginning. We are committed to a continuous evolution of this alliance and will be adding more critical partners in the future across the globe to ensure our customers have the most robust defense network possible.

By combining our technology with these partners’ deep consulting expertise, we are delivering:

  • Machine-Speed Security: Natively integrating Frontier AI to provide real-time, automated defense against autonomous threats.
  • Intelligence-Led Resilience: Leveraging Unit 42® experts to fast-track the discovery and remediation of exposures at machine speed.
  • Hardened Defenses: Utilizing early access to frontier models from partners like OpenAI and Anthropic to simulate and block attack chains before they hit the mainstream.

The stakes are high. The attack cycle has compressed with the time from initial access to data exfiltration collapsing to just 39 seconds. Machine-speed MTTR (mean time to respond) is no longer an ambitious goal, it is a requirement.

This initiative underscores our commitment to providing every client with integrated, real-time protection.

Discover further details: Palo Alto Networks Frontier AI Defense.

Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.  All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

The post Beyond the Frontier — Expanding the Ecosystem for Autonomous Defense appeared first on Palo Alto Networks Blog.

❌