An AI assistant can be wonderfully articulate about a decision it had no authority to make. In a financial-agent test published by Palo Alto Networks, an adversarial instruction dressed a withdrawal up as an internal test. The agent complied. The interesting failure was permission: a story about testing had become grounds for using a money-moving tool. The company’s red-team example makes a rather expensive distinction between an answer and an action.
- What it sells: security for AI models, applications and agents, from inspection to runtime enforcement.
- Where it came from: Palo Alto’s AI security work plus Protect AI, acquired in July 2025.
- Why buyers care: agents can call tools, expose data and spend money while sounding entirely reasonable.
- The commercial signal: Palo Alto reports more than 800 AIRS customers and over $100 million in ARR.
Prisma AIRS by Palo Alto is an attempt to put supervision around that new employee: the one who never sleeps, works very quickly, and has read too many instructions from strangers. Its customers are enterprises building or operating AI systems. Their security teams need to inspect the ingredients, test the behavior and control the resulting actions. A warning on the final paragraph of a chatbot answer arrives rather late if a tool has already done the damage.
A notebook was the first crime scene
One strand of this business began somewhere less theatrical than an autonomous agent. Protect AI emerged publicly in 2022 with NB Defense, a free security tool for Jupyter notebooks. Notebooks are working documents for data scientists: code, experiments and results live together. They are also places where secrets, sensitive data and vulnerable dependencies can accumulate. The first intervention met practitioners where they were already working.
The founders were Ian Swanson, Daryan Dehghanpisheh and Badar Ahmed. Their background included AI and machine-learning work at AWS and Oracle. That experience supplied a useful perspective: the security problem extended through the materials and processes used to build AI, well before a user typed a question. Protect AI would develop model scanning, research and runtime capabilities around that broader territory.

The early thesis needed adjustment. Swanson told GeekWire that an initial focus on adversarial machine learning had found little traction. Customers were deploying models at scale with security gaps in their infrastructure. ChatGPT then changed the buying conversation. His recollection was succinct: “The conversation at every boardroom flipped overnight.”
Protect AI bought Huntr, Rebuff, Laiyer AI and SydeLabs to assemble more of the required capabilities. Swanson said some investors had worried about this acquisition strategy while capital was still limited. The lesson for another founder is conditional: buying a small team can shorten the route to a complete product, provided integration costs and customer needs have been understood. A collection of acquisitions is only useful when the pieces work together.
The shopping bill was real
Protect AI raised $108.5 million across its seed, Series A and Series B rounds. The $60 million Series B announcement came on August 1, 2024, with Evolution Equity Partners leading. Palo Alto Networks introduced Prisma AIRS on April 28, 2025, and completed its Protect AI acquisition on July 22. October’s AIRS 2.0 release brought the acquired technology into the platform.
Palo Alto’s fiscal 2026 filing records $608 million in cash and $27 million in replacement awards attributable to the acquisition price.
That purchase accounting is a more useful number than an unlabelled deal estimate. It also explains a common identity muddle. The 2022 company is Protect AI. Prisma AIRS is the later Palo Alto platform, with capabilities originating both inside the parent and through acquisitions. Giving the product brand the startup’s entire biography makes the story wonderfully tidy and factually untidy.
Inspect the file. Then watch the action.
Start with the model. A downloaded AI artifact may include code as well as weights. Certain serialization formats can execute code when loaded. Protect AI’s open-source ModelScan checks supported formats for unsafe code without simply loading the model in the usual way. It gives developers a practical entry point and a reminder to scan before use, after training and before deployment.
The commercial AI Model Security offering scans within a customer’s environment and integrates with development workflows. That placement matters when the model itself contains proprietary intellectual property. A supply-chain check asks whether an artifact is safe to introduce; it does not establish that every answer the model will produce is sound.
Next comes adversarial testing. Red teaming deliberately tries to elicit unsafe behavior before ordinary users or attackers do. Runtime protection then inspects live interactions through network or API integration, applying policies against threats such as prompt injection and data leakage. Posture management and inventory help teams locate assets and assess the environment around them. These functions address different moments in the same lifecycle.
AIRS competes on the proposition that enterprises want these controls coordinated. The alternative may be a combination of narrower tools. Check Point AI Guardrails, through the Lakera API, for example, screens AI messages and agent tool interactions. Buyers should compare actual coverage, integration effort and detection behavior on their own workloads. A longer feature list is an invitation to investigate, rather than a performance verdict.
The gateway gets a vote
The March 23, 2026 Prisma AIRS 3.0 launch made agents the explicit focus: discover them, assess their risks and protect their execution. The distinction matters because an agent can chain together tools and carry a goal across several steps. A system may pass a test of one response and still fail when the response becomes a database query or a file operation.

Palo Alto closed its Koi acquisition in April to extend security to agentic endpoints, then closed Portkey in May. The AIRS AI Gateway became generally available on July 16. It places policy enforcement between AI applications, model providers and tool interactions, including MCP and agent-to-agent traffic. The advertised controls cover identity, permitted tools, runtime inspection, usage visibility and budgets.
Here security and finance share a desk. An agent with a runaway loop can consume an extravagant number of tokens without ever intending harm. A central budget policy gives the platform team a place to constrain that activity. The architectural condition is important: traffic needs to pass through an enforcement point. A beautifully configured gateway cannot govern a path that bypasses it.
The firewall needed better manners
One revealing product improvement sits in the March 2026 release notes. When the runtime firewall detected an AI threat, it could drop the packet and reset the connection. To the application, that looked like an ordinary network failure. The application could then retry, adding delay and work.
The custom error response gives applications a distinguishable security block, an HTTP response and an identifier tied to logs. This is a small design lesson with wide application: enforcement has to communicate. Developers need to know whether to retry, ask a user to change a request or stop. A defensive control that speaks only in broken connections makes its colleagues guess.
A defensive control that speaks only in broken connections makes its colleagues guess.
Who buys permission?
The audience spans security operations, platform engineering, AI teams and governance functions. A bank’s assistant, a retailer’s service agent and an internal coding tool may expose different assets, but each needs someone to define permitted behavior. Palo Alto’s NVIDIA Enterprise AI Factory collaboration puts AIRS on BlueField infrastructure; Accenture also described collaborating on enterprise agent guardrails at the 3.0 launch. The selling route reaches both infrastructure and implementation partners.
Commercial licensing uses Palo Alto’s Software NGFW credit pools and BYOL model; API intercept usage is token based. A deployment budget therefore needs to account for licensed capacity, traffic and integration work. The purchasing decision belongs beside architecture planning, where teams can identify which requests need inspection and which artifacts need scanning.
ARR measures recurring business on an annualized basis. It is distinct from revenue recognized during a reporting period.
On its September 1, 2026 earnings call, Palo Alto reported those adoption milestones within four quarters of general availability. They show a commercial audience for the problem. They do not prove that every threat is caught, or that every enterprise should buy the same arrangement.
The useful habits are available to any team: inspect a model before trusting its packaging; test what an agent can actually do; give tools limited credentials; make blocks intelligible. Repeat the tests when tools or workflows change. Model formats must be supported, policies must fit legitimate work, and permissions must be enforced where the action occurs. The charming assistant still needs an adult to decide which keys it receives.