Following the general availability of Prisma AIRS in July 2026, Palo Alto Networks is moving fast to transition from a standalone gateway to an embedded control plane — and the August-September release cycle shows where that ambition meets its current limits.
This picks up where our analysis of AI gateway category formation left off. That piece mapped three gateway lineages competing to own the security enforcement layer between enterprise users and large language models. Palo Alto’s post-GA momentum is the most aggressive move yet to resolve that competition by embedding directly into the model providers’ own environments.
Palo Alto reports that Prisma AIRS processed over 68 trillion tokens in the month surrounding its GA announcement (vendor-reported scale metric). The strategy is straightforward: rather than waiting for traffic to hit a gateway, Palo Alto is embedding Prisma AIRS directly into the enterprise environments of the two most significant model providers.
Native Integrations, Real Scope Limits
In August 2026, the company rolled out native integrations with OpenAI Codex Enterprise and Anthropic’s Claude Enterprise. The OpenAI integration allows administrators to route Codex prompts through Prisma AIRS for inline inspection, DLP, and threat detection directly from the OpenAI dashboard. The implementation does not require plugins, traffic steering, or developer workflow changes.
But infrastructure decision-makers must note the scope limitations: the current implementation does not scan assistant responses, tool calls, tool results, files, or images. It is a prompt-only filter. For agents that generate their risk through tool execution rather than prompt content, this leaves a significant inspection gap.
The Anthropic integration via inference hooks covers Claude, Claude.ai, Design, and Cowork — but it is restricted to text content and currently limited to the US region. Similarly, the new AI Discovery feature, which connects Prisma AIRS to Cortex Cloud AI-SPM for visibility across AWS, Azure, and GCP, is restricted to Americas SCM tenants.
These geographic and functional boundaries matter. For enterprises operating globally or relying on multimodal agent workflows, the native integrations cover a narrower slice of the attack surface than the marketing suggests.
From Gateway to Endpoint
By September 2026, the focus shifted to the developer workflow. The Cortex AES integration with Prisma AIRS combines endpoint governance with cloud-side inspection, targeting coding agents including Claude Code, Cursor, OpenAI Codex, GitHub Copilot, and Antigravity. AES enforces security verdicts directly on the endpoint, notifies developers inside the agent’s chat, and records every decision in the AES portal attributed to the device, agent, session, and policy.
This closes a gap the August integrations left open: rather than only inspecting prompts at the cloud level, the September integration brings enforcement to where developers actually work.
Agent-Specific Security Layers
Beyond traffic inspection, Palo Alto is layering in features designed for agentic workflows. AI Skill Security provides static analysis of skill packages before deployment, checking for risks including arbitrary code execution, secrets disclosure, data exfiltration, obfuscated behavior, and excessive permissions. Memory Poisoning Detection tests whether agents are vulnerable to attacks that corrupt persistent memory through normal conversation — a threat class that becomes relevant as agents store context across sessions.
These features address real gaps in the agent security stack. The question is whether they will consolidate into a coherent detection engine or remain separate products stitched together under a unified brand.
What Builders Should Watch
Palo Alto’s strategy to own the control plane by embedding directly into model providers’ enterprise environments creates a new dependency for infrastructure teams. Whether that dependency is worth accepting depends on two factors: whether your threat model aligns with the current, limited scope of these native integrations, and how fast Palo Alto can consolidate the detection engines behind the unified marketing.
The Codex integration not scanning tool calls means agents that execute code through MCP servers remain partially invisible. The Anthropic integration being US-only and text-only means global enterprises and multimodal workflows get incomplete coverage. For now, the two-gateway stack pattern we described in the category formation piece remains relevant: Prisma AIRS may be the first gate, but most enterprises will need a second layer for the traffic these native integrations miss.
Verification Note
All scale metrics (68T+ tokens processed) are vendor-reported, sourced from the July 2026 GA announcement. Product features and regional limitations are sourced from Palo Alto Networks’ official documentation. The characterization of Prisma AIRS as a stitched-together set of acquisitions comes from third-party security analysis and has not been independently verified by Forkast.
