PALO ALTO, CA – July 25, 2026 – In a significant leap forward for enterprise AI adoption, Palo Alto Networks today announced the general availability of its Prisma AIRS AI Gateway, a groundbreaking AI control plane designed to unify and secure the rapidly expanding AI landscape within modern organizations. This pivotal launch addresses the growing chasm between the accelerating pace of AI innovation and the traditional, often lagging, security and governance frameworks. The company is integrating AI innovations acquired from its recent Portkey acquisition, demonstrating a swift commitment to providing a robust solution just weeks after the deal’s closure.
The enterprise world is undergoing a profound transformation, shifting from software-driven operations to an AI-orchestrated future. This paradigm shift, while promising unprecedented efficiency and innovation, inherently creates a tension between the need for rapid deployment (velocity) and the imperative for stringent oversight and risk mitigation (control). Palo Alto Networks asserts that a unified architecture is not merely beneficial but essential to navigate this duality. The Prisma AIRS AI Gateway aims to be that foundational element, providing organizations with the critical capabilities to scale AI initiatives securely and with comprehensive governance.
The Accelerating AI Footprint: A Growing Gap in Control
The urgency for such a solution is underscored by alarming data from Palo Alto Networks’ next-generation firewall telemetry. This data reveals a dramatic surge in Machine Control Plane (MCP) activity, climbing from a mere 11% late last year to a staggering 41.4% by mid-2026. This indicates a rapid integration and reliance on AI-powered systems for core business functions.
Complementing this, monthly AI transaction volume has experienced an astonishing twelve-fold increase over the same six-month period. More concerningly, some individual AI sessions have been observed transferring hundreds of megabytes of sensitive enterprise data outbound. This suggests that the AI footprint organizations can currently govern is likely the smallest it will ever be, with the exponential growth trajectory indicating a rapidly expanding attack surface and a widening control deficit.
The primary drivers of this rapid AI adoption are identified as coding assistants, enterprise agents, and copilots – tools that are deeply embedded in the workflows of development, operations, and business units. As these AI tools interact with enterprise data and systems, they inevitably export that data with each request. This creates a security and governance challenge of unprecedented scale and speed, demanding immediate attention from IT and security leaders.
The Collateral Damage of Unchecked AI Adoption
The current landscape of AI adoption within enterprises is characterized by a fundamental mismatch: the speed at which AI capabilities are being embraced far outpaces the development and implementation of robust security and governance infrastructure. This leaves organizations vulnerable in several critical areas:
- Shadow AI Proliferation: Teams, eager to leverage AI’s benefits, often deploy unsanctioned AI tools and models without proper IT oversight. This "shadow AI" creates blind spots, making it impossible to track usage, manage costs, or ensure compliance.
- Data Exfiltration Risks: The inherent nature of AI interactions, particularly with large language models (LLMs) and agentic systems, involves the transfer of data. Without proper controls, sensitive proprietary code, intellectual property, customer data, and even credentials can be inadvertently exposed or maliciously exfiltrated.
- Inconsistent Security Policies: Traditional security perimeters are ill-equipped to handle the distributed and dynamic nature of AI workloads. Applying consistent security policies across a multitude of AI agents, models, and interactions becomes a monumental task.
- Lack of Runtime Visibility and Control: Many existing solutions focus on static policy enforcement or network-level controls. They fail to provide granular visibility into what AI agents are actually doing at runtime or offer the ability to intervene and control their actions in real-time.
- Unmanageable Costs and Resource Drain: The rapid, often unmonitored, use of AI services can lead to unpredictable and spiraling costs, along with significant consumption of compute and network resources.
Faced with this complex and rapidly evolving threat landscape, most IT leaders find themselves at an impasse. They are often forced into one of two untenable extremes: either block AI traffic entirely, stifling innovation and productivity, or remain permissive, hoping to implement controls later, a strategy that inherently accepts significant risk. Both approaches are fundamentally flawed because they bypass the crucial step of real-time observation and control of AI agent behavior.
Accelerating AI Adoption with Unwavering Control: The Prisma AIRS AI Gateway Solution
To enable safe and scalable AI adoption, Palo Alto Networks posits that a single, unified control plane is indispensable. This control plane must sit strategically between every AI interaction, ensuring that all communication with backend AI models and agentic systems is governed and secured. The Prisma AIRS AI Gateway is engineered to fulfill this critical role, bringing together AI governance, identity, and runtime controls into a singular, cohesive platform.
With the AI Gateway, organizations can now:
- Gain Comprehensive Visibility: Understand precisely how AI is being used across the enterprise, identifying who is using what, for what purpose, and at what cost.
- Enforce Granular Governance: Define and enforce policies around approved AI models, tools, and access permissions, ensuring compliance and mitigating risks.
- Secure AI Interactions: Protect sensitive data and intellectual property from exfiltration, prevent malicious prompt injection attacks, and ensure the secure use of credentials.
- Manage Costs Effectively: Monitor and control AI spending through detailed usage tracking and budget enforcement mechanisms.
- Enable Secure Agentic Workflows: Establish trusted identities for AI agents and ensure they operate within defined parameters.
The Architecture of Trust: How the AI Gateway Operates
The Prisma AIRS AI Gateway is designed to be a central enforcement point, seamlessly integrated into the AI workflow. It sits inline between every AI interaction, connecting users and applications to model providers and agentic systems. This includes direct interactions between AI applications and LLMs, Machine Control Plane (MCP) tool calls, and Agent-to-Agent (A2A) communications.
Functionally, it acts as a unified gateway for LLMs, MCPs, and A2A interactions, providing a single point of enforcement for all operational and security controls. This architecture allows development teams to continue utilizing their preferred coding assistants, enterprise agents, and copilots without disruption, while the platform team gains centralized ownership and control over AI security and governance at the infrastructure layer.
The capabilities delivered through this unified control plane are multifaceted and comprehensive:
Unprecedented Observability for AI Deployments
A core tenet of the AI Gateway is its ability to provide a single, unified view of all AI activity. Every request, from any source, is mapped to this comprehensive view, allowing organizations to track:
- Usage Patterns: Who is using which AI tools and models, and how frequently.
- User and Project Identification: Pinpointing AI activity to specific users, teams, or projects for accountability and resource allocation.
- Token Counts: Monitoring the consumption of tokens by various LLMs, a key metric for cost management and performance analysis.
- Latency and Cost: Understanding the performance characteristics and financial implications of AI interactions.
This level of detailed telemetry empowers organizations to immediately identify and retire "shadow AI" infrastructure, bringing rogue AI deployments under central management and control.
Robust Governance for the AI-Powered Enterprise
The AI Gateway provides a centralized hub for defining and enforcing AI governance policies. This includes:
- Approved Model and Tool Catalog: Centrally define which AI models and external tools are permitted for use, eliminating the risk of developers accessing unvetted or malicious services.
- Seamless Integration with Developer Workflows: Policy enforcement occurs at the infrastructure layer, meaning developers do not need to reconfigure their tools or applications.
- FinOps and Usage Management: Detailed tracking of every request’s cost, token consumption, and latency, broken down by team or project. This enables instant answers to cost-related queries, the ability to shut down unsanctioned AI usage, and proactive enforcement of budgets and rate limits before access is granted.
Fortified Security for Coding Assistants and Proprietary Data
Coding assistants are powerful tools but can pose significant risks if not properly secured. The AI Gateway addresses these risks by:
- Credential Protection: Preventing the exposure of sensitive credentials, API keys, and access tokens that might be embedded in code or development environments.
- Proprietary Code Safeguarding: Ensuring that sensitive source code and intellectual property are not inadvertently shared with external AI models.
- Scoped Credentials: Replacing raw provider keys with dynamically generated, scoped credentials that are specific to each user and team, significantly reducing the blast radius of any potential compromise.
- Development System Security: Protecting critical development systems and infrastructure from risky AI actions.
Essential Operational Controls for AI Workflows
The AI Gateway acts as a crucial layer for enforcing operational policies and ensuring the smooth functioning of AI pipelines:
- Data Protection: Implementing policies to prevent the leakage of sensitive data in AI prompts and responses.
- Usage Limits and Rate Limiting: Enforcing predefined limits on AI usage per user, team, or project to prevent abuse and manage resource consumption.
- Policy Checks: Performing inline policy checks on AI interactions to ensure compliance with organizational standards.
- Universal API Distribution: Traffic is distributed across various AI providers via a Universal API, ensuring that quotas are strictly enforced and that service outages with one provider do not stall critical AI pipelines.
Establishing Trust Through Agent Identity Security
As AI agents become more autonomous and integrated into business processes, establishing their identity and trustworthiness is paramount. The AI Gateway facilitates this by:
- Verifiable Ephemeral Identities: Binding a verifiable, ephemeral identity to AI agents at the point of execution. This ensures that the identity is tied to the specific instance of the agent and its current operation.
- Authentication and Authorization: Acting as an enforcement point to ensure that only authenticated agents with approved identities can make authorized calls to AI models and services. This prevents unauthorized or spoofed agents from accessing sensitive resources.
Real-Time Runtime Security for AI Interactions
Leveraging the advanced capabilities of Prisma AIRS AI Runtime Security, the AI Gateway provides deep inspection of every AI interaction in real-time. This includes:
- Inline Prompt and Response Inspection: Analyzing both the input prompts sent to AI models and the responses received to detect and prevent threats.
- Protection Against Data Leakage: Stopping sensitive information, including source code, secrets, and customer data, from leaving the network.
- Neutralizing Prompt Injection Attacks: Actively detecting and neutralizing sophisticated prompt injection attempts, which are designed to manipulate AI models into unintended or malicious actions. This protection is aligned with the latest security best practices, including the OWASP LLM Top 10 and the OWASP Top 10 for Agentic Applications.
A Foundational Architecture for the Agentic Enterprise
Anand Oswal, Executive Vice President and General Manager of Palo Alto Networks’ Network Security business unit, emphasized the foundational role of an AI gateway in the modern enterprise architecture. He explained, "Every new AI agent creates another decision point. As enterprises embrace AI, they need a unified command center to manage these decision points. Our Prisma AIRS AI Gateway is built to be that command center, providing the visibility, governance, and security that organizations require to confidently scale their AI initiatives."
The Prisma AIRS AI Gateway is built upon an architecture that has been rigorously tested and proven in the most demanding enterprise environments, designed to handle the evolving and ever-increasing demands of AI workloads. Unlike point solutions that may focus on filtering text strings or routing single API calls, the AI Gateway is engineered for scale, capable of managing the sheer volume and complexity of enterprise-wide AI interactions.
Palo Alto Networks, recently recognized by Gartner as a "company to beat" in AI Security Platforms, is uniquely positioned to guide organizations through this transformative period. The launch of the Prisma AIRS AI Gateway signifies a commitment to providing the essential tools and expertise needed to build a secure and governable AI-powered future.
Organizations are encouraged to learn more about the Prisma AIRS AI Gateway and register for an upcoming webinar to witness its capabilities in action. As the agentic enterprise becomes a reality, Palo Alto Networks invites businesses to collaborate on building this future securely, together.
