Palo Alto Networks tackles the risks of autonomous AI agents
AI agent security now has to govern what autonomous software can do, not just what it can say.
The shift from chatbots to autonomous agents changes the enterprise risk equation now that agents can access tools, retain information and act without waiting for a human prompt. Palo Alto Networks Inc. is addressing that change through Prisma AIRS integrations designed to inspect agent activity within Google Cloud environments. According to Spencer Thellmann (pictured), principal product manager at Palo Alto Networks, the larger challenge is that the same capabilities making agents useful also create their most consequential vulnerabilities.
“We can’t treat agents like a chatbot,” Thellmann said. “Agents are autonomous applications that take action on behalf of users or other agents. They do this by invoking tools, and they have memory, both short and long term, just like you and I do. It’s those things that make an agent powerful – their autonomy, their memory and their tool use – that also make them uniquely dangerous.”
Thellmann spoke with theCUBE’s John Furrier for the Google Cloud: AI Agents in Action Series on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how Palo Alto Networks is securing autonomous agents, model activity and tool interactions within Google Cloud. (* Disclosure below.)
AI agent security moves beyond prompts
Traditional chatbot security largely concentrates on inspecting inputs and responses for prompt injection, data leakage or harmful content. Autonomous agents require broader oversight because they may call external services, manipulate enterprise resources or coordinate with other agents. Security controls therefore must evaluate intent and behavior while activity is happening, Thellmann noted.
“A flip side of autonomy is your agent can do anything, which means it can do anything,” he said. “That could include doing things like deleting production databases, which no one wants happening. Tools can be manipulated. Memory can as well.”
The scale of agent deployment compounds the problem. Enterprises may eventually operate far more agents than employees, leaving security teams to interpret continuous activity from nonhuman identities. Static policies alone will struggle to distinguish a legitimate automated task from an action that is technically permitted but operationally dangerous, Thellmann emphasized.
“You’ll have these autonomous beings, non-humans, within your network that are just doing things all the time, either in isolation or together,” he added. “Reconciling what they’re doing and making a deterministic call as to whether or not that should happen is the sort of next frontier for AI security.”
Runtime controls follow agents into production
Security products also need to operate inside the platforms where developers build and deploy agents. Palo Alto Networks has announced an integration of Prisma AIRS runtime security with Google Cloud’s Agent Gateway, a component of the Gemini Enterprise Agent Platform, with broader availability expected this fall. The connection is intended to inspect tool calls as they pass between agents and external systems, according to Thellmann.
“How this works is through service extensions, where by adding a service extension to the gateway, I can today use it to send all MCP tool calls and responses to Prisma AIRS API for inspection,” he said. “We’re going to broaden that in the fall by extending the capability to also scan all user inputs and outputs to Gemini Enterprise Agent Platform agents.”
Model Context Protocol connections present a two-way exposure. Sensitive credentials can leave an enterprise through an agent request, while a compromised MCP server can return malicious links, malware or instructions embedded in tool descriptions. Runtime inspection therefore must assess the request, the response and the metadata surrounding the transaction, Thellmann pointed out.
“A server that’s legitimate today could be sort of illegitimate tomorrow,” he said. “One area where we see that is in tool descriptions, where the description of a tool can contain an indirect prompt injection attack, which could do something like coerce an agent into leaking its conversation history to someone who shouldn’t have access to it.”
Agents begin policing the AI supply chain
Agent-based security is also extending into model governance. Palo Alto Networks has packaged its model-scanning service as an agent available through Google Cloud Marketplace. The system examines model files against policies configured in Strata Cloud Manager, allowing organizations to check licensing, publisher verification and suspicious components before deployment.
“The cool thing about this is that because it’s built on ultimately an A2A card … other agents can talk to it now,” Thellmann said. “If you have some kind of agent that’s responsible for pulling models from the Internet and then running them in some kind of inference service, that agent could self-police itself by sending the model that it’s about to do something with to our model scanning agent for inspection.”
That model reflects a broader movement toward machine-to-machine security decisions. Rather than requiring a person to submit every model manually, an agent can request a policy verdict from another agent before continuing a workflow. Security becomes part of the automated process instead of a separate review imposed after development.
“All that I have to do is go to the marketplace, assuming that I already have a license for model scanning, and then I can spin up the agent within Gemini Enterprise Agent Platform,” Thellmann said. “I can start sending it models and getting verdicts back that match the policy that I’ve set up in Strata Cloud Manager.”
Demand for these controls is rising alongside enterprise agent adoption. Prisma AIRS more than tripled its customer base within three months, reflecting growing interest in model scanning, red teaming and runtime protection, according to Thellmann. Palo Alto Networks is now concentrating its product roadmap on securing agents across cloud platforms, software-as-a-service environments and endpoints.
“Our focus right now is singularly on AI agents because of some of the problems that we’ve discussed today,” he said. “I spend all of my waking hours thinking about how to help our customers secure their agents across cloud, SaaS platforms and endpoint agents. I think we’ll have more to tell you about those three areas soon.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of the Google Cloud: AI Agents in Action Series:
(* Disclosure: TheCUBE is a paid media partner for the Google Cloud: AI Agents in Action Series. Neither Google Cloud, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
Image: SiliconANGLE
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.