Palo Alto Networks Launches Agentic AI Security Service Using Anthropic and OpenAI Models

Palo Alto Networks launched Unit 42 Continuous Frontier AI Defense, an always-on offensive-security service using gated Anthropic and OpenAI models to find, validate and help remediate enterprise exposures.

John Miller
Written by John Miller
Published
Share

Palo Alto Networks has launched Unit 42 Continuous Frontier AI Defense, a new agentic offensive-security service that uses advanced AI models from Anthropic and OpenAI to continuously search for, validate and help remediate enterprise security exposures. The service is built around a proprietary multi-model harness that Palo Alto Networks says can route different security tasks to the model best suited for the job.

The company said the service uses gated capability models including Anthropic Claude Mythos 5 and OpenAI GPT-5.6-Cyber, alongside open-weight models. Rather than treating AI-assisted security testing as a periodic assessment, Palo Alto Networks is positioning the offering as an always-on process that can adapt as an organization’s systems change.

The launch extends Unit 42’s Frontier AI Defense work, which began earlier this year with point-in-time exposure analysis and security planning. Palo Alto Networks said the new version is available worldwide through annual subscriptions, with options that vary depending on the OpenAI, Anthropic and open-source models used.

Continuous testing replaces a one-time assessment model

According to Palo Alto Networks’ announcement, Continuous Frontier AI Defense starts with a full-estate baseline scan and then keeps testing as an organization’s environment changes. The aim is to identify vulnerabilities, misconfigurations, exposed assets and attack paths before they can be weaponized.

The service combines frontier AI models with Unit 42 threat intelligence and offensive-security expertise. Palo Alto Networks describes the multi-model harness as software that routes work to the model most appropriate for a particular task, a design intended to improve coverage while managing the cost of using highly capable models at scale.

That matters because the models are not being used only to flag possible weaknesses. The service is also designed to validate whether a weakness can be exploited and how an attacker could move through an environment after gaining access. Palo Alto Networks said the adversary-simulation component can test first- and third-party web applications, APIs, cloud infrastructure, source-code repositories and network assets.

The remediation layer is meant to turn those findings into prioritized fixes. The company said customers can receive code-level guidance and virtual-patch recommendations, and can pair the service with its Frontier Virtual Patching offering when a traditional software patch is not yet available.

Anthropic and OpenAI models are used under controlled access

The service’s use of frontier models is notable because both vendors restrict access to some of their most capable cybersecurity systems. OpenAI says GPT-5.6-Cyber is available through its Daybreak Red program for approved users conducting authorized vulnerability research, exploit validation and security testing. In its Daybreak announcement, OpenAI said the model was trained to reduce refusals and improve performance on advanced cybersecurity tasks while remaining subject to identity verification, monitoring and approved-use controls.

Anthropic likewise limits access to its Mythos-class models because of their dual-use capabilities. Palo Alto Networks’ announcement specifically names Claude Mythos 5 as one of the gated models in the new service. Anthropic has described Mythos as a highly capable model for cybersecurity research and has tied access to vetted organizations and trusted-access programs.

Palo Alto Networks is not simply exposing those models directly to customers. Its pitch is that Unit 42 adds the controls, threat intelligence and human security expertise needed to use the models in an enterprise setting. The company says the service can choose among multiple models rather than relying on a single model for every task, which may matter when one model is stronger at vulnerability discovery and another is better suited to validation, reasoning or remediation guidance.

The approach also reflects a broader shift in cybersecurity. Frontier models can search large codebases, reason across complex software interactions and test attack chains far faster than a traditional manual review. Those same capabilities can help defenders find problems earlier, but they can also shorten the time available to fix weaknesses before attackers exploit them. Palo Alto Networks is betting that continuous AI-assisted testing will become necessary as that window narrows.

Palo Alto Networks cites early testing across more than 100 engagements

Palo Alto Networks said it developed and tested the approach over six months and across more than 100 Unit 42 customer engagements, supported by a $17 million investment in research and methodology development. Those figures are company-reported and have not been independently verified by MarketReview.

The company also said its own internal deployment uncovered what it described as a year’s worth of exposures in three weeks. In customer assessments, Palo Alto Networks said Frontier AI Exposure Analysis found exposures in every customer tested, with 37% of those findings rated high or critical in severity. It added that most exposures came from first-party applications and that more than two-thirds of exposures found in third-party applications did not have a known CVE.

Those results are central to the company’s argument for continuous testing. A conventional penetration test gives security teams a snapshot of risk at a particular moment, but modern enterprise environments change constantly as code is deployed, cloud resources are reconfigured and third-party components are updated. Palo Alto Networks is trying to turn that snapshot into a persistent testing process that can repeatedly reassess the environment.

The commercial model is also different from a one-off consulting engagement. Continuous Frontier AI Defense is sold as an annual subscription, with the mix of models varying by plan. Palo Alto Networks says every subscription uses the multi-model harness to match AI models to specific security tasks.

The next test for the service will be whether enterprises see enough improvement in discovery and remediation speed to justify adding another continuous security layer to already complex cybersecurity stacks. For Palo Alto Networks, the launch gives Unit 42 a way to package frontier-model access, offensive-security expertise and threat intelligence into a recurring service at a time when AI is changing both sides of the security equation.

John Miller

About the author

John Miller

Economics Contributor

John Miller writes about the economic forces behind markets and financial decisions. He covers inflation, interest rates, employment, supply and demand, public policy and the channels through which economic changes affect investors, borrowers and households.

View author profile