Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Palo Alto Networks introduced Prisma AIRS in April 2025 as a platform for securing AI applications, models, datasets, and agents across their lifecycle. Its announced capabilities covered model scanning, AI posture management, automated red teaming, runtime security, and agent protection. The launch describes the company’s intended product scope—not independently verified security results—and the platform has since evolved, including Prisma AIRS 3.0 in March 2026 and general availability of its AI Gateway in July 2026.

What is Prisma AIRS?

Prisma AIRS is Palo Alto Networks’ AI security platform. The company introduced it on April 28, 2025, describing it as a way to discover, assess, and protect AI applications, models, datasets, and agents that an organization builds or uses. Its original launch grouped the offering into five areas: model scanning, AI posture management, AI red teaming, runtime security, and AI agent security. Palo Alto Networks’ launch announcement explains that initial scope.

That scope should be read as a product announcement, not proof that the platform prevents every listed attack. The cited company materials establish what Palo Alto said it was offering; they do not provide an independent efficacy assessment or a like-for-like competitive test.

How does Prisma AIRS protect AI apps, models, and agents?

The 2025 launch organized protection around different points in the AI lifecycle. The areas address distinct security questions rather than one interchangeable control:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Capability announced in 2025 What it is intended to address
Model scanning Vulnerabilities and potentially malicious content in AI models, including tampering, malicious scripts, and deserialization attacks.
AI posture management Configuration and ecosystem risks, such as excessive permissions and misconfigurations that can expose sensitive data.
AI red teaming Automated probing of AI applications and models for weaknesses before or during deployment.
Runtime security Threats arising as AI systems operate, including prompt injection, toxic content, and sensitive-data leakage.
AI agent security Agent-specific risks such as identity impersonation, memory manipulation, and misuse of tools.

These examples are Palo Alto’s stated threat coverage, not independently confirmed product outcomes. In practice, organizations evaluating the platform would need to establish which controls are available in their intended deployment, how they integrate with existing AI workflows, and how they perform against the organization’s own threat models.

What changed after the 2025 launch?

Protect AI acquisition completed

At launch, Palo Alto described its intent to acquire Protect AI. That is no longer a pending transaction: Palo Alto announced completion on July 22, 2025, and said Protect AI technology would be a cornerstone of Prisma AIRS. The company said the integration would contribute model scanning, posture management, AI red teaming, runtime protection, and agent security. The completion announcement establishes the acquisition status and Palo Alto’s stated integration plans.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Prisma AIRS 3.0 and AI Gateway

The April 2025 capability list is not a complete description of the current platform. Palo Alto announced Prisma AIRS 3.0 on March 23, 2026, describing discovery, assessment, and protection for agentic AI. On July 16, 2026, it announced that Prisma AIRS AI Gateway was generally available, with AI governance, identity, and runtime controls. See the AIRS 3.0 announcement and the AI Gateway availability announcement for Palo Alto’s release-specific descriptions.

Those dated releases show how the product has changed; they do not establish the exact feature entitlements, integrations, or deployment requirements available to every customer. Confirm current packaging and availability directly with Palo Alto before making a purchasing or architecture decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

What else did Palo Alto announce at RSA Conference 2025?

Prisma SASE and Prisma Access Browser 2.0

The same April 2025 news cycle included Prisma SASE updates, including Prisma Access Browser 2.0. Palo Alto positioned the browser and related capabilities as a way to apply GenAI visibility and access policies, coach users when they handle sensitive data, detect evasive web attacks in the browser, and provide access to legacy applications through the browser. The broader announcement also included endpoint data loss prevention (DLP), branch application acceleration, a unified SASE agent, and expanded Oracle Cloud Infrastructure (OCI) presence. At the time, Palo Alto said the announced SASE features were expected to become generally available in Q4 FY25; that was a forecast, not confirmation of their current availability or packaging. The release is described in Palo Alto’s SASE announcement.

The company cited two figures in support of its browser-security framing: that 85% of work was happening in browsers, and that 44% of security incidents involved malicious activities initiated or enabled through employees’ browsers. Palo Alto attributed the 44% figure to the 2025 Unit 42 Incident Report. These are vendor-published figures, not a measurement of the effectiveness of Prisma Access Browser.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Cortex XSIAM 3.0

Another announcement discussed Cortex XSIAM 3.0, including Cortex Exposure Management and Advanced Email Security. Network World reported a customer statement from Chase Hymel, CISO of the State of Louisiana, who said the organization had reduced mean time to respond (MTTR) from over 24 hours to under two minutes and automated resolution of 86% of incidents. These are outcomes reported by that customer, not independently established typical results or a benchmark for other organizations. Network World’s coverage provides the reporting and attribution.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should an enterprise evaluate?

Prisma AIRS’ announced breadth may make it relevant to teams responsible for AI security, but a launch description alone cannot establish fit. Evaluate the product against the systems and controls your organization actually needs:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Coverage: Map your requirements across models, applications, datasets, agents, and runtime activity. Check whether the release and edition you are considering address each area.
  • Controls: Determine how posture visibility, permission management, red-team testing, and runtime prompt or response protections work in your environment.
  • Deployment and integration: Confirm supported architectures, connections to your AI development and operations workflows, and how controls affect users and applications.
  • Availability and packaging: Verify current availability, licensing, and feature entitlements for your region and intended deployment; announcement dates do not settle these details.
  • Evidence: Ask for evidence relevant to your own threat model and deployment. The cited announcements do not supply independent security efficacy results or a competitive product comparison.

In its original launch, Palo Alto executive Anand Oswal said Prisma AIRS would let organizations “discover, assess and protect every AI app, model, dataset and agent in your environment.” That statement conveys the company’s goal; the breadth of the claim is not an independent guarantee that every asset will be found or protected.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.