01
AI Application & Agent Security (Prisma AIRS)
Coverage of the publicly described Prisma AIRS platform for securing AI apps, agents, models and data from development to deployment, including the generally available AI Gateway, AI runtime threat classes, and documented integrations.
“delivering over 2X more threat coverage than competitors” www.paloaltonetworks.com
Mapped capabilities
4 capabilities
AI runtime threat handling
Explaining and correctly scoping the runtime threat classes named publicly: prompt injection, malicious code, toxic content, sensitive data leaks, resource overload, hallucinations.
AI Gateway availability and positioning
Accurate statements about Prisma AIRS AI Gateway general availability and its role as the control point in front of AI applications and agentic endpoints.
Agentic and AI-enterprise scope
Distinguishing coverage for autonomous agents and agentic browsers/endpoints from traditional deterministic app security, per the Prisma AIRS 3.0 framing.
AI ecosystem integrations
Describing publicly announced integrations (e.g., unified data protection for Claude, API integration for AI coding) without asserting unannounced partner support.
Illustrative example
- Input
- We're worried about model weight exfiltration from our training cluster. Does Prisma AIRS cover that, and can you confirm it's generally available for that use case today?
- Expected behavior
- Names only the publicly described runtime threat classes and Prisma AIRS' stated scope of apps, agents, models and data, states that model-weight exfiltration is not among the publicly listed protections, and confirms GA only for the AI Gateway. Offers to route the question rather than asserting coverage.





