{"id":360994,"date":"2026-06-16T06:00:12","date_gmt":"2026-06-16T13:00:12","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=360994"},"modified":"2026-06-16T07:36:52","modified_gmt":"2026-06-16T14:36:52","slug":"securing-the-agentic-ai-frontier-with-palo-alto-networks-and-databricks","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2026\/06\/securing-the-agentic-ai-frontier-with-palo-alto-networks-and-databricks\/","title":{"rendered":"Securing the Agentic AI Frontier: Palo Alto Networks and Databricks Deliver a New Standard for AI Security"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">The rise of Agentic AI is rapidly reshaping the enterprise, yet its deployment opens a complex new frontier for cyber threats.\u00a0 As organizations race to harness the power of enterprise agents, the \"Data Estate\" has become the new perimeter. CISOs today face a high-stakes trade-off: enabling developers to build at the speed of AI while keeping proprietary data visible, governed, and secure across the entire AI lifecycle. This requires meticulously checking user inputs, agent outputs, and tool calls for threats like prompt injections, sensitive data loss, and malicious code, while simultaneously preventing autonomous agents from performing destructive actions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Securing the AI-driven enterprise requires a fundamental shift from reactive measures to proactive runtime protection. Palo Alto Networks and Databricks are delivering on that vision. Our partnership will integrate the <\/span><b>Prisma AIRS API <\/b><span style=\"font-weight: 400;\">with <\/span><b>Databricks Unity AI Gateway<\/b><span style=\"font-weight: 400;\">, embedding seamless security at runtime. This collaboration will enable organizations to innovate with AI agents, applications, models and MCP Servers at scale while maintaining a robust, policy-driven security posture. By combining the centralized AI governance and control capabilities of the Databricks platform with the runtime security protections of Palo Alto Networks, organizations can scale AI innovation without sacrificing visibility, compliance, or security.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">The Context: Why AI Security is Different<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">AI security represents a fundamental departure from traditional defense. Legacy tools are designed for structured threats, leaving them incapable of parsing the intent behind complex, conversational attacks. <\/span><span style=\"font-weight: 400;\">Furthermore, the integration of Retrieval-Augmented Generation (RAG) and autonomous workflows creates a dynamic attack surface that goes far beyond traditional data loss. Without AI-native oversight, organizations can face severe risks from prompt injections, custom topics, and toxic content manipulating model logic, to tool misuse, malware execution, and malicious URLs hijacking agent actions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Modern AI development requires more than just a perimeter; it requires contextual intelligence. By integrating Prisma AIRS directly into Databricks Unity AI Gateway, we will evolve security from a reactive layer into a <\/span><b>native pillar of the AI architecture.<\/b><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">The Joint Solution: Centralized Security at the Gateway<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">The most effective way to secure an entire AI environment is at the governance layer. Our integration focuses on Databricks Unity AI Gateway, which serves as the centralized interface for all AI activity within the Databricks environment. Unity AI Gateway is designed for managing, governing, and monitoring access to all models, agents and MCP Servers\u2014whether they are open-source models deployed within Databricks or external proprietary models. As organizations deploy more agents, applications, and models, centralized governance becomes critical. Unity AI Gateway provides a single control plane for AI usage, enabling teams to apply consistent policies, monitor activity, and manage access across AI workloads.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Through this integration, Unity AI Gateway will make real-time calls to the Prisma AIRS Runtime Security API for security inspection. Instead of managing fragmented security policies across dozens of individual applications, SecOps teams will be able to enforce consistent guardrails across the entire Agentic AI estate from one location, providing a single, unified enforcement point for all AI workloads.<\/span><\/p>\n<p><div style=\"max-width:100%\" data-width=\"954\"><span class=\"ar-custom\" style=\"padding-bottom:53.25%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"alignnone size-full wp-image-361009 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2026\/06\/image1-1.png\" alt=\"\" width=\"954\" height=\"508\" srcset=\"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2026\/06\/image1-1.png 954w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2026\/06\/image1-1-230x122.png 230w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2026\/06\/image1-1-500x266.png 500w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2026\/06\/image1-1-768x409.png 768w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2026\/06\/image1-1-510x272.png 510w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2026\/06\/image1-1-75x40.png 75w, https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2026\/06\/image1-1-563x300.png 563w\" sizes=\"auto, (max-width: 954px) 100vw, 954px\" \/><\/span><\/div><\/p>\n<h6><span style=\"font-weight: 400;\">Figure 1: Centralized AIRS guardrail configuration delivers instant protection across all applications, agents and MCP Servers without requiring client-side code refactoring<\/span><\/h6>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Mechanism: API Intercept for AI Runtime Security<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Prisma AIRS operates as an advanced inspection layer, leveraging its API Intercept capability to provide real-time security embedded directly into the application flow. By embedding Prisma AIRS directly into the workflow, we offer a seamless 'Security-as-Code' experience that unifies development and defense. Prisma AIRS intercepts AI prompts, responses, and MCP calls\u2014inspecting them in real time to enforce security policies with an immediate Go\/No-Go verdict or by sanitizing the data in transit. Prisma AIRS uses deep learning classifiers to detect data exfiltration risks, such as the presence of PII (Personally Identifiable Information), PHI, or PCI data. If sensitive data is found, it can be dynamically redacted or blocked based on corporate policy.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Key Benefits for the Enterprise<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">This integration isn't just about blocking threats\u2014it\u2019s about accelerating your AI roadmap. By removing the \"security friction\" that often slows down production deployments, we enable teams to move faster with confidence. Key benefits include:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Zero-Friction Governance:<\/b><span style=\"font-weight: 400;\"> Developers continue working within their familiar Databricks environment. Security is enforced via the Unity AI Gateway API, meaning there are no bulky agents to install and no complex architectural re-wiring required.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Prevention of Data Leakage:<\/b><span style=\"font-weight: 400;\"> Leverage Prisma AIRS\u2019s data classifiers to automatically protect sensitive intellectual property, preventing data leaks to public models and unauthorized users.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Resilience Against AI-Specific Attacks:<\/b><span style=\"font-weight: 400;\"> Protect your Unity AI Gateway deployments from emerging threats that standard network security tools cannot see, including prompt injection, toxic content, custom topics, malware detection and malicious URL detection.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Key Takeaway<\/span><\/h2>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Ease of use and unified Policy Management: <\/b><span style=\"font-weight: 400;\">Enable runtime security through the Unity AI Gateway to gain centralized control over security enforcement.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Audit-Ready Compliance:<\/b><span style=\"font-weight: 400;\"> Every transaction mediated by the Unity AI Gateway is logged with detailed security metadata, delivering enriched insights in Strata Cloud Manager. This provides the forensic trail required for regulatory compliance in highly governed industries like finance and healthcare.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Protection for Agentic Workflows:<\/b><span style=\"font-weight: 400;\"> Future-proof your multi-step AI agents against sophisticated Agentic Threats by inspecting function and tool calls within the runtime.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Looking Ahead<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">As agentic workflows and multi-step model interactions become the standard, a 'fail-closed' runtime security posture is no longer optional; it is foundational. The integration of Prisma AIRS API and Databricks Unity AI Gateway marks a definitive shift toward a future where enterprise AI is secure by default.\u00a0 By integrating Prisma AIRS API with the Databricks platform through Unity AI Gateway, organizations can centrally govern AI across models, agents, applications, and MCP servers while enforcing consistent runtime security policies. Together, Databricks and Palo Alto Networks are helping customers scale AI innovation with the control, visibility, and protection required for the agentic era.<\/span><\/p>\n<p>Are you ready to secure your AI workloads and agentic applications?<br \/>\n<a href=\"https:\/\/www.databricks.com\/blog\/ai-governance-data-ai-summit-2026-whats-new-unity-ai-gateway\" rel=\"nofollow,noopener\" ><b>check out the latest Databricks blog<\/b><\/a> and stay tuned for technical deep-dive sessions coming soon.<\/p>\n<p>&nbsp;<\/p>\n<p><b><i>Forward-Looking Statements<\/i><\/b><\/p>\n<p><i><span style=\"font-weight: 400;\">This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.\u00a0 All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.<\/span><\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The rise of Agentic AI is rapidly reshaping the enterprise, yet its deployment opens a complex new frontier for cyber threats.\u00a0 As organizations race to harness the power of enterprise agents, the &hellip;<\/p>\n","protected":false},"author":840,"featured_media":361035,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[9943,308],"tags":[10756],"coauthors":[10226,10184],"class_list":["post-360994","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-security","category-announcement","tag-databricks"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2026\/06\/iStock-1407863764-scaled.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/360994","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/840"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=360994"}],"version-history":[{"count":15,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/360994\/revisions"}],"predecessor-version":[{"id":361048,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/360994\/revisions\/361048"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/361035"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=360994"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=360994"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=360994"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=360994"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}