Exclusive: Palo Alto Networks' new service to fight AI hacks
Add Axios as your preferred source to
see more of our stories on Google.

Illustration: Annelise Capossela/Axios
Palo Alto Networks wants to fight AI with AI by setting a mix of frontier models and open-weight models loose on customers' networks around the clock to find vulnerabilities before hackers do.
Why it matters: It's the latest example of major cybersecurity vendors tapping AI agents to defend at the same speed and scale that AI is giving attackers.
Driving the news: Palo Alto Networks is rolling out a new subscription service Tuesday that allows customers to use a mix of gated frontier models — including Anthropic's Mythos 5 and OpenAI GPT-5.6-Cyber — and open-weight models to find security flaws on their systems and recommend fixes, the company shared first with Axios.
- The service continuously tests web apps, APIs, cloud infrastructure, source code repositories and network assets as a customer's environment changes, and attempts to string individual flaws together into viable attack paths.
- Customers can also pair the service with Palo Alto's virtual patching tools to mitigate vulnerabilities before an official patch is available.
The big picture: Security vendors are racing to keep pace as increasingly capable AI models give both attackers and defenders new tools.
- "The capability and technology continues to evolve much faster than you can create security for it," Palo Alto Networks CEO Nikesh Arora told Axios.
By the numbers: In Palo Alto Networks' own testing, the company found that no single AI model caught more than 40% of the vulnerabilities on a company's complex environment.
- At the same time, the vulnerabilities that Mythos 5 and GPT-5.6-Cyber found only overlapped less than 10% of the time.
Between the lines: Tapping multiple AI models in defense, alongside human expertise, is the future for the cyber industry, especially given that each model is trained on different data, Arora said.
What to watch: As AI expands into legal work, desktop tools and other enterprise applications, Arora said Palo Alto Networks will look at where enterprise AI adoption ends up concentrating to determine what it needs to secure next.
- "If you believe that half of what's going to happen or be possible with AI hasn't been invented yet, then half of that security is missing, too," Arora said.
Go deeper: Forget doomsday: The AI hacking crisis is already here
