Skip to content
AI.info

The Pulse

Palo Alto Networks puts frontier AI on continuous attack duty

Palo Alto Networks launches Unit 42 Continuous Frontier AI Defense, a subscription service that uses Anthropic and OpenAI cyber models to find and validate enterprise vulnerabilities. The company says its testing found a year’s worth of exp

Palo Alto Networks puts frontier AI on continuous attack duty

AI.info Team ·

Some breach timelines are shrinking from weeks to hours, a compression of almost 97% that Palo Alto Networks says is changing the job of enterprise security teams. The company is responding with a subscription service that keeps frontier AI models testing customer environments instead of waiting for a scheduled assessment.

Announced on September 22, Unit 42 Continuous Frontier AI Defense uses Anthropic’s Claude Mythos 5, OpenAI’s GPT-5.6-Cyber and open-weight models to identify vulnerabilities, connect them into attack paths and recommend fixes. Palo Alto Networks says the service is available worldwide on annual subscriptions, with pricing dependent on the models included.

Three weeks for a year of exposures

Palo Alto Networks says it developed and tested the service over six months, using more than 100 Unit 42 customer engagements and a $17 million investment in research and development. During an internal deployment, the company found what it describes as a year’s worth of exposures in three weeks.

Customer assessments found exposures in every organization tested, according to the company. Thirty-seven percent of those exposures were rated high or critical in severity. Most came from first-party applications, while more than two-thirds of exposures in third-party applications had no known CVE attached to them.

Those figures come from Palo Alto Networks’ own assessments rather than an independent benchmark. The release does not identify the customers, disclose the total number of exposures found or provide a comparison with conventional penetration testing.

Why Palo Alto is using several models

The service is built around a proprietary multi-model harness that routes tasks to the model judged best suited to each job. Palo Alto Networks says the approach is intended to improve coverage, reduce blind spots between models and control the cost of running frontier systems at scale.

Continuous Frontier AI Defense starts with a full-estate baseline scan and then continues testing as an organization’s environment changes. Its scope includes first- and third-party web applications, application programming interfaces, cloud infrastructure, source-code repositories and network assets.

The system does not stop at listing weaknesses. Unit 42 says its offensive security experts validate whether findings can be exploited and chain individual flaws into end-to-end attack paths. The service then returns prioritized fixes, code-level guidance and recommendations for virtual patches.

Unit 42 moves from snapshots to ongoing testing

The launch extends Palo Alto Networks’ Unit 42 Frontier AI Defense service, introduced in April as a point-in-time exposure analysis followed by a security blueprint. In August, the company added access to OpenAI’s GPT-5.6-Cyber and Anthropic’s Claude Mythos 5 for its exposure-analysis work.

The new offering adds a continuous testing engine and automatic retesting when applications or environments change. Palo Alto Networks also says customers can pair the service with Frontier Virtual Patching to reduce exposure before a public disclosure or an official software fix is available.

“AI has created an asymmetric advantage for threat actors against organizations trying to defend at human speed. Modern cybersecurity requires machine-speed defense. We're combining Unit 42's offensive testing and threat intelligence expertise with industry-leading AI harnesses and exclusive access to gated capability models to give defenders back the upper hand.”

Sam Rubin, Senior Vice President of Unit 42, Palo Alto Networks

OpenAI and Anthropic supply the models

Palo Alto Networks is positioning the service as a joint operating layer for models from competing AI companies. McCall McIntyre, OpenAI’s head of global cyber partnerships, said defenders need frontier capabilities inside the tools and services they already use.

“Frontier AI is compressing the time it takes to find and exploit vulnerabilities, and defenders need frontier AI capabilities within the tools, workflows, and services they already trust. Through Daybreak and our work with Palo Alto Networks's Unit 42, we are pairing OpenAI GPT Cyber Models with deep security expertise, strong governance, and human judgment to help organizations validate the attack paths that matter and move from discovery to remediation at machine speed.”

McCall McIntyre, Head of Global Cyber Partnerships, OpenAI

Anthropic’s Michael Moore, identified in the release as its cybersecurity lead, said Claude Mythos had found flaws that had survived decades of human review and more than 10,000 high-severity vulnerabilities across software used worldwide. Palo Alto Networks’ service is designed to test those findings against real enterprise systems rather than treat model output as proof of compromise.

Continuous Frontier AI Defense is available globally, but Palo Alto Networks has not disclosed subscription prices or specific customer deployments. The immediate question for buyers is whether always-on offensive testing can produce enough validated findings to justify the cost without creating a new stream of false positives, operational interruptions or sensitive vulnerability data that must be managed.

Source

Palo Alto Networks

Explore

More articles