Palo Alto NetworksAI Security

    AI Runtime Security

    Runtime protection for AI apps, models, and data against AI-specific threats.

    Palo Alto Networks Prisma AIRS AI Runtime Security protects AI applications, models, and data at runtime — the point where compound AI systems are most exposed. It secures network, foundational, and AI-specific threats with one solution, via Network Intercept for application-layer inspection or API Intercept for agnostic, decryption-free protection of any model. Faltrox deploys and operates it as the runtime layer of AI security.

    Overview

    What AI Runtime Security is

    AI applications are attacked at runtime — when they call models, query vector databases, invoke plugins, and reach out to the internet. These AI-specific threats sit outside the reach of traditional security. AI Runtime Security is the Prisma AIRS capability that protects AI apps, models, and data precisely at that runtime layer.

    It offers two deployment modes: Network Intercept provides application-layer decoding and segmentation for thousands of apps and protocols, protecting 40+ models across AWS, Azure, and Google Cloud plus direct OpenAI API calls; API Intercept is fully agnostic and protects any public or private model without decryption overhead. Cloud-Delivered Security Services layer on best-in-class web, DNS, injection, and data protection, and east-west inspection covers containerised and virtualised workloads. Faltrox deploys it into the AI stack and operates the runtime protection.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    AI Applications

    Protects compound AI applications at the runtime layer where they are most exposed.

    02

    Any Model

    Secures 40+ models across the major clouds, plus direct OpenAI API calls, public or private.

    03

    AI-Specific Threats

    Prevents prompt injection, agentic threats, and AI-specific attacks in one solution.

    04

    Injection Attacks

    AI-powered prevention of 90%+ of zero-day command and SQL injection attacks.

    05

    Cloud Workloads

    East-west traffic inspection protects containerised and virtualised AI workloads.

    06

    Sensitive Data

    2x data-leakage coverage of rivals with 1,000+ predefined data patterns.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Deploy

      Choose Network Intercept for application-layer inspection or API Intercept for agnostic, decryption-free model protection.

    2. 02

      Inspect

      Traffic to and from AI models, apps, and data is inspected for network, foundational, and AI-specific threats.

    3. 03

      Prevent

      Cloud-Delivered Security Services block web attacks, DNS attacks, injection, and data leakage with best-in-class efficacy.

    4. 04

      Contain

      East-west inspection protects containerised and virtualised workloads and returns custom error responses on detection.

    5. 05

      Operate

      Faltrox places and tunes the AI Runtime Security instances and operates the runtime protection.

    Capabilities

    Key capabilities

    Network Intercept

    Application-layer decoding and segmentation for thousands of apps and protocols, protecting 40+ models.

    API Intercept

    Fully agnostic, decryption-free protection for any public or private model via API.

    Unified Threat Coverage

    Secures network, foundational, and AI-specific threats with a single solution.

    Injection Prevention

    AI-powered prevention of 90%+ of zero-day application command and SQL injection attacks.

    Web & DNS Protection

    40% better protection from web-based attacks, covering 25+ DNS attack types.

    Data Protection

    2x greater data-leakage coverage than rivals with 1,000+ predefined patterns.

    Advanced Malware Detection

    99% malware detection accuracy, 26% more detections than traditional sandboxes.

    East-West Inspection

    Built-in inspection protects containerised and virtualised AI workloads.

    Works with

    Part of the platform

    Palo Alto Networks products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Palo Alto Networks AI Runtime Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What is the difference between Network Intercept and API Intercept?

    Network Intercept inspects at the application layer — decoding and segmenting thousands of apps and protocols for deep protection. API Intercept is agnostic and API-based, protecting any public or private model without decryption overhead. Faltrox chooses the mode per deployment based on your architecture and performance needs.

    02What AI-specific threats does it stop?

    Prompt injection, agentic threats, and application command and SQL injection targeting AI apps — plus foundational and network threats — in one solution. It applies AI-powered prevention that stops over 90% of zero-day injection attacks.

    03Does it protect models we run ourselves?

    Yes — API Intercept is fully agnostic and protects any public or private model, and Network Intercept covers 40+ models across AWS, Azure, and Google Cloud. Self-hosted and cloud-provider models are both in scope.

    04How does it protect the data AI apps touch?

    With best-in-class data protection — 2x the data-leakage coverage of other cloud solutions and over 1,000 predefined data patterns — so sensitive data flowing through AI applications is detected and controlled.

    05How does Faltrox operate it?

    We place the AI Runtime Security instances in your AI stack, choose the intercept mode, tune the threat and data policies, and operate the runtime protection — delivering it as the runtime layer of managed AI security.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us