Palo Alto NetworksAI Security

    Prisma AIRS

    An AI security platform that discovers, protects, and monitors your whole AI ecosystem.

    Palo Alto Networks Prisma AIRS (AI Runtime Security) defends the enterprise AI ecosystem against a new wave of threats that traditional security cannot address. It discovers your AI applications, models, users, and datasets automatically, protects models, data, and apps against AI-specific and foundational attacks, and monitors runtime risk continuously. Faltrox operates it as the security platform for enterprise AI adoption.

    Overview

    What Prisma AIRS is

    Integrating AI into applications is far more than plugging in a model — modern AI apps are "compound systems" that stitch together multiple models, plugins, vector databases, and internet search, each element introducing runtime vulnerabilities attackers can exploit. Traditional security tools cannot see or protect these AI-specific attack surfaces. Prisma AIRS is Palo Alto’s answer: an enterprise AI security platform built for exactly this.

    It does three things: discovers your AI ecosystem automatically (mapping applications to models, users, external sites, plugins, and data sources across AWS, Azure, and Google Cloud); protects models, data, and apps against AI-specific and foundational attacks through Network Intercept and API Intercept deployment; and monitors runtime risk exposure continuously. It protects 40+ models across the major clouds, secures containerised and virtualised workloads with east-west inspection, and layers on Cloud-Delivered Security Services. Faltrox operates it — mapping the AI estate, tuning protection, and monitoring runtime risk.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    AI Applications

    Discovers and protects the compound AI applications your organisation builds and runs.

    02

    AI Models

    Protects 40+ models across AWS, Azure, and Google Cloud, public or private.

    03

    AI-Specific Attacks

    Defends against prompt injection, agentic threats, and attacks traditional tools miss.

    04

    Data & Datasets

    Best-in-class data protection with 1,000+ predefined patterns and 2x coverage of rivals.

    05

    Cloud Workloads

    Protects containerised and virtualised workloads with built-in east-west traffic inspection.

    06

    Runtime Risk

    Monitors the runtime risk exposure of the whole AI ecosystem continuously.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Discover

      An intuitive onboarding process maps AI applications to their models, users, external sites, plugins, and data sources across your clouds.

    2. 02

      Visualise

      A Neuron view visualises the AI ecosystem and its interconnections, revealing complex and sometimes unknown relationships.

    3. 03

      Protect

      Network Intercept and API Intercept secure network, foundational, and AI-specific threats — with or without decryption overhead.

    4. 04

      Enforce

      Cloud-Delivered Security Services add web, DNS, injection, and data-leakage protection with best-in-class efficacy.

    5. 05

      Monitor

      Faltrox monitors runtime risk continuously and tunes protection as the AI estate evolves.

    Capabilities

    Key capabilities

    AI Ecosystem Discovery

    Automatically discovers AI applications, models, users, and datasets and maps their interconnections.

    Network Intercept

    Application-layer decoding and segmentation for thousands of apps, protecting 40+ models across the major clouds.

    API Intercept

    Agnostic API-based protection for any public or private model without decryption overhead.

    AI-Specific Threat Prevention

    AI-powered prevention of 90%+ of zero-day command and SQL injection and agentic threats.

    Data Protection

    2x greater data-leakage coverage than rivals with 1,000+ predefined data patterns.

    Advanced Malware Detection

    99% malware detection accuracy — 26% more detections than traditional sandboxes.

    East-West Inspection

    Protects containerised and virtualised workloads with built-in east-west traffic inspection.

    Continuous Risk Monitoring

    Continuously monitors the runtime risk exposure of the entire AI ecosystem.

    Works with

    Part of the platform

    Palo Alto Networks products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Palo Alto Networks Prisma AIRS for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What is a "compound AI system" and why does it change security?

    Modern AI apps are not a single model — they stitch together multiple models, plugins, vector databases, and search functions. Each element is a runtime attack surface, and traditional tools cannot see them. Prisma AIRS is built to discover and protect that whole compound system rather than just the model.

    02How does it protect models without decryption overhead?

    Through API Intercept — a fully agnostic, API-based deployment that secures any public or private model and protects AI apps, models, and data without the decryption overhead of inline network inspection. Network Intercept is available where full application-layer inspection is needed.

    03Does it work across multiple clouds?

    Yes — it discovers and protects AI usage across AWS, Microsoft Azure, and Google Cloud, protecting 40+ models and mapping the AI ecosystem consistently across all three.

    04How is Prisma AIRS different from the AI Runtime and Agent Security products?

    Prisma AIRS is the platform; AI Runtime Security and AI Agent Security are capabilities within it — runtime protection for AI apps and models, and control for agentic AI respectively. Faltrox scopes which components your AI adoption needs.

    05How does Faltrox operate it?

    We map your AI ecosystem, place and tune the AIRS instances, configure protection and data policies, and monitor runtime risk continuously — operating it as the security platform for your enterprise AI adoption alongside our AI/LLM penetration testing.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us