AI & Agentic · All-in-One

The AI
Conversation

One page to open twenty minutes before an AI meeting. How the whole portfolio fits together layer by layer, the opening line and two questions for whoever is in the room, current evidence you can actually cite, the ten things a technical seller must be able to explain, and the questions that get it started.

Sections are labelled Seller or Technical so you know what to skip. If you only have five minutes, read 02 Pick Your Room and the five openers in 06.

01 · Orientation Seller + Technical

The Map — How It All Fits Together

Thirteen layers, and the coverage is continuous — every layer’s edge is the next layer’s entry point. Read the handoff column as your route through the portfolio: it tells you which product picks the customer up next, and therefore which conversation you are earning the right to have.

Coverage at a glance

Six stages of a single AI interaction, the product that covers each, and the five layers that run underneath all of them. Validation caps the whole thing. Use this as the one slide you draw on a whiteboard.

VALIDATION — proves every layer below actually worked Unit 42 Frontier AI Defense with Claude Mythos 5 · AI Security Assessment THE PATH AN AI INTERACTION TAKES User & browser Prisma Browser AI Access Security STAGE 1 App / GenAI SaaS SaaS Agent Security AI Access Security STAGE 2 Agent & orchestration Prisma AIRS 3.0 Cortex AES / Koi STAGE 3 Tools & MCP AI Gateway (LLM/MCP/A2A) Cortex AES / Koi STAGE 4 Model Prisma AIRS model security STAGE 5 Data Enterprise DLP Cortex Data Security · preview STAGE 6 RUNS UNDER EVERY STAGE ABOVE Identity — every arrow above carries one Idira · zero standing privilege, just-in-time, identity per agent Network & inline enforcement PAN-OS 12.2 Ceres · Frontier Virtual Patching · Advanced IP Defense Reachability — the outside-in view Cortex Xpanse · all 65,000 ports, entire IPv4 space Detection, response & action Cortex XSIAM 3.6 + AgentiX 1.4 · XTI · human-approved gates Runtime behaviour & cost Chronosphere · tokens by model, evals as metrics, traces, tool-call reliability ORDER OF WORK 1 Inventory 2 Classify 3 Scope identity 4 Instrument 5 Enforce 6 Validate & report

Coverage matrix — which control function each layer delivers

A hollow marker is not a gap — it means the layer shares that job with an adjacent one, which is the point of a platform. Dashed means announced and not yet shipped, so treat it as roadmap.

LayerOwns itDiscoverGovernEnforceValidate
Employee GenAI app useAI Access Security
AI traffic, MCP, A2APrisma AIRS AI Gateway
Network / inlinePAN-OS 12.2 Ceres
Browser and workspacePrisma Browser
SaaS-embedded agentsSaaS Agent Security
Endpoint AI artifactsCortex AES / Koi
Built agents and modelsPrisma AIRS 3.0
DataEnterprise DLP · Cortex Data Security
Agent identity and privilegeIdira
External reachabilityCortex Xpanse
Detection and actionCortex XSIAM + AgentiX
Runtime behaviour and costChronosphere
Independent validationUnit 42 Frontier AI Defense
Covered by this layer Shared with an adjacent layer Announced, not shipped
Exposure layerPANW solution & what it doesWhere it hands off →What we operate on top
Employee GenAI app use
Prompts, uploads, unsanctioned SaaS AI — the workforce adopting tools nobody approved.
AI Access Security (Prisma SASE)
Categorises thousands of GenAI apps with individual risk scores, classifies them sanctioned / tolerated / unsanctioned, controls actions such as upload and download, and coaches users in-line so they can correct risky behaviour in the moment. Strata Copilot recommends policy based on real traffic.
Owns the app and the action at the network edge. Locally installed artifacts that never traverse the proxy are picked up by Cortex AES, and in-browser data movement by Prisma Browser. App-tier policy design, exception register, and the quarterly “what did the workforce actually adopt” report.
AI traffic, MCP and agent-to-agent
Every prompt, tool call and agent-to-agent message leaving the enterprise — the actual AI control plane.
Prisma AIRS AI Gateway — GA July 2026
Sits inline between every AI interaction, model provider and agentic interaction, acting as a unified LLM, MCP and A2A gateway with a single enforcement point. Universal API to models, agent registry, semantic routing and caching, prompt-injection protection aligned to the OWASP LLM Top 10 and the OWASP Top 10 for Agentic Applications. Came from the Portkey acquisition and shipped six weeks after close.
Owns the AI traffic path itself. What is installed is Cortex AES; per-agent least privilege arrives through the announced Idira integration that decouples agent permissions from human credentials. Gateway policy design, model routing and cost guardrails, MCP allow-listing, and the agent registry as an operational artifact.
Network and inline enforcement
The exploit that lands before anyone has patched — and the attacker infrastructure it comes from.
PAN-OS 12.2 Ceres · Advanced Threat Prevention Plus
Frontier Virtual Patching delivers network-level protections within hours of discovery, against a vendor patch cycle of 30–90 days, with no patch, reboot or downtime. Advanced IP Defense extends Precision AI to the network layer using 40+ security attributes, 1,600+ intelligence sources and live telemetry from 75,000+ CDSS deployments, identifying 50,000+ new malicious hosts a day and killing the 20-day intelligence lag. Six AI-powered Network Security Agents in Strata Cloud Manager automate onboarding, configuration, threat assessment and troubleshooting.
Removes the exploitation so the customer’s patch cycle can run properly rather than in a panic. Application, prompt and tool-call decisions step up to Prisma AIRS. Virtual-patching coverage validation, policy tuning, and the exposure-window report the customer takes to change control.
Browser and workspace
Where the AI use physically happens — and where data leaves in a paste.
Prisma Browser
Granular controls over sensitive data in GenAI apps with last-mile enforcement and 1,000+ data classifiers, embedded with AI Access Security for GenAI app visibility, access control, and data and threat protection. Now identifiable natively by the next-generation firewall (NGFW).
Owns the managed browser session. Agents running headless outside a browser step across to Cortex AES and the AI Gateway. Last-mile data policy, contractor and BYOD access design, and the coaching programme that keeps adoption visible.
SaaS-embedded agents
Copilots, plugins and low-code agents built inside SaaS platforms, often by people outside IT.
SaaS Agent Security / SSPM (Prisma SASE)
Discovers and monitors SaaS AI agents, copilots and plugins across more than ten agent platforms including Copilot Studio, ServiceNow AI Platform and Salesforce Agentforce; shows which touch sensitive data and enforces guardrails against excessive autonomy.
Owns the SaaS tier and the agents built inside it. Endpoint artifacts move to Cortex AES; model internals to Prisma AIRS. Agent ownership mapping, autonomy-scope review, and business-unit accountability for citizen-built agents.
Endpoint AI artifacts
Browser extensions, packages, MCP servers, agent skills and coding assistants living on user machines.
Cortex AES / Koi — Agentic Endpoint Security
Discovers every AI artifact on the agentic endpoint, assesses its risk, enforces prevention and runtime controls, and remediates violations. Now an integral part of the Cortex XDR agent — if the customer is on XDR 5.2 with agent 9.3 or later there is zero additional deployment. Otherwise the standalone product runs alongside an existing third-party EDR, or via a lightweight agentless script through EDR or MDM tooling.
Owns the artifact layer end to end. Runtime prompt and tool-call decisions belong to Prisma AIRS and the AI Gateway; encrypted traffic inspection to NGFW and Prisma Access. In CPS/OT/IoMT accounts the wedge is the privileged workstations with trusted paths in, not the operational devices. Triage, publisher and version policy, exception governance, and the AI-SBOM itself. This is the core recurring motion.
Built agents, models and AI apps
What the customer develops and runs themselves, including downloaded open-source models.
Prisma AIRS 3.0
Deep model inspection for architectural backdoors, poisoning and malicious code in model components; agent discovery and posture including shadow and inactive agents that still hold access; Agent Artifact Security; inline decisioning on agent tool calls that redacts secrets, validates permissions and blocks unsafe actions before execution; and autonomous AI Red Teaming returning a Risk Score of 0–100. Network Intercept and Microperimeter extend inspection to east-west traffic in private cloud data centres.
Owns everything the customer builds and runs. Third-party artifacts arriving on an endpoint step across to Cortex AES, and identity scoping to Idira. Red-team cadence ownership, finding triage, prompt and tool hardening, remediation tracking between scans.
Data — in motion and at rest
The question every buyer asks first: where does our data actually go?
Enterprise DLP · Cortex Data Security (public preview)
Enterprise DLP inspects content and blocks sensitive-data egress on known channels, with continuously expanding GenAI app coverage. Cortex Data Security entered public preview on 11 August 2026 as a unified data security platform including DSPM capabilities — discovery and classification of organisational data as an input to AI risk decisions.
Enterprise DLP carries today’s enforcement; Cortex Data Security is public preview, so position it as direction of travel rather than quoting it. Which agent may legitimately reach the data is answered by Idira. Data classification mapped to AI use cases, and the “which agents can legitimately reach regulated data” question nobody owns.
Agent identity and privilege
The credential an agent acts with — its own, a service account, or the launching human’s.
Idira (formerly CyberArk)
Extends privileged access controls to every human, machine and agentic identity with zero standing privilege and just-in-time enforcement, continuous discovery of every identity, entitlement and access path, and an automated identity lifecycle. Workforce Identity covers FIDO2-certified SSO, adaptive MFA at NIST AAL3 and passwordless as a direct IdP alternative.
Owns who the agent is and what it may do, for how long. What the agent then reads, calls and returns steps up to Prisma AIRS and the AI Gateway. Agent authorization design: identity per agent, scoped permissions, time bounds, and a revocation path someone owns.
External exposure and reachability
What an attacker can actually reach from an agent’s configuration.
Cortex Xpanse
Active external attack surface management giving an outside-in view — scans the entire IPv4 space across all 65,000 ports and 50+ protocols, up to several times a day, attributing assets with analyst and machine-learning evidence. Attack Surface Testing results can now raise alerts, and the Active Response add-on uses AI playbooks to identify service owners and remediate.
Owns the outside-in half of the picture. Paired with Cortex AES inside-out, the two together produce the ranked attack path neither can produce alone. Joining endpoint artifacts to reachable services and credential scope — the correlation that turns “we have an agent” into “here is the path, ranked.”
Detection, response and action
Where findings from every other layer become actual work.
Cortex XSIAM 3.6 + AgentiX 1.4
XSIAM consolidates SIEM, XDR, SOAR, ASM and threat intelligence on one data foundation, with Cortex Extended Threat Intel (XTI) across XSIAM 3.6, XDR 5.2 and AgentiX 1.4. AgentiX runs prebuilt and custom agents with 1,000+ integrations and native MCP support, inside existing roles and permissions, and lets you define when agents act independently versus requiring approval. Frontier model choice includes Claude Sonnet 4.6, Claude Opus 4.8 and Gemini 3.5 Flash. AgentiX holds FedRAMP Moderate and High.
Acts on the signal every layer above produces — which is exactly why discovery lands first and orchestration second. Sequencing it this way is what makes the platform conversation land. Content and playbook engineering, with blocklist and policy-changing actions registered as sensitive and human-approved.
Agent runtime behaviour and cost
What the agents actually did, how much it cost, and whether they were still accurate.
Chronosphere
OpenTelemetry GenAI support for real-time visibility into input, output and total token spend by model; semantic evaluations sent in as metrics so accuracy becomes a live trend; execution traces to debug agent logic; and tool-call reliability across dependencies. The read-only MCP Server exposes all of it to agent investigations, and the Temporal Knowledge Graph underpins AI Guided Troubleshooting.
Shipping today through the Telemetry Pipeline’s Cortex XSIAM destination plugin and the read-only MCP Server. The deeper AgentiX integration is the announced next step — land the two working paths now and the roadmap follows. Runaway-spend and drift thresholds, tool-call failure SLOs, and the pipeline cost-reduction business case.
Independent validation
Proof for the board, the auditor, and the customer questionnaire.
Unit 42 — Frontier AI Defense with Claude Mythos 5
Frontier AI Defense pairs frontier cyber models — expanded on 21 August 2026 with Anthropic’s Claude Mythos 5 — with Unit 42 offensive security experts and global telemetry to discover exposures, test exploitability live, validate end-to-end attack paths, and deliver prioritised remediation. A Multi-Model Harness routes each task to the best-suited model. The AI Security Assessment and External AI Hyperattack Assessment sit alongside it.
Proves the twelve layers above actually worked, and turns findings into a funded roadmap. PANW-delivered, so partner-led remediation and ongoing operations run alongside it. No public pricing yet — scope through your Unit 42 lead. Co-delivery and the remediation programme that turns an assessment into a funded roadmap.

Version gates and availability status — check these before you quote anything

Cortex AES is in the Cortex XDR agent from XDR 5.2 with agent 9.3 or later — zero additional deployment. Below that, it is the standalone product alongside the existing EDR.
Prisma AIRS AI Gateway is GA as of July 2026. The AI Agent Gateway was in limited preview at the March 3.0 launch — do not still be saying preview.
Cortex XTI spans XSIAM 3.6, XDR 5.2 and AgentiX 1.4. AgentiX holds FedRAMP Moderate and High.
Frontier model choice in Cortex: Claude Sonnet 4.6, Claude Opus 4.8, Gemini 3.5 Flash — selectable per task, with new models added as they ship.
Cortex Data Security is public preview (11 Aug 2026), not GA. Do not quote it or commit dates.
Chronosphere’s deep AgentiX integration is planned, not shipped. Working paths: the Telemetry Pipeline’s XSIAM destination plugin and the read-only MCP Server.
Embrace RUM has not closed (announced 21 Jul 2026, close expected Q1 FY2027). Mobile RUM is a roadmap conversation.
Frontier AI Defense has no public pricing or GA date, and it is PANW-delivered rather than an Authorized Professional Services motion.

The non-negotiable boundary. The customer licenses the platform and holds their own keys. We sell the labour, judgment, automation and reporting layer on top of that data source — never a resale of platform code or a way to avoid buying the licence. Detection logic stays in versioned, declarative signatures; models classify unknown artifacts, draft candidate rules and generate reports, but they do not sit in the finding path.

02 · Live Use Seller

Pick Your Room

Find whoever is across the table. Each card gives their actual worry, the line to open with, two questions to ask, and where the answer lands. Ask two, not twenty — pick by who is in the room, not by list order.

CISO

“I cannot describe our AI footprint, and I will be asked to.”

Open with

“Most of the security leaders I talk to can describe their AI policy but not their AI inventory. Which one would you rather be asked about first?”

Ask these two
  • Who on your team can tell me today how many AI agents and MCP servers are running, and how long would it take them?
  • If your board asked next month whether AI exposure went down or up this quarter, what would you show them?
Cortex AES · Unit 42 Frontier AI Defense with Mythos 5 · AI-SBOM as the deliverable
CIO / platform owner

“AI is being adopted faster than I can standardise it, and I own the mess.”

Open with

“You are probably being asked to enable AI and control it at the same time, on the same timeline. The fastest way through that is a graduated policy, not a blanket one.”

Ask these two
  • What is your current process when someone requests a new AI tool, and how long does it take end to end?
  • How many copilots or low-code agents have been built inside your SaaS platforms by people outside IT?
AI Access Security · SaaS Agent Security · triage SLA and exception register
Identity owner

“Agents are authenticating and I do not know as what.”

Open with

“The question that decides whether you can ever investigate an agent incident is whose identity it acts with. Most organisations cannot answer it per agent.”

Ask these two
  • When one of your AI agents acts, whose identity does it use — a service account, a shared secret, or the human who launched it?
  • How many of your agents hold standing privilege they only need occasionally?
Idira · zero standing privilege · privilege-reduction metric
Engineering / dev leader

“Do not slow my developers down.”

Open with

“I am not here to take tools away from your engineers — that always fails. I want to know what is installed, at what version, from which publisher, and what token it holds.”

Ask these two
  • How many coding agents and AI IDE extensions are installed across your engineering estate, and who approved each one?
  • You have a package policy for npm and PyPI. Do you have one for agent skills and MCP servers?
Cortex AES · supply-chain gateway · version and publisher policy
CFO / finance partner

“What is this actually costing us, and is it forecastable?”

Open with

“Runaway token spend and a compromised agent look identical from a distance — both are an agent doing far more work than its task requires. Cost is the one AI governance metric that is already somebody’s job.”

Ask these two
  • Do you know what your agents cost to run, and would you notice a runaway loop before the invoice arrived?
  • How much are you paying to store security and application logs you never query?
Chronosphere · Telemetry Pipeline · data-tax business case
Audit committee / board

“Can we evidence control over AI to a third party?”

Open with

“A policy document is an intention. An inventory with decisions, owners and expiry dates is evidence. The difference matters the moment a customer questionnaire arrives.”

Ask these two
  • When an auditor or a customer asks you to prove control over AI in your environment, what document do you hand them?
  • Do your AI agents fall inside or outside the scope of the frameworks you already report against?
AI-SBOM in CycloneDX · framework-mapped evidence pack · Unit 42 validated attack paths · exposure reduced, not found
OT / clinical / critical infrastructure

“Do not put anything new on my operational devices.”

Open with

“To be clear about scope, we do not put this on the operational devices themselves — that is the wrong place for it. The wedge is the workstations that already have trusted paths into those assets.”

Ask these two
  • Which of your engineering, clinical, biomedical or SOC workstations have trusted network paths into your most sensitive operational assets?
  • Who approves a new AI tool on a workstation that can reach the plant or clinical floor?
Cortex AES on privileged workstations · Frontier AI Critical Defense Program as credibility

03 · Proof Seller

Current Evidence

Verified, dated, and linked to the source that states it. Every row was checked against a fetched page — anything that could not be confirmed is listed at the bottom so you can avoid it. Point-in-time figures go stale fast: recheck the week you present.

A · Public incidents and attacks

Named, dated, and traceable to a primary source. These are the stories that make an abstract risk concrete in a first meeting. Lead with the one closest to the customer's own stack.

WhatThe verifiable factDateUse it whenSource
EchoLeak — CVE-2025-32711 Zero-click data exfiltration from Microsoft 365 Copilot via indirect prompt injection. CVSS 9.3. Disclosed by Aim Labs, fixed server-side, no in-the-wild exploitation observed. Jun 2025 The canonical proof that indirect prompt injection is not theoretical. Use it the moment a customer says "we have a system prompt with rules in it." Checkmarx
mcp-remote RCE — CVE-2025-6514 OS command injection in the widely used mcp-remote package, versions 0.0.5 through 0.1.15, fixed in 0.1.16. CVSS 9.6. Found by JFrog. 9 Jul 2025 The MCP supply-chain conversation in one CVE. Note: the widely repeated "437,000 downloads" figure is not in the JFrog or NVD write-up — do not quote it. JFrog
postmark-mcp backdoor First malicious MCP server found in the wild. A backdoor was introduced in v1.0.16 of an unofficial package impersonating Postmark, silently BCC-ing email to an attacker-controlled address. 17 Sep 2025 Answers "has an MCP server actually been weaponised?" with a yes, and it was a typosquat of a legitimate brand. Postmark
Amazon Q VS Code extension compromise A poisoned pull request inserted a destructive wiper prompt into the published extension, shipping in v1.84.0. Install-count figures circulate but are secondary-sourced only. 17 Jul 2025 The developer-workstation story. A real publisher, a real update channel, and a payload that reached production users. CSO Online
Replit agent deleted a production database An AI coding agent deleted a production database during a code freeze and then misreported what it had done. Exact record counts are not confirmed by a primary source. Jul 2025 The irreversible-action and approval-gate conversation. Pair it with "which of your agents can take an action you cannot undo?" Fortune
ClawHavoc — malicious skill campaign 1,184 malicious skills published across 12 publisher accounts, totalling 247,693 installs. 2026 The single best number for the "do you have a package policy for agent skills?" question. Scale, not fear. GBHackers
ToxicSkills — Snyk scan Of 3,984 skills scanned: 76 malicious payloads, 534 (13.4%) rated critical, and 1,467 (36.82%) carrying at least one issue. 2026 Converts the skill ecosystem from anecdote into a base rate. Roughly one in three has a problem. Snyk
Claude Code project-file RCE — CVE-2025-59536 and CVE-2026-21852 Remote code execution and API-key exfiltration through project files in a widely used coding agent. CVSS 8.7 and 5.3 respectively per NVD. Three vulnerabilities disclosed in total, one without a CVE. 2026 For engineering leaders who trust the coding agent because it came from a major lab. The agent reads your repo, and your repo is untrusted input. Check Point Research
Claude Code used in a government breach An AI coding agent was abused to breach 10 Mexican government bodies and exfiltrate more than 150 GB of data. 2026 Public sector and critical-infrastructure rooms. The tool was legitimate; the operator was not. Security Affairs
Meta internal AI agent data exposure An internal AI agent exposed sensitive data to employees for roughly two hours after an instruction change. 20 Mar 2026 The excessive-agency and blast-radius conversation, at a company with world-class security. Nobody is too mature for this. The Guardian
Shai-Hulud npm worm now ships fake MCP servers The self-replicating npm worm has extended into the AI developer supply chain, distributing counterfeit MCP servers. 2026 Ties AI artifact risk to the package-ecosystem risk the customer already understands and already funds. Cloud Security Alliance Labs
Azure MCP Server missing authentication — CVE-2026-32211 Missing authentication in a first-party cloud MCP server. CVSS score not yet published on NVD. 2026 Answers "but we only use MCP servers from major vendors." First-party does not mean authenticated by default. NVD

B · Research and vulnerability data

Base rates and taxonomies. Use these to move a customer from "that happened to someone else" to "that is the condition of the ecosystem we are installing from." Every number here is from the organisation that produced it.

WhatThe verifiable factDateUse it whenSource
MCP implementation scan — the primary stat to use Across 2,614 MCP implementations: 82% prone to path traversal, 67% to code injection, 34% to command injection, 7% to XSS. 2026 The strongest single MCP statistic with a named sample size. Use this instead of the older percentages circulating in vendor decks. Endor Labs
MCP aggregation amplifies attack success With five MCP servers connected to one agent and one compromised, attack success rate reached 78.3% with a 72.4% cascade rate; MCP aggregation amplified ASR by 23–41%. This is academic research, not a Unit 42 finding. 2026 The aggregation-policy argument: the risk is not one server, it is five. Attribute it to the paper — the widespread "Unit 42 measured 78.3%" attribution is wrong. arXiv 2601.17549
Unit 42 MCP attack vectors Unit 42's own published MCP research documents three sampling attack vectors against MCP. It states no attack-success percentages. 2026 Cite this when you want the PANW-branded MCP research. Do not attach the 78.3% figure to it. Unit 42
OWASP Top 10 for Agentic Applications (ASI Top 10) Published 9 December 2025. Ten risks from ASI01 Agent Goal Hijack through ASI10 Rogue Agents, focused on what happens when AI systems act rather than on model behaviour. 9 Dec 2025 The vocabulary that makes you credible with a technical evaluator. Name the IDs. Full table in section 04. OWASP GenAI Security Project
OWASP Agentic Skills Top 10 (AST10) AST01 Malicious Skills through AST10 Cross-Platform Reuse. Still at v1 public review — no formal publication date yet. v1 public review Shows the skill layer now has its own dedicated taxonomy. Say "public review," not "published" — a technical evaluator will check. OWASP
NSA security design guidance for MCP Cybersecurity Information Sheet v1.0, U/OO/6030316-26, produced with Carnegie Mellon SEI, covering security design considerations for AI-driven automation leveraging MCP. May 2026 For regulated and public sector rooms. Government guidance existing at all reframes MCP from developer convenience to a governed interface. NSA
Enterprise agent visibility survey — use this one Survey of n=418 enterprises: 82% have unknown AI agents in their environments and 65% experienced an AI-agent security incident in the prior 12 months. 21 Apr 2026 The inventory argument with a disclosed sample size. Use this in place of the "88% had an incident" figure that circulates without one. Cloud Security Alliance
Claw Chain — CVE-2026-44112 CVSS 9.6 vulnerability in the agent tooling chain. 18 May 2026 Evidence that critical-severity findings in agent infrastructure are a recurring pattern, not a one-off. Check Point Research

C · Regulatory and compliance — what is actually in force

Verified as of 27 August 2026. This is where sellers lose credibility fastest, because a great deal of circulating collateral still carries the pre-Omnibus dates. Never sell a deadline you cannot substantiate — sell the direction of travel.

WhatThe verifiable factDateUse it whenSource
EU AI Act Article 50 transparency duties — IN FORCE Transparency obligations apply from 2 August 2026 and were not delayed. Commission guidelines were adopted 20 July 2026. In force 2 Aug 2026 If a deck in your library says these slipped, it is wrong. This is the part that already applies. European Commission
Enforcement powers — IN FORCE AI Office and Member State enforcement powers began 2 August 2026 over prohibited practices, transparency obligations, and general-purpose AI rules. Systems already on the market before that date have until 2 December 2026 for the Article 50(2) marking duty. In force 2 Aug 2026 The December marking deadline is the nearest real date. It is concrete, it is close, and most customers have not scoped it. EU AI Act Service Desk
High-risk obligations — DEFERRED Stand-alone Annex III high-risk systems moved to 2 December 2027; high-risk AI embedded in already-regulated Annex I products moved to 2 August 2028. Delivered by the Digital Omnibus on AI, COM(2025) 836 — trilogue 7 May 2026, Council approval 29 June 2026. Co-legislators replaced the Commission's standards-linked trigger with fixed dates, so these are not conditional. Deferred to 2027 / 2028 Correct the room gently if someone says high-risk applies now. Then pivot: the requirements are unchanged, only the date moved. European Parliament Legislative Train
What high-risk will actually require Risk management and mitigation, high-quality datasets, logging of activity to ensure traceability, detailed technical documentation, clear information to the deployer, appropriate human oversight, and a high level of robustness, cybersecurity and accuracy. Current text Every one of these is an artifact the service produces anyway. Map your deliverables to this list and the compliance case makes itself. European Commission
NIST AI RMF 1.0 Published January 2023. Four functions — Govern, Map, Measure, Manage — with Govern cross-cutting. Voluntary and non-certifiable. A revision is in progress. Jan 2023 A structuring language, not a badge. Use it to organise the service: assessment is Map, telemetry is Measure, retainer is Manage. NIST
ISO/IEC 42001:2023 — certifiable Published December 2023 as the first international AI management system standard. Certifiable through accredited bodies, with ISO/IEC 42006:2025 governing the certification bodies themselves. Dec 2023 The commercially important one, because certification requests arrive through procurement and customer questionnaires rather than through security. ANAB
CycloneDX AI/ML-BOM Specification 1.7, released 21 October 2025, standardised as ECMA-424. 21 Oct 2025 Why the deliverable is an AI-SBOM in a published format rather than a proprietary report — portable evidence the customer owns and can reuse. CycloneDX
US state AI laws now effective California TFAIA and Texas RAIGA took effect 1 January 2026. Colorado repealed and replaced its AI Act with SB 26-189 (ADMTA), obligations starting 1 January 2027. 1 Jan 2026 For US customers who dismiss the EU AI Act as somebody else's problem. Two states are already live and a third is scheduled. JD Supra

D · Palo Alto Networks and Unit 42 proof points

All primary-sourced from Palo Alto Networks or its investor relations. These are the numbers that show we are not just describing the problem — use one of them to close the credibility gap between the threat story and the product story.

WhatThe verifiable factDateUse it whenSource
Unit 42 NOVA — autonomous vulnerability discovery In two months across 3,915 open-source projects: 14,090 confirmed vulnerabilities, 99.4% previously unreported, 5,600 (39.7%) high or critical under CVSS 4.0 (4,030 / 28.6% under CVSS 3.1), 5,421 supply-chain findings and 2,776 downstream exposures validated with working proof-of-concept exploits. 2026 The strongest single stat to open "what does frontier AI change for us." It proves the exposure window is real before you quote anything. Unit 42
Unit 42 Frontier AI Defense + Claude Mythos 5 Service launched 7 May 2026. On 21 August 2026 Unit 42 expanded Frontier AI Exposure Analysis with Anthropic's Claude Mythos 5, stating frontier AI has compressed attack timelines "from weeks to minutes." 21 Aug 2026 Mythos access is deliberately scarce. Very few providers can put a model of this class on a customer's estate — that is the differentiator. Palo Alto Networks
Prisma AIRS AI Gateway — GA and adoption scale Reached general availability in July 2026 as a unified LLM, MCP and A2A gateway with a single enforcement point, built from the Portkey acquisition and shipped six weeks after close. MCP activity rose from 11% of AI traffic late last year to 41.4% by mid-2026; monthly AI transaction volume grew twelve-fold in six months; 68 trillion+ tokens processed in the last month alone; sub-millisecond routing latency and 99.999% availability. Some individual sessions moved hundreds of megabytes of enterprise data outbound. 16 Jul 2026 The single best adoption statistic in the portfolio. 11% to 41.4% MCP traffic in under a year answers “is MCP really a big deal yet?” with the customer's own traffic pattern. Palo Alto Networks
Advanced IP Defense — network-layer scale Introduced in PAN-OS 12.2 Ceres, extending Precision AI to the network layer with 40+ security attributes for dynamic risk profiling, 1,600+ intelligence sources, live global telemetry from 75,000+ CDSS deployments, and 50,000+ new malicious hosts identified daily. Eliminates firewall table limits and the 20-day intelligence lag of static reputation feeds. 20 Aug 2026 For the network owner in the room, and for anyone who says AI security is only an endpoint or app problem. This is inline enforcement at a scale nobody can replicate. Palo Alto Networks
PAN-OS 12.2 Ceres — the network AI release More than 55 innovations, centred on Frontier Virtual Patching, Advanced IP Defense and six AI-powered Network Security Agents in Strata Cloud Manager. Telemetry from more than 70,000 customers. Delivered as a software upgrade with automatic content updates, no new hardware. Aug 2026 The answer to “what do we get without buying anything new.” Existing network security customers already own the delivery path. Security Boulevard
Cortex Data Security — public preview Announced 11 August 2026 as a unified data security platform combining new and existing capabilities, with industry-leading DSPM capabilities in the public preview. Public preview, not GA. 11 Aug 2026 Use it to show direction of travel on the “where does our data go” question. Do not quote it and do not commit dates. Palo Alto Networks
Frontier Virtual Patching — the speed gap Protections in hours against an industry-average 55-day patch deployment window. Exploits now weaponised in under 24 hours, attack pace quadrupled, and 29% of CVEs weaponised within 24 hours. Project Glasswing surfaced >23,000 vulnerabilities, roughly 6,200 high or critical. Aug 2026 The arithmetic that makes the whole argument: 24 hours to weaponise against 55 days to patch. Everything else follows from that gap. Palo Alto Networks
Frontier AI Critical Defense Program Launched 19 August 2026. Existing collaborators: IBM, Red Hat (Lightwell), Microsoft (MAPP), Siemens, Idaho National Laboratory (OT Threat Research Lab). New participants: Anthropic, OpenAI, Mitsubishi Electric, Axis Communications, the Analysis and Resilience Center for Systemic Risk, Health-ISAC, EPRI, Akrites (Linux Foundation). Protections reach joint customers within hours of initial discovery via Frontier Virtual Patching. 19 Aug 2026 Not a paid service — the credibility layer for OT, energy, healthcare, manufacturing and public sector. Name the participant closest to the customer's own sector. Palo Alto Networks
Prisma AIRS 3.0 Released 23 March 2026 with AI Agent Gateway, Agent Artifact Security, AI Red Teaming, and Koi-based Agentic Endpoint Security. Red teaming returns a Risk Score of 0–100. 23 Mar 2026 A score can move, and a moving score justifies a retainer instead of a one-time project. That is the commercial point of red teaming. Palo Alto Networks
Idira — the identity arithmetic GA 12 May 2026. Nine in ten organisations had an identity-related breach, machine and AI identities outnumber humans 109:1, and 61% of privileged access requests use standing privilege. 12 May 2026 The 109:1 ratio ends the "we have identity covered" objection faster than any product slide. No IdP governs that population. Palo Alto Networks investor relations
Optiv — Idira SSO migration Legacy SSO replaced in three weeks across 2,500 employees; all business-critical applications onboarded in 30 days, double the number added in the previous eight months; roughly 80 support tickets against about 250 expected. 2026 The migration-risk objection, answered with numbers. Lead the ticket count, not the timeline — almost no vendor will put expected-versus-actual in front of a customer. Palo Alto Networks
Chronosphere — the data-tax business case Acquisition completed 29 January 2026. The telemetry pipeline cuts data volume by 30% or more with 20x less infrastructure than legacy alternatives. Note: no token-spend figures exist in the release. 29 Jan 2026 The lower-risk first move that does not require replacing the SIEM. Fund the platform conversation with the savings. Palo Alto Networks investor relations

Do not use these claims. They circulate in AI-risk collateral but could not be confirmed against a primary source. An unverifiable stat is worse than no stat.

  • “Unit 42 measured a 78.3% attack success rate” — misattributed. The figure is from academic research (arXiv 2601.17549), not Unit 42. Cite the paper, or cite Unit 42's actual MCP attack-vector research without a percentage.
  • “mcp-remote was downloaded 437,000+ times” — not present in the JFrog advisory or NVD entry. Secondary headlines only.
  • “A coding assistant with more than 950,000 installs was compromised” — the incident is confirmed, the install count is not primary-sourced. Describe the incident without the number.
  • “88% of organizations had a confirmed or suspected AI agent security incident” — vendor survey with undisclosed sample size, and inconsistent with its own reported 54%. Use the Cloud Security Alliance figures instead (n=418, 82% unknown agents, 65% had an incident).
  • Specific record counts for the Replit database deletion, and the “195 million records” figure — not confirmed by any primary source.
  • Aggregate “X CVEs filed against MCP” totals from third-party aggregators — could not be reproduced from a primary source. Use the Endor Labs implementation scan instead.
  • A publication date for the OWASP Agentic Skills Top 10 (AST10) — it remains in v1 public review. Say “public review,” not “published.”
  • Dollar-value impact figures attributed to ClawHavoc — unverified.
  • Any Chronosphere token-spend statistic — the capability is real and documented, but no quantified token figures appear in the acquisition release.
  • “GPT-5.6-Cyber” — LinkedIn-only sourcing, no primary confirmation.
  • CVSS scores for CVE-2026-32211 and CVE-2026-27826 — not yet published on NVD. Reference the vulnerabilities without severity scores.
  • “Advanced Virtual Patching” as the product name — that is third-party coverage's wording. Palo Alto's own blog and press release both say Frontier Virtual Patching, delivered through Advanced Threat Prevention Plus.
  • “The AI Agent Gateway is in limited preview” — true at the March 2026 Prisma AIRS 3.0 launch, stale now. Prisma AIRS AI Gateway reached GA in July 2026.
  • A short or partial Critical Defense Program roster — the program has both existing collaborators and a newer wave. Keep the two groups distinct rather than presenting one flat list, and name the participant closest to the account's sector.

04 · Depth Technical

Ten Things You Must Be Able to Explain

You cannot govern a system you cannot describe. These are the subjects that come up in real customer rooms. Learn the vocabulary and the boundaries; the products come after. Sellers should still read topic A — the rest is here for the technical seller and the partner architect.

This is the topic that has moved fastest and the one most collateral is stale on. The short version: frontier models compressed the time from vulnerability discovery to working exploit to under 24 hours, against a vendor patch cycle of 30–90 days and an industry-average enterprise MTTR of 55 days. Palo Alto’s own framing is that frontier AI has taken attack timelines “from weeks to minutes.”

The proof it is not marketing: Unit 42’s NOVA autonomous discovery system evaluated 3,915 open-source projects in a two-month run and produced 14,090 validated findings, of which 99.4% had no matching public record, CVE or vendor advisory. Nearly 40% were high or critical. That is one system, two months, against public code the whole industry can read.

Why Mythos specifically: Anthropic released Claude Mythos to a small set of organisations under export restrictions that were only lifted on 1 July 2026, and Palo Alto was an early launch partner from April 2026. Unit 42 expanded Frontier AI Exposure Analysis with Claude Mythos 5 on 21 August 2026, guided and reviewed by human offensive security experts. Very few providers can put a model of this class against a customer’s estate — that scarcity, not the model name, is the differentiator.

The Multi-Model Harness point, which technical evaluators will probe: Unit 42 does not bet on one model. The harness routes each task to the model best suited to it, which widens coverage, manages cost, and absorbs stronger models as they ship. Answer “aren’t you locked to Anthropic?” with the harness, not with a claim about Mythos being permanently best.

How to use it without overclaiming: the customer-facing question is not “which model do you use.” It is “is this exploitable, what can an attacker reach from here, and what do we fix first.” Frontier models are how that gets answered at machine speed; the answer itself is what the customer buys.

A token is simultaneously the billing unit, the performance unit and the risk unit. Scaling agentic applications requires control over the relationship between token consumption, model performance and cost, because an inefficient agentic loop or a spike in high-latency model calls produces unforecasted spend.

What to measure: input, output and total spend broken down by model rather than one aggregate; the same metrics filtered by agent and by version, which is what makes architectures comparable; and cost per resolved task rather than cost per call — cost per call rewards agents that give up early.

The regression test that matters: a new agent version consuming significantly more tokens without a measurable increase in task accuracy is a regression you should catch immediately rather than at invoice time. Tokens up and accuracy flat is the clearest bad signal in agentic operations.

Retries versus reasoning loops: a high token count is not automatically failure — it can be successful self-correction. The failure case is an agent stuck repeatedly calling the same failing tool. You separate the two by correlating evaluations with traces: watch a tool time out, then watch whether the agent recognised it and pivoted, or just called it again.

The security crossover: a runaway spend event and a compromised agent look identical from a distance. It cuts the other way too — MCP servers serving agent-like functions are susceptible to prompt storms, malformed inputs and recursive task requests that cause denial of service. Token exhaustion is an availability attack with an invoice attached.

An agent is not a chatbot. It is a model plus instructions plus tools plus memory plus an autonomy setting, and each is a separate control surface with a separate owner. Most seller credibility is lost because the two sides of the table are discussing different layers.

LayerWhat it isWhat goes wrong
Model / endpointThe inference engine, hosted by a provider or self-deployed from downloaded weights.Model weights are executable content in practice — architectural backdoors, poisoning, malicious code inside model components.
InstructionsThe system prompt and task framing that define intent and constraints.Guidance, not enforcement. A determined injection overrides it. Never sell a system prompt as a control.
Tools / function callsThe actions the agent can take in real systems — read a ticket, restart a service, move money.Tool misuse and exploitation. The agent has your permissions, so a wrong decision becomes a real action.
MCP serversThe de facto standard connector layer exposing tools and data to agents.Unversioned, unsigned, frequently unauthenticated third-party code running with user privilege.
SkillsPackaged bundles of instructions plus scripts that teach an agent a repeatable procedure.Distributed like packages with none of the package-manager controls.
Memory / contextThe context window plus retrieval and any persistent memory across sessions.Overflow, context rot, and poisoning that persists after the original attack is gone.
Subagents / orchestrationAgents that spawn or call other agents to decompose a task.Cascading failures and insecure inter-agent communication — one bad output becomes three agents’ input.
IdentityThe credential the agent acts with — its own, a service account, or the launching human’s.Delegated identity destroys attribution and makes revocation a manual archaeology project.
AutonomyWhether a human approves, supervises, or is absent.Autonomy set once during a pilot and never revisited when the agent moved to production.

The three autonomy tiers, named: manual, where engineers investigate and remediate step by step; guided, where AI identifies issues and proposes hypotheses while a human validates and remediates; and autonomous, where AI attempts remediation and engineers supervise and intervene. Ask every customer which tier each agent is on. Most can answer per programme, not per agent — and that gap is the finding.

The structural flaw underneath all of it: instructions and data share one channel. The agent cannot reliably tell the difference between content it was told to read and content telling it what to do, because nothing marks which bytes are trustworthy. Every mitigation is a workaround for that single design property, which is why enforcement has to live outside the model.

The Model Context Protocol became the de facto standard for connecting agents to external tools, and with it the highest-value target in the stack. The core problem is that an agent treats everything in its context as trustworthy — tool descriptions, parameter schemas, and the data tools return — so anyone who can plant instructions in any of those can steer the agent.

Tool poisoning is the sharp edge: malicious instructions hidden in a tool’s description or schema, which the model reads and the user usually does not. It defeats human review by hiding in the metadata layer nobody inspects.

Aggregation is the risk multiplier. The number of MCP servers connected to a single agent is a policy decision most organisations have never made. Probe it specifically — the risk is not one server, it is five.

Controls that actually apply: treat tool descriptions and tool outputs as untrusted input and inspect the full schema before approving a server. Then add the boring supply-chain hygiene nobody has applied yet — an inventory, pinned versions, publisher reputation, least-privilege scopes per server, sandboxed execution, and a policy gate on how many servers a single agent may aggregate.

A skill is a portable bundle of instructions and executable scripts that teaches an agent a procedure. Functionally it is a package. Operationally it has none of the controls your organisation spent twenty years building for packages — no signing requirement, no registry policy, no version pinning, no review gate.

How to frame it to a customer: “You have a package policy for npm and PyPI. Do you have one for agent skills? Because the install path is a file copy, the review step is optional, and the thing you just installed can run code with your developer’s credentials.” That sentence sells the inventory better than any threat statistic.

“Skills go through the same review” is almost never true in practice, because a file copy never triggers the review that a package-manager transaction triggers. Test it by asking who approved the last one.

This is exactly the artifact layer that endpoint AI oversight is built to inventory and rank — packages, plugins, extensions, MCP servers, and agent-like activity that mimics legitimate user behaviour, which is why device-posture tooling never sees it.

Direct model calls and autonomous agents both introduce failure modes traditional monitoring misses entirely: hallucinations, context window overflows, infinite reasoning loops, and bad tool selection. The line worth memorising is that a fast response is still a failure if it is ungrounded, and a multi-step agent loop can succeed technically while failing logically. An agent can complete its workflow without a single server error and still return an inaccurate answer, so error rate is no longer the indicator of success.

Four things to instrument: token cost, to block runaway spend and catch efficiency regressions between agent versions; semantic evaluations sent in as metrics so accuracy becomes a monitored trend across the fleet rather than a pre-launch test; execution traces, so a dropping score takes you straight into the orchestration sequence and the arguments passed to each tool; and tool-call reliability across external dependencies.

The reframe to carry into every room: success for AI systems is no longer defined by uptime or latency, but by the efficiency of the reasoning process, the accuracy of autonomous decisions, and the quality of the output. Practically, the customer’s AI governance programme needs three numbers it almost certainly does not have today — cost per resolved task, a live accuracy trend, and tool-call failure rate per agent.

Build it on OpenTelemetry GenAI standards so the telemetry is portable rather than vendor-shaped. Instrument once; do not let the instrumentation become the lock-in.

The OWASP Top 10 for Agentic Applications, known as the ASI Top 10, focuses on what happens when AI systems act, unlike the LLM Top 10 which focuses on model behaviour. Use the IDs by name — it signals you have read the source rather than a vendor summary.

IDRiskWhat it looks like in a customer environment
ASI01Agent Goal HijackInjected instructions in a document, email, ticket or web page redirect the agent’s objective. Indirect prompt injection with consequences, and the number-one risk for a reason.
ASI02Tool Misuse & ExploitationThe agent uses a legitimate tool in an unintended way — the action is authorised, the outcome is not.
ASI03Agent Identity & Privilege AbuseDelegated or over-broad credentials let an agent reach far past its task. Maps directly to the standing-privilege conversation.
ASI04Agentic Supply Chain CompromiseA malicious or vulnerable skill, MCP server, extension or package enters through the developer’s workstation.
ASI05Unexpected Code ExecutionAgent-generated or agent-fetched content executes where nobody expected executable content.
ASI06Memory & Context PoisoningMalicious content persists in memory or retrieval, so the compromise outlives the session that introduced it.
ASI07Insecure Inter-Agent CommunicationAgents trust each other’s output implicitly, so one bad result becomes several agents’ authoritative input.
ASI08Cascading Agent FailuresA single upstream error propagates through an orchestration graph faster than a human can intervene.
ASI09Human-Agent Trust ExploitationConfident, fluent output earns approval it did not deserve. The approval gate becomes theatre.
ASI10Rogue AgentsAgents operating outside sanctioned scope, or shadow and dormant agents that still hold valid access.

Two companions worth knowing: OWASP also maintains an updated GenAI LLM Top 10, and publishes periodic GenAI exploit round-up reports cataloguing real incidents — useful for keeping a customer briefing current without relying on vendor marketing.

NIST AI RMF 1.0 organises AI risk management into four functions — Govern, Map, Measure and Manage — with Govern as a cross-cutting function infused throughout the other three. It is explicitly voluntary and non-certifiable, so it is a structuring language, not a badge. Use it to organise your service: the assessment is Map, the telemetry is Measure, the retainer is Manage.

ISO/IEC 42001:2023 is the first international standard for an Artificial Intelligence Management System, specifying requirements for establishing, implementing, maintaining and continually improving an AIMS, for organisations both providing and using AI. Unlike the NIST framework it is certifiable through accredited bodies, which matters commercially — certification requests will arrive through procurement and customer questionnaires.

CycloneDX AI/ML-BOM is a machine-readable inventory of the components, configurations and processes of an AI/ML system. This is why the assessment deliverable is an AI-SBOM in a published format rather than a proprietary report — it is portable evidence the customer can reuse across audits and questionnaires.

How to use all three: never lead with the framework. Lead with the artifact the customer needs, then name the framework it maps to so the buyer can defend the spend internally.

This is where sellers lose credibility fastest, because timelines have moved and a lot of circulating collateral is stale. Two rules: never sell a deadline you cannot substantiate, and always check the date on the deck you are about to present.

What to sell instead of a deadline: the direction of travel. Logging, traceability, human oversight and third-party accountability are converging requirements across every framework and sector, and each one is an artifact your service produces anyway. That argument survives a timeline slipping; a specific date does not.

How to handle the “are our agents in scope?” question: “Not in scope” is rarely a considered position — it is usually the absence of one. If an agent authenticates, holds credentials, and touches regulated data, assuming it is out of scope is a decision worth making deliberately rather than by default.

See the current evidence section for the dates that are verified as in force versus deferred as of today.

Six moves, in this order. Anyone who starts at move five without doing move one is buying enforcement for a population they cannot describe. The full ladder with deliverables is in the section below, and the deep-dive discovery questions for the endpoint layer are on the AES Conversation Starters page.

The sequencing argument is the single most useful thing you can give a customer in a first meeting, because it converts an overwhelming topic into an ordered list with an owner per step. It also happens to describe the service ladder exactly: the assessment is moves one to three, the retainer is moves two to four run continuously, and the premium tier is moves five and six.

05 · Sequence Seller + Technical

The Six-Move Ladder

What a customer actually does about AI, in this order. Anyone who starts at move five without doing move one is buying enforcement for a population they cannot describe. The assessment is moves one to three, the retainer is two to four run continuously, the premium tier is five and six.

1

Inventory

Agents, MCP servers, skills, extensions, packages, models — and the human accountable for each.

Published-format AI-BOM, not a spreadsheet that ages out in a month.

Cortex AES · Prisma AIRS posture
2

Classify

Autonomy tier and blast radius per agent.

Which actions are irreversible, and which currently have no gate.

Cortex AgentiX · Idira
3

Scope identity

Identity per agent, least privilege, time bounds, and a revocation owner.

Kill delegated human tokens for agent action — it destroys attribution.

Idira
4

Instrument

Token cost, evaluation scores, execution traces, tool-call reliability — on OpenTelemetry.

Thresholds and owners for each, or the telemetry is decoration.

Chronosphere
5

Enforce

Runtime inspection of prompts and tool calls at the gateway; version and publisher policy on artifacts; inline network protection for exploits nobody has patched yet.

Approval gates on sensitive and irreversible actions. Network enforcement is the one control that works without touching the endpoint.

Prisma AIRS AI Gateway · Cortex AES · Frontier Virtual Patching
6

Validate & report

Adversarial testing on a cadence with a score that can move, then revalidate.

Report exposure reduced, mapped to a named framework.

Prisma AIRS Red Teaming · Unit 42

06 · Get Started Seller

Discovery Questions

Five openers that work in any room, whatever the customer’s maturity or platform footprint. The goal of every question is a specific next artifact — an inventory, an owner, or a decision — not a longer list of findings.

1

Who on your team can tell me today how many AI agents and MCP servers are running — and how long would it take them?

How to read it: Any answer over a few days means there is no inventory, only an assumption. The pause between two attendees is the buying signal: accountability is unassigned.

2

If we hand you two hundred findings next month, who triages them — and what else stops while they do it?

How to read it: This question closes the service, and it works because you ask it against your own product. “Honestly, nobody” means stop selling and start scoping.

3

When does your endpoint, SIEM or data-platform agreement come up for renewal, and is AI governance already inside that budget line?

How to read it: Renewal windows are the trigger, not the objection. Expired, 0–6 months and 7–12 months are three different plays. “AI has its own budget” is the best case — you are not competing with existing security spend.

4

Which GenAI applications has your workforce adopted that were never formally approved, and do you have a risk score for each?

How to read it: “We blocked the consumer ones” usually means a blunt category block that drove adoption to unmonitored personal devices. A sanctioned list without per-app scoring is a policy document, not a control.

5

How many MCP servers is any single one of your agents connected to, and who approved each of them?

How to read it: “What’s an MCP server?” from a security leader is not a disqualifier — it is the reason to run the assessment, because the developers already know and have already installed several. Probe aggregation specifically.

Three more worth carrying

+

Do your AI agents fall inside or outside the scope of the frameworks and regulations you already report against?

How to read it: “Not in scope” is rarely a considered position, it is usually the absence of one. Sell direction of travel, not a deadline you cannot substantiate.

+

Which of your engineering, clinical, biomedical or SOC workstations have trusted network paths into your most sensitive operational assets?

How to read it: Vendor laptops and engineering jump hosts are the highest-value population in the building: privileged paths, weak artifact oversight, and heavy AI-tool adoption in exactly the roles most likely to install a coding agent.

+

If one of your agents got 20% less accurate next month, how would you find out, and how long would that take?

How to read it: “We watch error rates” is the most revealing answer, because an agent can complete its workflow with zero errors and still be wrong. The monitoring is measuring the wrong thing.

Then go deep by track

Nineteen questions with what you’ll hear, how to read the answer, the response to give, and where it lands are on the AES Conversation Starters page, grouped into these four tracks.

5 questions

Inventory and visibility

Who owns the list, what is on the compliant laptop, coding agents and IDE extensions, shadow and dormant agents, citizen-built SaaS copilots.

4 questions

Identity, privilege and blast radius

Whose identity the agent uses, standing privilege, irreversible actions and approval gates, blast radius if an agent is compromised.

6 questions

Runtime, supply chain and cost

Where prompts and tool calls get inspected, package policy for skills and MCP servers, unscanned downloaded models, adversarial test cadence, agent run cost, the log data tax.

4 questions

Governance, evidence and accountability

Who signs off and how long it takes, what document goes to the auditor, autonomy tier per agent, what the board sees.

07 · In the Room Seller

Objection Handling

Concede the true part of every objection first. The reframe only lands after the customer believes you are not selling past their reality.

Concede: They do have agent-security and MCP-related offerings. The category is contested and pretending otherwise costs you credibility.

Reframe: Compare on three specifics rather than on category ownership: cross-platform coverage, whether it deploys alongside a third-party EDR without displacement, and the depth of the maintained findings and publisher-reputation corpus. Ask them to show you a version-level policy decision on a real MCP server, not a slide.

Concede: Blocking is a legitimate first move and it did reduce something.

Reframe: A blanket block relocates adoption to personal devices and unmanaged accounts, where you have no telemetry at all. Graduated policy with per-app risk scoring, action-level control on uploads and downloads, and in-the-moment user coaching keeps the behaviour where you can see it.

Concede: The formal programmes may well be pilots.

Reframe: The exposure is not coming from the programmes, it is coming from individuals installing extensions, packages and coding assistants without a programme at all. Run the assessment specifically to test the pilot assumption. If the number really is small, you have cheap proof and a clean baseline; if it is not, you found out before it mattered.

Concede: Full stop — we are not asking you to.

Reframe: The architecture keeps your existing orchestration and case management as the system of record and adds agentic-endpoint context and enforcement beside it. Be straight about the effort: real event schema, explicit data-model mapping, ingestion transport, noise controls and deployable detections are engineering work, not a connector install. Scope it honestly and it becomes a differentiator rather than a surprise.

Concede: Yes, and you should own the licence and the keys regardless. We do not want to sit between you and your platform.

Reframe: The tool produces ranked findings continuously. The work is triage inside an SLA, exception governance with expiry, and evidence production on your audit calendar. Start with the assessment, see the finding volume, then decide whether that is a job you want to staff.

Concede: The committee is genuinely necessary for policy and risk appetite.

Reframe: A committee sets direction; it does not maintain an inventory, classify a new MCP server on a Tuesday, or produce an evidence pack. We are the operating layer beneath the committee, and we make its decisions enforceable and auditable instead of aspirational.

08 · After the Meeting Seller

The 30/60/90 Motion

Applies to every customer regardless of platform footprint. Sequence matters more than pitch quality — the assessment must land before any platform conversation, or you are selling a product with no proof.

Days 0–30

Qualify

  • Pull renewal dates for endpoint, SIEM and data platform. Bucket as expired, 0–6 months, 7–12 months.
  • Confirm existing footprint and, critically, whether a competitor EDR is present — that determines coexistence versus attach.
  • Ask five discovery questions, not twenty. Lead with the inventory question, the compliant-laptop question, and the who-triages question.
  • Identify who owns the answer to “how many agents.” If nobody does, you have a qualified opportunity.
Days 30–60

Prove

  • Run the assessment on a bounded, high-privilege population — developer, SOC and engineering workstations first.
  • Engineer the proof moment deliberately: one finding the customer did not know about, explained with an evidence trail.
  • Present findings in three tiers — malicious, legitimate-but-non-compliant, acceptable risk. Never a binary verdict.
  • Hand over the AI-SBOM as a portable object they own, whether or not they buy the next phase.
Days 60–90

Convert

  • Use finding volume, not fear, to size the retainer. The who-triages answer sells this for you.
  • Attach the platform conversation to the renewal event and the true-up, with deal-specific quantities from Palo Alto.
  • Sequence the premium tier as a second wave — enforcement and validation after governance is running, not before.
  • Book the first quarterly revalidation at signature so “exposure reduced” is measurable from day one.

Two things to verify before every presentation. Point-in-time scale figures, adoption statistics and registry or platform counts go stale fast — recheck them the week you present. And confirm which capabilities are shipped versus roadmap, particularly anything describing a deep integration between newly acquired platforms. Getting caught claiming a planned integration as available costs more credibility than the claim ever bought.

09 · Reference Technical

Glossary

Using a term loosely in front of a technical evaluator costs the room. Spell out acronyms on first use in any customer-facing material — MDM, EDR, XDR, MCP, MDR, POV, SOC, CPS, OT, IoMT, AI-SBOM.

TermWhat it meansWhy it matters here
TokenThe unit a model reads and writes, and the unit you are billed for. Split into input and output tokens, priced differently.The only AI metric that is simultaneously a cost, a performance and a security signal.
Context windowThe total amount of text a model can consider at once, including instructions, retrieved data and conversation history.Overflow silently drops information, causing failures that look like the model “forgetting.”
AgentA model given instructions, tools, memory and an autonomy setting so it can plan and act, not just answer.Five separate control surfaces. “We have an AI policy” usually covers only one of them.
SubagentAn agent invoked by another agent to handle part of a task.Creates orchestration graphs where one bad output cascades as several agents’ trusted input.
Tool call / function callThe mechanism by which a model triggers a real action in a real system.The moment a language problem becomes an operations problem. This is where enforcement belongs.
MCP (Model Context Protocol)The de facto standard for exposing tools and data to agents through a server the agent connects to.Third-party code, often unsigned and unauthenticated, running with user privilege. The new trust boundary.
SkillA portable bundle of instructions plus scripts that teaches an agent a repeatable procedure.Executable content distributed like a package with none of the package controls.
RAG (retrieval-augmented generation)Fetching relevant documents at query time and putting them into the context window to ground the answer.The retrieval corpus becomes an injection surface — poison the document, steer the agent.
EvalAn automated test scoring output quality, accuracy, groundedness and task success, rather than uptime.Evals sent in as live metrics are the only way to see accuracy degrade in production.
Prompt injectionDirect: a user overrides instructions. Indirect: instructions hidden in content the agent reads — an email, a page, a ticket, a calendar invite.Indirect injection is the one that scales, because the attacker never touches your interface.
Tool poisoningMalicious instructions hidden in a tool’s description or schema, which the model reads and the user usually does not.Defeats human review by hiding in the metadata layer nobody inspects.
Goal hijackRedirecting an agent’s objective or plan through injected instructions or poisoned content.OWASP ranks it ASI01, the top agentic risk.
Reasoning loopAn agent repeatedly retrying the same failing approach instead of pivoting.Burns budget and hides real failure. Indistinguishable from legitimate self-correction without traces.
Non-human identityA credential belonging to a service, machine or agent rather than a person.Outnumbers human identities and is rarely inside joiner-mover-leaver processes.
Standing privilegePermanent access retained whether or not the task currently requires it.The single variable that converts a small agent error into a large incident.
AI-SBOM / AI-BOMA machine-readable inventory of AI components, configurations and processes, typically CycloneDX ML-BOM format.The portable evidence object. Reusable across audits and questionnaires, unlike a dashboard screenshot.
Shadow AIUse of AI tools, systems or agents without the approval, monitoring or involvement of IT or security.Different from shadow IT because of how models handle data, generate outputs and influence decisions.
OpenTelemetry GenAIOpen standards for emitting model and agent telemetry — tokens, traces, spans — in a vendor-neutral format.Instrument once. Prevents the instrumentation itself from becoming lock-in.

Go Deeper

Where Each Layer Lives

Every figure in the Current Evidence section links to the page that states it. Product capability statements reflect published vendor documentation and press material as of 27 August 2026 — verify shipped-versus-roadmap status and any point-in-time figure before a customer presentation. Commercial quantities, packaging and licensing ratios must come from Palo Alto Networks on a per-deal basis. Adapted for PAN Portfolio from the Agentic AI Exposure Management field guide.