AI Affairs, home

Friday 25 September 2026

Corporate

Palo Alto Networks launches annual AI security testing subscription

Unit 42 will use cyber-focused models from Anthropic and OpenAI. Palo Alto Networks says it spent $17 million developing the approach across six months.

Palo Alto Networks headquarters in Santa Clara, California, south entrance view.
Photo: Namaste jinx, CC BY-SA 4.0, via Wikimedia Commons (cropped)

Palo Alto Networks launched Unit 42 Continuous Frontier AI Defense on 22 September as an annual subscription, after spending $17 million developing its approach across six months and applying it in more than 100 customer engagements, the company said.

Key points

  • The service uses Anthropic’s Claude Mythos 5, OpenAI’s GPT-5.6-Cyber and open-weight models, Palo Alto Networks says.
  • Subscriptions are available worldwide, with options varying by the models used, according to the company.
  • Unit 42 says its earlier customer assessments found exposures at every organisation tested, with 37% of exposures rated high or critical.
  • Palo Alto Networks says three weeks of testing on its own systems found as many exposures as it would ordinarily expect in a year.

Annual plans combine Claude Mythos 5 and GPT-5.6-Cyber

The subscription gives customers continuous testing rather than a single assessment. Palo Alto Networks says Unit 42 begins with a scan of a customer’s systems, then tests them as the environment changes. Its software routes individual tasks among the Anthropic and OpenAI models and open-weight alternatives.

The tests cover web applications, APIs, cloud infrastructure, code repositories and network assets. Unit 42 says the service checks whether a weakness can be exploited, traces possible attack paths and recommends code changes or temporary virtual patches. Customers can pair it with Palo Alto Networks’ Frontier Virtual Patching service to implement virtual patches before an official fix is available, the company says.

Palo Alto Networks says every subscription uses its multi-model software to assign security tasks. That places the choice of models inside a continuing Unit 42 service, rather than a one-off purchase of access to either model.

Sam Rubin, Senior Vice President of Unit 42 at Palo Alto Networks, said the company was combining its offensive testing and threat intelligence work with access to the restricted models. Michael Moore, Cybersecurity Lead at Anthropic, said Claude Mythos had found more than 10,000 high-severity vulnerabilities in widely used software.

Unit 42 extends its April assessment

Unit 42 introduced Frontier AI Defense in April as a point-in-time analysis of an organisation’s exposure, followed by a security blueprint, Palo Alto Networks says. In August, it announced plans to add GPT-5.6-Cyber and Claude Mythos 5 to that assessment. The new subscription takes the testing beyond that individual review.

Palo Alto Networks says attackers using AI have reduced the time needed to exploit some vulnerabilities by almost 97%, from weeks to hours. Its proposed response is to keep testing customer systems as they change and pass prioritised fixes to security teams. The company describes that testing as offensive security work conducted on behalf of customers.

The shift from a point-in-time assessment to an annual subscription changes what customers buy: continuing tests and recommendations rather than a single analysis and blueprint. The available plans also tie the service’s configuration to the mix of models selected, while Unit 42 supplies the testing method and routes work between them.

Palo Alto Networks reports $17 million development spend

Palo Alto Networks says its $17 million went towards research, development and refinement of the testing method. It developed the approach through six months of work on its own systems and more than 100 Unit 42 customer engagements. The spending is the company’s investment in the approach; customers pay for the resulting service through annual subscriptions.

In its internal deployment, Palo Alto Networks says three weeks of testing uncovered as many exposures as it would normally expect to find over a year. That comparison concerns weaknesses found on the company’s systems. Its separate customer results come from Frontier AI Exposure Analysis, the earlier assessment service.

That analysis found exposures at 100% of customers assessed, according to Palo Alto Networks. The company says 37% of the exposures were rated high or critical. Those results describe findings from customer assessments, while the annual subscription offers repeated testing as systems change.

Palo Alto Networks says most exposures found in the assessments came from customers’ own applications. Among exposures in third-party applications, it says more than two in three had no known CVE.

Topics: Agents, Enterprise adoption, Foundation models