Palo Alto Networks Bundles Four Security Products Into New AI Coding Platform

AI Security

The launch combines endpoint discovery, agent identity, and gateway controls into one platform for securing AI coding agents, competing directly with CrowdStrike and Google Cloud.

By Shashi Bellamkonda

220,000
installs found at Cambia Health Solutions in under two weeks
$13B
projected 2026 spend on AI coding tools
109:1
machine to human identities, per Palo Alto Networks
4
product lines merged into one console

Palo Alto Networks introduced Secure AI Coding on September 10, a platform built to secure the AI agents now writing, deploying, and running code inside enterprise environments. The company points to a scan at Cambia Health Solutions that turned up 220,000 software installations across 14 data sources in under two weeks (Koi.ai, "Cambia Health Solutions," 2026), evidence of how much AI tooling already runs inside enterprises without security teams knowing it is there.

The company also points to AI coding tool spending on pace to top $13 billion this year (IdeaPlan, "AI Coding Assistant Market Share 2026," 2026), and says machine identities already outnumber human identities 109 to 1 inside the typical enterprise, a figure drawn from its own research (Palo Alto Networks, "Idira 2026 Identity Security Landscape," 2026).

The Launch Covers Discovery, Identity, Supply Chain, and Runtime

Secure AI Coding bundles four product lines under one console. Cortex Agentic Endpoint Security, built on Palo Alto Networks's April acquisition of the startup Koi, is the same technology behind the Cambia Health Solutions scan. It finds coding agents, browser extensions, skills, and Model Context Protocol servers already running on developer machines. Idira issues each agent its own verified, task-scoped identity in place of standing developer credentials. AI Model Security scans those same skills and servers for malicious code before an agent can use them. The AI Gateway inspects prompts and model traffic in real time and enforces spending limits.

All four modules ship under one console rather than as separate purchases.

Security Teams Gain a Single View of Agent Activity

For customers, the pitch is consolidation. Instead of pulling logs from an endpoint tool, an identity provider, and a network gateway separately, a security team gets one console that traces an action back to the specific agent that took it. Neil Boland, chief information security officer at Major League Baseball, credited the integration with letting engineering teams adopt new AI coding agents without adding a separate security review step. Palo Alto Networks says the same architecture governs data movement and AI spend alongside identity and access.

"Prisma AIRS lets our engineers safely use the latest AI coding agents."

CrowdStrike and Google Take Different Paths to the Same Problem

Palo Alto Networks is not alone here. CrowdStrike introduced its Agentic Identity Provider on September 2, built on its acquisition of SGNL, giving AI agents verified identities and replacing standing privileges with continuous, risk-based authorization. That product competes with Idira but does not extend to endpoint discovery or supply chain scanning. Google Cloud took a different route after completing its $32 billion acquisition of Wiz in March. The Wiz AI Application Protection Platform covers security from code to cloud to runtime, and Google's CodeMender agent automates vulnerability remediation, a scope closer to Palo Alto Networks's supply chain and gateway modules than to its identity layer.

The Real Bet Is Breadth Against Point Products

CrowdStrike and Google Cloud are each selling depth in one layer, identity for one, code-to-cloud posture for the other. Palo Alto Networks is selling breadth across four layers at once, wagering that enterprises would rather manage one console than stitch together separate best-of-breed tools themselves.

That bet is untested outside the customer testimonials Palo Alto Networks published at launch.

CIO/CTO Viability Question

Ask Palo Alto Networks, CrowdStrike, and Google Cloud each to walk through the same incident end to end. Compare how many consoles and logins it actually takes to trace an agent's action from the code it touched to the identity it used, then weigh that against what you already run today.

Works Cited
CrowdStrike. "Introducing the CrowdStrike Agentic Identity Provider, the Foundation for AI Agent Identity Security." CrowdStrike, 2 Sept. 2026, crowdstrike.com.
Google Cloud. "Google Completes Acquisition of Wiz." Google Cloud, 11 Mar. 2026, cloud.google.com.
IdeaPlan. "AI Coding Assistant Market Share 2026." IdeaPlan, 2026, ideaplan.io.
Koi.ai. "Cambia Health Solutions." Koi.ai, 2026, koi.ai.
Palo Alto Networks. "Idira 2026 Identity Security Landscape." Palo Alto Networks, 2026, paloaltonetworks.com.
Palo Alto Networks. "Secure AI Coding: Governing Every Agent, Artifact, and Identity." Palo Alto Networks Blog, 10 Sept. 2026, paloaltonetworks.com.

Disclaimer: This blog reflects my personal views only. Content does not represent the views of my employer, Info-Tech Research Group. AI tools may have been used for brevity, structure, or research support. Please independently verify any information before relying on it.