The autonomous AI agent is the most powerful — and the most dangerous — new participant in the modern enterprise. It reasons, decides, and acts across internal systems, external APIs, and sensitive data with minimal human oversight. And until now, it has operated largely ungoverned. Palo Alto Networks (NASDAQ: PANW) has moved decisively to close that gap — announcing its intent to acquire Portkey, a pioneer in AI Gateway technology, and integrate it into its Prisma AIRS platform to create the industry's first truly unified control plane for agentic AI security.
The Problem: AI Agents Are Privileged Insiders Without a Security Perimeter
The enterprise security landscape has fundamentally changed. The threat model of the past decade — centred on protecting networks, endpoints, and cloud infrastructure from external attackers — has been joined by a new category of risk that existing frameworks were never designed to address: AI agents operating as highly privileged insiders.
Unlike human employees, AI agents execute at machine speed and scale — making thousands of automated decisions across internal and external systems, invoking APIs, accessing sensitive databases, and communicating with other agents, all with minimal human oversight. As Nikesh Arora, Chairman and CEO of Palo Alto Networks, puts it: "AI agents have become privileged insiders, reasoning and executing on behalf of users and companies. With that power comes a new category of risk. You cannot build an agentic enterprise without a centralised control plane to secure it."
The consequences of this governance gap are concrete: fragmented security coverage, unauthorised data access, prompt injection attacks, model manipulation, and runaway token consumption that translates into operational cost spirals. Enterprises moving AI agents into production have been forced to choose between developer speed and enterprise safety. Palo Alto Networks intends to eliminate that trade-off entirely.
What Portkey Does: The AI Gateway as the Central Nervous System
Founded in 2023 by Rohit Agarwal and Ayush Garg, Portkey was built to solve exactly this problem. Its platform functions as a centralised AI Gateway — a unified control layer that sits between enterprise systems and all AI model interactions, routing, monitoring, and securing every interaction in real time. Rather than leaving AI traffic ungoverned across disparate tools and APIs, Portkey creates a single vantage point through which all agentic activity flows.
Crucially, Portkey is already battle-tested at genuine enterprise scale — processing trillions of tokens per month for Fortune 500 companies, with the ultra-low latency required for agent-to-agent communication. This is not a prototype or a research project. It is production-hardened infrastructure that major enterprises have already trusted to govern their AI workloads at scale.
The platform delivers five core capabilities that address the enterprise agentic AI security gap comprehensively:
- →Observability — complete visibility into all AI agent traffic across every model invocation, API call, and agent-to-agent interaction
- →Governance & Policy Enforcement — consistent security policies enforced at runtime across all models and agents, ensuring every interaction is identified, authenticated, and authorised
- →Semantic Routing — intelligent routing of AI traffic to the optimal model for each request, based on cost, latency, capability, and compliance requirements
- →Cost Control — management and optimisation of token consumption to prevent runaway spend without constraining agent performance
- →Agent Registry & Access Controls — a structured registry of all agents operating within the enterprise, with granular access controls that connect directly to identity security primitives
"As autonomous agents join the enterprise workforce, they also become a new, unmanaged attack surface. By integrating Portkey into Prisma AIRS, organizations will be able to confidently deploy and govern AI agents. With Portkey, we are providing enterprises with visibility into all their agentic traffic, and enabling them to control and protect against agentic threats."— Lee Klarich, Chief Product & Technology Officer, Palo Alto Networks
Prisma AIRS 3.0: The Platform Portkey Is Joining
Prisma AIRS (AI Runtime Security) is Palo Alto Networks' dedicated platform for securing the agentic AI lifecycle — released as Prisma AIRS 3.0 earlier in 2026 with coverage spanning model scanning, runtime security, and automated red teaming. It was designed from the ground up to address the security challenges that emerge as enterprises move from isolated AI experiments to autonomous, production-grade agentic systems.
Prior to the Portkey acquisition, Prisma AIRS had a critical gap: it could scan models and monitor runtime behaviour, but lacked a production-hardened gateway capable of intercepting, routing, and governing AI traffic at the volume and latency required by real enterprise agentic workloads. Portkey fills that gap precisely — bringing a battle-tested component that has already proven it can operate at Fortune 500 scale without introducing latency that would impair agent-to-agent communication. Once integrated, Portkey will serve as the AI Gateway for Prisma AIRS — inspecting every AI interaction and enforcing security and governance policies across the entire agentic lifecycle.
What This Means for Enterprise Security Teams
For CISOs and enterprise security leaders, the Portkey integration into Prisma AIRS represents a concrete answer to one of the most pressing questions of 2026: how do we govern AI agents operating at machine speed, across systems we cannot fully enumerate, without slowing down the AI initiatives that drive business value?
Following the close of the acquisition, expected in Palo Alto Networks' fiscal Q4 2026, existing Portkey customers will continue to receive full support — while also gaining access to tighter integration with Palo Alto Networks' broader security portfolio, including CyberArk for identity security. The unified architecture will allow organisations to move autonomous AI workloads into production with built-in security, reliability, and management — removing the trade-off between agent autonomy and security governance that has slowed enterprise AI deployment.
As Rohit Agarwal, CEO and Co-Founder of Portkey, summarises the joint vision: "By joining Palo Alto Networks, we will establish the AI Gateway as the foundational layer of the secure AI enterprise. Together, we will provide the infrastructure that allows every organisation to deploy autonomous agents with the confidence that their data and operations are fully protected."
