Back/Palo Alto Networks acquires Koi for agentic AI security; unveils Managed XSIAM amid fast breaches
tech·February 19, 2026·panw

Palo Alto Networks acquires Koi for agentic AI security; unveils Managed XSIAM amid fast breaches

ED
Editorial
Cashu Markets·3 min read
TL;DR
  • Palo Alto Networks is acquiring Koi to close AI security gaps from autonomous agentic endpoints and developer tools.
  • Palo Alto will integrate Koi into Prisma AIRS and Cortex XDR to broaden AI‑attack‑surface visibility and enforcement.
  • Palo Alto says the integration enables safe deployment of agentic automation using telemetry, policy controls, and automated remediation.

New defences for an AI-era threat landscape

Palo Alto Networks moves to plug a newly identified AI security gap with a definitive agreement to acquire Koi, a specialist in "Agentic Endpoint Security," the company announces on Feb. 17. The deal targets risks created by autonomous AI agents and developer tools that act as powerful insiders with broad permissions and deep access to sensitive data, bypassing traditional file‑based controls. Palo Alto frames the acquisition as a way to restore centralized oversight across distributed automation by surfacing agent identities, actions, permissions and model artifacts so security teams can enforce least‑privilege policies and prevent weaponization of trusted automation.

The acquisition is positioned to augment Palo Alto’s Prisma AIRS™ AI security platform and to strengthen Cortex XDR® endpoint protections once integrated, executives say. Koi’s capabilities are described as addressing behavior changes driven by extensions, plugins, scripts and model artifacts operating outside centralized oversight — elements that conventional endpoint detection misses. By bringing these signals into Prisma AIRS and Cortex XDR, Palo Alto aims to broaden visibility across the AI attack surface and give customers policy and enforcement tools tailored to agentic workflows.

Company technologists argue the move is part of a broader push to reduce attack velocity rather than merely detect threats post‑breach. Lee Klarich, chief product and technology officer, says agentic tools act like “ultimate insiders” and that Agentic Endpoint Security is the next frontier of enterprise risk reduction. Palo Alto stresses that the integration will enable enterprises to deploy agentic automation with confidence by combining telemetry, policy controls and automated remediation at the endpoint and across cloud-native workflows.

Managed SOC push: MSIAM 2.0 aims to outpace attacks

On the same day Palo Alto introduces a managed offering, Unit 42 unveils Managed XSIAM 2.0 (MSIAM), a 24/7 managed SOC built on the AI‑driven Cortex XSIAM platform that pairs continuous expert hunting with a 250‑hour Breach Response Guarantee. The service is designed to boost SOC maturity on day one, integrate third‑party EDR and existing tools, and bridge the gap between machine‑speed attacks and human response while addressing industry talent shortages.

Unit 42 report: AI and identity compress breach timelines

Palo Alto’s Unit 42 2026 Global Incident Response Report finds attackers using AI and automation to compress the time from initial access to data exfiltration to as little as 72 minutes in the fastest cases, a roughly fourfold acceleration year‑over‑year. The report links 90% of breaches to misconfigurations or security gaps, notes identity is involved in 89% of investigations and warns that third‑party SaaS supply‑chain attacks have risen sharply, recommending unified platforms, elimination of implicit trust and AI‑enabled detection to contain high‑velocity incidents.

Cashu Markets
Cashu
Markets

By Cashu Markets. Providing market news, analysis, and research for investors worldwide.

© 2026 Cashu Technologies Pty Ltd. All rights reserved. Cashu Markets is a trademark of Cashu Technologies Pty Ltd.

The content published on Cashu Markets is for informational purposes only and should not be construed as investment advice, a recommendation, or an offer to buy or sell any securities. All opinions expressed are those of the authors and do not reflect the official position of Cashu Technologies Pty Ltd or its affiliates. Past performance is not indicative of future results. Investing involves risk, including the possible loss of principal. Always conduct your own research and consult with a qualified financial advisor before making any investment decisions.

Cashu Markets and its contributors may hold positions in securities mentioned in published content. Any such holdings will be disclosed at the time of publication. Market data is provided on an "as-is" basis and may be delayed. Cashu Technologies Pty Ltd does not guarantee the accuracy, completeness, or timeliness of any information presented.

Cashu Markets
Cashu
Markets

Setting up your session...