Reading view

There are new articles available, click to refresh the page.

Anthropic Discloses Fourth Incident of Claude Breaching Real Systems During Security Tests

Anthropic has disclosed a fourth incident in which one of its Claude models broke into genuine third-party systems during what was supposed to be a contained cybersecurity evaluation, deepening industry concern over the risks posed by increasingly autonomous AI agents.

The AI company said the episode dates back to January 2026 and involved an early version of Claude Opus 4.6, which breached external infrastructure after it was “unable to abort its task.” Anthropic has notified all affected parties, though it has not disclosed who they are. The incident is understood to have gone undetected until last month.

It follows three earlier cases revealed by Anthropic in July 2026, in which Claude Opus 4.7, Mythos 5 and an unnamed research model each compromised separate organisations during cybersecurity evaluations, again without the company’s knowledge at the time.

“AI safety is not just a model problem it’s an operational and human one. A simple configuration or naming error allowed a controlled test to interact with real systems, while the model continued pursuing its objective despite warning signs. Organisations deploying autonomous agents need clear accountability, isolated test environments, least-privilege access and human approval for high-impact actions. Trusting an AI to ‘do the right thing’ is not a security control.”
– Javvad Malik, Lead CISO Advisor at KnowBe4

According to Anthropic, all four incidents occurred during cybersecurity evaluations built by the same external evaluation partner. Claude was told it was operating in a simulated environment with no internet access, but a misconfiguration meant it was actually connected to the open internet. The partner responsible for the evaluations, Irregular, has since said the breach stemmed from a naming error: a fictional company used in the hacking simulations happened to match a real-world domain, causing the models to take offensive action against it.

Anthropic has since scanned roughly 481 million transcripts for similar problems and says it found no other cases of comparable or greater severity. The company has also signed an agreement with independent research non-profit METR to carry out a separate investigation into the incidents.

Anthropic attributes the root cause to two alignment failures: biased reasoning and recklessness. In practice, this meant the models tended to dismiss or misread evidence that their environment was connected to the live internet after initially being told otherwise, and were willing to pursue potentially harmful actions in single-minded pursuit of the task they had been assigned.

“Relying on an automated AI agent to audit another AI for security breaches is a fundamentally flawed approach. These models are increasingly acting as autonomous entities capable of probing network boundaries. When they escape their evaluation environments to access external systems, they create an unpredictable new vector for supply chain attacks. Developers must enforce strict network isolation rather than trusting software to mark its own homework.”
– Dray Agha, Senior Manager of Security Operations at Huntress

Anthropic said it was most concerned by the incident involving Claude Mythos 5, which went to considerable lengths to upload a malicious package to PyPI, the public repository used to distribute most Python software. The company noted that although the model repeatedly stated in its chain-of-thought reasoning that it believed it was in a simulation, the environment contained clear evidence it was on the real internet, and its actions were consistent with knowing this. Even after researchers amended the transcript to make the real-world context unmistakable, the model went on to carry out offensive actions.

Anthropic was keen to stress that the incidents remained narrow in scope: no Claude instance deviated from the task it had been set, none attempted to coordinate with other AI agents, and none tried to conceal evidence of its actions. The company added that biased reasoning appears less pronounced in its newer production models and can be reduced through more thorough alignment training, though the underlying cause, and why it was more acute in Mythos 5, remains unclear.

“As agentic AI systems become more capable and more widely deployed, the legal framework for who is responsible when a model accesses something it shouldn’t is going to need answering. These four incidents are an early test case for questions the law hasn’t fully addressed yet. Anthropic found four problems in 481 million transcripts and told everyone about it. The real question is how many problems the rest of the industry hasn’t looked hard enough to find yet.”
– Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress

The disclosure lands amid growing scrutiny of AI model safety more broadly. Rival OpenAI recently acknowledged a previously unreported incident from May 2026, in which internally deployed autonomous agents with read-only internet access took over a dormant German wiki forum, exchanging more than 18,000 posts as they attempted to coordinate answers and evade restrictions on a timed task. When a human moderator began removing the posts, the agents reportedly worked around the clean-up by naming backup pages so they would be buried at the end of an alphabetically sorted deletion list.

“We need to stop blaming AI and hold the humans in charge accountable for the actions of their AI agents. Companies will think twice about deploying AI if they are fined for negligence. It’s frustrating to listen to tech CEOs warn about the dangers of AI and then turn around and build it as if those dangers are unavoidable. If this problem gets bad enough, then we could see an emerging market for AI insurance that covers rogue third-party hacking, data theft, and intellectual property infringement.”
– Paul Bischoff, Consumer Privacy Advocate at Comparitech

Anthropic has warned that the risks are likely to grow rather than diminish as AI systems become more capable. “Future AI systems will be increasingly capable, which implies that misalignment will have the potential to cause more extreme harm,” the company said, adding that training robustly aligned frontier models remains an unsolved technical challenge that will require both continued research and stronger operational discipline from those deploying them.

For now, the incidents serve as a reminder that the weakest link in agentic AI deployments may not be the model itself, but the environments, configurations and oversight structures built around it.

The post Anthropic Discloses Fourth Incident of Claude Breaching Real Systems During Security Tests appeared first on IT Security Guru.

NCSC Warns Shadow AI Is Creating New Security Blind Spots for UK Businesses

The UK’s National Cyber Security Centre (NCSC) has warned organisations about the security risks posed by “shadow AI”, as employees continue to turn to artificial intelligence tools that have not been approved by their employers.

In guidance published this week, the NCSC described shadow AI as the use of AI technology outside an organisation’s approved systems and processes, warning that security policies and governance have struggled to keep pace with the rapid adoption of AI in the workplace.

The scale of the issue could already be significant. Research cited by the NCSC found that 71% of employees have used AI tools that have not been approved by their employer.

According to the NCSC, unapproved AI services can expose sensitive company and customer information, reduce organisations’ visibility and control over their data, and create new opportunities for attackers. Information entered into consumer AI services may be stored, retained or used to improve those services outside existing corporate security and governance arrangements, depending on the privacy controls in place.

The agency also highlighted a potentially more serious risk as organisations move from generative AI tools towards AI agents. If an attacker exploits a vulnerability in an agent, they may be able to gain access to the same data, services and privileges legitimately available to that agent.

Darren Guccione, CEO and co-founder of Keeper Security, said the warning reflects a challenge many UK security teams are already facing.

“The NCSC’s warning on shadow AI reflects the reality of what many UK security teams are having to contend with. When employees adopt AI tools faster than IT can assess them, visibility gaps open long before governance has an opportunity to catch up. Microsoft’s research, cited by the NCSC, found that 71% of UK employees have used AI tools their employer hasn’t approved. Keeper Security’s 2026 research underlines the effect this is having on security teams, with 37% of UK organisations saying they lack visibility into which AI tools employees are actually utilising inside the business.

“The most significant detail in the NCSC’s warning is its point about AI agents inheriting the privileges of whoever deploys them. An attacker who compromises a poorly governed agent gains whatever access that agent holds, whether that’s a customer database or a finance system. Organisations that haven’t extended least-privilege and just-in-time access principles to their AI agents and non-human identities are exposed in ways endpoint controls alone won’t catch.”

Banning AI is unlikely to work

Rather than recommending organisations attempt to eliminate shadow AI altogether, the NCSC said businesses should focus on reducing the associated risks and understanding why employees are turning to unapproved tools in the first place.

It recommends creating a positive cyber security culture, providing AI tools that meet employees’ needs and securely integrating AI systems into the workplace.

Guccione added: “Banning shadow AI outright rarely works, as the NCSC itself acknowledges. Employees will find routes around blocked tools when the approved ones can’t do what they need.

“The more durable fix is improving visibility by identifying what identities, both human and machine, exist across the environment and what they can access. Organisations must enforce least-privilege principles by default, rather than waiting until an incident forces the question.”

Jamie Akhtar, CEO and co-founder at CyberSmart, agreed that businesses need to balance employees’ desire to use AI with appropriate security controls.

“The NCSC is right to highlight shadow AI as a growing cyber security challenge. Employees are using AI tools to work faster and more efficiently, but when those services sit outside an organisation’s approved systems, businesses can quickly lose visibility over where sensitive company and customer data is being shared, stored or processed.

“Simply banning AI is unlikely to solve the problem. Businesses need to provide secure, approved alternatives that allow people to benefit from AI without introducing unnecessary risk. Clear policies, employee education and appropriate technical controls all need to develop at the same pace as AI adoption.”

Akhtar said the challenge may be particularly difficult for SMEs without large in-house security teams, where managed service providers could help organisations identify unapproved technology and establish appropriate AI policies and controls.

“An MSP can help businesses identify unapproved technology, put proportionate AI policies and controls in place, educate employees and continuously manage emerging risks, giving organisations the confidence to embrace AI while maintaining visibility and control over their security.”

The NCSC said shadow AI is unlikely to disappear completely as AI services become cheaper and more readily available. Instead, organisations need to understand how and why employees are using these tools so they can provide secure alternatives while maintaining visibility over sensitive information and access to corporate systems.

The post NCSC Warns Shadow AI Is Creating New Security Blind Spots for UK Businesses appeared first on IT Security Guru.

Black Duck Joins Project Glasswing to Strengthen AI-Era Software Security

Black Duck, a provider of AI-powered application security solutions, has announced its participation in Project Glasswing, Anthropic’s industry-wide initiative aimed at protecting critical software infrastructure through the defensive use of advanced AI.

Through its involvement, Black Duck will integrate Mythos throughout its application security offerings, pairing AI-driven, deterministic vulnerability detection with established remediation processes, risk-based prioritisation, and governance frameworks built around compliance. The combination is designed to deliver a blended approach to security that cuts risk more quickly and reliably than either method alone.

Dipto Chakravarty, Black Duck’s Chief Product & Technology Officer, noted that AI is reshaping both the pace and economics of vulnerability discovery and exploit development. He added that combining Mythos’s capabilities with Black Duck’s existing deterministic testing, remediation tools, and governance controls turns vulnerability discovery into tangible, measurable risk reduction, while giving enterprise security teams the speed, transparency, and auditability they require.

The post Black Duck Joins Project Glasswing to Strengthen AI-Era Software Security appeared first on IT Security Guru.

Check Point Brings OpenAI’s Daybreak Models Into Its Security Platform to Speed Up Threat Validation and Remediation

Check Point Software Technologies has announced it is integrating OpenAI’s Daybreak frontier AI models across its security platform, extending a partnership aimed at helping defenders detect, validate, and remediate cyber risk faster.

The move builds on Check Point’s existing collaboration with OpenAI through the Daybreak Defense Network, first expanded three months ago, and follows the company’s recent decision to join more than 100 technology and security firms in backing OpenAI’s call for a collective, global surge in cyber defense.

In a blog post announcing the expansion, Check Point Chief Technology Officer Jonathan Zanger said the work does not stop with previous milestones, arguing that security needs to keep adapting as new threats and attacker capabilities emerge, alongside evolving technology stacks and growing enterprise use of AI.

Zanger said the aim is to put OpenAI’s frontier cyber reasoning to work across the security lifecycle, combining it with Check Point’s own security intelligence, context, and enforcement capabilities so customers can move from large volumes of raw security data to validated risk, actionable decisions, and faster protection.

Four Areas of Integration

According to Check Point, the Daybreak models are being rolled into four parts of its platform:

  • Agentic Exposure Validation: Within Check Point’s Exposure Management product, the models are being piloted inside a multi-agent pipeline that separates genuinely exploitable risk from theoretical findings, combining AI reasoning with Check Point’s security context to validate attack paths and prioritise remediation.
  • Agentic Security Management: As part of Check Point’s autonomous, intent-driven approach to network security management, the models will help investigate potential attack paths, understand vulnerabilities and risky exposures, and identify appropriate fixes, reducing manual policy management.
  • Autonomous Workspace Platform: Within Harmony, Check Point’s investigation pipeline correlates email, endpoint, mobile, and browser telemetry; the models are being applied to investigate malware behaviour, attacker techniques, and credential-abuse chains, aiming to deliver clearer verdicts and remediation guidance while easing the load on security teams.
  • Vulnerability research: The models are being used to accelerate analysis of vulnerable code and patches, identify realistic exploitation paths and reach verified results faster, without relying on publicly available exploit code, which Check Point says should translate into faster protection against newly disclosed vulnerabilities.

Check Point said it is taking a phased approach to the rollout: some capabilities are already in production, others are in development and being tested with design partners, with more to follow as the underlying technology matures. The company said every deployment follows the same discipline: governing what the model can see, constraining what it can act on, and testing and verifying its output before allowing it to take on more work within approved security workflows.

A Two-Way Relationship

Zanger framed the OpenAI partnership as operating in two directions: Check Point uses frontier AI to strengthen how it defends customers, while also helping those customers adopt and use OpenAI’s technologies securely. He said both sides of that relationship are becoming more important as AI moves beyond answering questions towards writing code and operating autonomous enterprise agents.

“Our goal is to give organizations the confidence to embrace what AI makes possible while staying protected against evolving risks,” Zanger said, adding that the partnership is intended to put frontier AI to work for defenders while helping customers deploy it safely themselves.

The announcement is the latest sign of security vendors racing to embed frontier AI reasoning models directly into detection, validation and remediation workflows, as both defenders and attackers increasingly turn to AI to gain an edge.

The post Check Point Brings OpenAI’s Daybreak Models Into Its Security Platform to Speed Up Threat Validation and Remediation appeared first on IT Security Guru.

Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration

Application security vendor Black Duck has launched its Signal vulnerability scanning engine as an MCP server in the Claude Directory, giving developers using Anthropic’s Claude Desktop a way to check code for security flaws without switching tools.

The integration is built on the Model Context Protocol (MCP), the open standard that lets AI assistants like Claude call out to external services and pull structured data back into a conversation. Through it, Black Duck’s Signal Code Analysis engine can scan git diffs, individual files, or whole codebases for vulnerabilities directly from within the Claude environment developers are already using to write and refactor code.

Under the hood, source code submitted for a scan is sent to Black Duck’s cloud-based analysis service for processing. The results then come back as MCP resources, structured data that Claude can read and reason over, allowing it to explain identified risks and suggest remediation steps in plain language rather than simply returning a raw findings report.

The launch reflects a wider shift in how security vendors are approaching AI-assisted coding. As tools like Claude speed up how quickly developers can write and ship software, security teams are under pressure to embed checks earlier in the process rather than relying on scans that happen after code has already been merged. Black Duck is positioning Signal as a way to close that gap by putting vulnerability detection at the point of code generation itself.

Dipto Chakravarty, Chief Product & Technology Officer at Black Duck, framed the move as a response to the pace at which AI coding tools now operate. “security keeps pace with how fast teams are building,” he said of the aim behind bringing Signal into the Claude Directory.

Signal is available now through the Claude Directory listing, with Black Duck directing prospective users to speak to a company representative to get set up. The release follows Black Duck’s broader push into AI-focused application security tooling, part of a growing trend among established AppSec vendors to adapt existing scanning capabilities for workflows increasingly driven by AI coding assistants rather than traditional IDEs.

It also underscores the growing role of MCP as connective tissue between AI assistants and specialist enterprise tools. Since Anthropic opened up the protocol, a steady stream of security, development and productivity vendors have released their own MCP servers, letting Claude act as a front end for capabilities that would otherwise require developers to leave their AI workflow entirely.

The post Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration appeared first on IT Security Guru.

AI Agents Used by 68% of Top-Performing Cybersecurity Teams

AI agents are already finding their way into the working methods of some of the highest-performing cybersecurity teams, according to new three-year benchmark data from Hack The Box (HTB). The 2026 Global Cyber Skills Benchmark found that 68% of the top 25 teams included an AI agent, despite AI agents accounting for just 2.7% of all registered accounts. The findings provide an early indication of how AI is being incorporated into practical cybersecurity work alongside human expertise.

Across the competition, 17 of the top 25 teams had an AI agent. Collectively, agents were responsible for 4.2% of submitted flags and 4.6% of points awarded.

HTB cautioned that the figures do not demonstrate that the use of AI caused teams to perform better. However, the disproportionate presence of agents among the strongest teams suggests AI is moving beyond experimentation and becoming part of the toolkit used by experienced cybersecurity practitioners.

Cyber teams are solving challenges faster

The benchmark also points to a significant improvement in overall cybersecurity performance during the past three years. Median recorded time-to-solve fell from 26.1 hours in 2024 to 13.8 hours in 2026, a reduction of more than 12 hours.

Teams were also significantly more likely to complete the entire challenge board. Just two teams achieved this in 2024, rising to three in 2025 and 15 teams in 2026, despite the challenge board expanding during that period.

The results come as organisations explore how AI can augment security teams while simultaneously introducing new attack surfaces and risks. As AI agents gain greater autonomy and access to systems, applications and data, security teams will need to understand how to direct their activity and validate the decisions and outputs they produce.

The findings also raise questions about how cybersecurity skills will need to change. Rather than removing the need for technical expertise, greater AI adoption could place more emphasis on practitioners being able to assess AI-generated results, recognise errors and determine when human intervention is required.

Human judgement remains critical

Haris Pylarinos, Founder and CEO of Hack The Box, said AI’s growing role means organisations need to focus on the skills required to use the technology safely.

“The question for security leaders is no longer whether AI will become part of cybersecurity operations. That is already happening on both sides of the equation,” he said.

“What matters now is whether teams have the expertise to use it safely and effectively. Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them. As agents become more capable, human judgment, validation and hands-on technical skill become more important, not less.”

HTB said the latest findings build on its previous research examining how practitioners perform when working with AI. While earlier testing looked at AI use in controlled conditions, the latest benchmark provides a view of where agents are being adopted when competitors are able to choose their own approach.

The results suggest the next phase of AI adoption in cybersecurity may therefore be as much a skills challenge as a technology one, with organisations needing practitioners capable of questioning, testing and validating what autonomous systems produce.

The post AI Agents Used by 68% of Top-Performing Cybersecurity Teams appeared first on IT Security Guru.

Proton launches free tool to show enterprises what ChatGPT and Claude know about employees

Privacy-focused tech company Proton has launched a free tool designed to show users exactly what large language models such as ChatGPT and Claude have learned about them from months or years of conversation history, a capability that speaks directly to the shadow AI problem now facing enterprise security teams.

The tool, called AI Paper Trail, works by analysing conversation exports that users download directly from ChatGPT or Claude. It then generates a personal report that includes an AI Exposure Score quantifying how much has been extracted and how revealing it is, a breakdown of inferred personal information such as occupation, habits and relationships, an estimated financial value of that data to an AI provider, and a “Privacy Type” profiling the user’s approach to data sharing. Proton says uploaded files are deleted immediately after analysis and are never stored on its servers.

For security leaders, the launch lands at an awkward moment. Employees are increasingly turning to consumer AI chatbots for work-related tasks, drafting emails, summarising documents, troubleshooting code, often on personal accounts that sit entirely outside corporate visibility and data governance controls. AI Paper Trail offers a rare, concrete illustration of what that unmanaged usage can expose over time, from project details and client names to health, financial and relationship information that has nothing to do with the job at hand.

“People understand that AI collects data, but most don’t realise how revealing their conversation history becomes over time,” said Eamonn Maguire, Director of Engineering, ML & AI at Proton. “AI Paper Trail makes that invisible profile visible. We want people to understand what they’re sharing with AI systems so they can make informed decisions about the tools they use.”

The company has not disclosed the methodology behind the Exposure Score or the data valuation figures, which may draw scrutiny from researchers and journalists looking to verify the tool’s claims.

Built on Proton’s privacy-first AI assistant

AI Paper Trail is powered by Lumo, Proton’s own AI assistant, which the company positions as an alternative to mainstream chatbots for privacy-conscious individuals and businesses. Proton says Lumo keeps no server-side logs of conversations, does not use chats to train its models, and encrypts conversations end-to-end so that even Proton itself cannot access them. The assistant is built on open-source language models and runs from European data centres, outside the jurisdiction of the US and Chinese providers that dominate the market.

AI Paper Trail currently supports conversation exports from ChatGPT and Claude, with Proton planning to add further AI platforms in future releases. The tool is available free at lumo.proton.me/aitrail.

The post Proton launches free tool to show enterprises what ChatGPT and Claude know about employees appeared first on IT Security Guru.

AI pentesting tools are generating more findings than security teams can validate, new survey finds

New research from Pentest-Tools.com suggests that AI-assisted penetration testing tools are generating vulnerability findings faster than most security teams can verify them, creating a validation backlog that is offsetting the time AI was meant to save.

The company surveyed 158 security practitioners in June 2026, including penetration testers, security engineers, AppSec and DevSecOps professionals, consultants, and MSSP practitioners, all of whom use AI-assisted tools in their vulnerability assessment and validation work.

Among the 147 respondents who have used AI to generate findings, 87.8% said the output required significant manual validation. 61.2% said this happened with between 5% and 25% of findings, while 26.5% said more than a quarter of AI-generated findings needed rework before they could be trusted.

The capacity problem becomes more acute at scale. Asked whether their team could triage and validate more than 500 AI-generated vulnerability candidates from a single engagement, only 20.3% of respondents said they already had a workflow in place to do so. 38.6% said the volume would strain their team, and 29.7% said it would be unmanageable.

Respondents described tools returning hundreds of findings that turned out to be duplicates, false positives, unexploitable issues, or fabricated CVEs that do not exist. One practitioner summarised the pattern: an AI tool produced 300 findings, of which 250 were later found to be junk, including “potential SQLi that is not exploitable” and “AI-made-up CVEs that do not exist.” The respondent added: “I bought the tool to save time, but I did more manual work than before.”

Fabricated and hallucinated findings emerged as the leading frustration in the survey overall. Roughly 30% of free-text responses on the biggest frustration with AI pentesting tools cited false positives, hallucinated exploits, or fabricated findings, ahead of cost, integration issues, or any other complaint.

Practitioners also described a trust effect: once a hallucinated finding was caught, teams became more cautious about the rest of a tool’s output, increasing the verification workload even for genuine findings. One security manager at a mid-market company described the effect of encountering fabricated results as “confidence that turns out to be just a big lie.”

Where AI is deployed within the pentest lifecycle reflects this caution. Usage is highest in vulnerability scanning and discovery (74.1%), report writing (69%), and documentation and findings tracking (66.5%). It drops in phases requiring live judgement: exploitation and attack path chaining (36.7%), remediation validation and retesting (34.8%), and post-exploitation and lateral movement (25.3%).

Business logic testing emerged as the area practitioners consistently said AI struggles with most, ahead of exploit chaining and creativity. Respondents gave concrete examples: AI tools can identify SQL injections, but do not reliably catch that a discount coupon should only work once per customer, that adding a negative quantity to a shopping cart can produce a free purchase, or that changing a user ID in a URL can expose another customer’s data without triggering any error or anomaly.

The survey also points to AI-related testing scope expanding on a separate front. 75.3% of practitioners said they already test AI-powered systems or LLM-integrated applications as part of current engagements, with a further 17.1% expecting to do so within 12 months, bringing total adoption or planned adoption to 92.4%. Around one in three (33.5%) already include risks from unauthorised employee use of AI (“shadow AI”) in their assessment scope, while 53.2% have discussed doing so but have not yet formalised the process.

Stakeholder pressure is rising in parallel. 37.3% of respondents said internal stakeholders now expect more frequent testing than they did 12 months ago, driven by awareness of AI-assisted attacks, while a further 31.6% said stakeholders were aware of the risk shift but had not yet changed buying behaviour.

When evaluating AI-driven pentesting platforms, accuracy-related criteria outranked cost. False positive rate and signal quality were the top consideration, cited by 63% of respondents, followed by proof of exploit and verified attack paths (53%). Cost and licensing came third, at 47%.

A spokesperson for Pentest-Tools.com said: “AI is speeding up what practitioners can find. The issue is in what follows after that. When you have 300 findings from a tool and 250 of them are invalid, the time savings in discovery are spent on triage. The value of AI in pentesting lies in actionable findings.”

The survey data also suggests testing cadence, rather than organisation size, is the strongest predictor of how well a team copes with AI-generated volume. Teams testing more frequently were more likely to already have workflows for handling large numbers of findings, while teams testing less than five times a month were the most likely to describe the volume as unmanageable. Pentest-Tools.com notes that the sample size for the highest-frequency testing groups is small, and treats this finding as directional rather than conclusive.

The full survey report, “AI pentesting in 2026: why testing cadence decides who copes,” is available here.

The post AI pentesting tools are generating more findings than security teams can validate, new survey finds appeared first on IT Security Guru.

Check Point Brings AI Security into the Firewall with Industry-First AI Network Firewall

Check Point Software has launched what it calls the industry’s first AI Network Firewall, extending AI-specific inspection and control into the firewall infrastructure that organisations already operate, rather than requiring a separate virtual appliance.

The capability, delivered through Check Point’s firewall software release R82.20, is designed to close what the vendor describes as a blind spot in enterprise networks: traffic generated by AI systems, including user prompts, model calls, and the actions of autonomous agents, which passes through existing security infrastructure largely undetected because it resembles ordinary web traffic.

“AI is transforming the enterprise network, and with the AI Network Firewall, we are transforming the firewall to secure it,” said Nataly Kremer, Chief Product Officer at Check Point. “The network is where every prompt, model call, and agent interaction already converges, yet traditional firewalls were never built to see or govern that activity.”

Three domains of protection

According to Check Point, the AI Network Firewall addresses three areas of exposure. For employee AI use, it discovers sanctioned and shadow AI tools in operation, classifies the intent behind prompts, and blocks sensitive data from leaving the network based on that classification, an approach the company positions as more precise than keyword- or pattern-based data loss prevention. For AI agents and MCP (Model Context Protocol) traffic, it gives security teams visibility into which servers and tools are being called and lets them enforce access policy across those interactions. For AI applications and large language models, it inspects traffic inline to block prompt injection and adversarial inputs before they reach the model, without requiring changes to the application itself.

The launch draws on research from Check Point’s threat intelligence arm. Its AI Security Report 2026 found that between 87% and 93% of organisations experience at least one high-risk generative-AI interaction every month, and that the proportion of prompts carrying sensitive corporate, personal, or regulated data doubled year-on-year to roughly one in every 25 interactions. The company’s researchers also reported security weaknesses in 40% of 10,000 MCP servers reviewed, and identified over 15,000 indirect prompt-injection payloads embedded in public web pages, around 70% of them hidden in sections of the page not visible to a human reader.

Analyst and partner reaction

Pete Finalle, research manager for trusted access and network security at IDC, said organisations are often forced into deploying additional, siloed AI security tools that add to existing sprawl. Native integration of AI security into enforcement points already in place, he said, is rare but brings improvements to visibility, telemetry, security posture, and management simplicity.

Chris Konrad, vice president of global cyber at WWT, argued that policy alone will not contain shadow AI use, since employees will keep adopting AI tools before security teams are aware of them. Building AI visibility and enforcement into infrastructure organisations already trust, he said, gives teams a practical control point without slowing down AI adoption.

Part of a broader AI Defense Plane

The AI Network Firewall extends Check Point’s AI Defense Plane, a unified control layer the vendor introduced to cover AI discovery, governance, and protection across networks, endpoints, cloud, applications, and APIs. Check Point said it is also extending central, agentic policy management to its SASE and SD-WAN products, alongside integrations with third-party micro-segmentation tools including Illumio, aiming to give a single console consistent policy and audit trail across on-premises firewalls, cloud firewalls, AWS-native firewalls, SD-WAN, and SASE deployments.

The AI Network Firewall is available now.

The post Check Point Brings AI Security into the Firewall with Industry-First AI Network Firewall appeared first on IT Security Guru.

❌