Palo Alto Networks' AI agents will attack your systems — so real attackers can't first
Palo Alto Networks is selling always-on AI agents that attack its customers' systems on purpose. Unit 42 Continuous Frontier AI Defense uses gated frontier models from Anthropic and OpenAI to find, validate and help fix exposures continuously — because attackers now compress weeks of hacking into hours.

Palo Alto Networks wants to sell you an attacker. The cybersecurity giant announced on Monday that its Unit 42 threat-intelligence arm now offers an always-on service in which autonomous AI agents continuously probe customers' systems — finding exposures, proving they can actually be exploited, and mapping the attack paths — so that real attackers don't get there first.
The service, called Unit 42 Continuous Frontier AI Defense, is built on a bet that could shape the next phase of the security industry: the same frontier AI models that are making attacks faster and cheaper can be turned, continuously, into the defense. It is one of the first commercial offerings to put gated, capability-rich frontier models from Anthropic and OpenAI into an offensive-security product.
What the service actually does#
Traditional penetration testing is episodic: a red team shows up a few times a year, produces a report, and leaves. Palo Alto Networks is replacing that cadence with agents that never clock out. The company describes the system as agentic offensive security — the AI agents work through attack tasks on their own rather than waiting for human instructions, chaining reconnaissance, scanning, and exploit-validation steps autonomously.
The coverage spans the surfaces enterprises actually get breached through: web applications, cloud infrastructure, source-code repositories, and the APIs that connect software systems. When the agents find something, they don't just log it — they confirm whether it can genuinely be exploited, map the full attack path, and then hand security teams fixes, including code-level remediation suggestions and virtual-patching options that block the exposure while a real patch is built.

The multi-model bet#
The product's engine is a mix of gated frontier models — Anthropic's Claude Mythos 5 and OpenAI's GPT-5.6-Cyber — alongside open-weight models, coordinated by a proprietary harness that assigns each scan to whichever model is strongest at it. The cyber-specialized variants matter: these are frontier models tuned for security work, distributed under restricted access rather than general release.
Palo Alto Networks said its internal testing forced that design: no single model proved sufficient. One might catch roughly 40% of flaws in complex environments while another found different ones, with overlap under 10%. The multi-model harness combines the outputs and layers Unit 42's threat intelligence and human expertise on top.
This is a continuity play, not a from-scratch launch. Unit 42's Frontier AI Defense debuted in April as a point-in-time exposure analysis; in August, the company expanded its Frontier AI Exposure Analysis with GPT-5.6-Cyber and Claude Mythos 5. The new service converts that capability from a one-off assessment into continuous testing.

Why now: attacks run at machine speed#
The announcement lands in the middle of a genuinely frightening trend in offensive security. Palo Alto Networks says threat actors using AI to find and exploit vulnerabilities have compressed some attack cycles by almost 97% — from weeks to hours.
Unit 42 documented one such incident this month: a human attacker used frontier AI models and agentic frameworks to breach an enterprise network in under 10 hours — work the firm estimates would take human operators roughly two weeks. The attacker mapped internal microservices, pulled credentials from code repositories, and escalated into the organization's secrets-management system, coordinating more than 50 techniques from the MITRE ATT&CK framework. According to the Unit 42 report, nothing about the techniques was novel — the weapon was speed and orchestration. Dark Reading's analysis of the trend concludes companies have roughly six months before automated attacks become widespread.
That is the pitch in one line: if the attacker's timeline is now measured in hours, the defender's testing cycle can't be measured in quarters.
What it changes for security teams#
The honest case for the product is the find-to-fix gap. Enterprises already know they have exposures; the problem is prioritization. A service that continuously proves which exposures are truly exploitable — and maps the blast radius of each — converts a quarterly report into a living attack surface, letting teams fix what's actually weaponizable first.
The company is backing the pitch with real numbers: six months of development, more than 100 customer engagements, $17 million invested in refining the approach, and internal trials that the company says uncovered a full year's worth of exposures inside its own environment in three weeks. Those are company-supplied figures, but they suggest this isn't a demo repackaged as a product.
The uncomfortable part is the dual-use bargain. The exact capability Palo Alto Networks is selling to defenders — agentic systems that autonomously find and validate exploits using frontier models — is the same class of capability attackers are already wielding. The commercial logic is that controlled, subscribed access helps defenders more than it arms attackers. Whether the gated models' restrictions hold — and whether regulators eventually scrutinize selling offensive agent capabilities as a service — is the open question hanging over this entire category.
What to watch#
Watch for three things. First, copycats: if continuous agentic testing works, every major security vendor will announce a version within a year, and the differentiator will be whose models find the most real exposures with the fewest false positives. Second, proof beyond the vendor: independent customer reports on exposure-reduction numbers, not just Palo Alto Networks' internal trial claims. Third, the gated-model question: how Anthropic and OpenAI police offensive use of Mythos and GPT-5.6-Cyber, and whether the restrictions survive contact with a commercial product that probes real corporate infrastructure. The service is available globally through annual subscriptions, with pricing depending on the model mix — an early datapoint for how the economics of 'AI agent labor' get priced when the labor is attacking you on purpose.