September 22, 2026, (Inside AI) — Palo Alto Networks announced on Tuesday a new cybersecurity service that runs on frontier AI models from Anthropic and OpenAI, betting that continuous machine-driven testing can keep pace with attackers who now use the same technology to hunt for weaknesses in corporate networks.
The offering, called Unit 42 Continuous Frontier AI Defense, pairs Anthropic's Claude Mythos 5 and OpenAI's GPT-5.6-Cyber with open-weight models to probe web applications, application programming interfaces and cloud infrastructure for exploitable flaws. The Santa Clara, California company said the service will be sold worldwide through annual subscriptions, with pricing set by how customers mix proprietary and open-source models.
The launch lands at a moment when offensive AI has compressed the time between a vulnerability appearing and an attacker using it. Security teams that once patched on a monthly cadence now face automated scanning tools that never sleep. Palo Alto's answer is to fight automation with automation, letting models comb through code and configuration continuously rather than at scheduled intervals.
Why Subscription Pricing Follows Model Choice
The subscription model ties cost directly to the model mix a customer selects, an unusual structure in enterprise security. Most vendors bundle detection and response into flat per-seat or per-asset tiers. Palo Alto instead lets buyers trade capability against budget, since frontier models cost far more per query than open-weight alternatives.
Read: Microsoft Launches MAI-Cyber-1 and Perception AI for Cybersecurity
That choice carries strategic weight. Anthropic and OpenAI both restrict how their models can be used for offensive security research, and enterprise buyers increasingly want to know which model touched their code and under what terms. By naming Claude Mythos 5 and GPT-5.6-Cyber explicitly, Palo Alto gives procurement teams something concrete to evaluate. Inside AI could not independently verify the specific model versions or their performance claims.
The service also promises remediation guidance, including code-level fixes and virtual patching. Virtual patching matters because many industrial and legacy systems cannot be updated quickly. A virtual patch blocks the exploit path at the network layer while the underlying flaw waits for a maintenance window.
Competitors have moved in the same direction. Microsoft, Google and CrowdStrike all market AI-assisted security operations, and several startups pitch autonomous penetration testing. Palo Alto's differentiator is the Unit 42 brand, its threat intelligence arm, which gives the service a human research layer on top of model output.
The timing reflects a broader shift in how enterprises budget for defense. Gartner has projected that spending on AI-enabled security tools will outpace overall security growth through the decade, though exact figures vary by analyst. What is clear is that chief information security officers now treat AI both as a threat vector and as a staffing solution amid persistent talent shortages.
One open question is accuracy. Frontier models still hallucinate, and a false positive in a security context wastes analyst time while a false negative can be catastrophic. Palo Alto has not published independent benchmark results for the service, and the company did not disclose how it handles model errors or liability when a missed vulnerability leads to a breach.
Another question is data handling. Customers must let external models inspect their code and cloud configurations, which raises confidentiality concerns for regulated industries. Palo Alto has not detailed whether it uses private instances, data retention limits or regional processing guarantees.
The service will compete against established vulnerability management platforms that already integrate AI features at lower price points. Palo Alto is betting that frontier models plus continuous testing justify a premium, and that buyers will accept annual commitments to get them. Whether that bet pays off will depend on proof, not positioning.