Prisma AIRS — New Features, August 2026 (Palo Alto Networks TechDocs)

Tag: S-2026-08-13-prisma-airs-august-features Type: report (vendor product documentation — “New Features” page) Author(s): Palo Alto Networks (TechDocs) Date of source: 2026-08 (page dates all four features only “Release Date: August 2026”; no day given — S-tag uses fetch date 2026-08-13) Date ingested: 2026-08-13 Authority weight: medium — primary vendor documentation, unambiguous on what shipped, self-interested on capability; no independent verification Raw file: S-2026-08-13-prisma-airs-august-features in /_raw_sources/

What it claims

Palo Alto Networks’ August 2026 Prisma AIRS feature drop ships four capabilities. (1) AI Discovery with Cortex AISPM: by connecting to Cortex Cloud’s AI Security Posture Management, Prisma AIRS discovers and inventories “every AI model, endpoint, dataset, and agent” across AWS, Azure and GCP, surfaces posture risks, shows dependency relationships (“blast radius”), and recommends red-teaming workflows for discovered agents/endpoints; Americas-region SCM tenants only. (2) Native n8n support in AI Red Teaming: a dedicated connection method lets organisations red-team AI agents built in n8n by pointing at the production webhook URL — REST and streaming modes, multi-turn session handling, optional multimodal file attacks — replacing manual generic REST/streaming target configuration. (3) OpenAI Codex Integration: the Runtime API integrates natively with OpenAI Codex Enterprise so all developer prompts across an OpenAI organisation are routed through Prisma AIRS for inline inspection, configured from the Codex Enterprise admin dashboard with “no plugins, no traffic steering, no developer workflow changes”; block verdicts are issued before prompts reach the model or any connected MCP server; coverage spans DLP (secrets, credentials, PII, proprietary code) and threat detection (malicious code patterns, malicious URLs, prompt manipulation). (4) Anthropic Inference Hooks integration: for enterprise Claude tenants with Prisma AIRS configured, Anthropic sends each prompt (from Claude, Claude.ai, Design and Cowork surfaces) to the AIRS Runtime API for inspection before inference; a block verdict stops the prompt reaching the model, returns a customisable error, and is correlatable to AIRS scan reports via a reference ID; a single policy covers all Claude surfaces. US region, text content only.

Notable quotes

  • “Block policy-violating prompts on the inference path, not after the fact.” (Anthropic Inference Hooks section)
  • “no plugins, no traffic steering, no developer workflow changes required” (OpenAI Codex section)
  • “Show dependency relationships between assets so you can understand blast radius.” (AI Discovery section)

What’s speculative vs. asserted

  • Asserted as shipped fact: the four features, their mechanics, and the regional/content limits (US-region/text-only for Inference Hooks; Americas-only for AI Discovery).
  • Vendor-asserted, unverified: detection/DLP effectiveness, “complete visibility”, inventory comprehensiveness.
  • Not stated at all: any regulatory standard (EU AI Act, DORA, NIST AI RMF are never mentioned); EU availability/data-residency for the new integrations; retention/immutability of scan reports and block-verdict records.

Topics this feeds

  • AI Governance Platforms — first-party model-provider policy hooks (Anthropic) now have a major third-party security platform attached; extends the inline pre-inference enforcement locus and the discovery/inventory contest.
  • Palo Alto Networks — company page (created from this source).

Open questions raised

  • EU availability: both headline integrations are US/Americas-limited — what does an EU/UK FS firm get today, and where does prompt content transit? (unstated)
  • Do blocked-prompt records and scan-report correlation constitute retainable evidence to Art. 12 / SS1/23 grade? No retention model is documented.
  • Anthropic side of the Inference Hooks contract: which other AIRS-class vendors can register hooks, and is this an emerging first-party governance interface? (not addressed by this source)