What happened
Palo Alto Networks said its AI firewall, Prisma AIR S, now runs natively on Nvidia’s BlueField hardware and incorporates the Sentry component of Nvidia’s Open Agent Safety Platform. The company also outlined a future integration of its Idira identity suite with Nvidia’s OpenShell runtime.
In a blog post published on September 28, Palo Alto Networks detailed how its Prisma AIR S AI Runtime firewall, which already runs on Nvidia’s BlueField‑4 SmartNIC, will now draw on the Sentry component of Nvidia’s Open Agent Safety Platform. The company described the integration as an "AI gateway" built on Nvidia’s Vera CPU architecture.
Palo Alto also mentioned a planned connection between its Idira identity business—formerly CyberArk—and Nvidia’s OpenShell runtime, though it did not disclose any revenue expectations for these components.
The announcement coincided with Nvidia’s launch of the Open Agent Safety Platform, a suite of tools designed to curb rogue AI‑agent behavior. Palo Alto’s move positions it among the first security vendors to embed its firewall directly into the AI‑agent safety stack.
Why it matters
The integration shows a growing convergence between network security vendors and AI‑agent safety tooling, indicating that AI‑driven workloads will increasingly rely on specialized security layers built directly into accelerator hardware. By its firewall in Nvidia’s stack, Palo Alto aims to protect the “front‑end network traffic of the AI factory,” a segment that traditional firewalls have struggled to secure. This move could set a precedent for other security firms to offer hardware‑native AI‑agent protections, potentially reshaping how data‑center operators secure multi‑tenant AI workloads.
security functions into the same silicon that runs AI agents reduces and attack surface compared with traditional, separate firewall appliances. This could become a critical differentiator as AI workloads scale and as incidents like the September 20 OpenAI sandbox escape raise concerns about agent misbehavior.
Palo Alto’s strategy reflects CEO Nikesh Arora’s view that most data‑center capacity is not multi‑tenant, limiting opportunities for conventional firewalls. By targeting the AI‑factory layer, the company hopes to capture a niche where hyperscalers and AI developers need built‑in safeguards.
If successful, this model may encourage broader adoption of hardware‑native security solutions, prompting cloud providers and AI platform vendors to prioritize integrated safety features in their product roadmaps.
Interactive Mechanism: How It Actually Works
Explore the underlying technology behind this development interactively.
crm_get_transaction(id='4092').What most distinguishes an AI agent from a basic chatbot?
What to watch next
Investors and analysts will watch Palo Alto’s upcoming fiscal Q1 earnings for any disclosed revenue tied to the Nvidia‑based offering, and monitor whether other security vendors announce similar hardware‑native AI‑agent solutions.
Palo Alto’s fiscal first‑quarter earnings, due later this year, will reveal whether the Nvidia‑based products generate measurable revenue and how the market responds to the integration.
Analysts will track whether competitors such as CrowdStrike or Zscaler announce comparable hardware‑native AI‑agent security offerings.
Further developments from Nvidia, such as expanded OpenShell capabilities or additional watchdog features, could enhance the value proposition of Palo Alto’s integrated firewall.