Prisma AIRS® AI Runtime Security
How do you secure an AI ecosystem you can't fully see? This solution brief shows how Prisma AIRS AI Runtime Security from Palo Alto Networks automatically discovers AI applications, models, users, and datasets, protects them against prompt injection, data leakage, malicious URLs, and agentic threats, and monitors runtime risk continuously. With network- and API-based deployment, HG Consulting can secure AI where it runs. Download the solution brief for details.
What is Prisma AIRS AI Runtime Security and why do we need it?
Prisma AIRS AI Runtime Security is a security platform from Palo Alto Networks designed specifically to protect enterprise AI applications while they are running. It focuses on the unique risks that come with compound AI systems – where models, plugins, vector databases, external tools, and internet search are all connected.
Traditional security tools were not built to understand how AI models behave, how prompts work, or how AI agents call tools and APIs. As a result, they often miss AI-specific threats such as prompt injection, data leakage through model outputs, or malicious URLs generated by RAG (retrieval-augmented generation) workflows.
Prisma AIRS helps you:
- Discover your AI ecosystem automatically – including AI apps, models, users, and datasets across AWS, Azure, and Google Cloud.
- Protect models, data, and apps – against both foundational network threats and AI-specific attacks like prompt injection and agent misuse.
- Continuously monitor runtime risk – to identify unprotected AI apps and risky communication paths before attackers exploit them.
It is already protecting 40+ models across Google Cloud, AWS, Azure, and traffic calling the OpenAI API, and it delivers:
- ~40% better protection from web-based attacks, including 25 DNS attack types.
- AI-powered prevention of ~90% of zero-day application command and SQL injection attacks.
- 2x the data loss prevention coverage of other cloud-based DLP solutions, with 1,000 predefined data patterns.
- ~99% malware detection accuracy, with 26% more detections than traditional sandboxes.
In short, if you are building or scaling AI into customer-facing or internal applications, Prisma AIRS helps you rethink runtime security so it matches how modern AI systems actually work.
How does Prisma AIRS protect AI models, data, and applications in practice?
Prisma AIRS focuses on three main protection areas: applications, models, and data – plus emerging agentic threats.
1. Application protection
- Advanced URL filtering for AI traffic: It scans URLs going between your AI apps and models to block or flag malicious URLs that might appear in model output due to poisoned RAG sources or training data.
- Prevents data exfiltration via URLs: Stops attacks that trick a model into building a URL with sensitive data embedded in parameters and sending it to an attacker-controlled domain.
- Fine-grained RAG web access control: You can set policies to allow, alert, or block specific domains that appear in prompts or responses.
- Deep segmentation: It segments all application components (port-to-port, namespace-to-namespace) to prevent both known and zero-day application-layer attacks.
2. Model protection
- Prompt injection defense: Detects and blocks direct and indirect prompt injections, including goal hijacking and “do-anything-now” style attacks.
- Custom error responses: You can configure tailored error messages back to users when threats are detected, instead of exposing raw system behavior.
3. Data protection
- Enterprise DLP built in: Uses Cloud-Delivered Security Services to stop sensitive data from leaking into or out of AI apps.
- 1,000+ predefined data patterns (regex and ML-based) and support for custom patterns in prompts and responses.
- 2x the coverage of other cloud-based DLP solutions, helping protect training data and production data from exposure in model outputs.
- Database query control: For AI that generates SQL, you can regulate which query types (Create, Read, Update, Delete) are allowed to prevent unauthorized database changes.
4. Agentic threat protection
- AI agent security for agents built on low-code/no-code or custom platforms.
- Defends against identity impersonation and memory manipulation attacks.
- Prevents tool and API misuse by ensuring connected tools are not abused by compromised or misdirected agents.
Together, these capabilities help you reimagine runtime protection so it covers the full AI stack – from user prompt to model output, and from app-to-model to app-to-database interactions.
How is Prisma AIRS deployed and integrated into our AI environment?
Prisma AIRS is designed to fit into your existing cloud and development workflows, rather than forcing a single deployment pattern. You can secure AI traffic either at the network layer, via APIs, or both.
1. Network-based deployment (Network Intercept)
- Cloud coverage: Supports AWS, Microsoft Azure, and Google Cloud.
- Automated deployments: Strata Cloud Manager provides Terraform templates and best-practice architectures to automate deployment into your cloud environments.
- Manual deployments: You can also select images and bootstrapping variables and deploy instances manually.
- Traffic coverage: Protects east-west, outbound, and inbound traffic – including app-to-app, app-to-model, and app-to-database flows, in both virtualized and containerized environments.
- Isolation: Provides port-to-port isolation to help maintain integrity across containerized and non-containerized workloads.
2. API-based deployment (API Intercept)
- Developer-friendly: Lets developers embed AI security directly into application and agent code using APIs.
- Real-time protection: Protects AI apps and agents in real time from known and unknown AI-specific threats, with options for custom error behaviors and user-specific policies.
- Asynchronous analysis: Developers and detection engineers can also collect data asynchronously for offline analysis.
- RAG data scanning: APIs can scan RAG data sources for poisoning or PII before they are used by models.
3. Discovery and runtime risk monitoring
- Automatically discovers AI apps, models, users, external sites, plugins, and data sources across your cloud environments.
- Maps how these components communicate so you can place AI Runtime Security instances where they have the most impact.
- Continuously evaluates unprotected AI apps and risky communication paths to reduce your runtime risk exposure.
4. Flexible consumption model
- You can use existing Flexible Software NGFW (FW-Flex) credits to deploy AI Runtime Security instances from Strata Cloud Manager.
- For API-based instances, developers create a deployment profile via FW-Flex credits, generate an API key in Strata Cloud Manager, and then call the APIs directly from application code.
By combining network-based and API-based intercepts, Prisma AIRS lets you reshape AI security around your architecture – whether you are securing a few high-value AI apps or a broad portfolio of models, agents, and workloads across multiple clouds.

