Palo Alto Networks (NASDAQ: PANW) has introduced Unit 42 Continuous Frontier AI Defense, an annual-subscription service that continuously tests enterprise environments for exploitable exposures and supplies prioritized remediation guidance. The company says the service is intended to give security teams a faster way to identify attack paths across applications, APIs, cloud infrastructure, source-code repositories and network assets as those environments change.
The service builds on the company’s earlier point-in-time Frontier AI Exposure Analysis. Rather than producing a single assessment, the new offering begins with a baseline scan and continues testing afterward. Palo Alto Networks says it uses offensive-security methods to validate whether identified weaknesses can be exploited and to determine how an attacker could move through an environment.
That is a direct operational change for security teams. A vulnerability list alone does not establish whether a weakness is reachable, whether it can be chained with another issue or which owner should act first. The company says the service provides prioritized fixes, code-level guidance and virtual-patch recommendations to move those findings toward remediation.
Its architecture combines Unit 42 threat intelligence and security expertise with a multi-model AI harness. According to the company, the harness routes work to the AI model best suited to a task and can use cyber-specialized models, including Anthropic’s Claude Mythos 5 and OpenAI’s GPT-5.6-Cyber, alongside open-weight models. The company did not describe the precise model-selection criteria, so customers will need to evaluate how the service’s controls and outputs fit their own security and change-management processes.
Palo Alto Networks says the continuous testing engine covers both first- and third-party web applications, APIs, cloud infrastructure, source repositories and network assets. That breadth matters because an attack path can span multiple systems and owners. A security team that receives a validated path and prioritized remediation guidance may spend less time sorting individual findings before it can decide what to investigate or fix.
The company’s performance claims are based on its own testing and customer work. It said that an internal deployment found a year’s worth of exposures in three weeks, and that earlier customer assessments found exposures in every customer assessed, with 37% rated high or critical in severity. Those figures describe the company’s experience rather than an independent benchmark, and Palo Alto Networks did not provide methodology details needed to compare results across different enterprise environments.
Virtual patching is another practical element. The service can recommend interim controls when a vulnerability becomes known before an official patch is available, according to the company. That can help a team reduce exposure while it plans a permanent change, but it does not eliminate the need to test mitigations, confirm ownership and monitor for side effects in production.
For IT and security operations, the benefit is a continuous workflow from discovery to validated exposure and recommended action rather than a periodic inventory of possible issues. The service remains a decision-support and testing capability, not an automatic production-change system. Enterprises will still need to set authorization boundaries, validate remediation steps and retain accountability for changes to their applications and infrastructure.
Unit 42 Continuous Frontier AI Defense is available worldwide, Palo Alto Networks said. Subscription options vary by the models used. The service arrives as attackers and defenders both apply AI to vulnerability research, putting greater value on security operations that can distinguish a theoretical weakness from an exposure that requires immediate attention.
