top of page

Can Palo Alto Networks Become Cybersecurity’s Operating System?

Aug 24
12 min read

Palo Alto Networks has assembled four new AI security layers within months, turning a Google News headline into a serious platform question. The company now spans AI gateways, agent endpoints, identity controls, observability, cloud defense, network security, and security operations.

That reach supports an ambitious interpretation of its strategy. Palo Alto Networks does not merely want to sell another collection of security products. It wants enterprises to treat its platforms as the control layer connecting users, applications, infrastructure, and autonomous AI agents.

Microsoft, CrowdStrike, Google, Fortinet, and Zscaler are pursuing overlapping positions. They start from different strongholds, including identity, endpoints, cloud infrastructure, productivity software, and network access. Palo Alto Networks must prove that its broader portfolio works as one system, not simply as a crowded catalog.

The operating-system comparison is therefore useful, but only as a testable thesis. An operating system provides shared controls, data, policy, and execution across many workloads. Owning numerous security products does not automatically create those qualities.

Palo Alto Networks has made the necessary pieces more visible. Its next challenge is integration, customer adoption, and measurable security outcomes across those pieces.

The Google News Headline Reflects a Real Strategic Shift

Palo Alto Networks has moved beyond selling defenses around AI applications and is building controls for the agents operating inside them.

The latest push took shape through several connected moves during 2026. In February, Palo Alto Networks completed its acquisition of CyberArk and added identity security as a core platform pillar. CyberArk’s technology governs privileged access for people, machines, and software agents.

That distinction matters because an AI agent is not merely another application. An agent can receive credentials, call tools, query databases, change records, and trigger additional software. Those actions give it operational authority that earlier chatbots rarely possessed.

Palo Alto Networks expanded that identity layer in April by completing its acquisition of Koi. Koi focuses on agentic endpoint security, which monitors AI agents and related software operating on employee devices.

In May, Palo Alto Networks completed its acquisition of Portkey, an AI gateway provider. An AI gateway is a control point that routes, observes, and governs traffic between applications, agents, tools, and AI models.

The Portkey acquisition connects that gateway with Prisma AIRS, Palo Alto Networks’ AI security platform. The company says the combination can inspect AI traffic, manage token use, enforce runtime policy, and prevent unauthorized agent behavior.

Chronosphere adds another part of the emerging architecture. Its observability technology collects operational telemetry, which helps teams understand how applications and infrastructure behave in production. That visibility becomes important when an agent failure resembles an application problem rather than a conventional attack.

Palo Alto Networks also introduced Prisma AIRS 3.0 in March. The release expanded its focus from protecting models and AI applications toward protecting autonomous agent systems across their lifecycle.

Earlier Prisma AIRS capabilities included model scanning, posture management, red teaming, and runtime protection. Version 3.0 extended that foundation toward agent discovery, identity, behavior, and execution controls.

Together, these moves create a recognizable stack. Portkey observes and governs agent traffic. CyberArk controls privileged identities. Koi watches agentic activity at endpoints. Chronosphere supplies operational telemetry. Prisma AIRS is intended to connect these signals with runtime defenses.

That architecture explains why the operating-system description keeps appearing in investor commentary and Google News coverage. Palo Alto Networks is trying to own the security control plane around AI activity.

However, this is not one discrete product launch with a settled outcome. It is a strategic construction project assembled through internal development and multiple acquisitions. Several important integrations remain underway.

The immediate change is still meaningful. Palo Alto Networks has chosen to treat AI agents as governed enterprise actors, not simply as traffic passing through a firewall.

Why AI Agents Make Platformization More Valuable

AI agents strengthen the case for consolidated security because their actions cross boundaries that traditional tools monitor separately.

A conventional employee usually enters an application through an identifiable device and account. Security teams can apply access controls, endpoint monitoring, network rules, and application policies at relatively stable checkpoints.

An agent can follow a much less predictable path. It might receive a request through a browser, consult a model, retrieve corporate data, and invoke an external service. It can then update a customer record or instruct another agent.

Each step may fall under a different security product. Identity software governs credentials. Endpoint products monitor local processes. Cloud tools inspect workloads. Network controls examine connections. Security operations platforms investigate the resulting alerts.

Attackers can exploit the gaps between those tools. A request may look acceptable to an AI gateway while the resulting database action violates identity policy. An endpoint product may observe unusual automation without understanding the original model prompt.

This fragmentation creates the opening for Palo Alto Networks. Its platformization strategy encourages customers to replace separate tools with integrated products that share policy, telemetry, and response workflows.

Platformization does not mean every product becomes identical. It means separate security functions operate through common data and control layers. A detection in one domain should inform prevention or remediation elsewhere.

That model has gained financial traction. Palo Alto Networks reported fiscal third-quarter 2026 revenue of $3.0 billion, up 31 percent from the prior year. Acquired businesses contributed $388 million of that amount.

Organic growth was lower than the headline increase. The company’s earnings presentation showed 14 percent year-over-year revenue growth when excluding CyberArk and Chronosphere. That distinction keeps acquisition-driven expansion separate from underlying business performance.

Next-Generation Security annual recurring revenue reached $8.1 billion, according to the company’s quarterly results. The measure grew 60 percent year over year, including $1.6 billion from CyberArk and Chronosphere.

Remaining performance obligations reached $18.4 billion, rising 36 percent. This measure covers contracted revenue that Palo Alto Networks expects to recognize later. CyberArk and Chronosphere contributed $1.8 billion to that total.

Those figures show scale and customer commitments. They do not independently confirm that the underlying products function as a unified operating layer. They also include substantial acquisition effects.

Palo Alto Networks uses a narrower platformization measure among its 5,000 largest customers. A customer can receive separate counts across several platform areas. Starting in its fiscal fourth quarter, the company plans to count qualifying Prisma AIRS adoption as an AI security platformization.

That reporting change deserves attention. It will give investors a clearer signal about significant AI security commitments. It also means the company defines and reports the metric itself.

The business case rests on more than subscription growth. Security teams face shortages, alert overload, and contracts that renew on different schedules. A shared platform can reduce operational handoffs and give automation access to broader context.

The model becomes more compelling when AI systems operate at machine speed. Analysts cannot manually reconcile every prompt, identity, endpoint, network session, and cloud action before an agent completes its task.

A consolidated control plane can correlate those events more quickly. It can also enforce a common rule, such as restricting a particular agent from sending sensitive data outside an approved environment.

Yet consolidation produces its own dependence. Customers must trust one vendor’s policy engine, telemetry, integrations, and availability across a larger part of their defenses. That raises the stakes when the platform fails or misses a threat.

The AI era therefore strengthens both sides of the argument. Integration becomes more valuable, while concentration becomes more consequential.

Palo Alto Networks Faces Microsoft and CrowdStrike for the Control Layer

The central contest is integrated platforms versus a security stack assembled from specialists and existing enterprise providers.

Microsoft enters this contest with an enormous distribution advantage. Many enterprises already use its identity, endpoint, cloud, productivity, and security products. That installed base gives Microsoft access to signals across user accounts, devices, email, applications, and infrastructure.

Microsoft Security Copilot adds AI-assisted investigation and automation to that environment. Its security agents can perform tasks according to customer-defined permissions, logic, and triggers.

That approach resembles an operating layer because Microsoft already controls many underlying enterprise systems. Customers do not need to move every signal into an entirely new vendor environment.

Microsoft’s weakness is also connected to its breadth. Security buyers may prefer independent controls that cover multiple clouds, identity providers, operating systems, and model vendors. A security platform tied too closely to one technology estate can create blind spots elsewhere.

CrowdStrike approaches the market from endpoint detection and response. Its Falcon platform has expanded into identity protection, cloud security, threat intelligence, security information management, and AI-assisted operations.

The endpoint remains a valuable starting point. Human users and AI agents often initiate actions from devices, browsers, development environments, and cloud workloads. Endpoint telemetry can reveal processes and behavior that network-only products cannot see.

CrowdStrike also competes directly for the security operations center. That is a critical battleground because the winning platform can shape how teams investigate alerts, automate responses, and store security data.

Palo Alto Networks brings a different foundation. It has deep positions in firewalls, secure access, cloud security, and security operations. CyberArk adds identity, while recent acquisitions target AI-specific control points.

This breadth gives Palo Alto Networks a credible answer to several questions at once. Which agent made a request? What privileges did it use? Where did it run? Which model received the data? What response followed?

Gartner described Palo Alto Networks as the company to beat in the AI security platform race in June 2026. Its vendor assessment cited acquisitions covering agentic endpoints, AI gateways, and agent identities.

The assessment also identified the opening for competitors. Rivals can close the gap by offering simpler agentic controls that govern autonomous systems across varied technology environments.

That qualification is important. Security buyers do not purchase architecture diagrams. They purchase controls that deploy reliably, integrate with existing systems, and reduce risk without creating excessive administrative work.

Fortinet remains strong in network security and secure access. Zscaler has a large position in zero-trust access and cloud-delivered inspection. Google’s ownership of Wiz gives it a stronger cloud security position.

Specialists also retain an advantage in narrow categories. A focused provider can often ship faster, support more model frameworks, or solve one emerging risk with greater depth. Enterprises may accept integration work to obtain that capability.

Palo Alto Networks’ answer is not that specialists will disappear. Its strategy assumes that a shared platform can absorb or connect enough specialized functions to reduce the need for separate control planes.

This is where the operating-system analogy becomes demanding. A useful operating system supports outside applications without surrendering control of core policy. Palo Alto Networks needs broad integrations while preserving consistent identity, telemetry, and enforcement.

If the company requires customers to replace every existing product, adoption will become slow and expensive. If it supports third-party data poorly, the platform will have incomplete context.

The winning approach will likely combine native products with credible interoperability. Security environments rarely align around one vendor immediately, especially when contracts and replacement cycles differ.

Palo Alto Networks must therefore win two arguments. Its integrated products must perform well individually, and their combined operation must deliver benefits that separate vendors cannot easily reproduce.

The Real Test Is Integration, Not Acquisition Volume

Buying the necessary components is faster than building them, but ownership does not guarantee technical or commercial integration.

Palo Alto Networks completed several consequential acquisitions within a short period. Each transaction added technology, employees, product roadmaps, customer contracts, and infrastructure that now require coordination.

Identity security presents one integration challenge. CyberArk’s products must continue serving existing standalone customers while connecting with Palo Alto Networks’ network and security operations platforms.

The company has said CyberArk will remain available as a standalone platform. It also says integration work has started. That dual-track approach protects customer choice, but it can complicate engineering and product positioning.

Portkey creates another challenge. An AI gateway sits directly in the path of application traffic, making reliability and latency important. Customers will resist a gateway that adds significant delay or becomes a single failure point.

The gateway must also work with many models, clouds, agent frameworks, and application architectures. Model providers change interfaces and capabilities frequently. A control layer must adapt without interrupting production workloads.

Koi brings endpoint visibility into agentic activity. That function needs clear boundaries with existing endpoint and extended detection products. Duplicate alerts or conflicting policy engines would weaken the promised consolidation benefits.

Chronosphere introduces large-scale observability data. Operational telemetry can enrich security analysis, but observability and security teams often have different workflows, retention requirements, and purchasing owners.

Combining these products requires more than placing them on a shared sales contract. The platform needs common identity models, data formats, policy definitions, response actions, and administrative experiences.

Palo Alto Networks acknowledges these uncertainties in its regulatory disclosures. Its fiscal third-quarter SEC filing discusses acquisition integration, competition, customer purchasing decisions, debt, and platformization execution.

The filing also shows why headline growth needs careful reading. CyberArk and Chronosphere changed reported revenue, costs, assets, obligations, and operating results. Investors must distinguish strategic progress from accounting consolidation.

Palo Alto Networks reported a GAAP operating loss of $183 million for its fiscal third quarter. It recorded GAAP operating income of $219 million in the comparable prior-year quarter.

That swing does not settle the platform debate. Acquisition-related expenses, amortization, and other accounting effects can alter short-term comparisons. It does show that rapid expansion carries measurable financial complexity.

Customer complexity matters just as much. Enterprises rarely renew firewalls, identity products, endpoint tools, cloud security, and observability services simultaneously. Platformization must accommodate contracts that expire across several years.

Security practitioners have raised this problem in public discussions. A customer may like the consolidated architecture but remain unable to replace incumbent products on one schedule. Competitors can also offer transition incentives during those gaps.

Migration creates operational risk. Replacing a security product can change policies, alerts, integrations, dashboards, and incident procedures. A flawed migration can reduce visibility at the exact moment the organization expects improvement.

Vendor concentration adds strategic risk. A shared platform can produce better correlation, but a platform outage or compromised administrative account can affect multiple defenses simultaneously.

Buyers also need evidence that AI automation improves outcomes. Faster alert processing has limited value if the system produces incorrect conclusions or takes unauthorized actions.

Autonomous remediation requires strict permissions and audit trails. A security agent that disables an account or isolates a workload can stop an attack. It can also interrupt business when its judgment is wrong.

Palo Alto Networks has the distribution and engineering resources to address these issues. It serves more than 70,000 customers, according to its corporate materials. That footprint provides both a sales advantage and a large environment for product feedback.

However, customer count does not reveal cross-platform depth. The stronger proof would show organizations using identity, AI gateways, endpoints, networks, and security operations through shared policies and workflows.

Independent performance testing will matter as well. Buyers should look for detection quality, false-positive rates, response times, deployment effort, and support for third-party systems.

The phrase “cybersecurity operating system” should remain a hypothesis until those outcomes become visible. The acquisitions make the hypothesis plausible. Integration evidence must make it durable.

Three Signals Will Decide Whether the Thesis Holds

Palo Alto Networks now has enough components, so the next evidence must come from adoption, integration, and competitive response.

The first signal is Prisma AIRS adoption among large customers. Palo Alto Networks said its Prisma AIRS customer count exceeded 300 during its fiscal third quarter.

The company also expects to recognize AI security as a separate platformization category. A qualifying customer must cross a specified annual recurring revenue threshold with Prisma AIRS software firewall usage.

Future earnings should reveal whether customers adopt Prisma AIRS as a meaningful control layer or purchase it for limited projects. Broader deployments would strengthen the operating-system thesis.

The most useful disclosure would separate new AI security customers from existing Palo Alto Networks accounts. It should also show how many connect Prisma AIRS with Cortex, CyberArk, network security, or observability products.

A rising customer count alone would provide incomplete evidence. Small tests and isolated model-scanning projects do not establish enterprise-wide control.

The second signal is visible product integration. Palo Alto Networks must connect acquired technologies through common policies and workflows without degrading their standalone capabilities.

A credible demonstration would follow one AI agent across several boundaries. It would identify the agent through CyberArk, inspect its model traffic through Portkey, and observe endpoint behavior through Koi.

The same workflow would correlate application performance through Chronosphere and send relevant events into Cortex. Security staff could then investigate and respond without manually reconciling several consoles.

That scenario would show an actual platform mechanism. A shared product bundle or unified contract would not provide the same proof.

Customers should also watch deployment requirements. Integration that demands a complete infrastructure replacement will limit adoption. Support for mixed environments would make the platform more credible.

The third signal is how Microsoft, CrowdStrike, Google, and other competitors respond. A market leader rarely retains a unique product map for long.

Microsoft can connect security agents with Entra identity, Defender, Sentinel, Azure, and productivity applications. CrowdStrike can extend Falcon’s endpoint and security operations reach toward agent governance.

Google can combine cloud infrastructure, model services, threat intelligence, and Wiz. Zscaler and Cloudflare can inspect AI traffic through network control points that already sit between users and applications.

Competitive launches will test whether Palo Alto Networks owns a durable advantage or merely moved first. They can also pressure the company to support more open integrations.

The operating-system thesis strengthens if competitors begin organizing their roadmaps around Palo Alto Networks’ control points. That response would validate the categories it selected, including agent identity, gateways, endpoints, and observability.

The thesis weakens if customers favor smaller security layers connected through open standards. That outcome would suggest orchestration matters more than owning every component.

Open architectures could become particularly important for AI agents. Enterprises will use multiple models, clouds, databases, and development frameworks. Few will accept security that works fully within only one vendor environment.

Regulation may influence this decision, although no single rule determines the market today. Requirements for access controls, auditability, data governance, and incident reporting support platforms with consistent evidence.

They can also favor separation of duties and independent controls. A regulator or auditor may question an architecture where one vendor provides enforcement, monitoring, investigation, and proof of its own performance.

Palo Alto Networks therefore faces a balancing act. It must present a unified system without turning unity into inflexibility. It must automate responses without giving agents excessive authority.

For investors following PANW through Google News, the headline question should not be answered by share-price momentum or acquisition activity. The decisive evidence will arrive through product usage and integration depth.

Security leaders should apply the same discipline. Start with the workflows that cross identity, endpoints, models, networks, and cloud infrastructure. Then test whether one platform reduces gaps without creating unacceptable dependence.

Teams evaluating these claims also need durable records of tests, architecture decisions, and vendor commitments. A searchable knowledge base can keep those materials connected as products and policies change.

The most useful next question is concrete: Can Palo Alto Networks trace one autonomous action across every relevant control and stop it under one enforceable policy?

If customers can answer yes at production scale, the Google News thesis will look less like a metaphor. Palo Alto Networks will have built something much closer to cybersecurity’s operating layer.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page