Palo Alto Networks Brings Frontier AI Models Into Continuous Cybersecurity Testing

· · Views: 2,609 · ⏱ 3 min time to read

Palo Alto Networks is using frontier AI models from Anthropic and OpenAI to continuously search corporate systems for exploitable weaknesses, as cybersecurity testing begins moving from scheduled penetration tests toward always-on automated assessment.

The company launched Unit 42 Continuous Frontier AI Defense, a global subscription service combining security researchers with multiple AI models and proprietary testing software.

Reuters reported that the service incorporates Anthropic’s Claude Mythos 5 and OpenAI’s GPT-5.6-Cyber, alongside open-weight models, to identify vulnerabilities and potential attack paths across enterprise systems.

One model is not enough for complex networks

Palo Alto’s technical approach is notable because the company is not betting on one frontier model doing everything.

Unit 42 says its testing across enterprise codebases and live environments found that no individual AI model detected more than 40% of vulnerabilities. It also found less than 10% overlap between exposures identified by leading models such as Claude Mythos 5 and GPT-5.6-Cyber.

Axios independently reported the same limitation, noting that Palo Alto’s evaluations showed a single model could uncover less than 40% of weaknesses in complex environments.

The company therefore uses a multi-model orchestration layer that routes different security tasks toward different models.

That resembles an emerging pattern in AI infrastructure: instead of searching for one universal model, systems combine specialized capabilities.

Attackers are accelerating vulnerability exploitation

Palo Alto says the change is being driven by the speed of modern attacks.

In one recent Unit 42 investigation, an attacker used more than 50 MITRE ATT&CK techniques in less than 10 hours, work the company estimates was completed 97% faster than a skilled red team could have performed it.

Unit 42 also says real-world time to data exfiltration has fallen below one hour, while automated scanners can begin weaponizing newly disclosed vulnerabilities within 15 minutes of a CVE becoming public.

Those figures help explain why periodic penetration testing is becoming harder to defend as the only line of assurance.

A quarterly security review produces a picture of one moment. Cloud environments, APIs, identities and application code can change between deployments.

AI is moving deeper into offensive security

Continuous Frontier AI Defense tests applications, identities, cloud infrastructure, APIs and network assets while attempting to determine whether vulnerabilities can actually be exploited.

Reuters reported that the service also provides remediation recommendations after vulnerabilities are identified.

Unit 42 says those recommendations can include prioritized fixes, code-level guidance and virtual patches.

For developers and security engineers, that changes the role of automated testing.

Security scanning has traditionally been good at producing long lists of possible vulnerabilities. AI-driven offensive testing attempts to go further by identifying which weaknesses can be connected into a realistic attack path.

That could make penetration testing begin to resemble observability: a continuously running infrastructure layer rather than an assessment scheduled a few times each year.

AI is helping attackers move faster. Security vendors are now betting that defenders can respond by making offensive testing just as continuous.

Share
f 𝕏 in
Copied