Home
Products
Releases
Best Practices
Resources
By Type
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
Products
Releases
Best Practices
Resources
By Type
Network Security
Cloud-Delivered Security Services
Advanced DNS Security
Advanced WildFire
Advanced Threat Prevention
Advanced URL Filtering
AI Access Security
Enterprise Data Loss Prevention
SaaS Security
IoT Security
Cloud Identity Engine
Cloud NGFW for AWS
Cloud NGFW for Azure
CN-Series
Common Services
License Activation & Subscription Management
Tenant Management
Identity & Access Management
Device Associations
FAQ
GlobalProtect
Next-Generation Firewall
PAN-OS
AIOps for NGFW
Firewalls
SD-WAN
Service Provider
Panorama
Strata Logging Service
Strata Cloud Manager
AI Runtime Security
VM-Series
Secure Access Service Edge
Common Services
License Activation & Subscription Management
Tenant Management
Identity & Access Management
Device Associations
FAQ
FedRAMP
Next-Generation CASB
Prisma Access
Autonomous DEM
Prisma Access Browser
Prisma SD-WAN
ION Devices
Remote Browser Isolation
Strata Cloud Manager
Strata Multitenant Cloud Manager
Cloud-Native Security
Prisma Cloud
Security Operations
Cortex XDR
Cortex XSOAR
Cortex XPANSE
Cortex XSIAM
What's New
What's New Releases
All Release Notes
View All Release Notes
Recently Updated Release Notes
Release Notes
SaaS Security Release Notes
PAN-OS Release Notes (PAN-OS 11.1)
Strata Cloud Manager Release Notes
AI-Powered Autonomous DEM Release Notes (AI-Powered ADEM)
Release Notes
PAN-OS Release Notes (PAN-OS 11.2)
PAN-OS Release Notes (PAN-OS 10.2)
Terminal Server (TS) Agent Release Notes (11.0)
User-ID™ Agent Release Notes (11.0)
See All Recently Updated Release Notes
Recently Updated Documentation
Enterprise DLP Reference
Administration
Getting Started
Activation & Onboarding
Getting Started
Data Security Administration
Strata Cloud Manager Activation & Onboarding
Prisma SD-WAN Administrator’s Guide
PA-5400 Series Next-Gen Firewall Hardware Reference
PA-7500 Next-Gen Firewall Hardware Reference
See All Recent Updates
Applications and Threats Content Updates
Best Practices for Migrating to Application-Based Policy
Data Center
Decryption
DoS and Zone
Get Started
Internet Gateway Security Policy
Secure Administrative Access
Security Policy
WildFire
Zero Trust
VIEW ALL
All Release Notes
Blog
Compatibility Matrix
Experts Corner
Infographics
Licensing, Registration, and Activation
OSS Listings
Translated Documents
VIEW ALL
API Documentation
Release Notes
Activation & Onboarding
Activation & Onboarding
AI Runtime Security Documentation
All Documentation
>
Clear
Search
Loading
Clear
AI Runtime Security Setup Prerequisites and Limitations
Updated on
Mon Mar 31 15:42:52 UTC 2025
Focus
Download PDF
Updated on
Mon Mar 31 15:42:52 UTC 2025
Focus
Home
AI Runtime Security
Activation & Onboarding
AI Runtime Security Setup Prerequisites and Limitations
Download PDF
AI Runtime Security
AI Runtime Security Setup Prerequisites and Limitations
Table of Contents
Filter
Expand All
|
Collapse All
AI Runtime Security Docs
Activation & Onboarding
AI Runtime Security Licenses
Activate Your Software NGFW Credits
Activate Strata Logging Service
Create and Associate a Deployment Profile for AI Runtime Security: Network Intercept
Generate a Device Certificate
AI Runtime Security Setup Prerequisites and Limitations
Onboard and Activate a Cloud Account in Strata Cloud Manager
Onboard Cloud Account in GCP
GCP Cloud Account Onboarding Prerequisites
Onboard GCP Cloud Account in Strata Cloud Manager
Onboard Cloud Account in Azure
Azure Cloud Account Onboarding Prerequisites
Onboard Azure Cloud Account in Strata Cloud Manager
Onboard Cloud Account in AWS
AWS Cloud Account Onboarding Prerequisites
Onboard AWS Cloud Account in Strata Cloud Manager
Manage Onboarded Cloud Accounts in Strata Cloud Manager
Panorama Managed AI Runtime Security: Network Intercept Overview
Create an AI Runtime Security Deployment Profile for Panorama
Panorama Managed AI Runtime Security Onboarding Prerequisites
AI Runtime Security: API Intercept Overview
Create and Associate a Deployment Profile for AI Runtime Security: API Intercept
Onboard AI Runtime Security: API Intercept in Strata Cloud Manager
Administration
AI Models on Public Clouds Support
Discover Your Cloud Resources
Analyze Risk in Network Traffic
Deploy AI Runtime Security: Network Intercept in Public Clouds
Deploy AI Runtime Security: Network Intercept in GCP
Deploy AI Runtime Security: Network Intercept in Azure
Deploy AI Runtime Security: Network Intercept in AWS
Configure Strata Cloud Manager to Secure VM Workloads and Kubernetes Clusters
Harvest IP-Tags from Public and Hybrid Kubernetes Clusters to Enforce Security Policy Rules
Deploy AI Runtime Security: Network Intercept for Panorama Managed Firewall
Configure Panorama to Secure VM Workloads and Kubernetes Clusters
Harvest IP-Tags from Kubernetes Clusters Secured by Panorama Managed AI Runtime Security: Network Intercept
Manually Deploy and Bootstrap AI Runtime Security: Network Intercept
Defend: Create Security Policy Rule to Prevent AI Security Threats
Create an AI Security Profile
Create Model Groups for Customized Protections
Create Traffic Objects for Zone-Based Security
Create and Configure API Security Profile
Manage Applications, API Keys, and Security Profiles
Monitor: Threat Logs and AI Security Logs
AI Runtime Security: API Intercept Scan Logs
Explore OWASP Coverage in AI Runtime Security
Use Case: Inspect Traffic between User and AI Medical Assistant
Release Notes
New Features in AI Runtime Security
What's New in 2025
What's New in 2024
Known Issues
Addressed Issues
Previous
Generate a Device Certificate
Next
Onboard and Activate a Cloud Account in Strata Cloud Manager
AI Runtime Security Setup Prerequisites and Limitations
A list of
AI Runtime Security
prerequisites and limitations.
Where Can I Use This?
What Do I Need?
AI Runtime Security
AI Runtime Security Licenses
Prerequisites
AI Runtime Security License
.
Review the
AI Models on Public Clouds Support Table
.
Terraform
version > 1.3 and < 2.
Each
AI Runtime Security
: Network intercept requires a minimum of 4 vCPUs.
Optional
Helm
if you want to protect the Kubernetes clusters.
Enable Cloud Management for
AI Runtime Security
: Network intercept using
Strata Cloud Manager
.
Contact Palo Alto Networks support or your account team and provide the following information: tenant service group (TSG) ID, tenant name, and region.
Limitations
Licensing Capacity Limit: Limited to processing up to 10K AI transactions per day per vCPU of
AI Runtime Security
: Network intercept.
The following regions are supported:
Strata Cloud Manager
and tenant service group (TSG): US region only.
Cloud Service Providers (AWS, Azure, and GCP): Any region supported.
Log Storage and AI Traffic Processing:
All logs are stored in the US region.
All AI traffic is sent to the US region for threat inspection.
AI Runtime Security
can harvest IP-tags only from public and hybrid clusters on GCP, Azure, and AWS cloud platforms.
Previous
Generate a Device Certificate
Next
Onboard and Activate a Cloud Account in Strata Cloud Manager