New Features - Prisma AIRS - September 2026
Gemini Agent Studio Connection Method for AI Red Teaming
Prisma AIRS AI Red Teaming now includes a dedicated connection method for agents built in Google's Gemini Agent Studio. Organizations building AI agents on Agent Studio and deploying on Gemini Agent Runtime can connect them directly to AI Red Teaming. The integration uses Google Cloud's native identity mechanisms, keeping all authentication within the customer's own GCP environment.
Security and platform teams managing AI agents on Google Cloud have faced a gap when assessing those agents for adversarial resilience. Connecting a Gemini Agent Studio agent to a AI Red Teaming tool previously required configuring a custom adapter with manual request formatting, authentication setup, and session handling. This created friction and risked misconfiguration, increasing the onboarding time and time to first scan.
The Gemini Agent Studio connection method authenticates using Google Cloud Workload Identity and service account impersonation. The customer creates a dedicated service account in their own GCP project, scopes it to their specific agent using IAM, and grants a connector identity the ability to act on its behalf. No long-lived credentials are exchanged or stored. To configure a target, users select the Gemini Agent Studio connection method when creating an Agent target type and provide four values: GCP project ID, region, agent engine ID, and the customer-created service account email. The platform validates the connection by reaching the agent through the configured identity.
If your organization builds or deploys AI agents in Gemini Agent Studio and needs to assess their resilience to prompt injection, jailbreaks, and other adversarial techniques, this connection method provides a direct, credential-free path from your GCP deployment to a full red-teaming assessment.
Microperimeter in Windows
You can now install the Microperimeter Agent on Windows workloads to redirect east-west traffic to a VM-Series firewall for L7 inspection, closing the security gap left by standard L3/L4 microsegmentation solutions that cannot detect lateral movement or application-layer exploits traversing allowed ports.
The Microperimeter Agent ( panredirect ) installs directly on the Windows workloads you designate — your most critical assets. Once configured, it captures inbound and outbound east-west traffic on specified network interfaces. The firewall applies L7 security policies — including Threat Prevention, App-ID™, and data filtering — before forwarding traffic to its destination. No network architecture changes are required.
The Microperimeter Agent for Windows complements the existing Linux support, giving you consistent L7 protection across mixed workload environments. You can deploy the Microperimeter Agent on Windows workloads using the panredirect Windows installer.
Multi-Modal Support for AI Red Teaming
Prisma® AIRS™ AI Red Teaming extends its scanning capabilities to include audio modality, allowing you to test voice-enabled AI applications and speech-to-speech models against adversarial inputs that text-based scans cannot detect. AI models that behave safely during text-based interactions can produce unsafe outputs when generating or processing audio, and this gap in coverage leaves your organization exposed to risks that only appear at cross-modal boundaries. During a scan, AI Red Teaming sends adversarial audio payloads, including commands layered over background noise and voice-based social engineering attempts designed to bypass identity controls, and evaluates each response using safety judges built for audio output.
If you operate LLM-powered voice applications such as customer service agents or automated phone systems, audio modality testing gives you a way to identify vulnerabilities specific to voice interfaces before deployment. Risks that this capability surfaces include voice cloning, hidden audio commands that circumvent a model's existing safety controls, and toxic or socially engineered speech in generated audio. Scan results include an embedded audio player directly in the report view, so you can review the exact audio prompts and responses associated with each finding without leaving the interface.
NVIDIA BlueField-3 DPU to Secure AI Factories
You can now deploy Prisma® AIRS as a containerized next-generation firewall directly on the NVIDIA BlueField-3 data processing unit (DPU) to protect AI factory host traffic at its natural boundary without consuming any host application compute resources.
AI factory servers combine regular compute, GPUs for AI inference and training, and DPUs for high-performance networking. Previously, deploying a firewall on these hosts meant competing with AI workloads for CPU and memory. The BlueField-3 DPU changes this by providing dedicated ARM cores, memory, and storage where Prisma AIRS runs independently of the host.
Prisma AIRS on BlueField-3 uses NVIDIA DOCA-based traffic steering through an Open vSwitch to selectively send north-south traffic to the firewall for inspection based on 5-tuple rules you configure. By default, traffic bypasses the firewall, which flows to inspect, allow, or block. This lets you target specific traffic profiles—such as application-to-LLM inference traffic, without inspecting high-throughput GPU interconnect traffic.
You deploy Prisma AIRS across all DPU nodes in your Kubernetes cluster using a single Helm chart, and you manage steering rules and security policy centrally from Strata Cloud Manager or Panorama through the VM-Series plugin. PAN-OS 11.2 or later and PAN-OS 12.1 or later are supported. ATP, Advanced WildFire, Advanced URL Filtering, and AI-Protection subscriptions are included.
Prisma AIRS Integration with Cortex AES for AI Coding Agent Security
You can now extend Prisma AIRS AI Runtime Security to developer endpoints through a new integration with Cortex Agentic Endpoint Security (AES). Security teams define detection rules once in the Prisma AIRS console in Strata Cloud Manager — covering prompt injection, sensitive data leakage, credential exposure, insecure output, and toxic content — and AES pushes those policies to AI coding agents such as Claude Code, Cursor, Codex, GitHub Copilot, and Antigravity running on developer machines, with no per-device hook setup required.
Prisma AIRS inspects prompts, MCP tool calls, and network calls in real time before and after execution; AES enforces the verdict on the endpoint, notifies the developer inside the agent's chat, and records every decision in the AES portal attributed to the device, agent, session, and policy. For more information, see Prisma AIRS Integration with Cortex AES for AI Coding Agent Security and AES documentation.