AI Agent Discovery with Cortex Cloud
Focus
Focus
Prisma AIRS

AI Agent Discovery with Cortex Cloud

Table of Contents

AI Agent Discovery with Cortex Cloud

Learn about Prisma AIRS AI Discovery powered by Cortex Cloud.
Where Can I Use This?What Do I Need?
  • Prisma AIRS AI Runtime Security
The AI Discovery Dashboard gives you a unified view of all AI workloads across your onboarded cloud accounts in Cortex cloud. Use it to assess coverage through Red teaming, investigate the results and security recommendation, and identify where to deploy AI Runtime Security with recommended guardrails/policy. With this functionality you will be able to navigate workload views, understand protection status, filter, review AI workload dependencies from Model/Database and access standpoint, and manage your onboarded Cortex cloud API connection.
Prerequisites
To use the AI Discovery you’ll need:
  • Cortex Cloud setup with Cloud Posture Management license bundled enabled.
  • To onboard desired cloud accounts in the Cortex Cloud management console to initiate the discovery.
You'll need to migrate your Prisma Cloud to Cortex Cloud in order to use this functionality.
To onboard a Cortex Cloud tenant to the Prisma AIRS AI Inventory:
  1. Login to your Cortex Cloud Dashboard and navigate to Settings > Configurations > Integrations > API key and generate an API key for Prisma AIRS integration.
    Ensure that you have the appropriate privileges to setup the API key in Cortex.
  2. Go to AI Security > AI Inventory > All Assets.
  3. Click Connect Cortex AI SPM:
  4. Enter the Connection Name, API Base URL, API Key ID and the API key that you previously generated in Cortex cloud from Step 1.
  5. Once the connection is established, it will take approximately one hour depending on the available assets data in the Cortex Cloud to sync between the two systems. Once synced, the All Assets tab shows all discovered assets across your onboarded accounts.
    The following sections provide information about assets displayed in the interface. It includes information about:
    • Asset Details
    • Security Coverage
    Asset Details
    This detailed view shows the metadata of the agent such as its name, on which platform it is running, the cloud provider and associated account as well as dependency graph showing how agent is connecting to various assets within the platform it operates on (i.e. models, database, applications, endpoint etc.).
    Security Coverage
    Security Coverage integrates directly with Prisma AIRS AI Red Teaming for AI agents and model endpoints. When you discover an asset on the Security Coverage page, you can initiate the Red Teaming workflow directly from the asset view.
    Complete the following two steps to finish the assessment and attach the coverage:
  6. Create a Red Teaming Target.
  7. Start the Scan.
    Once the target is created, you will be able to initiate the scan on the target. After the scan is complete, the results will be reflected on the Security Coverage screen:
    In addition to Red Teaming Scan Results, the view displays Active Posture Risks identified by the Cortex AI-SPM. Combining Posture Risks and Red Teaming Scan Findings in a single interface provides a comprehensive risk profile, enabling you to take holistic security actions on discovered assets.

Posture Management

Prisma AIRS AI Inventory displays security posture data alongside discovered assets, giving security teams risk context without switching tools. This feature supports:
  • Posture issues. Models, agents, model endpoints, and training datasets show posture issues sourced from Cortex Cloud AI-SPM, with severity ratings (Critical, High, Medium, Low), the violated policy rule, and remediation guidance.
  • Compliance mappings. Policy rules map to OWASP Top 10 for LLMs and other compliance frameworks, surfacing which requirements an asset is failing.
  • Dataset data classification. Training datasets display whether they contain PII or sensitive data, identified through Cortex data profiling.
  • The inclusion of the Security Coverage tab. Each asset detail page now includes a Security Coverage tab showing which AIRS products have assessed the asset, including AI Red Teaming results.
Posture data requires an active Cortex Cloud AI-SPM license connected to your AIRS tenant.
Prisma AIRS Posture Management integrates Cortex Cloud's AI Security Posture Management (AI-SPM) capabilities into the Prisma AIRS platform, providing unified visibility, risk assessment, and security controls across your AI asset landscape.
This integration addresses a critical gap in AI security: discovery without protection, and protection without discovery. By combining AI-SPM's asset discovery and posture analysis with Prisma AIRS's model security scanning, red teaming, and runtime protection, security teams gain a single platform to manage the full AI security lifecycle. The following key capabilities are supported:
  • AI asset discovery. Complete inventory of models, endpoints, datasets, and agents across AWS, GCP, and Azure.
  • Posture risk analysis. Identify misconfigurations, vulnerabilities, and compliance violations across all AI assets.
  • Data classification. Detect and classify sensitive data in training and inference datasets
  • Integrated security workflows. Launch model security scans, red teaming assessments, and runtime protection from a unified interface.
  • Compliance assessment. Evaluate AI assets against OWASP Top 10 for LLMs, EU AI Act, NIST, and MITRE frameworks.
  • Reporting. Generate PDF reports covering AI asset inventory and posture analysis.
What Posture Management Covers
Posture management operates on the AI assets Discovery has enumerated — models, agents, model endpoints, and datasets across AWS, Azure, and GCP. For each asset, two types of posture data are maintained:
Posture Policy Rules
Policy rules define the compliance standards and security controls your AI assets are evaluated against. Rules are classified as AI-class and map to established frameworks including the OWASP Top 10 for LLMs and other compliance standards.
Rules represent the expected secure state. Each rule describes a control — for example, requiring that model endpoints are not publicly accessible, or that training datasets do not contain unencrypted PII.
Posture Issues
A posture issue is raised when an asset violates a policy rule. Issues are categorized as:
  • Misconfigurations — asset is configured in a way that violates a security policy
  • Vulnerabilities — known weaknesses in the asset or its underlying infrastructure
  • Compliance violations — the asset does not satisfy a mapped compliance framework requirement
Each issue carries a severity rating:
SeverityMeaning
CriticalImmediate risk; requires urgent remediation
HighSignificant risk; should be prioritized
MediumModerate risk; address in normal cycle
LowMinor issue; informational or best-practice gap
Prerequisites
  • An active Cloud Posture Security (C1) license from Cortex Cloud (purchased independently from Prisma AIRS activation)
  • An active Cortex Cloud tenant with AI-SPM enabled.
    If you do not have a Cortex Cloud tenant, you will be redirected to Cortex Cloud Dashboard to complete tenant activation before proceeding.
Viewing Posture Issues
From the Asset Inventory
The AI Inventory list view shows issue counts per asset. You can filter the full inventory by posture severity to surface assets with the highest-priority issues first:
  1. Open the AI Inventory page.
  2. Use the severity filter to scope the view to Critical, High, Medium, or Low issues.
Assets are shown with their issue counts by severity level.
From the Asset Detail Page
Selecting any asset opens the detail panel, which includes posture data inline:
  • Issue counts by severity — a summary of how many critical, high, medium, and low issues exist for this asset
  • Individual issues — each issue includes the violated policy rule, a description of the violation, severity, and compliance framework mappings
  • Remediation guidance — steps to resolve the misconfiguration or violation
Dataset Data Classification
For training datasets, Discovery surfaces data classification results from Cortex AI-SPM in addition to posture issues. Data classification identifies whether a dataset contains:
  • PII (personally identifiable information)
  • Sensitive data matching configured data patterns
This is distinct from posture issues but informs risk assessment — a dataset with PII that is used to train a publicly exposed model represents a compound risk that posture alone does not capture.
Data classification results appear on the dataset asset detail page alongside posture issues.
Asset Relationships and Posture Risk
Because Discovery maintains dependency graphs between AI assets, posture issues on one asset can be understood in the context of what depends on it.
Example: a foundation model with a Critical misconfiguration that is used by three agents in production has a different blast radius than the same issue on an unused model. The relationship graph on any asset detail page shows:
  • Which agents use this model
  • Which datasets trained this model
  • Which endpoints serve this model
Use this context when prioritizing remediation — issues on heavily connected assets warrant earlier attention than isolated ones.
Security Coverage
Beyond posture policy checks, the Security Coverage tab on each asset detail page shows which AIRS security products have actively assessed the asset. This is complementary to posture: policy rules check configuration state, while security product assessments test for active exploitability and runtime behavior.
Posture Coverage by Asset Type
Asset TypePosture IssuesData Classification
Managed cloud modelsYesNo
Custom/self-hosted modelsNoNo
Managed agentsYesNo
Self-hosted agentsNoNo
Model endpointsYesNo
Training datasetsYesYes
Troubleshooting
Assets are not appearing after connecting my tenant.
Check that your Cloud Account Status in Cortex Cloud Tenant Console status shows as Connected status in Settings > Cloud Accounts. If any show Disconnected or Warning, resolve the issue in Cortex Cloud first. Initial ingestion may take up to one hour after first connecting a Cortex Cloud tenant with SCM.
A risk I resolved still shows in Prisma AIRS.
Risk status refreshes on a regular sync cycle from Cortex Cloud. After resolving a finding, allow until the next sync window for the updated status to appear in SCM.
Frequently Asked Questions
Q: Where does the posture policy rule set come from?
Rules are defined and maintained in Cortex Cloud AI-SPM as AI-class policies. They include mappings to OWASP Top 10 for LLMs and other compliance frameworks. You manage which policies are active and their enforcement configuration within Cortex.
Q: Can I create custom posture policies?
Policy rule management is handled in Cortex Cloud AI-SPM. Changes made there are reflected in the AIRS AI Inventory on the next sync cycle.
Q: How often does posture data refresh?
Cortex posture data syncs on a batch schedule (approximately twice daily). Issues resolved in Cortex will be reflected in the AIRS inventory after the next sync.
Q: An asset shows issues but I've already remediated them in my cloud provider. Why does the inventory still show them?
Posture state is derived from what Cortex has last scanned. The issues will clear after Cortex re-evaluates the asset and the updated state syncs to AIRS. If issues persist beyond two sync cycles after remediation, verify that the change is reflected in Cortex directly.
Q: Can I see a history of posture issues for an asset — not just the current state?
Current inventory views reflect the latest known posture state. Historical issue tracking is managed within Cortex Cloud AI-SPM.