AI Runtime Security Overview
Focus
Focus
Prisma AIRS

AI Runtime Security Overview

Table of Contents

AI Runtime Security Overview

Detect and block AI-specific threats in real time using network-level or code-level enforcement, or both, without replacing your existing .
Where Can I Use This?What Do I Need?
  • Prisma AIRS (Network Intercept)
  • Prisma AIRS (API Intercept)
  • Prisma AIRS license
AI traffic flowing between applications, agents, models, and external services carries a class of threats that traditional security tools don't inspect — prompt injections, sensitive data leakage, malicious content in AI-generated output, and agent-specific attacks such as memory poisoning and tool misuse. Prisma® AIRS™ AI Runtime Security detects and blocks these threats in real time as traffic flows through your AI applications and agents.
You enable AI Runtime Security through two approaches, and you can use one or both. Both modes share the same policy framework and security intelligence, so you configure policies once and they apply consistently across your entire deployment.
  • Network Intercept enforces security at the network layer without requiring changes to your application code. Your AI traffic passes through a Prisma AIRS software firewall that inspects and enforces policies inline.
  • API Intercept enforces security at the code layer — you integrate the Prisma AIRS RESTful API or Python SDK directly into your AI application or agent.
Protection spans five areas: prompt injection and jailbreak prevention (AI Model Protection), memory poisoning, tool misuse, and hallucination attack blocking (AI Agent Protection), sensitive data leakage prevention (AI Data Protection), malicious URL and malware detection in AI-generated content (AI App Protection), and harmful and toxic content moderation (AI Safety). Some capabilities — including contextual grounding for RAG applications and in-line data redaction — are currently available on API Intercept only.
Network Intercept deploys in three models to match your infrastructure: on public cloud (AWS, Azure, GCP), in Kubernetes environments using Hyperscale Security Fabric (HSF), or in private cloud and on-premises environments using the microperimeter model. You can combine deployment models across your environment.