Prisma AIRS Platform Architecture
Focus
Focus
Prisma AIRS

Prisma AIRS Platform Architecture

Table of Contents

Prisma AIRS Platform Architecture

Prisma AIRS is a modular AI security platform with four independent capability pillars you can deploy together or separately.
Where Can I Use This?What Do I Need?
  • Prisma AIRS
  • No prerequisites needed — this is a platform overview
Prisma® AIRS™ is Palo Alto Networks' AI security platform. It is built around four independent capability pillars — you can deploy one pillar, several, or all four based on where your AI security risks are greatest. No pillar requires another to function.

AI Runtime Security

AI Runtime Security detects and blocks AI-specific attacks and data loss in real time as traffic flows through AI applications and agents. It operates in two deployment modes that you can use separately or together:
  • Network intercept — an inline network-level enforcement point; no application code changes required. Deploy as a firewall instance in your cloud environment (AWS, Azure, or GCP) or manage through Strata Cloud Manager or Panorama.
  • API intercept (AIRS API) — code-level enforcement via a RESTful API or Python SDK embedded directly into your AI application source code.
AI Runtime Security protects AI applications, models, datasets, and agents against prompt injection, memory poisoning, tool extraction, contextual poisoning, goal hijacking, sensitive data leakage, and meddler-in-the-middle (MitM) attacks.

AI Supply Chain Security

AI Supply Chain Security protects the artifacts that enter your AI pipelines before they reach production. It has two sub-capabilities:
  • AI Model Security — scans model files (GGUF, Pickle, PyTorch, Safetensors) for hidden backdoors, malicious code, and deserialization vulnerabilities. Integrates with Hugging Face, private model registries, and CI/CD pipelines. Over 1.9 million Hugging Face models scanned; more than 9,000 critical vulnerabilities uncovered.
  • Agent Artifact Scanning — scans agent source code, skills, and tools for critical attack paths and unsafe capabilities before deployment.

AI Red Teaming

AI Red Teaming provides automated, enterprise-scale stress testing of AI applications, models, and agentic endpoints against real-world attack vectors — before you deploy them. Key facts:
  • Sets up in less than 10 minutes; complete reports generated in under 5 hours
  • 50+ attack techniques, 500+ attack scenarios
  • Attack library updated bi-weekly from Unit 42 and the Huntr bug bounty community, with more than 18,000 active threat researchers
  • Supports custom attacks, multi-turn scenarios, and custom target adapters for any AI endpoint

AI Gateway

AI Gateway is a centralized control plane for AI access, governance, and observability. Built on Portkey technology and integrated into Strata Cloud Manager, it supports 1,600+ large language models (LLMs) across 50+ providers through a single API endpoint.
AI Gateway operates in two deployment modes:
  • SaaS — Palo Alto Networks hosts the data plane; no infrastructure to manage
  • Hybrid — you host the data plane in your own environment for data residency or latency requirements
Sub-capabilities include a Unified LLM Gateway, MCP Gateway, Agent Gateway, Observability, Guardrails, Prompt Management, and an AI Catalog.

Modular Deployment Model

Because Prisma AIRS is modular, your documentation path depends on which capabilities you are deploying. Each capability pillar has its own administration book. Use Where to Go from Here to find the right starting point for your deployment.