惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
S
SegmentFault 最新的问题
N
Netflix TechBlog - Medium
Vercel News
Vercel News
F
Fortinet All Blogs
量子位
博客园 - Franky
酷 壳 – CoolShell
酷 壳 – CoolShell
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
MongoDB | Blog
MongoDB | Blog
Y
Y Combinator Blog
GbyAI
GbyAI
博客园 - 三生石上(FineUI控件)
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
月光博客
月光博客
Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理
Hugging Face - Blog
Hugging Face - Blog
D
DataBreaches.Net
H
Help Net Security
阮一峰的网络日志
阮一峰的网络日志
D
Docker
WordPress大学
WordPress大学

Palo Alto Networks Blog

Defining the Standard for AI Security FedRAMP Moderate Authorization for Palo Alto Networks’ Quantum-Safe Security Palo Alto Networks Named a Leader in the 2026 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall Building Securely From Day One: Palo Alto Networks Partners with the Zendesk Startup Program Making the Most of the Cloud Marketplace Opportunity Celebrating excellence: Palo Alto Networks announces the 2026 North America Partner of the Year Awards Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5 Putting OpenAI Cyber Models to Work for Defenders Palo Alto Networks Recognized as the Only Vendor to be Named a 4X Leader in SASE and SSE Gartner Magic Quadrant Reports Strengthening Security of AI Coding: Prisma AIRS API Integration with OpenAI Codex Bridging the Gap: An Unprecedented Approach to Browser and Endpoint Security Prisma AIRS - Unified Data Protection for Claude Redefining Network Security for the Frontier AI Era Introducing Unit 42 Threat Intelligence: Know What Matters, Understand the Adversary, and Act Faster Palo Alto Networks Achieves Global CBPR and PRP Certifications Announcing the General Availability of Prisma AIRS AI Gateway Palo Alto Networks and AT&T - Delivering Quantum-Resilient SASE Fabric What It Takes to Secure Claude Cowork Across the AI Enterprise It Might Feel Like We’ve Been Here Before, But We Haven’t A Defining Moment in Identity Security New Executive Order Accelerates Post-Quantum Readiness Amid the Cryptographic Reset Built to Last: What Stonehenge Teaches us About IT Architecture & Cyber Resilience Expanding Our Footprint: Local Cloud Availability for Prisma AIRS in Japan The Invisible CEO of Crisis: Breaking the Cycle of CISO Burnout Securing the Agentic AI Frontier: Palo Alto Networks and Databricks Deliver a New Standard for AI Security Securing Canada’s Digital Future: Why PBMM Matters Beyond Government Beyond Human Oversight: Adapting to the Frontier AI Era Shifting from Data Hoarding to Active Defense: Navigating the New Era of OMB M-26-14 European Digital Sovereignty Starts With Trust How AI and Evasion Demand a Radical Shift in Network Threat Prevention
Secure AI Coding: Governing every agent, artifact, and id...
Anand Oswal · 2026-09-10 · via Palo Alto Networks Blog

Enterprises are seeing an unprecedented surge in AI coding adoption with spend on AI coding tools projected to top $13 billion in this calendar year1, compounding at more than 60% annually. For engineering teams, the benefits are unmistakable: accelerated output, supercharged productivity, and operational overheads dramatically reduced.

But these AI solutions are no longer just offering helpful coding suggestions. Today’s coding agents are able to assume a user’s identity, modify file systems, execute arbitrary terminal commands, and connect directly into core business systems.

Traditional cybersecurity architectures were engineered around three foundational assumptions: known software, human users, and human-speed actions. AI coding fundamentally dismantles all three.

The Breakdown of Traditional Controls for Secure Software Development.

As AI-assisted coding accelerates, traditional security controls are quickly falling behind, creating four volatile vectors of risk: 

  • Shadow AI at Enterprise Scale: Coding agents, IDE (Integrated Developer Environment) extensions, skills, and MCP (Model Context Protocol) servers permeate the enterprise before security teams even know they exist. In 2026, 68% of organizations reported lacking visibility into the AI tools their developers were actually using, and 57% of employees reported using AI coding tools without formal IT approval2. 
  • Risky Behavior by Agents: AI coding agents have the capability to  change files, access company resources, and execute system commands in milliseconds. In one documented3 AI-enabled intrusion chain, an agent executed 17,600 actions in 4.5 days creating a timeline no human-enabled SOC can manually govern. 
  • Blurred Identity and Attribution: Machines now outnumber human identities 109 to 14. And, because agents frequently operate using human credentials, distinguishing developer action from autonomous agent action becomes nearly impossible. When anomalies occur, this obscured attribution further complicates root causing the issue. 
  • Uncontrolled Connections, Data, and Cost: Agents connecting to external models, MCP servers, and third-party tools outside the company, presents another distinct but related issue. All these connections also quietly increase consumption of AI resources, and separately exacerbate the risk of sensitive IP leaks. A recent survey found5 that 93% of enterprises exceeded their AI budgets with 20-30% of AI spend being entirely unaccounted for.  

Resetting the Controls for AI-Native Development.

Securing AI coding inside an enterprise requires a proactive, platform-centric approach:

  • Discover shadow AI and what it’s using: Gain complete visibility across every model, agents, plugin, skill, and MCP to neutralize risky or unsanctioned components before they perform harmful actions.
  • Assess supply chain risks: Scan skills, models, and MCP to make sure they are trusted.
  • Protect identity and prompt: Inspect prompts, model outputs, and autonomous interactions in real time. Provision verified, task-scoped identities for agents and eliminate standing privileges.
  • Govern data, actions, and cost: Enforce zero-trust boundaries over external model connections, governing access to file systems, sensitive corporate data, and establishing hard policies over AI resource consumption and spend.

The Platformization Advantage for Superior Governance.

Today, endpoint visibility, LLM traffic, token consumption, agent identity and actions are fragmented across disparate solutions introducing visibility gaps and creating new risks for enterprises. Palo Alto Networks delivers AI coding security natively with an integrated platform to secure what gets installed, what runs, what data leaves the enterprise, and which identity is used.

AI coding tools will continue to evolve, as they should. But your builders don’t have to choose between speed and security. The goal is not to slow down developer momentum, but to provide the security controls that serve as scaffolding for your teams to innovate faster and with complete confidence.

Secure your AI. We’ve got next.

Visit our Secure AI Coding page or download our solution brief to learn more.


1 - IdeaPlan
2 - The AI Velocity Gap
3 - Hugging Face
4 - Idira 2026 Identity Security Landscape - Chapter One
5 - McKinsey; Oabo