ATEON

Blog

Koi Agentic Endpoint Security: Governing AI Agents at the Endpoint

30 September 2026

Palo Alto Networks Koi Agentic Endpoint Security blog cover

Palo Alto Networks and Cortex logos

Koi Agentic Endpoint Security is an AI-native security solution built to govern AI agents and modern software components on endpoints in real time. Palo Alto Networks completed its acquisition of Koi in April 2026 and is bringing the technology into Cortex XDR and Prisma AIRS.

The Endpoint's New Attack Surface

Endpoints are no longer devices with defined perimeters but constantly changing execution environments. Every day, employees and AI agents add new applications, open-source packages, browser extensions, local LLM models, MCP (Model Context Protocol) servers and skills. Most organisations do not know how many agents are active, what data they access or what they are allowed to do. Traditional EDR tools struggle to monitor threats that originate from this non-binary software, and data exfiltration via prompt injection, unmanaged API permissions and malicious cross-agent interactions all happen in that blind spot.

Four Core Capabilities

Total Visibility: Builds a real-time inventory of the applications, operating systems, drivers, code packages, AI models, extensions, containers and skills on every endpoint. Beyond the inventory, it shows what data each component can reach, which external services it talks to, what actions it can take and where it creates exposure.

Actionable Risks: At the core of the solution is a risk engine driven by an LLM-based AI researcher. By correlating reputation, exploitability, code intent and privilege boundaries, it performs a context-aware risk analysis for every software version and turns low-context alerts into high-confidence, actionable findings.

Proactive Guardrails and Control: Defines which packages, extensions and AI tools may enter the environment. When an application or download is blocked, users are not left at a dead end; they can request approval with a business justification. Administrators can remove, update or reconfigure insecure components across all endpoints with a single click.

Real-Time Prevention: Synchronous security hooks placed in the agent's execution path catch malicious intent before it reaches the system shell or the model. Indirect prompt injection, unauthorised tool calls and automated data exfiltration are blocked instantly without disrupting the developer's workflow.

Benefits for Organisations

Manual reviews and fragmented tooling give way to a precise, real-time view of the modern software stack. Blunt "block everything" policies are replaced by continuous, context-aware trust, so organisations can adopt AI without compromising security. Because scanning, risk scoring and policy enforcement are automated, the load on security teams drops and endpoint posture keeps improving without slowing users down.

Integration with Cortex XDR and Prisma AIRS

Koi Agentic Endpoint Security is offered both as a standalone solution and as a module integrated into Palo Alto Networks platforms. Cortex XDR gains a new module to find and remediate risk in the AI software ecosystem, while Prisma AIRS extends to agentic AI on the endpoint to provide a single control plane across the enterprise.

To map the risk of the AI agents and tools on your endpoints and get to know Koi Agentic Endpoint Security, get in touch with ATEON's specialists.