Palo Alto Networks has launched Unit 42 Continuous Frontier AI Defense, an enterprise security service that uses several artificial-intelligence models to keep looking for exploitable weaknesses as a company’s software and infrastructure change.
The service became available worldwide on September 22, 2026, through annual subscriptions. Palo Alto Networks has not published a standard price; Reuters reports that pricing varies with the AI models a customer selects.
What the new Unit 42 service does
Traditional penetration tests usually give an organization a snapshot of its security at one moment. Palo Alto Networks is pitching Continuous Frontier AI Defense as an ongoing service: it establishes a baseline, then repeats tests when applications or infrastructure change.
According to the company’s official announcement, the system can examine first- and third-party web apps, APIs, cloud infrastructure, source-code repositories and network assets. It is designed to do more than list possible vulnerabilities. Unit 42’s offensive-security specialists validate findings and try to connect separate weaknesses into practical attack paths.
That distinction matters. Security teams often face a large queue of alerts without enough context to know which ones deserve immediate attention. A service that can demonstrate how several modest flaws combine into a serious compromise may help teams prioritize work more effectively.
Why Palo Alto uses several AI models
The service’s orchestration layer can route different testing jobs to Anthropic’s Claude Mythos 5, OpenAI’s GPT-5.6-Cyber and open-weight models. Palo Alto Networks says no single model found more than 40% of vulnerabilities in its evaluation of complex environments, while leading models had less than 10% overlap in the exposures they identified.
Those figures are manufacturer research, not an independent benchmark. Still, they explain the design: different models may notice different classes of weakness, so a multi-model setup could provide broader coverage than relying on one system.
Palo Alto Networks also says it uses zero-data-retention architectures so customer source code and telemetry are not retained or used to train public models. Prospective customers should still examine the exact data-flow, access-control and regional-processing terms that apply to their deployment.
From finding a flaw to fixing it
Continuous Frontier AI Defense produces prioritized remediation advice, including code-level guidance and recommendations for virtual patches. A virtual patch is a security control that blocks an exploit path before the underlying software receives a conventional fix. It can reduce immediate risk, but it does not replace correcting the vulnerable code.
The company says an internal deployment produced more than a year’s worth of conventional penetration-testing results in three weeks, found 3.2 times more high- and critical-severity vulnerabilities per product, and reduced average remediation time by 51%. Those are Palo Alto Networks’ own results and may not predict what another organization will see.
Who this is for
This is not a consumer antivirus product or a self-service scanner for a small website. It is aimed at enterprises with sizable application portfolios, cloud estates and security teams that already manage large numbers of findings.
The strongest fit may be organizations that release software frequently, depend on many APIs, or have cloud environments that change too quickly for occasional manual assessments. Human Unit 42 consultants remain part of the process, which is important because automated security findings can be incomplete, misleading or disruptive if acted on without review.
Pricing, availability and unanswered questions
Continuous Frontier AI Defense is available globally now as an annual subscription. Palo Alto Networks has not disclosed public package prices, minimum contract sizes or a fixed list of models included at each price level. Interested organizations must contact the company for a quote.
Independent evidence about detection accuracy, false-positive rates and long-term cost savings is also still limited. Buyers should ask how testing is isolated from production systems, what approval gates exist before active exploitation, how findings integrate with ticketing and development tools, and how performance will be measured over the contract period.
The practical change is clear: Palo Alto Networks is turning frontier AI from a one-time security assessment into a continuously running, expert-supervised service. Whether that produces better security per dollar will depend on the quality of the models, the human validation around them and how quickly a customer can turn verified findings into fixes.
Featured image: Palo Alto Networks.
