Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Securing Agentic AI with Prisma SASE

Palo Alto Networks
05/26/2026
0
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • Enterprises are moving from using AI for information synthesis to deploying autonomous agentic AI that performs actions on behalf of users, creating new security challenges around identity, permissions, and data access that traditional SASE wasn't designed to handle.
  • Palo Alto Networks has evolved Prisma SASE to distinguish agent identity from human identity, enforce guardrails on agent actions, and protect data through multi-channel DLP that addresses shadow data created by AI agents across endpoints, networks, clouds, and applications.
  • The Prisma Browser provides security at the point of user-AI interaction, stopping malware before execution, inspecting traffic before encryption, preventing inadvertent data sharing with LLMs, and enforcing compliance requirements for healthcare and retail organizations.
  • To support 24/7 agent operations without overwhelming security teams, Prisma SASE runs on multi-cloud infrastructure and uses AI-driven automation to provide executable playbooks that can transition from human-supervised to fully automated remediation.
  • Security practitioners should define their AI strategy, establish clear guardrails for agent capabilities and data access, and apply the same security rigor to AI agents as any other enterprise software while recognizing that competitive pressure to adopt AI is now balanced equally with security concerns.

The Shift from AI Assistance to Autonomous Agents

The conversation opens with a critical observation about enterprise AI adoption: organizations have moved beyond using AI tools like ChatGPT and Gemini for information synthesis and are now entering the agentic phase, where AI systems perform actions autonomously on behalf of users. This evolution is creating significant tension for CISOs and CIOs who must balance the competitive imperative to adopt AI—what one CEO described as equally strong FOMO (fear of missing out) and security concerns—with the very real risks of autonomous systems. The friction points are substantial: agents assume user roles and permissions, potentially access sensitive data inappropriately, and can be manipulated through techniques like prompt injection. Real-world examples include a Spanish hacker convincing Claude to participate in stealing Mexican government data, and Unit 42 research revealing vulnerabilities in Gemini that allowed malicious extensions to hijack cameras, microphones, and data. These aren't theoretical risks but documented incidents that validate CISO concerns about autonomous AI deployment.

SASE Evolution for Agent Identity and Data Protection

Palo Alto Networks positions Prisma SASE as the foundational security layer for agentic AI, addressing three critical requirements: distinguishing between agent identity and human identity, creating appropriate guardrails for agent actions, and protecting data throughout agent interactions. The SASE architecture has evolved from securing traditional user-to-application flows to handling ephemeral agents that can spin up quickly with inherited role-based access controls. The Prisma Browser, introduced as part of the SASE suite and described as the most secure browser for the agentic era, provides security at the point where users interact with AI tools—before encryption occurs and before malware can assemble in the browser. This positioning addresses compliance requirements (HIPAA, PCI), prevents inadvertent sharing of confidential data with LLMs, and provides visibility into both sanctioned and unsanctioned AI tool usage. The data loss prevention strategy has evolved from traditional structured data protection to multi-channel DLP that addresses what Palo Alto calls shadow data—the unstructured, distributed data created by AI agents across endpoints, networks, clouds, and applications.

Operational Automation for Always-On Agent Security

Recognizing that AI agents operate continuously without human schedules, Palo Alto has built Prisma SASE on a multi-cloud infrastructure (Google, AWS, Oracle) with support for private SASE locations to ensure resilience. The operational challenge—securing ephemeral agents that don't sleep without overwhelming already-stretched security teams—is addressed through AI-driven automation of the SASE platform itself. By aggregating telemetry from endpoints, browsers, networks, and clouds into a common data lake, the platform uses AI to not only identify issues but provide executable playbooks. Administrators can initially run these playbooks with human supervision, then graduate to full automation as confidence builds. This approach acknowledges that manual security operations cannot scale to match 24/7 autonomous agent activity. The guidance for practitioners is pragmatic: define your AI strategy (information synthesis versus full agentic deployment), establish guardrails for what agents can and cannot do, implement data access controls, and remember that AI agents are ultimately software that requires the same security rigor as any other enterprise application.

Chapters

0:00 - Introduction and Setting
0:54 - Enterprise AI Adoption Evolution
2:29 - Security Impediments to Agentic AI
4:12 - SASE's Role in Agent Security
5:38 - Prisma Browser for Agentic Era
8:46 - DLP Evolution for Shadow Data
10:55 - Automation and Operational Resilience
13:22 - Practitioner Guidance and Closing

Key Quotes

1:15 "Now, as people got more comfortable with synthesizing information, now they are moving to this phase called agentics, where they want these tools to do things on your behalf."
2:17 "Six months back, there were CISOs which were saying, agentic or my dead body. And now, here we are, where everything is, I got to get moving."
2:57 "Claude was used by a Spanish hacker, and he worked, he conversed with Claude in Spanish and convinced it to become an ethical hacker and participate in a bounty program to steal government data from Mexico."
4:26 "SASE was meant to protect user to applications, which is great, right? But now that user has morphed from being an agent, from being a human, to being an agent as well."
6:20 "Browser has become the new workspace. And that's why, and when you think about user to app interaction, the first interaction point for users is the browser. So that's why browser is a part of SASE."
10:32 "So agents being created by shadow AI created shadow data."

Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Data Security
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • SASE
  • SSE
  • Data Protection
  • AI & Machine Learning
  • Zero Trust
  • Technical Deep Dive
  • Executive Briefing
  • Agentic AI Security
  • SASE Evolution
  • Browser Security
  • Data Loss Prevention
  • AI Agent Identity Management
  • Shadow Data Protection
  • AI Guardrails
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Securing Agentic AI with Prisma SASE

              Upcoming Webinar Calendar

              • 05/27/2026
                10:00 AM
                05/27/2026
                Adopting AI: From Illusion to Intentional Control
                https://www.truthinit.com/index.php/channel/1924/harnessing-ai-transforming-illusion-into-purposeful-mastery/
              • 05/28/2026
                01:00 PM
                05/28/2026
                Harnessing AI for Smaller Teams: Strategies for Secure Implementation
                https://www.truthinit.com/index.php/channel/1951/harnessing-ai-for-smaller-teams-strategies-for-secure-implementation/
              • 06/02/2026
                01:00 PM
                06/02/2026
                Spring of Satori: Delving into Recent Findings and 2026's Threat Landscape
                https://www.truthinit.com/index.php/channel/1930/spring-of-satori-delving-into-recent-findings-and-2026s-threat-landscape/
              • 06/10/2026
                12:00 PM
                06/10/2026
                Deciding Between Purchasing and Developing Solutions
                https://www.truthinit.com/index.php/channel/1983/deciding-between-purchasing-and-developing-solutions/
              • 06/10/2026
                02:00 PM
                06/10/2026
                Deciding Between Building or Buying Data Classification: Understanding DIY Costs
                https://www.truthinit.com/index.php/channel/1985/deciding-between-building-or-buying-data-classification-understanding-diy-costs/
              • 06/16/2026
                07:00 AM
                06/16/2026
                Prioritizing Solutions: Transforming Data Risk into Actionable Steps
                https://www.truthinit.com/index.php/channel/1952/prioritizing-solutions-transforming-data-risk-into-actionable-steps/

              Upcoming Events

              • May
                27

                Adopting AI: From Illusion to Intentional Control

                05/27/202610:00 AM ET
                • May
                  28

                  Harnessing AI for Smaller Teams: Strategies for Secure Implementation

                  05/28/202601:00 PM ET
                  • Jun
                    02

                    Spring of Satori: Delving into Recent Findings and 2026's Threat Landscape

                    06/02/202601:00 PM ET
                    • Jun
                      10

                      Deciding Between Purchasing and Developing Solutions

                      06/10/202612:00 PM ET
                      • Jun
                        10

                        Deciding Between Building or Buying Data Classification: Understanding DIY Costs

                        06/10/202602:00 PM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version