Palo Alto Networks Wires OpenAI and Anthropic Models Into Its Defenses

The most advanced AI models have spent the past two years being sold mostly as finished products: a chatbot, an API, a copilot. On Tuesday, one of the largest cybersecurity companies in the world began selling them the way an automaker buys an engine, as a component wired into something bigger.

Palo Alto Networks said it will deliver Anthropic’s Mythos and OpenAI’s GPT-5.6 to enterprise customers through Unit 42, its threat-intelligence and incident-response arm, and fold both into a service it calls Continuous Frontier AI Defense.

The offering targets a problem security teams are only starting to confront. Frontier models can read code, find weaknesses, write exploit code, and chain attack paths together at machine speed. The same capability that lets a defender patch a flaw before attackers reach it lets attackers reach it first. Palo Alto’s bet is that putting the models in defenders’ hands narrows that gap.

Unit 42 is the company’s field operation of researchers and incident responders, the group that investigates breaches and publishes threat reports. The service pairs those experts with the two models, which the company described as “gated capability” systems whose access it controls. A multi-model approach lets customers test their exposures against more than one frontier system, the company said.

The arrangement casts Palo Alto Networks as a buyer rather than a builder of frontier AI. It did not train Mythos or GPT-5.6 and does not claim to match their underlying capability. Instead it buys access and packages the models behind its own analysts, its own threat data, and its own controls. Analysts said that is the pattern taking hold across the security industry: vendors treat frontier models as components to be procured and integrated, much the way they once treated antivirus signatures or network sensors.

The move had been telegraphed. In August, Unit 42 said it would expand its Frontier AI Exposure Analysis offering with OpenAI’s GPT-5.6-Cyber and Anthropic’s Claude Mythos 5. Tuesday’s announcement turned that preview into a delivery commitment for enterprise customers, pairing the models with Unit 42’s offensive-security experts and its real-world threat intelligence.

For the model makers, the deal opens a channel. Anthropic and OpenAI compete with each other for enterprise contracts, and both now reach security budgets through Palo Alto’s sales force and its installed base of customers, a distribution path that bypasses the cloud platforms and developer accounts through which their models are usually sold. Analysts said that kind of wholesale channel is becoming as important to AI labs as their retail one.

For enterprises, the pitch is speed. Security operations have historically moved at the pace of a human analyst reviewing an alert. A model that can read an entire codebase and reason about which flaw an attacker would exploit first can compress that work into minutes, the company argues. Unit 42 has published research describing frontier models identifying a vulnerability in software long considered secure and then weaponizing it quickly in testing.

In early testing, the models surfaced a vulnerability that had gone unnoticed for 27 years in software long considered secure, and a separate exercise weaponized a newly discovered flaw within minutes, according to Unit 42’s published research. Those results are the argument the company makes to chief information security officers: the speed at which flaws are found and turned into attacks has passed the speed of human review, and the only response is to run the same models on the defending side.

The service is organized around three tasks. Frontier AI Exposure Analysis deploys the models to find vulnerabilities, misconfigurations, and exposed assets before attackers can use them, validating each finding against Unit 42’s threat data. An Autonomous Security Blueprint benchmarks a customer’s defenses and builds a roadmap for the move to machine-speed response. Agentic Defense Transformation then carries out the remediation.

The risk cuts both ways. A model powerful enough to find real weaknesses is also powerful enough to describe how to exploit them, which is why access is gated and monitored. Palo Alto said the service keeps the models working inside customer environments under its supervision, aiming to put the capability to work for defense without handing raw tools to anyone with an account.

The deal lands as the security industry’s relationship to AI shifts. For two years the conversation centered on protecting AI systems from attack and screening AI-generated code for flaws. Increasingly it centers on a second question: who gets to use the most capable models, and on whose behalf. Palo Alto Networks is betting that in enterprise security the answer will be the defender.

The company did not disclose pricing or the terms of its agreements with Anthropic and OpenAI. The announcement nevertheless signals that the frontier model market is growing a wholesale tier alongside its retail one, and that the security vendors once seen as the users of AI are becoming its distributors.

Related Posts

  • September 23, 2026
  • 14 views
Anthropic and OpenEvidence to Give Free Medical AI to Poorer Countries

OpenEvidence began as a way for a doctor to ask a question and get an answer drawn from peer-reviewed research rather than a search engine. It is free for clinicians…

  • September 23, 2026
  • 18 views
Meta’s Muse Tops the Charts, Then Runs Into Amazon

Meta released Muse on Sept. 8 with a simple pitch: a personal AI agent that could book tickets, sort email and act across the web on a user’s behalf. The…