Palo Alto Networks has launched Unit 42 Continuous Frontier AI Defense, an AI-powered offensive security subscription service designed to continuously find, validate and help remediate enterprise exposures before attackers can weaponize them.[3][4][6][10]
The service, announced on 22 September 2026, integrates gated frontier AI models from Anthropic’s Claude Mythos family and OpenAI’s cyber-focused GPT line with Unit 42’s threat intelligence and offensive security expertise.[4][5][6][10]
Customers can subscribe worldwide on an annual basis, with pricing tiers that vary depending on the mix of Anthropic, OpenAI and open-weight models deployed in their environment.[3][4][5][6]
Continuous Frontier AI Defense is built atop a proprietary multi-model harness that orchestrates work across multiple cyber-specialized models, rather than relying on a single AI engine to detect every weakness.[1][6][10]
Unit 42’s internal evaluations found that no individual model identified more than roughly 40% of vulnerabilities in complex enterprise environments, and that leading cyber models such as Claude Mythos 5 and GPT‑5.6‑Cyber had less than 10% overlap in the exposures they surfaced.[1][10][11]
By routing specific offensive testing tasks to whichever model is best suited—for example, one tuned for application security versus another optimized for cloud misconfiguration analysis—the harness aims to close coverage gaps while keeping compute spend manageable.[1][6][10]
The service also uses zero‑data‑retention architectures so that enterprise source code and telemetry are not retained or used to train public models, a privacy guarantee that has become a differentiator in AI‑assisted security offerings.[1][10][11]
The launch comes amid a rapid shift toward AI‑driven cyberattacks, in which threat actors use agentic tools and open‑weight models with limited safety guardrails to discover, validate and chain exposures at machine speed.[11][15]
In a recent Unit 42 investigation into an AI‑assisted intrusion, an attacker compressed what would traditionally be weeks of tradecraft into less than 10 hours, employing more than 50 mapped techniques from the MITRE ATT&CK and ATLAS frameworks across the kill chain.[15]
The same case study reported time‑to‑exfiltration shrinking to under an hour in real‑world attacks and noted that automated adversary scanners could begin probing newly disclosed vulnerabilities within minutes of public CVE publication, underscoring the mismatch between human‑paced defenses and machine‑speed offense.[11][15]
MITRE has separately formalized adversary use of large language models and other AI services in techniques such as Obtain Capabilities: Artificial Intelligence (T1588.007), reflecting how AI tooling now underpins reconnaissance, payload development and social engineering operations.[12][13][14]
Palo Alto Networks says it validated the new service internally across its own products before general release, using continuous Mythos‑based scanning to achieve more than a year’s worth of traditional penetration‑testing output in roughly three weeks.[1][6][10][11]
According to the company, the multi‑model harness identified 3.2 times more high and critical vulnerabilities per product than legacy testing methods and helped engineering teams cut mean time to remediate by 51%.[11]
During more than 100 customer engagements, Unit 42 reports that two thirds of validated exposures in third‑party applications had no assigned CVE, that 37% of identified issues carried high or critical severity ratings, and that chained flaws often produced end‑to‑end attack paths such as full account takeover and payment fraud in financial‑sector environments.[11][15]
Continuous Frontier AI Defense extends Unit 42’s earlier Frontier AI Defense program, introduced in April 2026 as a point‑in‑time exposure analysis and security blueprint service to benchmark organizations’ readiness for frontier AI risks.[5][10][11]
The expanded offering adds continuous testing across web applications, APIs, cloud infrastructure, source code repositories and network assets, pairing AI‑driven discovery with advanced adversary simulation to prove which attack paths are actually exploitable in real environments.[3][4][6][10]
It also incorporates Anthropic’s Claude Mythos 5 and OpenAI’s GPT‑5.6‑Cyber alongside open‑weight models, increasing the range of capabilities available for tasks such as vulnerability discovery, exploit validation and code‑level remediation guidance.[4][5][6][10]
Unit 42 positions the service as part of a broader strategy that includes virtual patching support, allowing organizations to implement temporary controls even before vendor patches or public disclosures are available for newly identified flaws.[1][6][10]
For defenders, the announcement reinforces that defending at human speed against AI‑accelerated attackers is no longer tenable and that closing years of accumulated exposure requires continuous, automated testing tied directly to remediation workflows.[11][15]
Security teams evaluating the new service are likely to focus on how its multi‑model approach compares with in‑house use of single LLMs, how zero‑data‑retention guarantees align with their regulatory obligations, and whether the claimed gains in vulnerability coverage and remediation speed hold up in their own estates.[1][6][10][11]
Organizations that do not subscribe can still draw lessons from Unit 42’s research by mapping their own environments against MITRE ATT&CK and ATLAS techniques associated with AI‑assisted intrusions and by prioritizing exposures that can be chained into realistic attack paths, rather than chasing every theoretical weakness at equal urgency.[12][14][15]
References
- Unit 42 Continuous Frontier AI Defense – Palo Alto Networks
- Palo Alto Networks launches AI-powered security testing service By Investing.com
- Palo Alto Networks unveils AI-powered cybersecurity service using Claude, GPT models
- Unit 42、継続的AI駆動型攻撃的セキュリティのサブスクリプションを発表
- Palo Alto Networks Delivers Anthropic’s Mythos and OpenAI’s …
- Unit 42 Continuous Frontier AI Defense
- Stay protected in an AI world – Palo Alto Networks Blog
- Obtain Capabilities: Artificial Intelligence, Sub-technique T1588.007
- ATT&CK Changes
- MITRE ATLAS Reference – Adversarial AI Techniques – GTK Cyber
- An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
