Agentic Offensive Security: Palo Alto Networks Resells the AI Models Too Dangerous to Ship

Agentic Offensive Security: Palo Alto Networks Resells the AI Models Too Dangerous to Ship

Palo Alto Networks has turned Unit 42’s frontier AI experiments into a subscription. On September 22, the company announced Unit 42 Continuous Frontier AI Defense. The agentic offensive security service runs always-on attacks against your own estate, hunting exposures across web apps, APIs, cloud infrastructure, source code, and network assets, then prioritizing the fixes.

Its weapons are the industry’s most restricted models. The service runs on Anthropic’s Claude Mythos 5 and OpenAI’s GPT-5.6-Cyber, plus open-weight models. A proprietary multi-model harness routes each task to the model best suited for it.

That is the quiet story here. Anthropic has refused to generally release Mythos, judging its blast radius too high. OpenAI gates GPT-5.6-Cyber behind a vetted-access program. Most enterprises cannot buy these models directly — but they can now rent them through Palo Alto Networks, aimed at their own systems, with human experts supervising the loop. This is the new shape of agentic offensive security.

The timing is a six-month sprint. Unit 42 launched Frontier AI Defense in late April as a point-in-time exposure analysis. In August it added GPT-5.6-Cyber and Mythos 5, after briefing more than 1,000 security teams on the threat. The continuous version lands five months later, priced as an annual subscription.

The Competitive Picture for Agentic Offensive Security

The launch lands in a category converging fast from two directions: model labs turning defense into distribution, and exposure-validation vendors bolting AI onto existing platforms.

The gated-model arms dealers

Anthropic kicked this off in April with Project Glasswing, built around Claude Mythos. The company said the model can “surpass all but the most skilled humans at finding and exploiting software vulnerabilities.” It restricted access accordingly. By May, roughly 50 vetted partners had used Mythos to find more than ten thousand high- or critical-severity vulnerabilities in the world’s most systemically important software.

OpenAI matched it in August by expanding Daybreak, its cyber-defense program, into two tiers. Daybreak Blue unlocks frontier models for defensive work; Daybreak Red provides GPT-5.6-Cyber for exploit validation and red teaming. OpenAI is also committing one billion dollars in subsidized Daybreak access over six months. Both labs are racing to put their most dangerous capabilities into trusted hands — and Palo Alto Networks is one of the biggest of those hands.

The CTEM incumbents

Continuous threat exposure management is already a crowded, roughly $1.5 billion market, forecast to nearly triple by 2036. Pentera leads the exposure-validation pack. The Frost Radar 2026 leader runs AI-powered testing across internal networks, external attack surfaces, and cloud estates. CrowdStrike sells Falcon Exposure Management. Bishop Fox rebuilt its penetration-testing practice around Cosmos AI, its proprietary engine, in February.

Palo Alto Networks’ edge is not AI talent; it is access. Unit 42 pairs gated models with its threat intelligence and offensive-security consultants. That combination is one the CTEM vendors cannot yet match.

Everyone is racing the same clock

The urgency comes from Unit 42’s own incident-response data. The 2026 Global Incident Response Report draws on more than 750 engagements. Its fastest quartile of intrusions reached data exfiltration in 72 minutes — down from 285 minutes the year before. Over 90 percent of breaches stemmed from preventable exposure gaps, not attacker genius. The new service’s press release rounds this up to attackers “compressing breach cycles by almost 97 percent in some cases.” The documented baseline is a fourfold acceleration; the 97 percent figure is company framing.

What the Data Shows

Palo Alto Networks says it validated the approach over six months of in-house testing and more than 100 customer engagements. The effort carries a $17 million R&D investment. Internally, the company claims it found “a year’s worth of exposures in three weeks.” In customer assessments, every customer had exposures found — and 37 percent of them rated high or critical. Two-thirds of exposures in third-party apps had no known CVE, meaning no patch existed to wait for.

Those numbers are striking, and all of them are company-reported. The release gives no denominator for the 100 engagements, no independent audit, and no remediation metrics. The 75,000-customer company clearly has the delivery scale; the efficacy claims rest on its own testing.

Context matters too. This is a company in acquisitive overdrive. It closed the Embrace observability acquisition on August 27, after January’s Chronosphere deal, pushing beyond core security. A security-services launch built on other companies’ models is a cheaper way to expand than another acquisition.

One housekeeping note: the India-edition release arrived a day after the Santa Clara announcement. Its forward-looking boilerplate still calls the Embrace acquisition “proposed” — a month after the deal closed. Sloppy, but harmless. It does suggest how fast these releases get stamped out.

What’s New vs. Repackaged in This Agentic Offensive Security Play

Genuinely new

The continuous engine is the real upgrade. A full-estate baseline scan, then always-on retesting as the environment changes, turns a one-time audit into a standing capability. That matches how the threat actually behaves. Model-dependent pricing is also novel: subscriptions vary based on which OpenAI, Anthropic, and open-source models are in your harness.

Improved

Remediation depth. The service now pairs findings with code-level guidance and virtual patch recommendations. Customers can add Frontier Virtual Patching to block exploits before official patches exist. That addresses a bottleneck Anthropic flagged in May. The constraint is no longer finding vulnerabilities; it is verifying and fixing them.

Repackaged

This is the third evolution of the same service in five months. Point-in-time analysis came in April, gated-model expansion in August, continuous delivery in September. The underlying architecture — offensive experts plus frontier models plus threat intelligence — has not changed. The brand has.

Unclear

Pricing? The release lists only “varies by model mix” — no ranges. Liability? The release never says what happens when offensive testing against production systems breaks something.

And “exclusive access to gated capability models,” as the announcement claims, deserves an asterisk. Anthropic has roughly 50 Glasswing partners, and OpenAI runs an open Daybreak partner program. Unit 42’s access is privileged, but not sole.

The Questions That Weren’t Answered

Data governance comes first. An agentic service that maps your cloud estate sends your source code to Anthropic’s and OpenAI’s models. What do the models retain, where, and for how long? Neither the release nor the service page says.

Remediation accountability comes second. Continuous finding is a subscription; fixing is your problem. Unit 42’s own incident data says most breaches stem from unpatched, known exposure gaps. A service that multiplies findings faster than customers can remediate could widen the very gap it claims to close.

Model dependency comes third. If Anthropic tightens Mythos access, or OpenAI reprices GPT-5.6-Cyber, a subscription service built on both inherits that risk. Ask what the contract promises if the model rug gets pulled.

Last, efficacy. The “year’s worth of exposures in three weeks” claim has no defined unit. Ask for the metric behind it, the count of remediated exposures, and a reference customer before signing.

What This Agentic Offensive Security Shift Means for You

If you run security at a large enterprise, agentic offensive security has arrived at your procurement desk. Model access is now a differentiator vendors will price against — so make them prove it. Ask which models run which tasks, what data each one sees, and who is liable when offensive testing touches production.

If you are a CTEM vendor, the moat just moved. Pentera, Cymulate, SafeBreach, and XM Cyber own validation workflows, but Palo Alto Networks now sells workflow plus restricted models. Expect every major platform to chase lab partnerships within the year. Others will argue, credibly, that open-weight models close most of the gap.

If you are weighing this service, note what you are really buying. It is a channel to AI capabilities the labs will not sell you directly, wrapped in Unit 42’s expertise. That is genuinely scarce today. Price the subscription against how fast that scarcity erodes — OpenAI is spending a billion dollars to make it erode quickly.

Agentic Offensive Security: Palo Alto Networks Resells the AI Models Too Dangerous to Ship

Editor’s Note

This article draws on Palo Alto Networks‘ September 22, 2026 announcement and Unit 42 blog posts from April, May, and August 2026. It also draws on Anthropic’s Project Glasswing materials, OpenAI’s Daybreak documentation, the 2026 Unit 42 Global Incident Response Report, and reporting from SecurityWeek and market-research firms. Efficacy figures are company-reported and not independently verified. No services were evaluated hands-on.