* [Blog](https://www.paloaltonetworks.com.au/blog) * [Palo Alto Networks](https://www.paloaltonetworks.com.au/blog/corporate/) * [AI Security](https://www.paloaltonetworks.com.au/blog/category/ai-security/) * Introducing Unit 42 Conti... # Introducing Unit 42 Continuous Frontier AI Defense [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fblog%2F2026%2F09%2Fintroducing-unit-42-continuous-frontier-ai-defense%2F) [](https://twitter.com/share?text=Introducing+Unit+42+Continuous+Frontier+AI+Defense&url=https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fblog%2F2026%2F09%2Fintroducing-unit-42-continuous-frontier-ai-defense%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fblog%2F2026%2F09%2Fintroducing-unit-42-continuous-frontier-ai-defense%2F&title=Introducing+Unit+42+Continuous+Frontier+AI+Defense&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www.paloaltonetworks.com.au/blog/2026/09/introducing-unit-42-continuous-frontier-ai-defense/&ts=markdown) \[\](mailto:?subject=Introducing Unit 42 Continuous Frontier AI Defense) Link copied By [Sam Rubin](https://www.paloaltonetworks.com/blog/author/sam-rubin/?ts=markdown "Posts by Sam Rubin") Sep 22, 2026 5 minutes [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown) [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown) [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown) [Unit 42](https://unit42.paloaltonetworks.com) [Unit 42 Frontier AI Defense](https://www.paloaltonetworks.com/blog/tag/unit-42-frontier-ai-defense/?ts=markdown) Cybersecurity is in the middle of a generational shift. AI has disrupted a 30-year balance of power between defenders and adversaries. Armed with agentic AI tools and open-weight models stripped of safety guardrails, threat actors are discovering, validating, and chaining exposures at machine speed. In a recent Unit 42 investigation, the attacker used more than 50 MITRE ATT\&CK techniques to reduce weeks of methodical intrusion tradecraft into less than 10 hours---97% faster than a skilled red team could have done. Time-to-exfiltration has compressed to under an hour in real-world attacks. And when new CVEs are publicly disclosed, automated adversary scanners are weaponizing them within 15 minutes. Defending at human speed is no longer viable. Organizations must close years of accumulated exposure while securing the AI they are rapidly adopting. That demands action on five fronts: continuously find and fix vulnerabilities, reduce exposure, secure AI infrastructure, unify attack prevention, and automate detection and response at machine speed. Today, we are announcing [**Unit 42 Continuous Frontier AI Defense**](https://www.paloaltonetworks.com/unit42/ai-advantage) to put the first two priorities into practice. Powered by Anthropic's Mythos models and OpenAI's latest GPT cyber models, this always-on, agentic service combines our offensive security experts with proprietary multi-model harnesses to discover vulnerabilities, validate real-world exploitability, and accelerate remediation across applications, identities, cloud infrastructure, and network assets. Led by our offensive security experts, this service discovers, validates and remediates exposures before they can be exploited. We use proprietary AI harnesses and gated capability models---powerful models restricted from public use---to discover vulnerabilities, prove real-world exploitability, and accelerate remediation across applications, identities, cloud infrastructure, and network assets as an organization's environment changes. Continuous Frontier AI Defense builds on Unit 42's Frontier AI Defense, which [launched](https://www.paloaltonetworks.com/blog/2026/04/introducing-unit-42-frontier-ai-defense/) in April and introduced Frontier AI Exposure Analysis, a point-in-time exposure analysis, and a security blueprint that benchmarks current capabilities to help organizations modernize their cybersecurity systems. In August, Unit 42 expanded the list of frontier AI models to include OpenAI's GPT-5.6-Cyber and Anthropic's Claude Mythos 5, giving organizations access to additional AI capabilities. ## A Single AI Model Is Not a Security Strategy Frontier models are powerful, but no single AI model is a [cybersecurity silver bullet](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/) and the models require equally powerful AI scanning harnesses. Unit 42 research evaluation of model performance across enterprise codebases and live environments revealed two stark operational realities: * **Coverage caps:** No single AI model catches more than 40% of vulnerabilities in a complex environment. * **Visibility:** Leading cyber models such as Anthropic Claude Mythos 5 and OpenAI GPT-5.6-Cyber have less than 10% overlap in the exposures they identify. To solve the single model gaps, Continuous Frontier AI Defense runs on proprietary multi-model harnesses. These harnesses act as an intelligent orchestration layer, routing specific offensive testing tasks to the model best suited for the job. This approach aligns model strengths, eliminates individual gaps, and keeps compute spend economical. We combine these frontier models with Unit 42 threat intelligence, and frontline security expertise to turn raw vulnerability data into verified, actionable protection. Zero Data Retention (ZDR) architectures protect enterprise source code and telemetry, so customer data is never retained or used to train public models. ## What Happens When AI Meets Real Enterprise Architecture We did not build this service on theoretical assumptions. We built and validated it internally across Palo Alto Networks and across more than 100 customer engagements. During our internal deployment, continuous Mythos-based scanning achieved over a year's worth of traditional penetration testing results in just three weeks. The harness identified 3.2 times more high and critical vulnerabilities per product than legacy testing methods, and helped engineering teams cut mean time to remediate by 51%. When we executed the service across customer environments, the frontline data delivered a clear warning: * **Hidden exposures:** In third-party applications, two out of three validated exposures had no known CVE. Vulnerability-only scanners will never see them. * **High severity:** 37% of identified exposures rated high or critical in severity. * **Chained attack paths:** Flaws rarely existed in isolation. In one financial sector engagement, our harness identified a sequence of individually minor flaws: an application payment link that failed to re-verify identity, a skipped one-time password check, and a session routing flaw. Chained together, an attacker could achieve complete account takeover and payment fraud without any victim action. ## Moving from Discovery to Validated Protection Finding weaknesses without fixing them only creates noise. And, security teams do not lack findings; they already have more alerts than they can act on. The bigger challenge is knowing which weaknesses an attacker can actually exploit and chain into a viable path to compromise, and then remediating them. Unit 42 Continuous Frontier AI Defense translates findings directly into risk reduction: * **Continuous Testing Engine:** Provides a full-estate baseline scan followed by always-on testing as an organization's environment changes. * **Multi-Model AI Harness:** Unit 42 deploys proprietary multi-model harnesses, the software architecture to route work to the model best suited for the task, improving efficacy and coverage while managing the cost of frontier AI at scale. * **Leading Cyber Models:** The harnesses are built around gated capability models, including Anthropic Claude Mythos 5 and OpenAI GPT-5.6-Cyber, as well as open weight models. * **Advanced Adversary Simulation:** Proves real-world exploitability by validating end-to-end attack paths across first- and third-party web apps, APIs, cloud infrastructure, source code repositories, and network assets. * **Accelerated Remediation:** Delivers actionable and prioritized fixes, code-level guidance, and virtual patch recommendations. To implement virtual patches before vulnerabilities are publicly disclosed or official patches exist, organizations can pair this with Frontier Virtual Patching. Unit 42 Continuous Frontier AI Defense is available worldwide today on an annual subscription basis. Register for our upcoming virtual Threat Briefing to see how we apply Frontier AI, our proprietary multi-model harness, and offensive security expertise to protect Palo Alto Networks and our customers. To learn more about [Unit 42 Continuous Frontier AI Defense](https://www.paloaltonetworks.com/unit42/ai-advantage), register for the upcoming Virtual Threat Briefing [here](https://register.paloaltonetworks.com/frontier-ai-defense). *** ** * ** *** ## Related Blogs ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Unit 42](https://unit42.paloaltonetworks.com) [#### A New Era of Security: Frontier AI Defense](https://www.paloaltonetworks.com.au/blog/2026/05/frontier-ai-defense/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Partners](https://www.paloaltonetworks.com/blog/category/partners/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Unit 42](https://unit42.paloaltonetworks.com) [#### Unit 42 Expands Frontier AI Defense with Armadin Partnership](https://www.paloaltonetworks.com.au/blog/2026/04/unit-42-frontier-ai-defense-armadin-partnership/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Unit 42](https://unit42.paloaltonetworks.com) [#### Introducing Unit 42 Frontier AI Defense](https://www.paloaltonetworks.com.au/blog/2026/04/introducing-unit-42-frontier-ai-defense/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Cortex XDR is the only Certified Leader in AV-Comparatives EPR 7 years in a row](https://www.paloaltonetworks.com.au/blog/security-operations/cortex-xdr-is-the-only-endpoint-security-market-leader-to-be-certified-by-av-comparatives-7-years-in-a-row/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### Identity Meets the SOC: Redefining the Last Perimeter](https://www.paloaltonetworks.com.au/blog/security-operations/identity-meets-the-soc-redefining-the-last-perimeter/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Partners](https://www.paloaltonetworks.com/blog/category/partners/?ts=markdown) [#### Enhancing AI-Driven Defense with Anthropic's Claude Opus 4.7](https://www.paloaltonetworks.com.au/blog/2026/04/ai-driven-defense-anthropics-claude-opus/) ### Subscribe to the Blog! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www.paloaltonetworks.com.au/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language