* [Blog](https://www.paloaltonetworks.com.au/blog) * [SASE](https://www.paloaltonetworks.com.au/blog/sase/) * [Agent Security](https://www.paloaltonetworks.com.au/blog/ai-security/category/agent-security/) * Securing the Agentic Shif... # Securing the Agentic Shift: Data Protection Across the AI Data Path [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fblog%2Fsase%2Fsecuring-the-agentic-shift-data-protection-across-the-ai-data-path%2F) [](https://twitter.com/share?text=Securing+the+Agentic+Shift%3A+Data+Protection+Across+the+AI+Data+Path&url=https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fblog%2Fsase%2Fsecuring-the-agentic-shift-data-protection-across-the-ai-data-path%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fblog%2Fsase%2Fsecuring-the-agentic-shift-data-protection-across-the-ai-data-path%2F&title=Securing+the+Agentic+Shift%3A+Data+Protection+Across+the+AI+Data+Path&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www.paloaltonetworks.com.au/blog/sase/securing-the-agentic-shift-data-protection-across-the-ai-data-path/&ts=markdown) \[\](mailto:?subject=Securing the Agentic Shift: Data Protection Across the AI Data Path) Link copied By [Suraj Subramanian](https://www.paloaltonetworks.com/blog/author/suraj-subramanian/?ts=markdown "Posts by Suraj Subramanian") and [Elisa Hu](https://www.paloaltonetworks.com/blog/author/elisa-hu/?ts=markdown "Posts by Elisa Hu") Sep 01, 2026 4 minutes [Agent Security](https://www.paloaltonetworks.com/blog/ai-security/category/agent-security/?ts=markdown) [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown) [Data Security](https://www.paloaltonetworks.com/blog/network-security/category/data-security/?ts=markdown) [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [SaaS Security](https://www.paloaltonetworks.com/blog/network-security/category/saas-security/?ts=markdown) [Agentic Security](https://www.paloaltonetworks.com/blog/tag/agentic-security/?ts=markdown) Not long ago, the biggest AI data security concern was employees pasting sensitive information into ChatGPT. Now imagine a departing employee using a sanctioned AI application to review customer contracts and pricing data. The application is approved, but the employee is using a personal account, working with sensitive information, and asking AI to identify customer renewal risks. The app may be sanctioned, but the interaction isn't necessarily sanctioned. Now take that same scenario one step further. An AI agent acting on the employee's behalf can retrieve customer data through [Model Context Protocol](https://www.paloaltonetworks.com/cyberpedia/what-is-model-context-protocol-mcp) (MCP), call enterprise tools, and pass information to another agent through Agent2Agent (A2A) , without the employee manually uploading a single file. This evolution forces a fundamental shift in strategy. DLP can no longer focus solely on manual uploads; it must now protect what AI itself can access, retrieve, and share. # **Where the New Data Risk Emerges** Securing agentic AI requires recognizing that data exposure no longer happens through front-door prompts alone. The risk has fractured across three distinct operational layers: * **Human to AI:** Employees share source code, customer records, financial data, and other sensitive information with AI applications. The app is approved, but the account, intent, and data may not be. * **Agent to tool through MCP:** MCP gives agents a standardized way to connect with enterprise tools and data. If a tool returns more information than the task requires, sensitive data can enter model context without a user ever explicitly sharing it. * **Agent to agent through A2A:** As specialized agents collaborate, data traverses new trust boundaries. An agent with privileged access can retrieve sensitive information and pass it downstream to another agent operating in a different environment, often bypassing traditional perimeter controls. Across all three layers, the underlying problem is the same: traditional security looks at the payload, but misses the context. It cannot tell what an agent is actually trying to do, why it's doing it, or where that data will land next. This is why data security must evolve toward Authority-Aware DLP, a dynamic approach that aligns data access with user identity, intent and context.. By evaluating user and agent identities alongside data sensitivity, destination, and business intent, security teams can finally answer the only question that truly matters in real time: Should this user, application, or AI agent be allowed to perform this action on this data? That is how you move from blind blocking to precise control. # **Security Has to Follow the AI Data Path** Putting Authority-Aware DLP into practice requires a security architecture that follows the actual path AI data takes at the speed of the workloads themselves. Palo Alto Networks delivers this by embedding protocol-aware inspection natively across three critical layers of the enterprise footprint: * **Workforce and endpoints (** [**Prisma Access**](https://www.paloaltonetworks.com/sase/access)**):** Secure AI usage and endpoint agents, with visibility and control over MCP connections and sensitive data flows. * **AI applications \& agents (** [**Prisma AIRS™ AI Runtime Security**](https://www.paloaltonetworks.com/ai-security/ai-runtime-security)**):** Protect prompts, responses, MCP interactions, and agent-to-agent communications at runtime, helping teams scale AI securely. * **Enterprise infrastructure (** [**Next-Generation Firewalls**](https://www.paloaltonetworks.com/network-security/next-generation-firewall)**):** Protect sensitive data across data centers, private clouds, and AI infrastructure as it crosses network and trust boundaries. Together, these controls extend data protection across human-to-AI, agent-to-tool, and agent-to-agent interactions, helping enterprises accelerate AI adoption without losing control of their data. # **Extend Zero Trust From Humans to Agents** For years, Zero Trust has focused on people: verify identity, limit access, and protect sensitive data based on context. AI agents now need the same discipline. That means understanding agent identities and connections, limiting access to the data and tools required for a task, protecting sensitive context inline, and enforcing policy as information moves between agents. The question is shifting from "What can this user access?" to "What can this agent access, and what is it authorized to do with the data?" # **Protect Data at AI Speed** AI agents won't wait for a person to copy a file, approve a transfer, or click send. As agents take on more work, the volume and speed of enterprise data movement will only increase. Data security has to evolve with it. Whether it's an employee interacting with a sanctioned AI app, an agent retrieving data through MCP, or agents exchanging information through A2A, approval at one layer should not imply trust at the next. Organizations need consistent visibility and control over sensitive data wherever AI accesses it, from the first prompt to an MCP tool call to the next agent in a workflow. Ready to secure your AI agent data path? [Talk to our data security expert](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention#connect) today to audit your local agent footprint, inspect hidden MCP traffic, and enforce Zero Trust data protection across your entire AI ecosystem. *** ** * ** *** ## Related Blogs ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### Identity Meets the SOC: Redefining the Last Perimeter](https://www.paloaltonetworks.com.au/blog/security-operations/identity-meets-the-soc-redefining-the-last-perimeter/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Prisma AIRS - Unified Data Protection for Claude](https://www.paloaltonetworks.com.au/blog/2026/08/prisma-airs-unified-data-protection-for-claude/) ### [Agentic Identity Security](https://www.paloaltonetworks.com/blog/identity-security/category/agentic-identity-security/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Why Cryptographically Verifiable SPIFFE Identity is Key to Scaling AI Agents](https://www.paloaltonetworks.com.au/blog/identity-security/ai-agent-security-spiffe-machine-identity/) ### [Agent Security](https://www.paloaltonetworks.com/blog/ai-security/category/agent-security/?ts=markdown), [AI Governance](https://www.paloaltonetworks.com/blog/ai-security/category/ai-governance/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Develop AI Safely](https://www.paloaltonetworks.com/blog/ai-security/category/develop-ai-safely/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Announcing the General Availability of Prisma AIRS AI Gateway](https://www.paloaltonetworks.com.au/blog/2026/07/announcing-general-availability-of-prisma-airs-ai-gateway/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Data Security](https://www.paloaltonetworks.com/blog/network-security/category/data-security/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/sase/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [SaaS Security](https://www.paloaltonetworks.com/blog/network-security/category/saas-security/?ts=markdown) [#### SaaS Supply Chain Security: Managing Risky Connected Apps \& GenAI Plugins in Enterprise SaaS](https://www.paloaltonetworks.com.au/blog/sase/saas-supply-chain-security/) ### [Agentic Identity Security](https://www.paloaltonetworks.com/blog/identity-security/category/agentic-identity-security/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Machine Identity Security](https://www.paloaltonetworks.com/blog/identity-security/category/machine-identity-security/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### How to Assess Maturity When Machine Identities Outnumber Humans 109:1](https://www.paloaltonetworks.com.au/blog/identity-security/assess-maturity-when-machine-identities-outnumber-humans-1091/) ### Subscribe to Sase Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www.paloaltonetworks.com.au/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language