* [![perspectives](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com.au/perspectives)
* The Pilot Trap: Why Scaling AI is Impossible With Legacy AppSec Tools

# The Pilot Trap: Why Scaling AI is Impossible With Legacy AppSec Tools

![The Pilot Trap: Why Scaling AI is Impossible With Legacy AppSec Tools](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/02/Discover.png)  
**By [Ian Swanson](https://www.paloaltonetworks.com.au/perspectives/author/ian-swanson/ "Posts by Ian Swanson")** | **3 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=The Pilot Trap: Why Scaling AI is Impossible With Legacy AppSec Tools\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fperspectives%2Fthe-pilot-trap-why-scaling-ai-is-impossible-with-legacy-appsec-tools%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com.au/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com.au/perspectives/the-pilot-trap-why-scaling-ai-is-impossible-with-legacy-appsec-tools/?pdf=download&lg=en&_wpnonce=4139c4630b "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/02/Ian-BW-Headshot.jpeg)  
  Ian Swanson is Vice President of AI Security Products at Palo Alto Networks, where he leads strategy and product innovation to secure the next generation of artificial intelligence applications. He joined Palo Alto Networks following its acquisition of Protect AI, the company he founded and led as CEO, which became the industry's leading platform for managing risk and securing AI and machine learning environments end-to-end. Before founding Protect AI, Ian built and scaled global AI businesses at Amazon Web Services, where he led worldwide AI and ML, and at Oracle, where he served as Vice President of Machine Learning. Earlier in his career, he was the CEO and Founder of DataScience.com, an enterprise data science platform acquired by Oracle in 2018, and the CEO of Sometrics, acquired by American Express. Ian has also held executive roles at American Express and Sprint....

[Learn more](https://www.paloaltonetworks.com.au/perspectives/author/ian-swanson/)

## IN THIS ARTICLE

There is a strange paradox in enterprise AI right now. Innovation is moving at breakneck speed, and teams are spinning up copilots and experimenting with autonomous agents daily. Yet, if you look at actual production deployments, things slow to a crawl. We call this "Pilot Purgatory."

Amazing AI projects get built, but they get trapped in the testing phase, unable to scale across the business. As I discuss in my [video](https://www.paloaltonetworks.com/deploybravely#executives), the root cause is a fundamental mismatch in velocity: Organizations are innovating faster than they are building the controls to secure that innovation.

*But why?*

Because there is a widening gap between the AI models teams are building and the security controls required to run them safely. As my colleague, Anand Oswal, explained, AI is non-deterministic and adaptive.

Yet, we are trying to secure it using legacy Application Security (AppSec) tools designed for static code. It's like trying to secure a self-driving car using a padlock. The tool isn't just insufficient; it is irrelevant to the new threat surface.

## **The Copy-Paste Error**

The mistake we see most often is leaders assuming that traditional patterns --- static code reviews, one-time pentests --- will translate cleanly to AI.

*They don't.*

Tools designed for deterministic code are blind to non-deterministic risks. A static code analyzer cannot catch a poisoned model, just as a standard firewall (WAF) cannot understand a "jailbreak" prompt designed to trick an agent into bypassing its own rules.

When you rely on these legacy defenses, you are creating fundamental blind spots across the entire lifecycle.

## **Securing the Full Stack: Models, Apps, and Agents**

To escape the Pilot Trap, we have to stop treating AI as just "code" and start securing the three specific layers of the AI stack:

1. **The Model:** We need to scan model weights and datasets to detect poisoning or backdoors before they ever reach an application.
2. **The Application:** We need to prevent "Prompt Injection" attacks, where attackers trick the AI into bypassing its own rules --- something traditional Firewalls (WAFs) often miss.
3. **The Agent:** As we move to agentic workflows, we need to govern *actions*. If an agent tries to delete a database, that isn't a bug; it's a governance failure..

## **Architecture, Not Features**

Most organizations try to patch these gaps with isolated point tools --- one scanner for the model, a WAF for the app, and a separate governance tool for the agent. This fragmentation is exactly what keeps AI projects trapped in pilot purgatory.

Scalable AI security is not a "future requirement." It is the prerequisite for adoption today. But you cannot solve an architectural problem with a feature list. You need a unified platform.

When you deploy a cohesive platform like [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security), something powerful happens to your engineering culture. Teams move faster because they are confident. They stop viewing security as a "final hurdle" and start viewing it as a guardrail that travels with the application.

This is how you bridge the gap between innovation and control --- and finally move your AI investments out of the lab and into the business.

*This is Part 2 of our* ***[Deploy Bravely](https://www.paloaltonetworks.com/deploybravely#executives)*** *series.*

***Up Next:*** *[Badar Ahmed on why you need to "break" your own AI before the bad guys do.](https://paloaltonetworks.com/perspectives/stop-guessing-why-automated-red-teaming-is-the-new-standard-for-ai/)*

* [Secure AI Usage](https://www.paloaltonetworks.com.au/perspectives/all-articles/?cat=secure-ai-usage)
* [Staying Ahead of Evolving Threats](https://www.paloaltonetworks.com.au/perspectives/all-articles/?cat=staying-ahead-of-evolving-threats)

## Related Content

![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Securing-the-Wrong-Layer-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**Cybersecurity in 2026: What we predicted, what surprised us, and what's next**

At Palo Alto Networks, we are privileged to sit at the intersection of cybe...

[Haider Pasha](https://www.paloaltonetworks.com.au/perspectives/author/haider-pasha/ "Posts by Haider Pasha")
[](https://www.paloaltonetworks.com.au/perspectives/cybersecurity-in-2026-what-we-predicted-what-surprised-us-and-whats-next/)  
![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://www.paloaltonetworks.com.au/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://www.paloaltonetworks.com.au/perspectives/weaponized-intelligence/)  
![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/AdobeStock_704394220-16x7-1-scaled.png) BLOG

### AI

**Is Your Enterprise Architecture Ready for the Agentic Workforce?**

Exploring autonomous, agent-to-agent risk: Why your security needs governed...

[Anand Oswal](https://www.paloaltonetworks.com.au/perspectives/author/anand-oswal/ "Posts by Anand Oswal")
[](https://www.paloaltonetworks.com.au/perspectives/is-your-enterprise-architecture-ready-for-the-agentic-workforce/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* AU  
  Select your language
