Palo Alto Networks has introduced Unit 42 Continuous Frontier AI Defense, a subscription service designed to keep testing enterprise systems for vulnerabilities instead of relying on periodic penetration tests. The company says the service uses multiple frontier models, including Anthropic’s Claude Mythos and OpenAI’s GPT cyber models, with its own security tooling and human specialists.
The company is responding to a change in attack speed. Palo Alto Networks says AI-assisted attackers can compress work that once took weeks into hours, while newly disclosed vulnerabilities can be scanned and weaponized much faster than traditional security teams can respond.
The service is built around a multi-model approach. Palo Alto Networks says no single AI model in its evaluations found more than 40 percent of vulnerabilities in complex environments and that the overlap between leading models was low. Its system So routes different security tasks to different models rather than treating one model as a universal security engine.
The distinction is important for enterprise security. Finding a flaw is not the same as proving that it can be exploited. A continuous system has to understand whether several individually minor weaknesses can be chained into a meaningful attack path, then give engineers enough information to fix the actual route an attacker could use.
Palo Alto Networks says its internal deployment produced more than a year’s worth of traditional penetration-testing results in three weeks. It also reported a 51 percent reduction in mean time to remediate in its internal testing. Those are company-reported results rather than an independent industry benchmark, so they should be read as evidence of the product’s intended operating model rather than a universal performance claim.
The service also shows how AI is changing the economics of cybersecurity. Continuous testing would have been expensive if every test required a large human team. The goal of the new model is to automate repetitive discovery while keeping human experts involved where judgment is required.
Whether customers can trust such systems will depend on scope control, data handling and the accuracy of the findings. Security teams do not need more alerts. They need evidence that a weakness is real, exploitable and worth fixing first.
The technology is moving quickly, but the commercial test remains familiar. Products have to work consistently, fit existing systems and justify their cost.
Palo Alto Networks is effectively applying the same automation principle to the defender’s side of the security equation. Instead of waiting for a quarterly assessment, the service can keep looking as software changes. That could matter for modern environments where APIs, cloud resources and application dependencies change every day.
Continuous testing will only be valuable if its findings are accurate enough for security teams to act on them.
The service also shows the changing role of human security specialists. Palo Alto Networks is not eliminating them; it is using models to increase the amount of infrastructure they can examine. The useful question will be whether that combination reduces the backlog of real risks rather than simply producing more findings for already overloaded teams.
The value of continuous defense will ultimately be measured by fewer exploitable paths, not by the number of vulnerabilities an AI system can report.
The economics of continuous testing will also matter. Enterprise security teams already have more vulnerability reports than they can investigate. If an AI system produces thousands of low-value findings, automation can make the problem worse. Palo Alto Networks is So emphasizing validation and attack-path analysis, which is the part of the workflow that can turn a technical finding into a business risk. That distinction will be important as other security vendors introduce similar AI-driven services.