Why Is Palo Alto Networks Using Frontier AI to Attack Its Customers’ Own Systems?

Why would a cybersecurity company deliberately try to break into a paying customer’s systems?

And why would the customer agree to let some of the most capable AI models available help do it?

That is essentially the idea behind a new Palo Alto Networks service announced on September 22, 2026. Unit 42 Continuous Frontier AI Defense uses Anthropic’s Claude Mythos 5, OpenAI’s GPT-5.6-Cyber and open-weight models to keep looking for weaknesses, test whether those weaknesses can actually be exploited, and help organizations fix them before a real attacker gets there. (Palo Alto Networks · Reuters)

The word “attack” needs an important qualifier: this is authorized offensive security testing. The AI is not supposed to roam the internet looking for random companies to compromise.

Editorial illustration showing frontier AI probing a corporate network under controlled cybersecurity supervision

That distinction turns what sounds like a contradiction into a much more interesting question: if AI is making hackers faster, can defenders use the same class of technology to find their own weaknesses first?

What Did Palo Alto Networks Actually Launch?

Flow diagram showing AI discovering, validating and helping remediate enterprise security exposures

Palo Alto Networks launched an always-on offensive security service rather than a one-time AI vulnerability scanner.

The company says Unit 42 Continuous Frontier AI Defense begins with a baseline assessment and then continues testing as a customer’s technology environment changes. It can examine first- and third-party web applications, APIs, cloud infrastructure, source-code repositories and network assets. (Palo Alto Networks)

Its basic loop looks like this:

  1. Find a possible weakness.
  2. Test whether it is actually exploitable.
  3. Determine whether several weaknesses can be connected into an attack path.
  4. Prioritize what matters most.
  5. Recommend code-level fixes or other remediation.
  6. Repeat as the environment changes.

That “repeat” is what makes the September 22 announcement different from a traditional point-in-time security assessment.

Palo Alto Networks says the service is available worldwide through annual subscriptions. The model combination can vary by subscription, and the company did not publish a standard dollar price in the launch announcement. (Palo Alto Networks · Reuters)


Why Is Offensive Security Still Defense?

Comparison between a criminal cyberattack and an authorized offensive security test

Because the goal of offensive security is to behave enough like an attacker to discover what a real attacker could do—without being the attacker.

Penetration testers and red teams have done versions of this for years. They deliberately search for weaknesses, attempt to exploit approved targets and test whether one compromise could lead to something more serious.

The new element is how much of that reasoning can be accelerated by frontier AI.

OpenAI describes GPT-5.6-Cyber as a specialized model for approved defenders conducting advanced, authorized vulnerability research, exploit validation and security testing. Daybreak Red requires separate approval, and OpenAI says Trusted Access users may test only systems they own, operate or are explicitly authorized to test or analyze. (OpenAI GPT-5.6 Cyber · OpenAI Trusted Access for Cyber)

So the simplest analogy is not “AI becomes the burglar.”

It is closer to hiring a very fast security team to keep trying the doors, windows and alarm system in your own building—then showing you which combination of weaknesses could let a real burglar reach the vault.


How Is This Different From a Vulnerability Scanner or a Penetration Test?

Comparison of vulnerability scanning, human penetration testing and continuous AI offensive security

The difference is not simply “old software versus AI.”

A conventional vulnerability scanner, a human penetration test and continuous AI testing can all find security problems, but they approach the job differently.

Approach What it mainly does Typical cadence Main strength
Vulnerability scanning Searches for known weaknesses, risky configurations and other indicators Scheduled or recurring Broad, repeatable coverage
Human penetration testing Tries to exploit approved weaknesses and reason through attack paths Usually time-bounded Human judgment and creativity
Continuous frontier AI testing Repeatedly discovers, validates and chains possible weaknesses as systems change Ongoing Machine-speed repetition and reasoning at scale

The important word in Palo Alto Networks’ pitch is “validate.”

A company may have thousands of warnings. That does not mean every warning gives an attacker a useful path into something valuable.

The service is supposed to ask the harder question: can this weakness actually be exploited, and if so, what could an attacker reach next?

That is closer to the reasoning behind a penetration test than simply producing a longer list of alerts.


Why Use Claude Mythos 5 and GPT-5.6-Cyber Together?

Multi-model AI cybersecurity system combining different models to find different security weaknesses

Because different frontier models appear to find different things.

Palo Alto Networks built what it calls a multi-model harness: software that can route different security tasks to different models rather than assuming one model is best at everything.

Axios reported that in Palo Alto Networks’ own testing, no single AI model found more than 40% of the vulnerabilities in a complex environment. The vulnerabilities identified by Mythos 5 and GPT-5.6-Cyber overlapped less than 10% of the time, according to the company’s testing described to Axios. (Axios)

Those figures are worth treating as company-reported testing rather than an independent benchmark. But they illustrate the logic behind the architecture.

If Model A is unusually good at source-code reasoning while Model B spots a different class of exploit chain, forcing every job through a single model may leave gaps.

Anthropic launched Claude Mythos 5 for a small group of trusted cyberdefenders, while OpenAI requires separate approval and provisioning for GPT-5.6-Cyber through Daybreak. (Anthropic · OpenAI)

The unusual part of Palo Alto Networks’ offering is therefore not simply that it “uses AI.”

It is that it combines multiple high-capability cyber models with Unit 42’s attack knowledge and keeps the process running as the customer’s systems change.


What Does “No Known CVE” Actually Mean?

Diagram explaining the difference between a known CVE and a security exposure without a known CVE

This is one of the more important details in the announcement.

Palo Alto Networks says that more than two-thirds of the exposures its analysis found in third-party applications had no known CVE. It also says its customer assessments found exposures in every organization tested, with 37% of identified exposures rated high or critical. Those are Palo Alto Networks’ own reported results, based on more than 100 Unit 42 customer engagements. (Palo Alto Networks)

CVE stands for Common Vulnerabilities and Exposures. NIST describes it as a list of entries for publicly known cybersecurity vulnerabilities, with each entry containing an identifier, description and public reference. (NIST)

So “no known CVE” does not automatically mean “AI discovered a never-before-seen zero-day.”

That distinction matters.

An exploitable path can sometimes emerge from several conditions that are individually less dramatic: a configuration mistake, an overly permissive account, an application behavior, an exposed service or several smaller weaknesses that become dangerous when chained together.

Think of a building where no single door is obviously broken. The real problem might be that one employee entrance leads to an unlocked hallway, which leads to a poorly protected elevator, which reaches a restricted floor.

The attack path is the problem—even if there is no single famous defect with a number attached to it.


What Is a Virtual Patch?

Diagram showing a virtual patch blocking an exploit before a vendor software patch is installed

Finding a serious problem quickly is useful only if the organization can do something about it quickly.

That is where virtual patching enters the picture.

Palo Alto Networks says the new service can recommend code-level fixes and can be paired with its Frontier Virtual Patching technology. The company describes the approach as using network-level protections to reduce exposure before an official software patch exists. (Palo Alto Networks)

A virtual patch does not necessarily remove the underlying bug from the software.

Instead, it attempts to block the dangerous traffic or behavior that would exploit the flaw.

Imagine discovering that a door lock is defective but learning that a replacement will take a week to arrive. A virtual patch is closer to putting a guarded barrier in front of the door until the lock itself can be replaced.

That can matter even more if AI compresses the time between discovering a weakness and figuring out how to exploit it.


How Did Palo Alto Networks Get From AI Testing to an Always-On Service?

Timeline showing Palo Alto Networks expanding Frontier AI Defense from assessments to continuous AI security testing

The September announcement did not appear out of nowhere.

Palo Alto Networks has been building toward continuous frontier-AI testing throughout 2026.

Date What changed
April 17, 2026 Unit 42 Frontier AI Defense launched around finding and remediating exposure to AI-enabled attacks.
August 12, 2026 Palo Alto Networks said it was expanding exposure analysis using OpenAI’s GPT-5.6-Cyber.
August 21, 2026 Unit 42 announced expanded use of Anthropic’s Claude Mythos 5.
September 22, 2026 Continuous Frontier AI Defense was announced as an always-on subscription service.

The timeline is documented in Palo Alto Networks’ April launch, August 12 OpenAI expansion, August 21 Anthropic expansion and September 22 continuous-service announcement. (April launch · August 12 OpenAI expansion · August 21 Anthropic expansion · September 22 launch)

The progression is revealing.

The first question was: “Can frontier AI find serious security problems?”

The next question became: “Can it validate whether those problems are exploitable?”

Now the question is: “Why stop testing when the corporate environment changes every day?”

Cloud services appear and disappear. Code changes. APIs are updated. Employee permissions change. Third-party software changes.

A penetration test conducted several months ago cannot automatically account for everything that changed afterward.

That is the gap continuous testing is trying to address.


Does Palo Alto Networks’ Testing Prove That This Works?

Not yet in the strongest sense of the word “prove.”

Palo Alto Networks says it spent six months developing and validating the approach, invested $17 million in R&D and methodology optimization, and used it across more than 100 Unit 42 customer engagements. It says its own internal deployment found what it described as a year’s worth of exposures in three weeks. These are company-reported validation results. (Palo Alto Networks)

Those are meaningful operational claims.

But they are company-reported results, not the same thing as an independent, standardized benchmark comparing the service against conventional scanners, human red teams and competing AI-security systems.

That is an important distinction because cybersecurity effectiveness can depend heavily on the environment being tested, what counts as an exposure, how severity is assigned, how much access the tester receives and whether a discovered weakness would have translated into a successful real-world breach.

Palo Alto Networks’ findings are evidence that frontier AI can surface problems at significant scale.

They are not proof that AI has made traditional security testing unnecessary.


What Are the Risks of Letting Powerful AI Test Real Systems?

Governance diagram showing AI offensive security operating inside authorized boundaries with human oversight

The more capable the offensive tool becomes, the more important its boundaries become.

OpenAI’s own access rules illustrate why these boundaries matter. GPT-5.6-Cyber is separately approved and provisioned for advanced authorized vulnerability research, exploit validation and security testing, and OpenAI says Trusted Access cannot be used against systems the user does not own or have explicit authorization to test. (OpenAI GPT-5.6 Cyber · OpenAI Trusted Access for Cyber)

That does not tell us every operational safeguard Palo Alto Networks applies inside each customer deployment.

It does show why companies evaluating this type of service should care about questions such as:

  • Exactly which systems can the AI touch?
  • Can it execute exploits automatically, or are some actions gated by human approval?
  • How are credentials and sensitive source code handled?
  • What happens if a test could disrupt a production system?
  • How are actions logged and audited?
  • Who decides that an AI-generated finding is real enough to remediate?

The future of offensive AI security is therefore partly a capability problem and partly a governance problem.

Finding more weaknesses is useful.

Knowing when, where and how the AI is allowed to prove those weaknesses is just as important.


Why Does This Matter to People Who Do Not Run a Security Team?

Most people will never buy Unit 42 Continuous Frontier AI Defense.

They may still depend on organizations that eventually use systems like it.

Banks, hospitals, employers, cloud providers, retailers and software vendors constantly change the digital systems that hold customer information and run essential services. If automated defensive testing can shorten the period between a new weakness appearing and someone discovering it, that could reduce the time attackers have to exploit it.

But there is another side to the story.

The same broad improvement in AI reasoning and coding that helps defenders can also lower the time and expertise required to search for vulnerabilities. Palo Alto Networks argues that this is why cybersecurity needs to move from “human speed” toward machine-speed defense. Because that framing is part of the company’s commercial case for the service, its claims about speed and effectiveness should be weighed alongside independent evidence as the technology matures. (Palo Alto Networks)

The deeper shift is not that AI suddenly invented hacking.

It is that both sides of cybersecurity may be able to automate more of the slow, expert work that once limited how many systems could be examined at once.


What Should We Watch Next?

The next test is not whether an AI can discover impressive vulnerabilities in a demonstration.

It is whether continuous AI offensive testing produces better security outcomes in ordinary enterprise environments.

Several questions matter:

Will independent researchers reproduce the claimed improvement in vulnerability discovery?

How many AI findings turn out to be false positives or low-value issues?

Can companies fix exposures as quickly as AI discovers them, or will security teams simply receive a larger backlog?

Will other cybersecurity vendors gain access to similar frontier models and build comparable multi-model systems?

And perhaps most importantly: what happens when increasingly capable offensive AI tools become available to a much wider range of users?

Palo Alto Networks is betting that defenders need to adopt that capability before attackers can use it at scale.

The September 22 launch turns that argument into a commercial service—and gives the industry something concrete to measure.


Why It Matters in One Sentence

Palo Alto Networks is turning powerful cyber-focused AI from an occasional security-testing tool into an always-on authorized attacker, based on the idea that companies may need machines continuously trying to break their defenses if they want to find weaknesses before real attackers do.


Palo Alto Networks AI Cybersecurity: Key Questions Explained

Q. Is Palo Alto Networks really using AI to hack its own customers?

It is using AI for authorized offensive security testing. The goal is to find and validate weaknesses in customer-approved systems before malicious attackers exploit them.

Q. What is Unit 42 Continuous Frontier AI Defense?

It is a continuous offensive-security service announced by Palo Alto Networks on September 22, 2026. It uses multiple AI models to find exposures, test exploitability, map attack paths and recommend remediation.

Q. Which AI models does the Palo Alto Networks service use?

The launch announcement specifically names Anthropic’s Claude Mythos 5 and OpenAI’s GPT-5.6-Cyber, along with open-weight models. The exact model mix can vary by subscription.

Q. Why does Palo Alto Networks use more than one AI model?

Different models appear to find different weaknesses. Palo Alto Networks told Axios that in its own testing, no single model identified more than 40% of the vulnerabilities in a complex environment and that the findings from Mythos 5 and GPT-5.6-Cyber overlapped by less than 10%. (Axios)

Q. Does “no known CVE” mean the AI discovered a zero-day?

Not necessarily. A CVE identifies a publicly known vulnerability, while an exploitable exposure may result from configurations, application behavior or multiple weaknesses chained together without corresponding to one known CVE.

Q. What is virtual patching?

Virtual patching places a defensive control in front of a vulnerable system to block or mitigate exploitation while the underlying software still awaits a permanent fix.

Q. Is GPT-5.6-Cyber available for anyone to use for hacking?

No. GPT-5.6-Cyber requires separate approval and provisioning through OpenAI’s Daybreak program and is intended for approved defenders conducting authorized vulnerability research, exploit validation and security testing. (OpenAI)

Q. Does this mean human penetration testers are becoming unnecessary?

The launch does not establish that. Palo Alto Networks is using AI to automate more discovery, validation and repeated testing, but its own service combines models with Unit 42 security expertise and human judgment.

Q. What is the biggest unanswered question?

Whether continuous frontier-AI testing consistently produces better real-world security outcomes than existing approaches once costs, false positives, operational risk and remediation capacity are included.

Did this help make the story clearer? 🙂
WIN keeps unpacking the “why” behind the news—clearly and simply!


Sources

Service Launch and Continuous Testing

Palo Alto Networks — Unit 42 Continuous Frontier AI Defense announcement

Reuters — Palo Alto Networks unveils AI-powered cybersecurity service using Claude and GPT models

Axios — Palo Alto Networks’ new cyber service to fight AI hacks

Frontier Models and Authorized Cyber Use

OpenAI — Expanding Daybreak as the Cyber Defense Window Narrows

OpenAI — GPT-5.6 Cyber model

OpenAI — Trusted Access for Cyber overview

Anthropic — Claude Fable 5 and Claude Mythos 5

Background, Model Integrations and Virtual Patching

Palo Alto Networks — Introducing Unit 42 Frontier AI Defense

Palo Alto Networks — Putting OpenAI Cyber Models to Work for Defenders

Palo Alto Networks — Unit 42 expands Frontier AI Defense with Anthropic’s Mythos 5

Palo Alto Networks — Frontier AI Critical Defense Program

NIST — Common Vulnerabilities and Exposures glossary

Related stories