Agentic Endpoint Security Identifies AI Agent and Supply Chain Risks
Article
3 min

Agentic Endpoint Security Identifies AI Agent and Supply Chain Risks

A new offering from Palo Alto Networks picks up where traditional endpoint protection leaves off.

People working in the office

Organizations are adopting artificial intelligence agents and applications quickly, yet many are doing so without sufficient visibility. Traditionally, organizations have relied on extended detection and response solutions to establish a holistic, unified approach to security. Palo Alto Networks’ Cortex XDR, for example, extends protection across the network, cloud, endpoints and identity.

But traditional solutions weren’t designed for AI agents and AI supply chain threats. Organizations need a new capability, agentic endpoint security (AES), to manage these unique risks.

Organizations often assume that endpoint solutions can solve for AI vulnerabilities. In reality, many organizations have extensive blind spots about potential sites for compromised AI, including extensions, skills, packages and plug-ins, among others. Palo Alto Networks saw these risks firsthand when we ran Koi’s agentic AI solution on our own infrastructure. Our company is one of the most secure environments in the world, and yet Koi found — and successfully neutralized — 23,000 potential AI threats.

In April 2026, we completed our acquisition of Koi and launched a new category of protection that we believe is crucial for any organization implementing AI. Cortex AES, formerly known as Koi, provides holistic visibility and control over AI in the environment, whether it’s created internally or obtained from outside developers.

AES lets organizations discover AI tools and components, use granular risk profiles to understand behavioral intent and privilege boundaries, and apply real-time enforcement, stopping dangerous commands before execution and forcing instant updates to remove AI software that isn’t secure. Cortex AES also strengthens governance by blocking risky software before it’s installed and enforcing consistent agent configurations.

Why Traditional Endpoint Protection Isn’t Sufficient for AI Agent Threats

Endpoint security solutions are designed to find threats from binary resources, such as standard applications. However, AI can introduce nonbinary threats, which may be buried in the code within AI models that employees use on their desktops. AI agents are being adopted across entire organizations as coding assistants, browser agents and co-pilots with real credentials that execute code and install software on their own. The risk of AI supply chain threats is analogous to a hacker leveraging an unprotected third-party vendor to gain access to its real target, the enterprise customer. For example, hackers could embed malicious code in an AI app that a company brings into production and then, once inside, activate that code to move laterally through the environment.

In addition, developers are leveraging AI more than they ever have before, with few guardrails. “Vibe coding” has made it easy to put code into production that has not been scrutinized from a security perspective. Potentially, this code could have command and control applications that could ultimately cause harm to the business. Environments are experiencing code sprawl and agent sprawl, a situation that increases risk when organizations lack the ability to see and analyze what’s happening.

Agentic Endpoint Security Automates Discovery and Remediation

Endpoint security solutions are designed to find threats from binary resources, such as standard applications. However, AI can introduce nonbinary threats, which may be buried in the code within AI models that employees use on their desktops. AI agents are being adopted across entire organizations as coding assistants, browser agents and co-pilots with real credentials that execute code and install software on their own. The risk of AI supply chain threats is analogous to a hacker leveraging an unprotected third-party vendor to gain access to its real target, the enterprise customer. For example, hackers could embed malicious code in an AI app that a company brings into production and then, once inside, activate that code to move laterally through the environment.

In addition, developers are leveraging AI more than they ever have before, with few guardrails. “Vibe coding” has made it easy to put code into production that has not been scrutinized from a security perspective. Potentially, this code could have command and control applications that could ultimately cause harm to the business. Environments are experiencing code sprawl and agent sprawl, a situation that increases risk when organizations lack the ability to see and analyze what’s happening.

Reach out to CDW about running an agentic endpoint security trial in your environment.