From AI Copilots to Agentic SecOps: What Palo Alto Networks’ Acquisition of Console Tells Us About the Next Phase of Security Automation

Palo Alto Networks’ acquisition of Console points to the next step in security automation: from AI copilots to agentic execution. The deal shows how Cortex is evolving toward more autonomous SecOps, while also highlighting wider market consolidation, emerging agent control planes, and the unresolved challenge of discovering and governing unmanaged AI agents.

Palo Alto Networks’ acquisition of Console is more than another AI-related cybersecurity transaction. It signals a shift in what large security platforms expect of artificial intelligence.

The first wave of generative AI in security focused largely on assisting analysts: summarizing incidents, explaining alerts, generating queries, recommending remediation actions, and helping users navigate increasingly complex security platforms. The next phase is about execution.

Agentic systems do not just provide an answer. They can investigate an issue, determine which actions to take, orchestrate workflows across different systems, and execute tasks within defined boundaries.

That distinction makes the Console acquisition strategically relevant. Palo Alto Networks is adding technology intended to move Cortex further away from AI-assisted security operations toward increasingly agentic ones.

What Is Happening?

On September 1, 2026, Palo Alto Networks announced it had acquired Console, an AI-native platform that enables agentic workflows across enterprise operations. Console lets users express operational objectives in natural language and use AI agents to perform the analysis and actions needed to address them. Palo Alto Networks plans to integrate these capabilities into Cortex, where they are expected to support activities such as investigating signals, prioritizing work, and taking action across enterprise environments. Palo Alto Networks outlines these objectives in its official Console acquisition announcement.

Cortex is Palo Alto Networks’ security operations platform family. At its center, Cortex XSIAM combines capabilities such as SIEM, XDR/EDR, and SOAR on a unified data and automation layer. Console is intended to add more agentic execution capability on top of this foundation.

The acquisition, therefore, addresses a different layer of AI than several of Palo Alto Networks’ recent transactions.

The acquisition of Protect AI strengthened protection across the AI development and runtime lifecycle. Koi added capabilities to secure agentic activity at endpoints. Portkey provides an AI gateway for monitoring, orchestrating, and governing interactions involving autonomous agents.

Console adds another dimension: using agents to operate security processes.

Put simply, Palo Alto Networks is building capabilities on both sides of the equation.

  • Security for AI: protecting models, applications, agents, identities, endpoints, and interactions.
  • AI for security: using AI agents to investigate, decide, orchestrate, and execute security operations.

Console primarily strengthens the second dimension.

Why Is This Strategically Important?

For several years, cybersecurity vendors have competed to provide the most capable AI assistant. The typical proposition has been to help analysts understand alerts more quickly, summarize incidents, write queries, correlate information, or recommend the next action.

Useful as these capabilities are, the human analyst generally remains the execution layer.

Agentic SecOps transforms this model.

The objective is no longer simply to make analysts faster. It is to transfer parts of the operational workflow to software agents that can determine what needs to happen and perform at least some of those actions automatically.

Palo Alto Networks describes Console as enabling users to create agentic workflows through natural language and to automatically address alerts and issues. Its stated intention is to deepen Cortex’s ability to investigate signals, prioritize work, and take action.

This matters because the primary bottleneck in many security operations environments is no longer the availability of detection data. Enterprises often have large volumes of telemetry and an extensive portfolio of detection technologies. The harder problem is turning signals into timely, consistent action.

Traditional SOAR platforms already automate predefined processes. Agentic systems could shift the model, as workflows can become more dynamic and context-dependent rather than relying entirely on manually designed playbooks.

The broader transition from assistants to governed agentic execution is examined in PAC’s InBrief Analysis on agentic orchestration, including the implications for governance, operating models, guardrails, and human oversight.

The strategic value, therefore, lies less in adding another AI interface to Cortex and more in extending the platform to an execution layer for security operations.

That is a considerably more ambitious role.

The transaction also fits within a broader consolidation race across the AI stack. Two days after the Console announcement, NVIDIA agreed to acquire Hugging Face for $12.93 billion. The deals are not directly comparable in scale or product focus, but they illustrate the same structural direction: large platform vendors are spending heavily to control strategically important layers of the AI stack, spanning models, developer ecosystems, agent orchestration, governance, and operational execution.

What Does This Mean for Security Software Vendors?

The acquisition raises the competitive bar for AI capabilities in cybersecurity software.

Simply adding a conversational assistant to an existing security product will increasingly be insufficient. AI copilots are likely to become standard across security platforms. Differentiation will shift toward how effectively vendors translate analysis into controlled operational action.

This will favor vendors that combine several capabilities:

  • broad telemetry,
  • security context,
  • workflow orchestration,
  • integrations with third-party systems,
  • identity and permission controls,
  • and mechanisms for safely executing actions.

The competitive question, therefore, changes from:

How well does the AI understand a security incident?

to:

How much of the incident lifecycle can the platform reliably manage and execute?

This could put pressure on standalone AI security assistants and smaller automation vendors whose capabilities can be integrated into broader SecOps platforms.

At the same time, specialist vendors will still have opportunities where deep domain expertise is critical. Agentic security will require reliable access to identity systems, cloud infrastructure, endpoints, applications, data platforms, network controls, ticketing systems, and many other operational environments. Security platforms will not own all of these systems.

APIs, integrations, agent interoperability, cross-platform discovery, and trusted machine-to-machine interaction are increasingly important competitive assets.

The control-plane question is becoming as important as the quality of the individual agent: who can observe agents across environments, assign identities and policies, monitor their actions, and intervene when necessary?

Another issue is governance. The more authority security agents receive, the more critical identity, authorization, policy enforcement, auditability, and runtime monitoring become. Vendors capable of controlling which agents are allowed to access what and which actions they can execute will occupy increasingly important positions in the architecture.

Microsoft Agent 365 offers a useful comparison. Microsoft positions Agent 365 as a centralized control plane for agents, covering Microsoft-built agents as well as third-party or externally developed agents that are either synchronized with its registry or integrated via its SDK. This is not identical to Cortex: Agent 365 is a broader enterprise agent governance layer, whereas Cortex is rooted in SecOps and security execution. Yet the overlap is strategically significant. Both point toward an over-the-top control layer above heterogeneous agents and tools, providing identity, observability, governance, security, and policy enforcement. The competitive battleground may therefore shift from individual copilots to the control planes that manage entire agent populations.

PAC has examined Microsoft’s broader approach to AI-agent security and platformization in more detail in its InBrief Analysis on Microsoft’s evolving AI security strategy.

What Does This Mean for System Integrators?

For system integrators and security service providers, agentic SecOps presents both an opportunity and a challenge.

The opportunity stems from implementation complexity.

Enterprises will not move directly from manually operated SOC processes to fully autonomous security operations. They will need to determine which workflows can be safely automated, which decisions require human approval, what data agents may access, which systems agents may modify, and how actions are audited or reversed.

This creates demand across several areas:

  • SecOps process redesign,
  • Cortex integration,
  • workflow engineering,
  • identity and access design for agents,
  • integration with ITSM and infrastructure platforms,
  • AI governance,
  • and operating model development.

The most important consulting question may define the boundaries of autonomy.

For example, an enterprise may allow an agent to enrich an alert and automatically isolate a low-risk endpoint, while requiring analyst approval before disabling an employee identity, modifying a production firewall rule, or changing access to a business-critical system.

Designing these boundaries will require understanding business processes and risk tolerance, not merely configuring a security product.

Managed security services will also be affected. Providers whose SOC propositions depend heavily on human alert triage, ticket handling, and repetitive investigation will face mounting pressure to automate. Agentic platforms could perform an increasing share of precisely these activities.

Therefore, the opportunity for MSSPs and MDR providers shifts toward higher-value responsibilities:

  • operating and supervising agentic environments,
  • handling complex investigations,
  • managing exceptions,
  • maintaining automation logic and integrations,
  • and assuming clearly defined operational responsibility for security outcomes.

What Does This Mean for Enterprise Users?

Enterprises should not evaluate agentic SecOps primarily by how much human work it can eliminate.

The more important question is which security processes can be safely delegated.

There is a substantial difference between an AI assistant generating a recommendation and an autonomous system making changes in a production environment. Once an AI system can disable accounts, isolate endpoints, block traffic, modify configurations, or interact with other enterprise platforms, it effectively becomes a privileged operational actor.

Enterprises will therefore need controls for:

  • permissions,
  • segregation of duties,
  • approval thresholds,
  • logging,
  • escalation,
  • rollback,
  • and accountability.

Agent identity will become particularly important. Organizations already apply privileged access management and least-privilege principles to administrators and service accounts. Similar principles will increasingly need to apply to AI agents.

These governance challenges are explored further in PAC’s Expert View on the behavior and controllability of AI agents, which examines why transparency, predictability, and auditability become increasingly important as agents gain greater autonomy.

This raises a harder question: what about agents that were never registered with a platform, for example, a Make.com workflow or a self-built agent running independently? Based on currently public product information, Console should not be understood as a universal discovery mechanism for such agents. Console can expose its capabilities to external agents via MCP. When those agents use Console, they inherit its identity and policies, and their actions are logged, but that still requires an explicit connection to Console.

Palo Alto Networks addresses the broader discovery problem through Prisma AIRS and Cortex AI Security Posture Management, rather than Console alone. Its technical documentation for AI Agent Discovery distinguishes between discovering agent configurations and monitoring their runtime interactions. The current portfolio can discover and inventory AI assets and agents across supported environments, while Prisma AIRS also supports onboarding SaaS agents. Yet the published technical documentation outlines platform, permission, and integration dependencies, as well as limitations in runtime visibility.

Enterprises should therefore not assume that any unmanaged DIY agent, wherever it runs, will automatically become visible and governable.

The same caveat applies to Microsoft Agent 365. Microsoft supports third-party and custom agents, but external agents must be synchronized with the registry or integrated via the Agent 365 SDK. Observability depends on the activity data exposed to the service. Neither option should be interpreted as universal passive discovery of every rogue or self-built agent in an enterprise.

Enterprises should also avoid treating maximum autonomy as the goal.

The more pragmatic approach is progressive automation. High-volume, well-understood activities can move toward autonomous execution first. More consequential or ambiguous decisions should continue to require human approval until sufficient operational evidence exists to justify additional autonomy.

The relevant metric is not how many analysts an organization can remove from a workflow. It is whether agentic automation improves the mean time to investigate and respond while maintaining or enhancing operational control.

What Does This Mean for the Security Market?

The Console acquisition reinforces a broader shift in cybersecurity from AI assistance to AI execution.

Generative AI initially transformed the user interface of security platforms. Natural-language interaction made complex tools easier to query and helped analysts interpret large volumes of information.

Agentic AI could change the operating model.

As the technology matures, competition is likely to shift toward platforms capable of integrating detection, investigation, reasoning, orchestration, and action within a governed environment.

This will also accelerate convergence among categories that have historically been separate. SecOps, SOAR, observability, identity, IT operations, cloud operations, and AI governance increasingly provide the context or control points required by autonomous workflows.

This creates a new strategic control point: agent discovery and governance across vendor boundaries. Microsoft is approaching this through Agent 365, while Palo Alto Networks combines Cortex’s SecOps execution with Prisma AIRS’ AI-driven discovery and security capabilities. The architectures and primary use cases differ, but both aim to operate at a layer above individual agents rather than simply add another agent.

Palo Alto Networks’ acquisition sequence illustrates this two-sided strategy. Protect AI, Koi, Portkey, and the broader Prisma AIRS portfolio to strengthen AI security by discovering, assessing, governing, and protecting models, applications, and agents. Console strengthens AI for security by bringing agentic workflow execution to Cortex. Taken together, the portfolio is moving toward a combination of an AI security control plane and autonomous SecOps execution.

The strategic battle is therefore moving beyond who has the best security copilot.

The more important question will be which platforms enterprises trust to act on their behalf.

That raises the bar considerably. Accurate analysis remains necessary but is no longer sufficient. Agentic SecOps will depend on the ability to combine security context with reliable execution, tightly controlled permissions, transparent decision-making, and clear accountability.

Palo Alto Networks’ acquisition of Console is therefore not just another AI feature acquisition. It is part of a broader race to control and execute the agentic enterprise. The winners will need not only agents that can act but also the ability to discover, constrain, audit, and govern agents that enterprises did not necessarily purchase from them in the first place.

Palo Alto Networks’ acquisition of Console reflects the shift from AI-assisted security toward agentic SecOps. As vendors compete to control both AI security and agent execution, the market is moving toward platforms that can not only analyze threats, but also govern, orchestrate, and execute security actions across increasingly complex enterprise environments.

Conclusion

Palo Alto Networks’ acquisition of Console reflects the shift from AI-assisted security to agentic SecOps. As vendors compete to control both AI security and agent execution, the market is moving toward platforms that can not only analyze threats but also govern, orchestrate, and execute security actions across increasingly complex enterprise environments.

Share via ...