Cybersecurity Operations
Firewall and Network Security: from Check Point to AI agents
Firewall and network security moved from hand-edited rule bases on Check Point and Cisco boxes, to next-generation firewalls and cloud-delivered SASE, to AI copilots that explain policy. In 2026, agents from Palo Alto Networks, Check Point, Fortinet, Zscaler and Cato troubleshoot, tighten rules and patch virtually, while humans still approve high-impact changes.
Autonomy level
1.8 of 5 · Copilot
launch score
Projected 3.5 by 2031
- Tasks automated
- 2.0
- Approval load
- 1.5
- Production maturity
- 2.0
Overall is the mean of the three sub-scores. How scores work
The same job, five eras
Drag across the eras to see who did the work, with what, and what broke.
What job does firewall and network security software do?
Network security exists to decide, for every connection, whether it should happen. Who is talking to what, over which port, carrying which application, and is that allowed? For thirty years the answer lived in a rule base: an ordered list of allow and deny lines that someone wrote, someone reviewed, and almost nobody ever removed.
The job has not changed. What changed is where the decision sits and who writes it. It moved from a box at the edge of the data center, to a cloud service in front of every user, and now toward agents that read live traffic and propose or make the change themselves. My view, shaped by years of building identity infrastructure at LoginRadius, is that the decision is quietly moving from the network address to the identity behind it.
Era 1 · Before SaaS · 1994-2007
How did firewall and network security work before SaaS?
The commercial firewall era starts with Check Point FireWall-1 in 1994. Its idea was stateful inspection: decide on the first packet of a connection, then track the session instead of judging every packet alone. Cisco followed with the PIX appliance and, in 2005, folded PIX, its IPS line and its VPN concentrators into the ASA 5500 series.
The model was a castle with a moat. A firewall sat between the trusted inside and the untrusted internet, and remote workers tunneled in through IPsec and later SSL VPNs. Anything inside the wall was trusted by default. That trust model is why the corporate VPN became the front door attackers kept walking through.
The work was manual. An engineer received a change request, found the right place in a rule base that could run to thousands of lines, typed the rule, and pushed it in a maintenance window. Nobody could say with confidence which old rules were still needed, so they stayed. Rule bases only grew.
What broke was visibility. A port-and-protocol firewall saw that traffic was on port 80. It could not tell you which application was running over it, which user sent it, or whether the allow rule written in 1999 still had an owner.
Era 2 · The Cloud Move · 2007-2020
What changed when firewall and network security moved to the cloud?
Palo Alto Networks shipped its first product, the PA-4000 series next-generation firewall, in 2007. The pitch was to classify traffic by application and user instead of by port. That fixed the visibility problem and set the template for every firewall that followed: NGFW boxes from Palo Alto, Fortinet, Check Point and Cisco, with intrusion prevention and threat subscriptions billed every year.
The same year, Zscaler was founded on the opposite bet: move the inspection into the cloud and send users to it. In 2010 Forrester analyst John Kindervag named the zero trust model, and in 2014 Google published how BeyondCorp removed the privileged intranet entirely. The perimeter idea was losing its intellectual footing well before it lost its budget.
In 2019 Gartner named the merger of these ideas SASE: SD-WAN plus secure web gateway, CASB, firewall as a service and ZTNA, delivered from the cloud. Pricing shifted from appliance refresh cycles toward per-user subscriptions.
The work itself barely changed. Engineers still wrote rules, now in more consoles. Policy managers like AlgoSec and Tufin appeared because enterprises ran several firewall brands at once and could not reason about them together.
Era 3 · The Copilot Years · 2020-2024
What did AI copilots change in firewall and network security?
NIST published SP 800-207 in August 2020, which gave zero trust a reference architecture that procurement teams could cite. Remote work did the rest. ZTNA and SASE moved from slideware to purchase orders, and the zero trust blueprint became the default design conversation for new networks.
AI arrived as an assistant. Check Point announced Infinity AI Copilot in January 2024, Fortinet put FortiAI into FortiOS that spring, and in May 2024 Palo Alto Networks launched Strata Copilot under its Precision AI brand. These tools answered questions in plain English, explained why traffic was blocked, and drafted rules. A human still reviewed and pushed every change.
Cisco took a different swing with Hypershield in April 2024, promising AI-driven autonomous segmentation enforced through eBPF. That was the first major vendor to say out loud that a machine should write segmentation rules.
Meanwhile the edge itself was on fire. In January 2024 CISA ordered federal agencies to mitigate exploited Ivanti Connect Secure flaws. In April 2024 a maximum-severity PAN-OS GlobalProtect bug was exploited as a zero day. The security appliances were now the target.
Era 4 · The Agentic Shift · 2024-2026
The Agentic Shift: What do AI agents do in firewall and network security today?
In 2025 and 2026 every large network security vendor shipped or announced agents that act, not just answer. Fortinet said in April 2025 that FortiAI-Assist could create configuration and policy updates and remediate network issues on its own. Cisco introduced AgenticOps and AI Canvas in June 2025. Palo Alto Networks launched Cortex AgentiX in October 2025 with a Network Security Agent for policy control across its own and third-party firewalls, gated by human approval for impactful actions.
Check Point went furthest on the rule base itself. Its Agentic Network Security Orchestration Platform, announced in May 2026, turns business intent into multi-vendor firewall rules, tightens unused access from live traffic, and maps changes to PCI DSS and NIST. Some pieces are available now; the Playblocks agents are in early availability. Zscaler added the ZAgent framework for SASE administration in June 2026, and Cato launched agentic threat prevention and CVE mitigation that it says can apply protections within 45 minutes.
Here is the honest picture. Agents in production today troubleshoot, find over-permissive rules, write draft policy and apply virtual patches. Write access to the rule base still runs through approval gates for anything consequential. AI Canvas sat in controlled availability in the US months after launch. Most vendor outcome numbers are self-reported.
The bigger shift is identity. Palo Alto Networks closed its CyberArk acquisition in February 2026, and its CEO framed it as securing every identity, human, machine and agent. As I argued in zero trust in the age of AI, the classic model assumed the actor was a person. Now the actor writing firewall rules may be an agent, and that agent needs its own dynamic authorization.
Era 5 · The Next Five Years · 2026-2031
What will firewall and network security look like by 2031?
My bet is that by 2031 the firewall rule base stops being something people write. Humans will state intent, such as which team or agent may reach which application under which conditions, and agents will compile that into enforcement across NGFW, SASE and cloud controls, prune what is unused, and prove compliance continuously. That is the same direction as zero trust becoming the default for new networks.
The unit of policy will be identity, not address. Every user, workload and AI agent gets a verifiable identity and short-lived access, and the network enforces it. The acquisitions of 2025 and 2026, including Palo Alto Networks buying CyberArk, point straight at this.
The constraint is trust in the change itself. A bad rule pushed at machine speed is an outage or an open door at machine speed. So I expect routine tightening, troubleshooting and virtual patching to run with exception-only review, while new exposure to the internet, changes to crown-jewel segments, and anything touching the agent's own permissions stay behind a human approval.
The edge device problem will force the pace. Edge appliances keep getting exploited, as the 2026 GlobalProtect auth bypass showed, and FortiBleed showed that patching alone does not end the exposure. Teams that cannot patch fast enough by hand will let agents apply compensating controls first and ask later.
My prediction · by 2031 · medium confidence
By 2031, most enterprise firewall and SASE rule changes will be written and applied by agents from declared intent, with humans reviewing only exceptions and new internet exposure.
What has to be true
- Agent identities on network infrastructure get scoped, short-lived credentials and full audit trails
- Vendors move agentic policy features from early availability to GA with reliable rollback
- Multi-vendor estates can be modeled as one live network graph agents can reason over
- Auditors accept agent execution traces as change evidence for PCI DSS and similar frameworks
Projected autonomy 3.5 of 5
- Cylake, founded by Nir Zuk, targets commercial availability of its agentic platformsourcebeing verified
Then vs now: who does each step?
The job broken into its steps, and who or what does each one in each era.
| Job step | On-prem | SaaS and cloud | AI-assisted | Agentic | Next 5 years |
|---|---|---|---|---|---|
| Receive a request for new access | Paper or email ticket to the firewall engineer | ITSM ticket routed to a change advisory board | Ticket, with a copilot summarizing the request | Agent turns business intent into a draft rule | Intent is declared once; agents compile it everywhere |
| Analyze risk and rule conflicts | Engineer reads the rule base by hand | Policy manager such as AlgoSec or Tufin simulates it | Copilot explains overlaps and shadowed rules | Agent checks against a live model of the network | Agent validates continuously; human sees exceptions |
| Implement the change | Engineer types it in a maintenance window | Engineer pushes from a central manager | Engineer pushes a copilot-drafted rule | Agent pushes after human approval for high-impact changes | Agent pushes routine changes; humans approve exposure |
| Clean up unused or broad rules | Rarely done | Annual audit project | Hit-count reports reviewed by engineers | Agent proposes tightening from live traffic | Continuous least-privilege pruning by agents |
| Respond to a new edge CVE | Wait for vendor patch and a window | Emergency patch plus IPS signature | Patch, with copilot-assisted exposure lookup | Agent applies virtual patch; humans schedule upgrade | Agent applies compensating controls in minutes |
| Prove compliance | Spreadsheet exports for the auditor | Policy manager reports per framework | Copilot-drafted evidence summaries | Agent maps each change to PCI DSS and NIST | Continuous evidence with an audit trail per agent action |
How does the firewall and network security team change?
The firewall team was always small and always behind. The queue of change requests set the pace, and most of the skill went into not breaking things in a rule base nobody fully understood. Agents remove the typing and much of the analysis, so the queue shrinks.
What replaces it is judgment and governance. When I built SOC 2, PCI and ISO programs at Sageworks, the hard part was never the control itself, it was proving who changed what and why. That gets harder when the actor is an agent. The new team writes intent, sets guardrails, owns the agents' identities, and reviews the exceptions.
Roles that shrink
- Firewall engineers who mainly implement change tickets
- Manual rule base audit and cleanup projects
- VPN concentrator administration
- Tier-1 network troubleshooting
Roles that appear
- Agent supervisor for network policy changes
- Network intent and guardrail designer
- Agent identity and access owner
- Edge exposure and virtual patching lead
Skills to learn
- Writing precise, testable network intent
- Reviewing agent change plans and execution traces
- Identity-first access design for users, workloads and agents
- Scoping and rotating credentials for automation and agents
- Reading exposure data to decide what must never auto-apply
What gets easier for the humans?
| Before | After |
|---|---|
| A single access change took weeks of analysis, review and scheduling | An agent drafts and validates the rule; the engineer approves in one review |
| Unused and overly broad rules piled up for a decade | Agents flag unused access from live traffic and propose tightening |
| A new edge CVE meant waiting for a patch and a maintenance window | A virtual patch or compensating control lands first, the upgrade follows |
| Troubleshooting a blocked app meant reading logs across consoles | An agent correlates topology, policy history and logs into one answer |
| Audit evidence was assembled by hand from exports | Every change carries its compliance mapping and execution trace |
Decisions that stay human
- Exposing any new service or management interface to the internet
- Changes to segments that hold crown-jewel data or production control systems
- Granting or widening the permissions of the agents themselves
- Accepting residual risk when a patch is not yet possible
- Deciding which business intent is allowed in the first place
Where should agents not act alone?
Risks and failure modes, through a security and identity lens.
- 01
The agent becomes the most privileged identity on the network
An agent that can write rules on every firewall is a master key. It needs its own identity, narrow scopes per device and action, short-lived credentials and no ability to change its own permissions.
- 02
Agent-made rule changes that open exposure
A wrong allow rule pushed at machine speed is an open door at machine speed. New internet exposure and crown-jewel segments should always require human approval and automatic rollback on failure.
- 03
Prompt injection through tickets, logs and traffic
Agents read change requests, log lines and packet metadata that attackers can influence. Treat every input as untrusted and never let text in a ticket alone authorize a rule change.
- 04
Edge devices remain the soft target
Ivanti Connect Secure and PAN-OS GlobalProtect were both exploited in 2024, and GlobalProtect had another authentication bypass in 2026. Adding an AI management plane to the same appliances adds attack surface.
- 05
Audit gaps when agents act
Regulators and auditors will ask who approved a change. Every agent action needs a trace that links intent, the approving human, the agent identity and the exact diff applied.
Who is building agentic firewall and network security?
Incumbents adding agents vs agent-native entrants. Capability lines are checked against each vendor's own site.
Incumbents
Cortex AgentiX includes a Network Security Agent for threat response, policy control and network management across its own and third-party firewalls, with human approval for impactful actions.
Checked Oct 9, 2026Compare
Agentic Network Security Orchestration turns intent into multi-vendor firewall policy and tightens unused access; Policy Auditor and Policy Insights are available, Playblocks agents are in early availability.
Checked Oct 9, 2026Compare
FortiAI-Assist and FortiOS 8.0 agents provide conversational troubleshooting and configuration for FortiGate and SD-WAN, and identify MCP and A2A traffic.
Checked Oct 9, 2026Compare
- Cisco ↗being verified
AgenticOps with AI Canvas and Cloud Control for cross-domain troubleshooting; firewall agentic troubleshooting and PCI DSS compliance checks were announced for Security Cloud Control.
Checked Oct 9, 2026Compare
ZAgent framework lets administrators configure and troubleshoot Zero Trust SASE through natural-language prompts, with agents such as a ZDX root-cause agent.
Checked Oct 9, 2026Compare
Agentic Threat Prevention predicts likely attack paths per customer and enforces tailored protections; Agentic CVE Mitigation applies protections for new CVEs, in as little as 45 minutes by Cato's account.
Checked Oct 9, 2026Compare
Algo, an AI assistant connected to the AlgoSec platform, answers policy questions and creates change requests through FireFlow; version 2.0 is in tech preview.
Checked Oct 9, 2026
Agent-native
Founded by Palo Alto Networks founder Nir Zuk to build AI-native, agentic security that runs fully on-premises; announced with a $45M seed in March 2026, not yet generally available.
Checked Oct 9, 2026
Side-by-side comparisons: Top 5 NGFW (Next-Generation Firewall) Platforms of 2026: Palo Alto vs Fortinet vs Check Point vs Cisco vs Juniper, Top 5 SASE Platforms for 2026: Zscaler vs Palo Alto vs Netskope vs Cato vs Cisco.
Questions people ask
How is AI changing firewall management?
AI moved from copilots that explain rules (2024) to agents that draft rules from business intent, find unused access in live traffic, troubleshoot blocked traffic and apply virtual patches. Palo Alto Networks, Check Point, Fortinet, Cisco, Zscaler and Cato all ship or have announced such agents, with human approval on high-impact changes.
Will AI agents replace firewall administrators?
Not soon. They replace the typing and much of the analysis, so fewer people implement change tickets. The remaining work shifts to writing intent, setting guardrails, approving consequential changes and owning the agents' own access. Teams get smaller and more senior rather than disappearing.
Can an AI agent safely change firewall rules on its own?
For narrow, reversible changes such as tightening unused access or applying a virtual patch, yes, with an audit trail and rollback. New internet exposure, crown-jewel segments and anything that widens the agent's own permissions should still need a human approval.
Is SASE replacing the traditional firewall?
For users and branch traffic, largely yes: SASE combines SD-WAN, secure web gateway, CASB, firewall as a service and ZTNA in the cloud, a term Gartner coined in 2019. Data centers and cloud workloads still run NGFWs, so most enterprises operate both.
What happened to the corporate VPN?
It is being replaced by ZTNA and identity-aware access because VPN appliances grant broad network access and sit exposed on the internet. Exploited flaws in Ivanti Connect Secure and PAN-OS GlobalProtect in 2024 made the case for retiring them faster.
What is an agentic firewall?
It is a firewall or policy platform where AI agents take actions, not just give advice: compiling intent into rules, tightening policy, troubleshooting and applying protections, inside guardrails. Check Point's Agentic Network Security Orchestration and Palo Alto's AgentiX Network Security Agent are two current examples.
What are the biggest risks of AI agents in network security?
The agent becomes a highly privileged identity, so a stolen or manipulated agent can open the network. Prompt injection through tickets or logs, wrong rules pushed at machine speed, and missing audit trails are the other main risks. Scope, short-lived credentials and human approval gates address them.
Sources
- Brief History of Check Point Firewalls (Check Point CheckMates), accessed Oct 9, 2026
- Cisco ASA (Wikipedia), accessed Oct 9, 2026
- Palo Alto Networks Form S-1/A (SEC), accessed Oct 9, 2026
- Zscaler (Wikipedia), accessed Oct 9, 2026
- No More Chewy Centers: Introducing The Zero Trust Model Of Information Security (Forrester), accessed Oct 9, 2026
- BeyondCorp: A New Approach to Enterprise Security (USENIX ;login:), accessed Oct 9, 2026
- What is SASE? (Fierce Network), accessed Oct 9, 2026
- NIST SP 800-207 Zero Trust Architecture, accessed Oct 9, 2026
- ED 24-01: Mitigate Ivanti Connect Secure and Ivanti Policy Secure Vulnerabilities (CISA), accessed Oct 9, 2026
- PAN-OS GlobalProtect zero-day CVE-2024-3400 actively exploited (Centre for Cybersecurity Belgium), accessed Oct 9, 2026
- Check Point debuts AI Copilot to streamline and automate cybersecurity management (SDxCentral), accessed Oct 9, 2026
- Fortinet embeds new AI tools across its cybersecurity and networking portfolio (SiliconANGLE), accessed Oct 9, 2026
- Palo Alto Networks Delivers More Autonomous Cybersecurity through Copilots, accessed Oct 9, 2026
- Cisco Hypershield: A New Era of Distributed, AI-Native Security (Cisco), accessed Oct 9, 2026
- Fortinet unveils FortiAI innovations enhancing threat protection and security operations (Help Net Security), accessed Oct 9, 2026
- Fortinet Introduces FortiOS 8.0, accessed Oct 9, 2026
- Announcing Cisco AI Canvas: Revolutionizing IT with AgenticOps (Cisco Newsroom), accessed Oct 9, 2026
- Cisco Cloud Control US general availability (Cisco Blogs), accessed Oct 9, 2026
- Palo Alto Networks Unveils Cortex AgentiX, accessed Oct 9, 2026
- Palo Alto Networks completes acquisition of CyberArk, Form 8-K exhibit 99.1 (SEC), accessed Oct 9, 2026
- Check Point Launches Agentic Network Security Orchestration Platform, accessed Oct 9, 2026
- Zscaler Redefines Zero Trust SASE for the AI Era, accessed Oct 9, 2026
- Cato Networks Launches Agentic Threat Prevention, accessed Oct 9, 2026
- Cato Networks Sets New Benchmark, Cutting Time-to-Protect to 45 Minutes with Full Agentic CVE Mitigation, accessed Oct 9, 2026
- Algo AI assistant (AlgoSec), accessed Oct 9, 2026
- Introducing Cylake: AI-Native Cybersecurity with Total Data Sovereignty (Greylock), accessed Oct 9, 2026
- Cylake: $45 Million Seed Raised For AI-Native Cybersecurity Platform (Pulse 2.0), accessed Oct 9, 2026
Published Oct 9, 2026. Last verified Oct 9, 2026. Eras 4 and 5, vendors, and scores are re-checked every six to eight weeks; see the changelog and methodology.
Keep reading
Essays and analysis
- Zero Trust Architecture: The Technical Blueprint
- Zero Trust in the Age of AI: Why the Classic Model Isn't Enough Anymore
- FortiBleed: 74,000 Admin Credentials Cracked From Devices That Were Already Patched
- Palo Alto GlobalProtect VPN Auth Bypass: When Your Security Vendor's Cookies Become the Attack Vector
- Palo Alto Networks + CyberArk: The $25 Billion Deal Reshaping Cybersecurity
- Zero Trust for AI Agents: Implementing Dynamic Authorization in an Autonomous World
What died (Tech Graveyard)
What comes next (Future Tech)
Comparisons
- Top 5 NGFW (Next-Generation Firewall) Platforms of 2026: Palo Alto vs Fortinet vs Check Point vs Cisco vs Juniper
- Top 5 SASE Platforms for 2026: Zscaler vs Palo Alto vs Netskope vs Cato vs Cisco
- Top 5 Zero Trust Network Access (ZTNA) Solutions 2026
- Top 5 DNS Security Solutions 2026: Cloudflare vs Quad9 vs the Rest