Skip to content
Draft. This page is in editorial review and is not indexed yet.

Cybersecurity Operations

Firewall and Network Security: from Check Point to AI agents

Firewall and network security moved from hand-edited rule bases on Check Point and Cisco boxes, to next-generation firewalls and cloud-delivered SASE, to AI copilots that explain policy. In 2026, agents from Palo Alto Networks, Check Point, Fortinet, Zscaler and Cato troubleshoot, tighten rules and patch virtually, while humans still approve high-impact changes.

Verified Updated Oct 9, 2026By Deepak Gupta
1.8

Autonomy level

1.8 of 5 · Copilot

launch score

Projected 3.5 by 2031

Tasks automated
2.0
Approval load
1.5
Production maturity
2.0

Overall is the mean of the three sub-scores. How scores work

Autonomy by era: On-prem 0.2, SaaS and cloud 0.8, AI-assisted 1.4, Agentic 1.8, Next 5 years 3.5.

The same job, five eras

Drag across the eras to see who did the work, with what, and what broke.

Era 1 · 1994-2007

On-prem

0.2
Who did the work
A small network security team, often two or three firewall engineers inside the network group, worked change tickets by hand and owned the boxes end to end.
Tools
Check Point FireWall-1Cisco PIXCisco ASA 5500NetScreenIPsec and SSL VPN concentrators
Representative product
Check Point FireWall-1
What broke
Rule bases grew for years because no one could prove a rule was safe to delete. Port and protocol rules could not see applications or users.

Autonomy 0.2/5 · Manual

Era 2 · 2007-2020

SaaS and cloud

0.8
Who did the work
Firewall engineers became network security architects. Large enterprises added a policy management function and a change advisory board to approve rule changes across vendors.
Tools
Palo Alto Networks PA-series NGFWFortinet FortiGateZscaler Internet AccessCisco FirepowerAlgoSecTufin
Representative product
Palo Alto Networks PA-series NGFW
What broke
Multiple firewall brands with separate consoles and rule syntaxes. Change requests took weeks of analysis, review and approval.

Autonomy 0.8/5 · Tool-assisted

Era 3 · 2020-2024

AI-assisted

1.4
Who did the work
The same engineers, now with a chat assistant. SOC analysts began querying firewall logs through copilots, and vulnerability teams spent more time patching edge devices than tuning policy.
Tools
Palo Alto Strata CopilotCheck Point Infinity AI CopilotFortinet FortiAICisco HypershieldZscaler Private AccessNetskope
Representative product
Palo Alto Strata Copilot
What broke
Copilots explained and drafted, but every change was still a manual push. Edge VPN and firewall appliances became the most exploited entry points.

Autonomy 1.4/5 · Tool-assisted

Era 4 · 2024-2026

The Agentic Shift

1.8
Who did the work
Engineers shift from typing rules to approving agent proposals and defining intent and guardrails. One reviewer can now cover changes that used to need several engineers, but the review cannot be skipped.
Tools
Palo Alto Networks Cortex AgentiXCheck Point Agentic Network Security OrchestrationFortinet FortiAI-AssistCisco AI Canvas and Cloud ControlZscaler ZAgentCato Agentic Threat Prevention
Representative product
Palo Alto Networks Cortex AgentiX
What broke
Write access for agents runs through approval gates, so speed gains stall at the reviewer. Several flagship agent features are still early or controlled availability.

Autonomy 1.8/5 · Copilot

Era 5 · 2026-2031

Next 5 years

3.5
Who did the work
A smaller network security team that writes intent, owns guardrails and audits agent actions, with an agent supervisor role reviewing exceptions instead of a queue of change tickets.
Tools
Intent-based policy enginesIdentity-aware SASE and ZTNAAgent identity and authorization layersContinuous compliance mapping
Representative product
Intent-based policy engines
What broke
Proving an agent-made change is safe before it ships. Governing the agents' own credentials and scopes.

Autonomy 3.5/5 · Agents with approvals

What job does firewall and network security software do?

Network security exists to decide, for every connection, whether it should happen. Who is talking to what, over which port, carrying which application, and is that allowed? For thirty years the answer lived in a rule base: an ordered list of allow and deny lines that someone wrote, someone reviewed, and almost nobody ever removed.

The job has not changed. What changed is where the decision sits and who writes it. It moved from a box at the edge of the data center, to a cloud service in front of every user, and now toward agents that read live traffic and propose or make the change themselves. My view, shaped by years of building identity infrastructure at LoginRadius, is that the decision is quietly moving from the network address to the identity behind it.

Era 1 · Before SaaS · 1994-2007

How did firewall and network security work before SaaS?

Verified

The commercial firewall era starts with Check Point FireWall-1 in 1994. Its idea was stateful inspection: decide on the first packet of a connection, then track the session instead of judging every packet alone. Cisco followed with the PIX appliance and, in 2005, folded PIX, its IPS line and its VPN concentrators into the ASA 5500 series.

The model was a castle with a moat. A firewall sat between the trusted inside and the untrusted internet, and remote workers tunneled in through IPsec and later SSL VPNs. Anything inside the wall was trusted by default. That trust model is why the corporate VPN became the front door attackers kept walking through.

The work was manual. An engineer received a change request, found the right place in a rule base that could run to thousands of lines, typed the rule, and pushed it in a maintenance window. Nobody could say with confidence which old rules were still needed, so they stayed. Rule bases only grew.

What broke was visibility. A port-and-protocol firewall saw that traffic was on port 80. It could not tell you which application was running over it, which user sent it, or whether the allow rule written in 1999 still had an owner.

  1. Check Point ships FireWall-1, the first commercial stateful firewallsource
  2. Cisco launches the ASA 5500 to replace PIXsource

Era 2 · The Cloud Move · 2007-2020

What changed when firewall and network security moved to the cloud?

Verified

Palo Alto Networks shipped its first product, the PA-4000 series next-generation firewall, in 2007. The pitch was to classify traffic by application and user instead of by port. That fixed the visibility problem and set the template for every firewall that followed: NGFW boxes from Palo Alto, Fortinet, Check Point and Cisco, with intrusion prevention and threat subscriptions billed every year.

The same year, Zscaler was founded on the opposite bet: move the inspection into the cloud and send users to it. In 2010 Forrester analyst John Kindervag named the zero trust model, and in 2014 Google published how BeyondCorp removed the privileged intranet entirely. The perimeter idea was losing its intellectual footing well before it lost its budget.

In 2019 Gartner named the merger of these ideas SASE: SD-WAN plus secure web gateway, CASB, firewall as a service and ZTNA, delivered from the cloud. Pricing shifted from appliance refresh cycles toward per-user subscriptions.

The work itself barely changed. Engineers still wrote rules, now in more consoles. Policy managers like AlgoSec and Tufin appeared because enterprises ran several firewall brands at once and could not reason about them together.

  1. Palo Alto Networks releases its first next-generation firewallsource
  2. Forrester publishes the zero trust modelsource
  3. Google publishes BeyondCorpsource
  4. Gartner coins SASEsource

Era 3 · The Copilot Years · 2020-2024

What did AI copilots change in firewall and network security?

Verified

NIST published SP 800-207 in August 2020, which gave zero trust a reference architecture that procurement teams could cite. Remote work did the rest. ZTNA and SASE moved from slideware to purchase orders, and the zero trust blueprint became the default design conversation for new networks.

AI arrived as an assistant. Check Point announced Infinity AI Copilot in January 2024, Fortinet put FortiAI into FortiOS that spring, and in May 2024 Palo Alto Networks launched Strata Copilot under its Precision AI brand. These tools answered questions in plain English, explained why traffic was blocked, and drafted rules. A human still reviewed and pushed every change.

Cisco took a different swing with Hypershield in April 2024, promising AI-driven autonomous segmentation enforced through eBPF. That was the first major vendor to say out loud that a machine should write segmentation rules.

Meanwhile the edge itself was on fire. In January 2024 CISA ordered federal agencies to mitigate exploited Ivanti Connect Secure flaws. In April 2024 a maximum-severity PAN-OS GlobalProtect bug was exploited as a zero day. The security appliances were now the target.

  1. NIST publishes SP 800-207 Zero Trust Architecturesource
  2. CISA issues Emergency Directive 24-01 on Ivanti Connect Securesource
  3. PAN-OS GlobalProtect CVE-2024-3400 exploited as a zero day; Cisco unveils Hypershieldsource
  4. Palo Alto Networks launches Strata Copilot powered by Precision AIsource

Era 4 · The Agentic Shift · 2024-2026

The Agentic Shift: What do AI agents do in firewall and network security today?

Verified

In 2025 and 2026 every large network security vendor shipped or announced agents that act, not just answer. Fortinet said in April 2025 that FortiAI-Assist could create configuration and policy updates and remediate network issues on its own. Cisco introduced AgenticOps and AI Canvas in June 2025. Palo Alto Networks launched Cortex AgentiX in October 2025 with a Network Security Agent for policy control across its own and third-party firewalls, gated by human approval for impactful actions.

Check Point went furthest on the rule base itself. Its Agentic Network Security Orchestration Platform, announced in May 2026, turns business intent into multi-vendor firewall rules, tightens unused access from live traffic, and maps changes to PCI DSS and NIST. Some pieces are available now; the Playblocks agents are in early availability. Zscaler added the ZAgent framework for SASE administration in June 2026, and Cato launched agentic threat prevention and CVE mitigation that it says can apply protections within 45 minutes.

Here is the honest picture. Agents in production today troubleshoot, find over-permissive rules, write draft policy and apply virtual patches. Write access to the rule base still runs through approval gates for anything consequential. AI Canvas sat in controlled availability in the US months after launch. Most vendor outcome numbers are self-reported.

The bigger shift is identity. Palo Alto Networks closed its CyberArk acquisition in February 2026, and its CEO framed it as securing every identity, human, machine and agent. As I argued in zero trust in the age of AI, the classic model assumed the actor was a person. Now the actor writing firewall rules may be an agent, and that agent needs its own dynamic authorization.

  1. Palo Alto Networks launches Cortex AgentiX with a Network Security Agentsource
  2. Palo Alto Networks completes its CyberArk acquisitionsource
  3. Check Point launches Agentic Network Security Orchestrationsource
  4. Cato launches Agentic Threat Preventionsource

Era 5 · The Next Five Years · 2026-2031

What will firewall and network security look like by 2031?

Verified

My bet is that by 2031 the firewall rule base stops being something people write. Humans will state intent, such as which team or agent may reach which application under which conditions, and agents will compile that into enforcement across NGFW, SASE and cloud controls, prune what is unused, and prove compliance continuously. That is the same direction as zero trust becoming the default for new networks.

The unit of policy will be identity, not address. Every user, workload and AI agent gets a verifiable identity and short-lived access, and the network enforces it. The acquisitions of 2025 and 2026, including Palo Alto Networks buying CyberArk, point straight at this.

The constraint is trust in the change itself. A bad rule pushed at machine speed is an outage or an open door at machine speed. So I expect routine tightening, troubleshooting and virtual patching to run with exception-only review, while new exposure to the internet, changes to crown-jewel segments, and anything touching the agent's own permissions stay behind a human approval.

The edge device problem will force the pace. Edge appliances keep getting exploited, as the 2026 GlobalProtect auth bypass showed, and FortiBleed showed that patching alone does not end the exposure. Teams that cannot patch fast enough by hand will let agents apply compensating controls first and ask later.

My prediction · by 2031 · medium confidence

By 2031, most enterprise firewall and SASE rule changes will be written and applied by agents from declared intent, with humans reviewing only exceptions and new internet exposure.

What has to be true

  • Agent identities on network infrastructure get scoped, short-lived credentials and full audit trails
  • Vendors move agentic policy features from early availability to GA with reliable rollback
  • Multi-vendor estates can be modeled as one live network graph agents can reason over
  • Auditors accept agent execution traces as change evidence for PCI DSS and similar frameworks

Projected autonomy 3.5 of 5

  1. Cylake, founded by Nir Zuk, targets commercial availability of its agentic platformsourcebeing verified

Then vs now: who does each step?

The job broken into its steps, and who or what does each one in each era.

Who or what does each step of Firewall and Network Security, by era
Job stepOn-premSaaS and cloudAI-assistedAgenticNext 5 years
Receive a request for new accessPaper or email ticket to the firewall engineerITSM ticket routed to a change advisory boardTicket, with a copilot summarizing the requestAgent turns business intent into a draft ruleIntent is declared once; agents compile it everywhere
Analyze risk and rule conflictsEngineer reads the rule base by handPolicy manager such as AlgoSec or Tufin simulates itCopilot explains overlaps and shadowed rulesAgent checks against a live model of the networkAgent validates continuously; human sees exceptions
Implement the changeEngineer types it in a maintenance windowEngineer pushes from a central managerEngineer pushes a copilot-drafted ruleAgent pushes after human approval for high-impact changesAgent pushes routine changes; humans approve exposure
Clean up unused or broad rulesRarely doneAnnual audit projectHit-count reports reviewed by engineersAgent proposes tightening from live trafficContinuous least-privilege pruning by agents
Respond to a new edge CVEWait for vendor patch and a windowEmergency patch plus IPS signaturePatch, with copilot-assisted exposure lookupAgent applies virtual patch; humans schedule upgradeAgent applies compensating controls in minutes
Prove complianceSpreadsheet exports for the auditorPolicy manager reports per frameworkCopilot-drafted evidence summariesAgent maps each change to PCI DSS and NISTContinuous evidence with an audit trail per agent action

How does the firewall and network security team change?

The firewall team was always small and always behind. The queue of change requests set the pace, and most of the skill went into not breaking things in a rule base nobody fully understood. Agents remove the typing and much of the analysis, so the queue shrinks.

What replaces it is judgment and governance. When I built SOC 2, PCI and ISO programs at Sageworks, the hard part was never the control itself, it was proving who changed what and why. That gets harder when the actor is an agent. The new team writes intent, sets guardrails, owns the agents' identities, and reviews the exceptions.

Roles that shrink

  • Firewall engineers who mainly implement change tickets
  • Manual rule base audit and cleanup projects
  • VPN concentrator administration
  • Tier-1 network troubleshooting

Roles that appear

  • Agent supervisor for network policy changes
  • Network intent and guardrail designer
  • Agent identity and access owner
  • Edge exposure and virtual patching lead

Skills to learn

  • Writing precise, testable network intent
  • Reviewing agent change plans and execution traces
  • Identity-first access design for users, workloads and agents
  • Scoping and rotating credentials for automation and agents
  • Reading exposure data to decide what must never auto-apply

What gets easier for the humans?

BeforeAfter
A single access change took weeks of analysis, review and schedulingAn agent drafts and validates the rule; the engineer approves in one review
Unused and overly broad rules piled up for a decadeAgents flag unused access from live traffic and propose tightening
A new edge CVE meant waiting for a patch and a maintenance windowA virtual patch or compensating control lands first, the upgrade follows
Troubleshooting a blocked app meant reading logs across consolesAn agent correlates topology, policy history and logs into one answer
Audit evidence was assembled by hand from exportsEvery change carries its compliance mapping and execution trace

Decisions that stay human

  • Exposing any new service or management interface to the internet
  • Changes to segments that hold crown-jewel data or production control systems
  • Granting or widening the permissions of the agents themselves
  • Accepting residual risk when a patch is not yet possible
  • Deciding which business intent is allowed in the first place

Where should agents not act alone?

Risks and failure modes, through a security and identity lens.

  1. 01

    The agent becomes the most privileged identity on the network

    An agent that can write rules on every firewall is a master key. It needs its own identity, narrow scopes per device and action, short-lived credentials and no ability to change its own permissions.

  2. 02

    Agent-made rule changes that open exposure

    A wrong allow rule pushed at machine speed is an open door at machine speed. New internet exposure and crown-jewel segments should always require human approval and automatic rollback on failure.

  3. 03

    Prompt injection through tickets, logs and traffic

    Agents read change requests, log lines and packet metadata that attackers can influence. Treat every input as untrusted and never let text in a ticket alone authorize a rule change.

  4. 04

    Edge devices remain the soft target

    Ivanti Connect Secure and PAN-OS GlobalProtect were both exploited in 2024, and GlobalProtect had another authentication bypass in 2026. Adding an AI management plane to the same appliances adds attack surface.

  5. 05

    Audit gaps when agents act

    Regulators and auditors will ask who approved a change. Every agent action needs a trace that links intent, the approving human, the agent identity and the exact diff applied.

Who is building agentic firewall and network security?

Incumbents adding agents vs agent-native entrants. Capability lines are checked against each vendor's own site.

Incumbents

  • Cortex AgentiX includes a Network Security Agent for threat response, policy control and network management across its own and third-party firewalls, with human approval for impactful actions.

    Checked Oct 9, 2026Compare

  • Agentic Network Security Orchestration turns intent into multi-vendor firewall policy and tightens unused access; Policy Auditor and Policy Insights are available, Playblocks agents are in early availability.

    Checked Oct 9, 2026Compare

  • FortiAI-Assist and FortiOS 8.0 agents provide conversational troubleshooting and configuration for FortiGate and SD-WAN, and identify MCP and A2A traffic.

    Checked Oct 9, 2026Compare

  • Cisco ↗being verified

    AgenticOps with AI Canvas and Cloud Control for cross-domain troubleshooting; firewall agentic troubleshooting and PCI DSS compliance checks were announced for Security Cloud Control.

    Checked Oct 9, 2026Compare

  • ZAgent framework lets administrators configure and troubleshoot Zero Trust SASE through natural-language prompts, with agents such as a ZDX root-cause agent.

    Checked Oct 9, 2026Compare

  • Agentic Threat Prevention predicts likely attack paths per customer and enforces tailored protections; Agentic CVE Mitigation applies protections for new CVEs, in as little as 45 minutes by Cato's account.

    Checked Oct 9, 2026Compare

  • Algo, an AI assistant connected to the AlgoSec platform, answers policy questions and creates change requests through FireFlow; version 2.0 is in tech preview.

    Checked Oct 9, 2026

Agent-native

  • Founded by Palo Alto Networks founder Nir Zuk to build AI-native, agentic security that runs fully on-premises; announced with a $45M seed in March 2026, not yet generally available.

    Checked Oct 9, 2026

Side-by-side comparisons: Top 5 NGFW (Next-Generation Firewall) Platforms of 2026: Palo Alto vs Fortinet vs Check Point vs Cisco vs Juniper, Top 5 SASE Platforms for 2026: Zscaler vs Palo Alto vs Netskope vs Cato vs Cisco.

Questions people ask

How is AI changing firewall management?

AI moved from copilots that explain rules (2024) to agents that draft rules from business intent, find unused access in live traffic, troubleshoot blocked traffic and apply virtual patches. Palo Alto Networks, Check Point, Fortinet, Cisco, Zscaler and Cato all ship or have announced such agents, with human approval on high-impact changes.

Will AI agents replace firewall administrators?

Not soon. They replace the typing and much of the analysis, so fewer people implement change tickets. The remaining work shifts to writing intent, setting guardrails, approving consequential changes and owning the agents' own access. Teams get smaller and more senior rather than disappearing.

Can an AI agent safely change firewall rules on its own?

For narrow, reversible changes such as tightening unused access or applying a virtual patch, yes, with an audit trail and rollback. New internet exposure, crown-jewel segments and anything that widens the agent's own permissions should still need a human approval.

Is SASE replacing the traditional firewall?

For users and branch traffic, largely yes: SASE combines SD-WAN, secure web gateway, CASB, firewall as a service and ZTNA in the cloud, a term Gartner coined in 2019. Data centers and cloud workloads still run NGFWs, so most enterprises operate both.

What happened to the corporate VPN?

It is being replaced by ZTNA and identity-aware access because VPN appliances grant broad network access and sit exposed on the internet. Exploited flaws in Ivanti Connect Secure and PAN-OS GlobalProtect in 2024 made the case for retiring them faster.

What is an agentic firewall?

It is a firewall or policy platform where AI agents take actions, not just give advice: compiling intent into rules, tightening policy, troubleshooting and applying protections, inside guardrails. Check Point's Agentic Network Security Orchestration and Palo Alto's AgentiX Network Security Agent are two current examples.

What are the biggest risks of AI agents in network security?

The agent becomes a highly privileged identity, so a stolen or manipulated agent can open the network. Prompt injection through tickets or logs, wrong rules pushed at machine speed, and missing audit trails are the other main risks. Scope, short-lived credentials and human approval gates address them.

Sources

  1. Brief History of Check Point Firewalls (Check Point CheckMates), accessed Oct 9, 2026
  2. Cisco ASA (Wikipedia), accessed Oct 9, 2026
  3. Palo Alto Networks Form S-1/A (SEC), accessed Oct 9, 2026
  4. Zscaler (Wikipedia), accessed Oct 9, 2026
  5. No More Chewy Centers: Introducing The Zero Trust Model Of Information Security (Forrester), accessed Oct 9, 2026
  6. BeyondCorp: A New Approach to Enterprise Security (USENIX ;login:), accessed Oct 9, 2026
  7. What is SASE? (Fierce Network), accessed Oct 9, 2026
  8. NIST SP 800-207 Zero Trust Architecture, accessed Oct 9, 2026
  9. ED 24-01: Mitigate Ivanti Connect Secure and Ivanti Policy Secure Vulnerabilities (CISA), accessed Oct 9, 2026
  10. PAN-OS GlobalProtect zero-day CVE-2024-3400 actively exploited (Centre for Cybersecurity Belgium), accessed Oct 9, 2026
  11. Check Point debuts AI Copilot to streamline and automate cybersecurity management (SDxCentral), accessed Oct 9, 2026
  12. Fortinet embeds new AI tools across its cybersecurity and networking portfolio (SiliconANGLE), accessed Oct 9, 2026
  13. Palo Alto Networks Delivers More Autonomous Cybersecurity through Copilots, accessed Oct 9, 2026
  14. Cisco Hypershield: A New Era of Distributed, AI-Native Security (Cisco), accessed Oct 9, 2026
  15. Fortinet unveils FortiAI innovations enhancing threat protection and security operations (Help Net Security), accessed Oct 9, 2026
  16. Fortinet Introduces FortiOS 8.0, accessed Oct 9, 2026
  17. Announcing Cisco AI Canvas: Revolutionizing IT with AgenticOps (Cisco Newsroom), accessed Oct 9, 2026
  18. Cisco Cloud Control US general availability (Cisco Blogs), accessed Oct 9, 2026
  19. Palo Alto Networks Unveils Cortex AgentiX, accessed Oct 9, 2026
  20. Palo Alto Networks completes acquisition of CyberArk, Form 8-K exhibit 99.1 (SEC), accessed Oct 9, 2026
  21. Check Point Launches Agentic Network Security Orchestration Platform, accessed Oct 9, 2026
  22. Zscaler Redefines Zero Trust SASE for the AI Era, accessed Oct 9, 2026
  23. Cato Networks Launches Agentic Threat Prevention, accessed Oct 9, 2026
  24. Cato Networks Sets New Benchmark, Cutting Time-to-Protect to 45 Minutes with Full Agentic CVE Mitigation, accessed Oct 9, 2026
  25. Algo AI assistant (AlgoSec), accessed Oct 9, 2026
  26. Introducing Cylake: AI-Native Cybersecurity with Total Data Sovereignty (Greylock), accessed Oct 9, 2026
  27. Cylake: $45 Million Seed Raised For AI-Native Cybersecurity Platform (Pulse 2.0), accessed Oct 9, 2026

Published Oct 9, 2026. Last verified Oct 9, 2026. Eras 4 and 5, vendors, and scores are re-checked every six to eight weeks; see the changelog and methodology.