Security1 publisher2 min readPublished
Palo Alto bets a reported $400M that the endpoint threat now arrives with valid credentials
Palo Alto Networks is folding the startup Koi into Prisma AIRS and Cortex XDR to watch agents that run on a user's own credentials. The announcement names no incident, and Globes reported the price near $400 million.
The Watch · Security desk

What happened
- Palo Alto Networks said Tuesday it plans to buy the startup Koi, framing the deal around security risks emerging as organisations adopt agentic AI.
- Terms were not disclosed, and the Israeli business outlet Globes reported that Palo Alto will pay approximately $400 million.
- It is Palo Alto's second AI-focused acquisition in six months, after the $3.35 billion Chronosphere observability deal announced in November.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure An agent operating on a user's credentials sits inside the trust boundary endpoint tooling was built to defend, so the population newly at risk is whoever already authorised the agent.
- constraint Palo Alto supplies the argument and no case file, so a buyer cannot size the exposure from the announcement and has to measure agent privileges in their own estate first.
- decision Cortex XDR customers now face a procurement choice about whether agent governance belongs inside their endpoint contract at all, and Palo Alto has priced its own answer.
- precedent The reported price gives the next agent-security startup a benchmark to negotiate against, in a market where the large security vendors are already buying AI-focused companies.
The threat model in the announcement is legitimate software that turns dangerous once it is compromised, misconfigured or abused [5]. Palo Alto's case is that agentic tools act with broad privileges, interact with multiple systems and move data in ways older security products were not designed to monitor [3]. Endpoint protection spent years detecting malicious files and stopping known malware techniques [4]. The agent described here operates using a user's credentials and takes actions on that user's behalf, and it may do so automatically and at speed [6].
Lee Klarich, Palo Alto's chief product and technology officer, said "AI agents and tools are the ultimate insiders" [7]. "They have full access to your systems and data, but operate entirely outside the view of traditional security controls," Klarich said [8].
The argument comes without a case. The announcement names no intrusion, no CVE and no threat actor, and it offers no telemetry on how many agents run in an enterprise or with which privileges [16]. CyberScoop read the language as an attempt to define a new product category while enterprises are still deciding how to govern AI tools spreading through developer workflows and everyday office software [15].
On price, Globes reported approximately $400 million; Palo Alto did not disclose terms [2]. In November the company said it would buy the AI-focused observability firm Chronosphere for $3.35 billion, and Koi is its second AI-focused deal in six months [11]. The Chronosphere price is about 8.4 times the figure reported for Koi [12]. CyberScoop places both inside a run of larger security companies buying AI-focused startups [14].
Koi's technology is to be integrated into the Prisma AIRS AI security platform and to enhance Cortex XDR, with the stated goal of better visibility into AI-driven activity on endpoints [9]. Palo Alto and Koi describe the approach as "Agentic Endpoint Security", built on visibility into AI-related software, continuous risk analysis and real-time policy enforcement [10]. Klarich framed the outcome as "ensuring that every agent, plugin, and script is governed, verified, and secure" [13]. The announcement gives no closing date, no regulatory step and no availability date for any of it [17].
What to watch
- A closing date or regulatory filing that confirms or corrects the roughly $400 million figure Globes reported.
- Whether Cortex XDR release notes ship agent inventory and real-time policy enforcement as controls a customer can actually enforce, and when.
- A documented case of an agent acting on a user's credentials during an intrusion, which would move this from argument to evidence.