* [Blog](https://origin-researchcenter.paloaltonetworks.com/blog) * [Palo Alto Networks](https://origin-researchcenter.paloaltonetworks.com/blog/corporate/) * [AI Security](https://origin-researchcenter.paloaltonetworks.com/blog/category/ai-security/) * Solving the AI Black Box ... # Solving the AI Black Box Problem with Prisma AIRS 2.0 [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2F2025%2F11%2Fai-black-box-problem-prisma-airs-2-0%2F) [](https://twitter.com/share?text=Solving+the+AI+Black+Box+Problem+with+Prisma+AIRS+2.0&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2F2025%2F11%2Fai-black-box-problem-prisma-airs-2-0%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2F2025%2F11%2Fai-black-box-problem-prisma-airs-2-0%2F&title=Solving+the+AI+Black+Box+Problem+with+Prisma+AIRS+2.0&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://origin-researchcenter.paloaltonetworks.com/blog/2025/11/ai-black-box-problem-prisma-airs-2-0/&ts=markdown) \[\](mailto:?subject=Solving the AI Black Box Problem with Prisma AIRS 2.0) Link copied By [Sailesh Mishra](https://www.paloaltonetworks.com/blog/author/sailesh-mishra/?ts=markdown "Posts by Sailesh Mishra") and [Jaimin Patel](https://www.paloaltonetworks.com/blog/author/jaimin-patel/?ts=markdown "Posts by Jaimin Patel") Nov 05, 2025 7 minutes [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown) [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown) [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [black box](https://www.paloaltonetworks.com/blog/tag/black-box/?ts=markdown) [Prisma AIRS](https://www.paloaltonetworks.com/blog/tag/prisma-airs/?ts=markdown) AI is driving the future by allowing for rapid innovation at an unprecedented scale to gain competitive advantage. Organizations have already made the movement from being "AI curious" to "AI forward." But this speed comes with the infamous "AI black box" problem. How do you successfully build and deploy your offerings that are based on AI models whose risks are based on deep embedded logic and nondeterministic behavior? Trust becomes an important catalyst to speed. Your ability to move with speed and absolute trust demands a robust, continuous security strategy. ## Discover, Assess, Protect as Part of the AI Security Lifecycle Your success in the AI race depends on addressing the security challenge proactively. We champion a simple, three-phase framework for AI Security, designed to empower you to deploy AI bravely: **Discover, Assess and Protect.** 1. **Discover:** You cannot assess the risk of what you cannot see. You must have a comprehensive, real-time inventory of all AI models, inference datasets, applications and AI agents across your entire enterprise to understand your full attack surface. 2. **Assess:** You cannot protect against the risks you have not identified. Confidence in the world of AI starts with thorough, scalable and contextual assessments of both the model artifact and its runtime behavior. 3. **Protect:** Finally, you must use these insights to deploy actionable security controls that neutralize threats and help maintain compliance across your ecosystem. ##### [***Prisma AIRS 2.0***](https://www.paloaltonetworks.com/blog/2025/10/prisma-airs-powering-secure-ai-innovation/)***is the unified platform that, along with a thorough discovery and a robust runtime protection, delivers the critical second pillar, the quintessential comprehensive assessment capability you need to move forward.*** ## The Dual Challenges of AI Risk Assessment The core challenge in AI security is the infamous "black box" problem. Traditional security operates by looking for known signatures and predictable execution paths, like a specific file hash or a buffer overflow attempt. AI systems are fundamentally different; their risks are based on hidden logic vulnerabilities (flaws in the training data or architecture) and response behaviors (unintended, harmful outputs). Traditional security would treat an AI model as a static asset, ignoring the fact that its greatest risks lie within its complex, embedded logic, and in the case of generative models, their nondeterministic behavior. This is why a dedicated AI security assessment capability is essential. Effective AI assessments must therefore solve for two distinct, yet interconnected, layers of risk: 1. AI Model Security: Securing the integrity of the model artifact itself, which comprises the entire AI supply chain, from training data to compiled weights. 2. [AI Red Teaming](https://www.paloaltonetworks.com/cyberpedia/what-is-ai-red-teaming): Securing the *behavior* of the model or app in its deployed context, addressing the immediate runtime [exposure to adversarial inputs](https://www.paloaltonetworks.com/cyberpedia/what-are-adversarial-attacks-on-AI-Machine-Learning). Prisma AIRS^®^, as a unified solution, delivers these capabilities and more, giving CIOs an actionable overview of their AI risk posture, from the core artifact to the live application behavior. ## AI Model Security Protects the AI Supply Chain, One Model at a Time Your AI models are now among your most valuable pieces of intellectual property, often representing millions of dollars in investment and years of proprietary data curation. However, the modern MLOps workflow often relies heavily on third-party and open-source models, which is a necessary speed multiplier that simultaneously creates supply chain vulnerabilities on an unprecedented scale. ### The Risk of a Malicious AI Model A model imported from a public repository or a partner may harbor hidden threats that can lead to major security incidents. This can range from embedded malware and Trojan models to hidden backdoors that facilitate IP exfiltration or allow an attacker to gain arbitrary code execution once the model is loaded into your sensitive environment. If your model's integrity is compromised, everything built on top of it is fundamentally flawed. ### Prisma AIRS AI Model Security Prisma AIRS delivers AI Model Security by moving inspection left, into the CI/CD pipeline and model registry. It is purpose-built to look deep inside the model artifact, inspecting the complex structure of the model weights, metadata and dependencies of over 35 model formats (including PyTorch, TensorFlow, Keras, etc.) for architectural weaknesses and explicit threats. **Verified Provenance and Threat Intelligence:** Prisma AIRS AI Model Security provides critical, curated intelligence, leveraging the collective power of [Unit 42](https://unit42.paloaltonetworks.com/) and the 19,000+ members of [Huntr](https://huntr.com/) community. Prisma AIRS goes beyond file scanning to check the provenance and integrity of open-source components, dependencies and complex data formats that often travel alongside the model, flagging components associated with known AI-specific vulnerabilities. ![Screenshot of Prisma AIRS Model Security Scans.](https://www.paloaltonetworks.com/blog/wp-content/uploads/2025/11/2025-10-model-security-scans-png.png) Prisma AIRS AI Model Security, by way of this deep integration and predeployment inspection, is designed to ensure the integrity of the core model asset before it reaches production, thereby neutralizing threats that traditional code and vulnerability scanners would inevitably miss. ##### ***Don't fall into the Guardrail Trap:*** [***Watch our latest webinar***](https://www.paloaltonetworks.com/engage/prisma-airs-webinar/4mmuoo9)***to learn about the risks you can face if an AI model within your AI ecosystem has hidden vulnerabilities.*** ## AI Red Teaming Is Turning Behavioral Risks Into Actionable Governance Even a perfectly clean, validated model artifact can be exploited through [prompt injection](https://www.paloaltonetworks.com/cyberpedia/what-is-a-prompt-injection-attack) or [behavioral manipulation](https://www.paloaltonetworks.com/cyberpedia/what-is-ai-prompt-security) once it is deployed. The speed of AI development and adoption requires continuous, scalable testing. Unfortunately, manual red teaming exercises are slow, expensive and quickly become outdated against the ever-evolving threats targeting AI systems. Human testers simply cannot generate the volume and variety of adversarial examples required to secure continuous delivery pipelines. ### The Risk of Malignant AI Behavior Behavioral risks, where an AI produces harmful, illegal or toxic outputs, are among the highest-impact that threat executives must manage. These failures can arise from sophisticated jailbreaks and insecure output handling that return malicious code or denial-of-service vectors. Because [large language models](https://www.paloaltonetworks.com/cyberpedia/what-is-llm-security) are nondeterministic, rare edge cases can and will occur even under normal usage. Left unchecked, they expose the organization to financial loss, data leakage, regulatory fines and severe reputational damage. That's why continuous, systematic red teaming (testing both intended workflows and adversarial edge cases) is essential. ### Autonomous, Context-Aware AI Red Teaming Prisma AIRS automates this critical function, providing continuous security testing that scales with your deployment velocity. This is security at the speed of AI. * **Dynamic Attack Simulation:** Prisma AIRS AI Red Teaming deploys a dynamic, conversational AI Red Teaming Agent that mimics the behavior of a real-world attacker. The agent adapts its attacks based on the application's response, using combinations of advanced techniques like obfuscation, role playing and attempted system prompt extraction to truly stress test the system's defensibility. * **Comprehensive, Contextual Coverage:** The platform executes over 500 distinct, real-world attack scenarios, including data exfiltration, generating harmful content and manipulating system prompts. Crucially, these scenarios can be customized to the application's business context to provide meaningful and high-fidelity insights. * **Governance and Actionability:** Prisma AIRS AI Red Teaming provides an aggregated, CIO-friendly risk score and findings report for your entire AI application portfolio -- a single, quantifiable metric for the board. Furthermore, every discovered vulnerability is mapped directly to key governance frameworks, including the [OWASP Top 10 for LLMs](https://www.paloaltonetworks.com/resources/infographics/llm-applications-owasp-10) and the [NIST AI Risk Management Framework](https://www.paloaltonetworks.com/cyberpedia/nist-ai-risk-management-framework). This mapping is vital, as it allows security teams to demonstrate auditable compliance. ![Screenshot of AI Red Teaming with Prisma AIRS.](https://www.paloaltonetworks.com/blog/wp-content/uploads/2025/11/screenshot-2025-10-17-at-7-44-47-pm-png.png) AI Red Teaming with Prisma AIRS delivers an auditable, prioritized list of vulnerabilities that AI teams can focus on. Faster and more proactive identification can aid in faster remediation, thereby enabling organizations to demonstrate trust to regulators and customers. ##### ***Red Team Your Systems Before Attackers Do:*** [***Watch the webinar***](https://www.paloaltonetworks.com/engage/prisma-airs-webinar/41duztd)***to find out why AI red teaming is an essential part of securing your AI deployments.*** ## Converting Uncertainty to Measurable Confidence Executives across every industry are pushing their teams to move from curiosity to full-scale deployment, and the winners of this AI race will be those who move with speed and with absolute trust. However, pursuing AI innovation without a foundational security strategy is simply accepting unacceptable financial and reputational debt. Stitching together point solutions is only a short-term fix. By delivering AI Model Security and AI Red Teaming in a single unified platform, [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security) is designed to be an effective answer to the AI black box problem, turning uncertainty into measurable confidence at scale. Secure your AI foundation. Secure your future. [Deploy Bravely](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security#demo). [*Contact us today*](https://www.paloaltonetworks.com/company/contact-sales#contact:~:text=Fill%20out%20the%20form%20to%20get%20in%20touch%20with%20our%20Sales%20Team)*to learn more about how Prisma AIRS can help you solve the AI Black Box problem.* *** ** * ** *** ## Related Blogs ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Partners](https://www.paloaltonetworks.com/blog/category/partners/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### The Power of Glean and Prisma AIRS Integration](https://origin-researchcenter.paloaltonetworks.com/blog/2026/02/power-of-glean-and-prisma-airs-integration/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Partners](https://www.paloaltonetworks.com/blog/category/partners/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Prisma AIRS Integrates Microsoft Foundry for Comprehensive AI Security](https://origin-researchcenter.paloaltonetworks.com/blog/2025/11/prisma-airs-integrates-azure-ai-foundry/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Ignite](https://www.paloaltonetworks.com/blog/category/ignite/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Prisma AIRS 2.0 Is Powering the Next Wave of Secure AI Innovation](https://origin-researchcenter.paloaltonetworks.com/blog/2025/10/prisma-airs-powering-secure-ai-innovation/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Event](https://www.paloaltonetworks.com/blog/category/event/?ts=markdown), [Partners](https://www.paloaltonetworks.com/blog/category/partners/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Securing the Future of AI](https://origin-researchcenter.paloaltonetworks.com/blog/2025/09/securing-the-future-of-ai/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Firewall](https://www.paloaltonetworks.com/blog/category/firewall/?ts=markdown), [Next-Generation Firewalls](https://www.paloaltonetworks.com/blog/category/next-generation-firewalls/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Securing AI Agent Innovation with Prisma AIRS MCP Server](https://origin-researchcenter.paloaltonetworks.com/blog/2025/06/securing-ai-agent-innovation-prisma-airs-mcp-server/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Securing the Agentic Endpoint](https://origin-researchcenter.paloaltonetworks.com/blog/2026/02/securing-the-agentic-endpoint/) ### Subscribe to the Blog! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://origin-researchcenter.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} ## Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/precision-ai-security/secure-ai-by-design?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) ## Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) ## Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language