Check Point converts installed firewalls into AI enforcement points as shadow AI spreads across enterprise networks

Check Point Software Technologies announced on Monday the Check Point AI Network Firewall, a capability delivered inside firewall software release R82.20 that gives security teams visibility and control over AI use by employees, applications and autonomous agents without additional infrastructure. The company said the protection runs from the physical and virtual firewalls customers already operate and scales across branches, data centres, cloud and multi-cloud environments, which removes the parallel deployment that competing approaches require.

The commercial logic rests on a claim about where AI traffic actually travels. Prompts, model calls and agent actions all traverse the corporate network, yet the appliances inspecting that network were designed for a period when application traffic was predictable and machine-generated conversation did not exist as a category.

"AI is transforming the enterprise network, and with the AI Network Firewall, we are transforming the firewall to secure it," said Nataly Kremer, Chief Product Officer at Check Point Software Technologies. "The network is where every prompt, model call, and agent interaction already converges, yet traditional firewalls were never built to see or govern that activity. By bringing AI security into the firewall organisations already run, we give security teams the visibility and control to enable AI adoption safely, in real time."

Enforcement at the existing perimeter answers a consolidation problem the security market created for itself

Enterprise security teams have spent three years accumulating point solutions for AI governance, each with its own console, policy language and telemetry format, and the operational cost of that accumulation has become the constraint on adoption rather than the technology itself. Check Point’s approach treats the installed firewall base as the distribution advantage, converting existing capital expenditure into AI coverage rather than asking buyers to fund a second architecture alongside the first.

Analyst commentary accompanying the announcement identified the same pressure. "Organisations are challenged to deploy dedicated AI security solutions, which are additive to their existing security architecture, contributing to the sprawl of disjointed, siloed security tools and agents," said Pete Finalle, Research Manager, Trusted Access and Network Security at IDC. "While rare, the native integration of AI security across existing enforcement points provides improvements to visibility, telemetry effectiveness, security posture, and management simplicity."

Check Point Research’s AI Security Report 2026 found that between 87% and 93% of organisations experience at least one high-risk generative AI interaction every month, and the proportion of prompts carrying sensitive corporate, personal or regulated data doubled over a year to one in every 25 interactions. The same research recorded an average of 10 AI applications running per organisation each month, a substantial share of them outside any formal procurement or review process.

The agent layer shows comparable weakness. Check Point Research reviewed 10,000 Model Context Protocol servers and identified security weaknesses in 40% of them, while separate work catalogued 15,300 indirect prompt injection payloads planted across public web pages, roughly 70% of which were concealed in page elements no human reader ever sees. Those figures describe an attack surface that grows with every tool an employee connects, which explains why the vendor has separated its coverage into employee AI use, MCP tooling and inline protection for applications and large language models against prompt injection and adversarial inputs.

Unified policy across hybrid estates is becoming the competitive battleground in network security

The AI Network Firewall becomes part of Check Point’s AI Defense Plane, the unified control plane the company uses to discover, govern and protect AI activity across network, endpoint, cloud, applications and APIs, with enforcement points spanning a standalone API for self-managed applications, endpoint agents, a containerised firewall for AI data centres and a web application firewall. Alongside the announcement, Check Point extended central policy management to its SASE and SD-WAN products, with zero-trust enforcement reaching IT, OT and micro-segmentation tools including Illumio, so that on-premises firewalls, cloud firewalls, AWS native firewalls, SD-WAN and SASE sit behind a single console and a single audit trail.

That consolidation targets a workflow problem senior operators recognise, since connectivity and security policy have historically been managed in separate tools by separate teams, generating reconciliation work whenever the environment changes. Open-platform integrations are intended to keep rules current automatically as infrastructure shifts underneath them.

"Policy alone will not solve shadow AI. Employees will continue using AI tools to move faster, often before security teams know those tools are present," said Chris Konrad, Vice President, Global Cyber at World Wide Technology. "Organisations need to understand which AI applications, agents, and MCP servers are interacting with their environment, and they must have the means to intercept or block unauthorised traffic. Integrating both AI visibility and active enforcement into the enterprise firewall is a practical approach because it builds on infrastructure organisations already operate and trust. That gives teams a control point to govern usage and reduce risk without slowing innovation."

For the wider security sector, the release signals that AI governance is being absorbed into the network layer rather than sustained as a standalone product category, which pressures the specialist vendors who built businesses on AI-specific gateways and gives incumbents with large installed bases a structural advantage in the next buying cycle.

Sindhu V Kashyap

Global Technology Journalist & Multimedia Storyteller | Covering Founders, Investors & Leaders Reshaping Tech | Writer · Interviewer · Moderator · Editor

Previous
Previous

Cloudflare's Q2 outage data traces connectivity failure from Guam's typhoon to a broken German signing key

Next
Next

9 days, 2 confessions: how OpenAI, Anthropic, and Hugging Face changed what a rogue AI agent means