October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Check Point Completed Its Lakera Acquisition: What It Means for Enterprise AI Security

Check Point completed its Lakera acquisition in October 2025. Here is what Lakera contributes to AI and agent security, what the $190 million figure means and what enterprise buyers should verify.
From TheFinanceBase Team6 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check Point Software Technologies announced its Lakera acquisition on September 16, 2025, and completed it on October 22, 2025. Check Point later reported approximately $190 million in net cash consideration. The transaction adds Lakera’s AI-application and AI-agent security technology to Check Point’s wider security platform; it is no longer a pending deal.

The deal at a glance

Item Verified detail
Buyer Check Point Software Technologies Ltd.
Target Lakera, an AI-native security company
Announcement September 16, 2025
Closing October 22, 2025
Reported consideration Approximately $190 million in net cash
Lakera locations Zurich and San Francisco
Strategic purpose Add specialized protection for AI applications, agents and model interactions

Check Point initially said the transaction was expected to close in the fourth quarter of 2025, subject to customary conditions. Its subsequent third-quarter results confirmed the October 22 closing. The company’s fourth-quarter and full-year results reported approximately $190 million of net cash consideration. That figure is an acquisition cost, not a customer subscription price.

The original announcement is available from Check Point.

Who Lakera was and what it built

Lakera presented itself as an AI-first security company rather than a conventional security vendor adding an AI feature. Founded in Zurich with a San Francisco presence, the company described a founding team with experience associated with Google and Meta. Its stated approach combined pre-deployment assessment, runtime controls and continuous adversarial testing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Its research program included the Gandalf adversarial-testing network. Check Point’s announcement referred to Lakera’s flagship products as Lakera Guard and Lakera Red. It also described post-acquisition offerings as Check Point AI Agent Security and Check Point AI Red Teaming. Those descriptions indicate integration and possible rebranding; they do not establish that the former product names, pricing or standalone purchasing options remain unchanged in 2026.

What technology Lakera adds

Runtime protection

Lakera’s technology was described as inspecting and enforcing policy around the interaction layer of an AI system, including:

  • LLM prompts and outputs
  • Prompt-injection attempts and harmful content
  • Sensitive-data leakage
  • Retrieval-augmented generation (RAG) data flows
  • Model Context Protocol (MCP) server interactions
  • AI-agent tool calls and multimodal workflows
  • Organization-specific guardrails and policy decisions

This is different from securing only the servers, endpoints or network carrying an AI application. A control at this layer can block, redact, allow, quarantine or alert on a request while the application is operating.

Pre-deployment testing

The offering also included AI posture assessment and red teaming before release. Adversarial testing can probe jailbreaks, prompt attacks and model-manipulation scenarios so developers can address weaknesses before users encounter them. Gandalf was described as maintaining a continuously updated attack corpus.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Three separate security jobs

Buyers should distinguish among:

  1. Pre-deployment evaluation: finding weaknesses before an application or model is released.
  2. Runtime enforcement: blocking or flagging activity as prompts, retrievals, outputs or tool calls occur.
  3. Monitoring and response: investigating detections, correlating events and improving policy after deployment.

Check Point attributed all three categories to the combined platform, but the announcement does not independently prove the effectiveness of every control in production environments.

Why Check Point wanted Lakera

Filling an interaction-layer gap

Check Point already marketed AI-related controls through products such as GenAI Protect, SaaS and API security, data-loss prevention and machine-learning protections for applications, cloud systems and endpoints. Lakera supplied more specialized controls for what happens inside an AI application: the instructions it receives, information it retrieves, actions it takes and content it returns.

Traditional network, endpoint and cloud controls do not automatically understand prompt injection, RAG poisoning, unsafe model behavior or an agent’s tool call. Those events can occur inside an otherwise permitted application session.

Platform consolidation

Check Point said Lakera would form the foundation of its Global Center of Excellence for AI Security and be integrated with the Check Point Infinity architecture. For an existing Check Point customer, one platform can simplify procurement, telemetry, policy administration and security-operations workflows. The trade-off is possible dependence on a large vendor where a specialist or cloud-neutral product might offer more portability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check Point’s strategic explanation is set out in its AI-security blog post.

Threats the combined offering targets

  • Prompt injection: instructions designed to make a model ignore its intended rules or disclose information.
  • Indirect prompt injection: malicious instructions hidden in webpages, emails, documents or other retrieved data.
  • Data leakage: sensitive information exposed through prompts, outputs, retrieval pipelines, logs or tool calls.
  • Model manipulation: attempts to produce unsafe, inaccurate or unauthorized behavior.
  • RAG poisoning: compromised retrieval content that influences a model’s response.
  • Agentic risk: an AI agent using tools, APIs or external systems beyond the user’s authorization.
  • MCP risk: weaknesses in connections between models, tools and MCP servers.
  • Policy and content violations: interactions that conflict with legal, safety or organizational rules.
  • Multimodal attacks: attacks combining text, images, audio, files or other input types.

Runtime inspection is not a complete AI-security program. It does not by itself fix compromised cloud accounts, excessive IAM permissions, insecure APIs or plugins, poisoned training data, vulnerable dependencies, weak data governance or a missing human-approval process.

What the performance numbers mean

Check Point’s acquisition announcement attributed these figures to the Lakera platform:

Claim Qualification
Detection Above 98%; vendor-provided, with no benchmark methodology specified in the announcement
Latency Below 50 milliseconds; test conditions and whether this is end-to-end production latency were not specified
False positives Below 0.5%; results can vary with policy strictness, workload, language and traffic mix
Language support More than 100 languages; coverage and parity by language were not detailed
Adversarial patterns More than 80 million associated with Gandalf; volume alone does not prove coverage of novel attacks

These are vendor claims, not an independent industry benchmark. A buyer should request the datasets, attack categories, model families, sampling methods and definitions of detection and false positive. A low inline-processing time may not include network hops, logging, policy evaluation and remediation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What changes for Check Point customers

The confirmed changes are organizational and strategic: Lakera’s technology is being integrated into Check Point’s Infinity architecture, and Check Point described AI Red Teaming and AI Agent Security offerings. The available transaction sources do not provide a complete 2026 account of pricing, packaging, regional availability, APIs, migration terms or support for every former Lakera customer.

Existing Check Point customers may value consolidated contracts and integration with their security operations. Organizations running multiple clouds, self-hosted models or a mixed security stack should verify whether enforcement can operate independently of Check Point infrastructure and whether data can be exported to existing SIEM, SOAR, DLP and IAM workflows.

How the deal fits the market

The acquisition came during a broader wave of security consolidation around AI applications and agents. 2025 coverage also discussed F5’s planned CalypsoAI acquisition and CrowdStrike’s planned Pangea acquisition, alongside cloud and security vendors adding controls for models and agents. Infosecurity Magazine and CRN covered that competitive context.

The market is moving from treating AI as a feature inside an existing security product toward dedicated controls for AI applications and autonomous actions. Check Point’s “end-to-end” and “first” descriptions are company positioning, not independently established rankings. Buyers should compare architecture and evidence rather than assume that an acquisition creates the industry’s most complete platform.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Buyer checklist for evaluating AI security

  1. Locate enforcement. Is the control deployed at an API gateway, application middleware, model-serving layer, agent tool boundary or endpoint?
  2. Map visibility. Confirm coverage for prompts, outputs, RAG documents, tool calls, MCP traffic, training data and model-to-model interactions.
  3. Test policy control. Check support for sensitive-data rules, regional languages, approval workflows, agent permissions and human-review thresholds.
  4. Define failure behavior. Determine whether a violation is blocked, redacted, replaced with a safe completion, quarantined or merely alerted.
  5. Demand reproducible metrics. Measure attack recall, false positives, false negatives, added latency, throughput and evasion resistance by model and language.
  6. Check portability. Test multiple clouds, self-hosted and open-source models, SaaS AI tools and private data centers if those are in scope.
  7. Integrate operations. Validate SIEM, SOAR, DLP, IAM, API-security and incident-response connections.
  8. Review data handling. Establish whether prompts, outputs, retrieved documents, identifiers and red-team payloads are retained, where they are stored and who can access them.
  9. Assess compliance terms. Review residency, encryption, retention, subprocessors, audit rights and regulatory support.

Also test failure modes that a demonstration can hide: an agent calling an unmonitored tool path, poisoned RAG content with no provenance check, excessive permissions, a model update that invalidates earlier testing, weaker multilingual or multimodal coverage, and logs that retain sensitive prompts longer than policy permits.

What remains unproven

  • Whether the claimed detection, latency and false-positive figures hold across a buyer’s models, languages and traffic.
  • Whether product integration improves measurable security outcomes for existing Check Point customers.
  • Whether Lakera Guard and Lakera Red remain separately available under those names.
  • Current customer pricing, packaging, usage limits, customer numbers, revenue and post-close retention.
  • How effectively runtime controls address multi-step agent behavior rather than isolated malicious prompts.

The acquisition is strategically significant, but its practical value will depend on integration quality, transparent testing, production coverage, portability, privacy terms and customer results—not the announcement alone.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.