DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Palo Alto Networks Completes Koi Acquisition: What Its Agentic Endpoint Security Means

Palo Alto Networks’ completed Koi deal adds endpoint-focused AI-software security to its product strategy. Here’s what the acquisition changes, what it cost, and what remains unclear for buyers.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Palo Alto Networks completed its acquisition of Koi Security on April 14, 2026, adding endpoint-focused AI-software security capabilities it plans to integrate with Prisma AIRS and Cortex XDR. The company disclosed $231 million in purchase consideration, substantially all cash, plus $61 million in replacement equity awards tied to future employee services. The deal gives Palo Alto Networks a way to extend its AI-security strategy to software and agents running on endpoints—but it does not, by itself, secure every AI system or settle what “agentic endpoint security” should include.

What happened in the Koi acquisition?

Palo Alto Networks announced a definitive agreement to acquire Koi Security on February 17, 2026, and said the acquisition had closed on April 14, 2026. The company described Koi as a privately held endpoint-posture company and said its technology would be integrated with Prisma AIRS and Cortex XDR. Palo Alto Networks’ announcement and closing announcement establish the transaction timeline.

A June 29, 2026 product brief describes Koi Agentic Endpoint Security as available both as a standalone solution and as an integrated module within Cortex XDR and Prisma AIRS. That is a public availability signal, not a complete feature, licensing, or platform-support matrix. The product brief does not establish that every capability is included with every edition or customer contract.

What Koi Security does

Koi is not best understood as a conventional antivirus or generic endpoint detection and response (EDR) vendor. Palo Alto Networks’ filing classifies it as an endpoint-posture management company. Its focus is identifying and assessing software installed or run on enterprise endpoints, including AI applications and coding agents, browser extensions, open-source packages, scripts, local language models, and Model Context Protocol (MCP) components.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
WatchGuard Firebox M290 with 1-yr Basic Security Suite (WGM29000701)
  • Enterprise-grade prevention, detection, correlation and response from the perimeter to the endpoint with our Total Security Suite.
  • Gain critical insights about network security, from anywhere and at any time, with WatchGuard Cloud.
  • Built-in compliance reports, including PCI and HIPAA, mean one-click access to the data you need to ensure compliance requirements are met.
  • Up to 18 Gbps firewall throughput. Turn on all additional security services and still see up to 2.4 Gbps throughput.

Koi says its risk engine, called Wings, correlates signals such as code changes, runtime behavior, ownership changes, update channels, network egress, and installation source. Those factors can help distinguish a tool’s provenance and behavior from its name alone, although the public description does not establish how each signal is implemented in the Palo Alto Networks product. Koi’s platform description outlines the Wings approach.

Why AI agents create an endpoint security concern

An AI agent is software that can use tools or take actions on a user’s behalf. Depending on its configuration and permissions, it may read or write files, call APIs, execute code, install components, interact with other tools, or use credentials granted by a user or administrator. A compromised plugin, altered update channel, overly permissive MCP server, or unsafe agent workflow can therefore turn ordinary endpoint software into a route to sensitive data or systems.

Palo Alto Networks argues that conventional endpoint controls may not provide enough context about agent frameworks, plugins, packages, scripts, extensions, and model artifacts. That is the company’s framing, not proof that all existing EDR products are blind to AI software: endpoint tools can already offer varying degrees of process, application, identity, and network visibility. The question is whether they can inventory relevant AI components, assess their risks, and apply useful controls without disrupting legitimate work.

Rank #2
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

Agent risk is not confined to the endpoint. It also involves identity and permissions, cloud infrastructure, APIs, model and software supply chains, application logic, and data governance. Koi principally strengthens the endpoint layer; it should not be treated as a complete AI-security program.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the security layers differ

  • AI application security: Protecting models, prompts, data, APIs, and AI applications.
  • AI runtime security: Monitoring and controlling AI workloads while they execute.
  • Identity and privilege security: Governing what people, services, and agents can access.
  • Endpoint security: Protecting the devices where AI tools, agents, plugins, and packages run.
  • Software supply-chain security: Assessing packages, dependencies, code, update channels, and provenance.

How Koi fits Prisma AIRS and Cortex XDR

Prisma AIRS

Palo Alto Networks positions Prisma AIRS as its broader AI-security platform, spanning AI applications, models, data, and runtime environments. Koi adds visibility into AI software and autonomous tools installed or operating on endpoints. The intended benefit is a more connected view of enterprise AI activity, but the acquisition does not establish end-to-end protection across every endpoint, cloud workload, model, identity, or API. Coverage will depend on deployment scope, integrations, licensing, telemetry, and configured policies.

Cortex XDR

Palo Alto Networks said Koi would enhance Cortex XDR with visibility into the AI attack surface and support for malware prevention. The later product brief describes Koi Agentic Endpoint Security as an integrated core module within Cortex XDR as well as Prisma AIRS. Public materials do not provide a full account of which controls are available in each product edition, whether a separate license is required, which operating systems are supported, or what endpoint components deployment requires.

Rank #3
WatchGuard Firebox M290 High Availability Firewall
  • Enterprise-grade prevention, detection, correlation and response from the perimeter to the endpoint with our Total Security Suite.
  • Gain critical insights about network security, from anywhere and at any time, with WatchGuard Cloud.
  • Built-in compliance reports, including PCI and HIPAA, mean one-click access to the data you need to ensure compliance requirements are met.
  • Up to 18 Gbps firewall throughput. Turn on all additional security services and still see up to 2.4 Gbps throughput.

Those details matter operationally. Buyers should determine whether the product discovers and inventories software, assigns risk scores, blocks or quarantines tools, detects suspicious activity, or combines those functions. Discovery, risk assessment, prevention, and response are distinct capabilities; evidence of one does not establish the others. Public product materials also do not specify whether the system inspects prompts, source code, model weights, network traffic, or only software posture and behavior.

What “Agentic Endpoint Security” means—and what it does not

Palo Alto Networks is using “Agentic Endpoint Security,” or AES, as a category for visibility and control over autonomous or semi-autonomous AI tools operating on endpoints. Its product brief organizes the offering around three functions: seeing AI software, assessing risks, and controlling the AI ecosystem. The label describes the company’s product positioning; it is not an established independent industry standard.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The underlying problem—unmanaged AI software with access to endpoint resources—is real enough to evaluate. But buyers should separate that problem from the vendor’s category name and ask what the product can demonstrably discover, explain, and control in their environment. A risk score is not proof that a tool is malicious, and the ability to identify a component does not prove that the product can prevent unsafe actions or data loss.

Rank #4
WatchGuard Trade up to WatchGuard Firebox M290 with 3-yr Basic Security Suite
  • Enterprise-grade prevention, detection, correlation and response from the perimeter to the endpoint with our Total Security Suite.
  • Gain critical insights about network security, from anywhere and at any time, with WatchGuard Cloud.
  • Built-in compliance reports, including PCI and HIPAA, mean one-click access to the data you need to ensure compliance requirements are met.
  • Up to 18 Gbps firewall throughput. Turn on all additional security services and still see up to 2.4 Gbps throughput.

What the deal cost

Palo Alto Networks’ filed accounting reports $231 million in total purchase consideration, substantially all cash, plus $61 million in replacement equity awards allocated to future employee services. The equity awards included 0.3 million restricted common shares vesting over three years, according to the company’s Form 10-Q. These figures describe different elements of the transaction; the $61 million in replacement awards should not be conflated with the $231 million purchase consideration. The SEC-hosted filing and Palo Alto Networks’ Form 10-Q provide the accounting details.

Some earlier coverage circulated an approximately $400 million figure. It should not be presented as the final purchase consideration: the company’s later filing reports $231 million in consideration and separately describes replacement awards.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why buy Koi rather than build the capability?

Palo Alto Networks has not publicly provided a detailed build-versus-buy analysis. A reasonable interpretation is that Koi brought specialized endpoint-posture technology focused on AI and agentic software, while Palo Alto Networks could connect it to existing endpoint and AI-security products. That may accelerate productization relative to building the capability internally, but it is an inference, not a disclosed rationale.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
SonicWall TZ370 TotalSecure | 1YR Advanced Edition | TZ370 Gen7 Firewall with 1 Year Advanced Protection Service Suite | Advanced SMB Appliance with SD-WAN and Threat Defense (02-SSC-6819)
  • SonicWall TZ370 with 1 Year APSS - TotalSecure (02-SSC-6819) - Designed for growing SMBs that need more throughput and scalability, delivering multi-gigabit firewall performance with best-in-class price to performance.
  • Advanced Protection Service Suite (APSS) offers next-generation security combining Gateway AV, IPS, Application Control, Content Filtering, 24×7 Support, Capture ATP sandboxing, and RTDMI. Protects against ransomware, zero-day exploits, and encrypted attacks with multi-layered threat prevention and scalable, enterprise-grade performance.
  • Protects against encrypted malware and intrusions using DPI-SSL inspection, IPS, anti-malware, and Capture ATP sandboxing with RTDMI detection.
  • Secure SD-WAN intelligently steers traffic across links to reduce MPLS costs and improve cloud application performance for branch users.
  • The SonicWall TotalSecure Trade Up program enables customers with an eligible SonicWall or third-party firewall to upgrade to a new Gen 7 appliance bundled with a protection service suite such as Essential or Advanced. This all-in-one option simplifies purchasing by combining next-generation hardware with active security services, helping organizations modernize defenses and maintain continuous protection in a single package.

The company also said it had been a Koi customer before the acquisition, suggesting prior familiarity with the technology. Its investor-call transcript discusses that relationship. The transcript does not, by itself, prove the product’s effectiveness or the rationale behind the purchase.

Who may benefit—and who should be cautious

Potentially strong fit

  • Enterprises whose employees use AI coding agents, browser extensions, local models, MCP servers, or other AI tools on managed devices.
  • Security teams trying to identify software installed outside approved channels, including shadow AI.
  • Organizations already using Palo Alto Networks products that want to assess whether the announced integration improves their existing investigation and policy workflows.

Reasons to pause

  • Organizations with little AI-agent use or existing endpoint and software-supply-chain controls that already meet their needs.
  • Companies using a different endpoint-security stack, where the value and interoperability of Koi’s integration remain to be established.
  • Developer-heavy environments where broad blocking of unfamiliar packages or tools could disrupt work.
  • Buyers that need confirmed licensing, operating-system coverage, deployment architecture, or data-handling details before evaluating a product.

Questions to ask before evaluating the product

  • Visibility: Can it discover AI tools installed outside approved channels, including local models, extensions, packages, scripts, coding agents, and MCP servers? Which endpoint types and operating systems are supported?
  • Risk evidence: What signals drive a risk score—provenance, ownership, update history, runtime behavior, permissions, or network destinations—and what evidence can an analyst inspect?
  • Control point: Can administrators block, quarantine, restrict, or require approval for a tool? Does enforcement happen before installation, at execution, or only after suspicious behavior?
  • Developer workflow: How are exceptions, temporary approvals, and appeals handled? What evidence helps teams distinguish a risky package from a merely unfamiliar one?
  • Integration: Which alerts, policies, and response actions are available in Cortex XDR and Prisma AIRS? Are they available in the customer’s edition, and are they connected workflows or linked views?
  • Architecture and privacy: Is a local agent or other endpoint component required? What data leaves the device, where is it processed, how long is it retained, and who can access it?
  • Commercial terms: Is Koi included in an existing Cortex XDR or Prisma AIRS subscription, or does it require a separate license? How is it priced, and what happens to existing Koi customer contracts?

The public materials cited here do not provide a complete SKU, price list, supported-platform table, deployment architecture, or feature matrix. Palo Alto Networks’ product materials direct prospective enterprise customers toward a sales conversation rather than publishing standard self-serve pricing. The company’s Agentic Endpoint Security page is one route for product information.

Bottom line

The Koi acquisition gives Palo Alto Networks a focused way to extend AI-security visibility and controls onto endpoints, with the stated goal of integrating the technology into Prisma AIRS and Cortex XDR. Its practical value will depend on evidence that those integrations deliver useful discovery, risk explanation, and policy enforcement in customers’ environments—not on the AES label alone.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.