Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Palo Alto Networks has completed its acquisition of Israeli cybersecurity startup Koi. The companies announced the deal on February 17, 2026, and Palo Alto Networks said it closed on April 14. Koi’s technology is being positioned to extend Prisma AIRS and Cortex XDR with visibility into AI agents and other software running on enterprise endpoints.
The transaction is also a reminder to treat acquisition-price headlines carefully: Globes reported an approximately $400 million deal, while Palo Alto Networks later disclosed $231 million in purchase consideration, substantially all in cash.
What happened to Koi?
Palo Alto Networks, not the city of Palo Alto, announced a definitive agreement to acquire Koi on February 17, 2026. The acquisition closed on April 14, according to Palo Alto Networks’ completion announcement.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →That means current coverage should describe Koi as acquired, rather than as a startup Palo Alto Networks merely intends to buy. Public materials indicate that Koi’s technology is now part of Palo Alto Networks’ strategy for securing the “agentic endpoint.” They do not establish that every technical integration, product migration, or commercial packaging change has been completed.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Koi was headquartered in Tel Aviv, Israel. Its leadership included chief executive Amit Assaraf, chief technology officer Idan Dardikman, and chief product officer Itay Kruk, according to Globes.
How much did Palo Alto Networks pay?
The most defensible current figure is $231 million in disclosed purchase consideration. The price should nevertheless be presented with context:
- Approximately $400 million: Globes reported this figure before Palo Alto Networks announced the transaction.
- $231 million: Palo Alto Networks reported this purchase consideration in its June 2026 Form 10-Q, describing it as substantially all cash.
The available public materials do not explain every difference between the two figures. Different definitions of transaction value, timing, contingent consideration, or accounting treatment could potentially contribute, but none should be stated as the confirmed explanation without supporting transaction documents. Calling the deal simply a “$400 million acquisition” would therefore overstate what is currently confirmed by Palo Alto Networks’ filing.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsWhat Koi built
Koi described its product category as Endpoint Security Posture Management, or ESPM. Its focus was broader than a conventional inventory of installed applications. Koi said its platform could analyze software artifacts including:
- Applications and code packages
- AI models and agent-related tooling
- Operating-system packages and drivers
- Browser extensions
- Containers
- MCP-related components and tools
Koi’s stated goal was to help security teams understand what software exists on an endpoint, where it came from, how it changes, and what it does. Its “Wings” risk engine was described as correlating signals such as code changes, runtime behavior, ownership changes, update channels, network egress, installation source, and policy drift. Those descriptions come from Koi’s product materials; they should be treated as vendor claims rather than proof that every capability works across every environment.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Koi also said it had raised $48 million. Its funding announcement named Battery Ventures, NFX, Team8, Picture Capital, and cybersecurity executives among its backers: Koi’s funding announcement.
Why AI agents create an endpoint problem
AI security is often discussed as a cloud, model, or application issue. Agentic AI adds a local execution problem.
An AI-enabled browser extension, coding assistant, desktop agent, or locally installed orchestration tool may be able to read files, access browsers and enterprise applications, call APIs, use credentials, install tools, communicate with external services, and execute multistep tasks. It may also change as its model, prompt, plugin, package, or tool configuration changes.
The risk is not limited to “AI malware.” It combines familiar security problems in a more dynamic form:
- Software supply-chain risk: Packages, extensions, models, and tools may come from changing or difficult-to-verify sources.
- Excessive permissions: An agent can be harmless in isolation but dangerous if it can access sensitive files, secrets, or high-impact APIs.
- Opaque tool use: Users may not see every external service or action an agent invokes.
- Dynamic behavior: Updates to models, plugins, or dependencies can change an agent’s behavior without a traditional application release.
- Machine-speed execution: An agent can perform multiple actions faster than a human can review them.
Palo Alto Networks argues that conventional controls may not provide enough visibility into AI activity occurring on employee devices, leaving a gap between cloud or network controls and software actually running at the endpoint. That is Palo Alto’s product-positioning argument, not a universally established finding. The company explains its view in its agentic endpoint security analysis.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
How Koi fits Palo Alto Networks
The strategic fit has three main elements.
Prisma AIRS
Prisma AIRS is Palo Alto Networks’ AI-security platform. Koi’s endpoint visibility is intended to complement controls for AI applications, models, agents, and runtime activity. The acquisition does not make Koi a replacement for Prisma AIRS; it is better understood as adding an endpoint-oriented layer to Palo Alto’s broader AI-security approach.
Cortex XDR
Cortex XDR provides endpoint detection and response among other security capabilities. Palo Alto Networks says Koi’s technology can help differentiate Cortex XDR by exposing activity involving agentic software and modern software components.
A consolidated control plane
Palo Alto Networks is pursuing a platform strategy spanning endpoint, network, cloud, identity, AI, and security operations. For existing customers, the potential benefit is correlating endpoint, identity, network, and AI-related telemetry in one security stack rather than adding a specialist tool. The trade-off is greater dependence on one vendor and its licensing, integration, and roadmap decisions.
Palo Alto Networks also said it had been a Koi customer since the summer before the acquisition announcement. That supports management’s explanation that the deal followed direct product exposure, although it remains a statement from Palo Alto Networks rather than independent validation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What customers should expect
The acquisition’s completion does not answer all of the practical questions buyers will have. Public materials reviewed for this article do not establish:
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
- Which Palo Alto product or SKU will include the capability
- Whether it will be sold through Prisma AIRS, Cortex XDR, a bundle, or another entitlement
- Whether Koi remains available as a standalone product
- Whether existing Koi customers will be migrated automatically
- How pricing will change
- Whether the Koi brand will remain
- Which operating systems, endpoint types, containers, and virtual machines are supported
Existing Koi customers should obtain a written support and migration plan from Palo Alto Networks. Cortex XDR and Prisma AIRS customers should ask whether the capability is available in their current contract or requires a new module. Organizations evaluating the technology should request coverage details and product demonstrations rather than assuming that acquisition automatically means immediate availability.
What the acquisition does not solve
Finding an AI agent is not the same as securing it. The most important control point is what the agent can access and do.
Even a strong endpoint inventory does not replace:
- Least-privilege identity and access controls
- Secrets management and API authorization
- Network egress controls
- Browser and extension governance
- Data-loss prevention
- Audit logging and incident response
- Model, application, and cloud-runtime security
“MCP security” also requires precision. A product might discover MCP servers and tools, monitor runtime behavior, enforce policy, authenticate connections, or act as a gateway. Those are different functions, and the available materials do not establish identical coverage for every MCP deployment.
Coverage can also be incomplete. Potential blind spots include portable binaries, encrypted or obfuscated code, offline activity, software inside virtual machines or containers, unmanaged personal devices, and remote or cloud-hosted agents whose actions are not visible locally.
Trade-offs for enterprise buyers
- Integration risk: Palo Alto Networks identifies integration, product development, market acceptance, vulnerability, and customer-adoption risks in its public disclosures.
- Maturity: Koi was a young company. Buyers should verify deployment history, scale, support capacity, and roadmap stability.
- Privacy: Inspecting code, extensions, models, runtime actions, and network behavior may raise employee-monitoring, data-residency, and sensitive-data concerns.
- False positives: Blocking unfamiliar packages or developer tools can disrupt legitimate workflows.
- Agent ambiguity: Security policy should distinguish a low-risk browser helper from an agent with privileged access to production systems.
- Platform dependence: A unified control plane can simplify operations but may increase switching costs and procurement dependence.
Questions to ask before buying
- Does the product identify locally installed AI agents, extensions, packages, models, and tools?
- Which operating systems and endpoint types are covered?
- Does it require an agent on every device?
- Can administrators create allowlists, blocklists, approval workflows, and exceptions?
- How are open-source packages and rapidly changing dependencies evaluated?
- Does the product combine static analysis with runtime behavioral monitoring?
- What endpoint data leaves the organization, and where is it processed?
- Can customers control regional processing or self-host any components?
- How are MCP servers and tools authenticated, inventoried, and governed?
- Is the capability included in an existing Cortex XDR or Prisma AIRS contract?
- What happens to current Koi customers, contracts, support, and data?
- How has the product been tested against malicious or adversarial agent behavior?
The investment and industry significance
For Palo Alto Networks, Koi represents a bet that agentic-AI security will become an endpoint and software-inventory problem—not only a model-security or cloud-security problem. The opportunity is especially relevant to enterprises allowing employees and developers to install AI assistants, browser extensions, packages, and local automation tools.
For buyers, the acquisition may improve the appeal of a Palo Alto-centered stack, particularly where Cortex XDR and Prisma AIRS are already deployed. It does not make Palo Alto Networks the automatic leader in agentic security, nor does it make a single product sufficient for AI governance. The meaningful test will be whether the combined offering provides measurable visibility, precise policy enforcement, manageable false-positive rates, and clear licensing across the customer’s actual endpoint and cloud environment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

