Ly Gravity

The Control Plane Nobody Voted For

Samtoshi • • Press Releases

Sixty-eight trillion tokens. That is the figure Palo Alto Networks attached to Prisma AIRS at general availability, and it is the kind of number designed to end a conversation rather than start one. I have spent a decade reading token counts stapled to protocols, and I have learned to distrust the ones that arrive without a denominator. Cumulative or monthly? Benign traffic included? Double-counted across retries? None of that is disclosed. So I did what I always do when a vendor leads with scale: I skipped the announcement and read the integration annex. Buried in the documentation was a sentence that should have been the headline. The Codex integration does not scan assistant replies, tool calls, tool results, files, or images. It reads the prompt. Only the prompt.

Read that again, slowly, because it describes the architecture of a product being sold as the security layer for autonomous agents. We have built an elaborate control plane for the age of agents, and the control plane is blind to the exact moment where agents act.

To understand why this matters beyond one vendor's product roadmap, you have to understand what the agent ecosystem actually is. In 2025 and 2026, the connective tissue of that ecosystem became the Model Context Protocol — MCP — an open specification that lets a model call external tools: a file system, a database, a payment rail, a code interpreter. MCP is, in the truest sense, a protocol. It is open, it is unowned, and it is quietly becoming the default way machines ask other machines to do things on their behalf.

The Control Plane Nobody Voted For

I have watched this pattern before. An open protocol emerges because it solves a coordination problem no single company can solve alone, and then, once it carries enough traffic, the security layer above it gets captured by whoever moves fastest to monetize fear. The protocol stays open. The enforcement around it concentrates.

Palo Alto's strategy here is unusually aggressive, and I want to describe it precisely rather than dismiss it. Instead of building an independent AI gateway and waiting for traffic to arrive, the company embedded Prisma AIRS directly inside the enterprise environments of the model providers — inside Codex, inside Anthropic's Claude Enterprise. No plugin. No traffic redirection. No change to the developer workflow. When an enterprise customer of those model providers wants inline inspection, DLP, and threat detection, the check happens inside the model vendor's own dashboard.

The pace of expansion tells its own story. In one month the company integrated on the model side. The next month it pivoted to the developer workflow, extending Cortex AES across Cursor, GitHub Copilot, and the other coding agents that have become the actual keyboards of the industry. One month, one battlefield. That is not the cadence of a mature product; it is the cadence of a company racing to cover ground it has not yet secured.

And the ground is defined by what the product cannot see. The integration is prompt-only. Anthropic coverage is United States only, and text only. AI Discovery, the cross-cloud visibility tool, reaches only Americas SCM tenants. For a global, multimodal enterprise, the native integration covers a narrower attack surface than the marketing implies. The boundary of the product is the boundary of the business, and both are drawn tighter than the story being told.

Here is where the analysis has to become technical, because the ethical stakes only make sense once the mechanics are clear.

The threat model for AI systems has migrated. In 2023, the risk lived in the prompt: a user typed something malicious, the model said something it shouldn't. Filtering the prompt was a defensible perimeter. By 2026, the risk lives in the execution chain: an agent, driven by a compromised MCP server or a poisoned tool result, takes an action — it calls a function, writes a file, moves a value. The prompt can be perfectly benign while the action is catastrophic. Prompt-level filtering does not merely miss some attacks; it is structurally blind to the class of attacks that now define the category.

Consider what the documentation admits. The integration does not scan tool calls, tool results, files, or images. That means an agent executing code through an MCP server is, for parts of Prisma AIRS, simply invisible. And MCP is precisely where the 2025–2026 attack surface concentrated: tool poisoning, where a malicious tool description hijacks the agent's behavior; privilege escalation, where an agent calls a tool it was never meant to reach. These are not edge cases. They are the center of the map, and the control plane has a hole cut out of exactly that center.

My best inference is that this is not a product strategy but an architectural limit. To scan a tool call, you must sit inside the execution chain. To sit inside the execution chain, the model provider must expose it to you. It is one thing to read a prompt routed to you from a dashboard; it is another to intercept a function invocation inside someone else's runtime. The prompt-only scope is less a roadmap choice than a measurement of how deep the integration actually reaches. That distinction — between a company that chose not to scan tool calls and a company that cannot — is the difference between a delay and a ceiling.

The newer modules tell a similar story. AI Skill Security performs pre-deployment static analysis: it looks for arbitrary code execution, credential leakage, data exfiltration, obfuscation, excessive permissions. Memory Poisoning Detection tests whether an agent's persistent, cross-session memory can be corrupted. Both are real threats, both entered mainstream awareness only after 2025, and both are being productized quickly. But static analysis, by its nature, cannot catch runtime-triggered behavior — the skill that behaves until a specific input arrives. It is the same blind spot that traditional static application security testing has carried for twenty years, transplanted into a new ecosystem with new branding. Deployment-time assurance is not runtime protection, and the gap between them is where incidents live.

There is also a quiet architectural cost that the marketing omits: inline inspection means every call passes through the security layer, and for a latency-sensitive workflow — a coding agent autocompleting in real time — that is not free. Nobody in the announcement mentioned the overhead, and I suspect the reason is that a security layer which adds milliseconds to every keystroke is a harder sell than a security layer that adds confidence.

Memory Poisoning Detection deserves one more sentence than it usually gets, because its very existence as a sellable feature reveals an architecture decision the industry made without voting. Persistent, cross-session memory is now a default trait of enterprise agents. That persistence is an attack-surface amplifier: a corrupted memory does not merely distort one answer, it distorts every future answer, silently, across sessions. We adopted stateful agents for continuity and only afterward began selling protection against the state we created. We traded soul for speed, and called it progress.

Then there is the matter of whether these modules are one engine or several. The product carries a distinctive patchwork texture: cloud gateway for prompt inspection, AI-SPM for cross-cloud visibility, endpoint adjudication through Cortex AES, static analysis here, memory testing there. Each plane is reasonable. Together they feel seamed. Third-party analysts suggest the suite was assembled through acquisition — plausible, and consistent with a company still stitching its data plane together. Whether detection data flows between these modules — whether the memory-poisoning signal informs the prompt filter — is unknown. If it does not, the product is a collection of tools wearing one name.

Now widen the lens. Palo Alto is not the only player, and the competitive shape matters. Zscaler and Netskope extend their existing secure-access platforms toward AI. Wiz, now inside Google, extends cloud posture. Cisco bought Robust Intelligence. Microsoft bundles Defender for AI with its own models and Azure. Against that field, Palo Alto's differentiation is narrow but sharp: it is the only one with native, first-party integration into the model providers' own enterprise environments.

But look at the same column of the matrix and you find the mirror image. Microsoft is strong on model-side integration too — because Microsoft owns models. Palo Alto's strength is borrowed from partners it does not control. It has the strongest integration today and the least control over whether that integration survives. The same table that shows its advantage shows its exposure.

One more element deserves naming, because it reframes the entire competitive question. The company's own materials concede that most enterprises will need a second layer of gateway — a second checkpoint beyond the first. That concession is an admission that the category is not yet solved, and it is also an invitation. The second layer could be Palo Alto's own expansion, or it could be the beachhead for the independent agent-security startups — the ones building runtime enforcement for tool chains — or the cloud platforms. A control plane that admits it needs a control plane is not a moat. It is a frontier.

Which brings us to the narrative itself, and the reason I distrust the sixty-eight trillion figure. For a public company, a milestone announcement is a genre. General availability plus a scale metric plus a rapid integration cadence is a complete investor-confidence story, and the token count is its chorus. The distribution advantage is real — embedding inside a model vendor's enterprise channel lowers customer-acquisition cost in a way independent gateways cannot match. But the same coverage limits that define the product's attack surface also cap its addressable market: United States, text-only, prompt-only, Americas tenants. A narrow product does not generate broad recurring revenue. The narrative can outrun the revenue for a while. It cannot do so forever.

Here is the counter-intuitive conclusion, and it is the one the coverage keeps stepping around.

Everyone is watching the attack surface. The prompt injection, the poisoned memory, the malicious skill — these are the threats that sell security products. But the structural risk is not the attack. It is the dependency. Palo Alto's embedded strategy places its enforcement layer inside environments owned by companies with both the motive and the means to build that layer themselves. Anthropic runs an alignment and safety research organization. OpenAI has a security team. Vertical integration is the natural gravity of a platform: why let a third party own the checkpoint through which every one of your enterprise customers must pass?

The embedded strategy is, in plain terms, building a toll booth on someone else's road. That works while the road owner is content to collect rent from the toll operator. It stops working the moment the road owner decides to run the booth themselves — or to hand it to a cloud platform that already owns the customer relationship. And the coverage gaps I described are exactly the door through which that displacement enters: every category the control plane cannot see — tool-chain runtime, non-US tenants, non-text modalities — is a category a competitor or the model vendor can claim.

I keep returning to a phrase that has haunted this industry since the first sanctions. Code is law, until the law breaks the code. The open protocol here is MCP. It is unowned, it is generous, and its security depends entirely on downstream commercial layers that have every incentive to enclose it. We are watching an open standard acquire a proprietary immune system. The protocol remains free; the immunity is becoming someone's product.

This is not a reason to reject the security layer. Agents genuinely need runtime governance, and pretending otherwise is how the last cycle ended. It is a reason to ask who should own it — and to notice that the answer forming by default is a small number of platforms that did not ask the protocol's community for permission. Faith in the protocol is not faith in the people who guard it.

The question worth carrying forward is not whether Prisma AIRS works. It is whether an open protocol can remain open once it becomes valuable enough to secure. MCP was built to let machines cooperate without a central authority. The control plane being built above it may quietly reintroduce one — not through a mandate, but through the ordinary gravity of a default. We built the temple, but forgot who the god is. The next twelve months will tell us whether the agent web inherits the open ethos of the protocols beneath it, or the closed reflexes of the platforms above.

Market Prices

BTC Bitcoin
$82,616.6 +1.01%
ETH Ethereum
$2,490.66 +0.51%
SOL Solana
$109.55 +0.29%
BNB BNB Chain
$744.2 +1.36%
XRP XRP Ledger
$1.4 +0.96%
DOGE Dogecoin
$0.0858 +1.37%
ADA Cardano
$0.2488 +6.83%
AVAX Avalanche
$10.33 +1.71%
DOT Polkadot
$1.24 +9.37%
LINK Chainlink
$12.79 +0.20%

Fear & Greed

64

Greed

Market Sentiment

Event Calendar

{{年份}}
08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$82,616.6
1
Ethereum ETH
$2,490.66
1
Solana SOL
$109.55
1
BNB Chain BNB
$744.2
1
XRP Ledger XRP
$1.4
1
Dogecoin DOGE
$0.0858
1
Cardano ADA
$0.2488
1
Avalanche AVAX
$10.33
1
Polkadot DOT
$1.24
1
Chainlink LINK
$12.79

🐋 Whale Tracker

🔴
0xa58c...cfa3
3h ago
Out
453,942 USDT
🔴
0xfc4d...c84d
12m ago
Out
12,914 SOL
🔴
0x74f1...cf50
1h ago
Out
4,952 ETH

💡 Smart Money

0x2305...a7ae
Institutional Custody
+$2.2M
82%
0x2be1...2802
Institutional Custody
+$3.1M
67%
0x680b...556a
Top DeFi Miner
+$1.9M
80%

Tools

All →