VYPR
researchPublished Sep 2, 2026· 1 source

Palo Alto Networks Acquires Console to Drive Autonomous Security Operations with AI Agents

Palo Alto Networks has acquired Console, an AI-native platform, to enhance its Cortex security operations portfolio and enable AI-driven workflows for autonomous threat investigation and remediation.

Palo Alto Networks has announced its acquisition of Console, an AI-native platform designed to bolster its Cortex security operations portfolio. This strategic move aims to accelerate the development of AI-driven workflows that can autonomously investigate, prioritize, and remediate cyber threats at machine speed. The acquisition comes at a critical juncture as security teams worldwide grapple with an overwhelming volume of alerts, increasingly sophisticated automated attacks, and mounting pressure to significantly reduce the time between threat detection and containment.

Console's technology empowers organizations to leverage natural-language instructions to create specialized AI agents. These agents are capable of analyzing vast amounts of enterprise data, coordinating complex tasks, and executing actions across diverse security and IT environments. The core philosophy behind Console is to allow users to define operational objectives, while the AI software handles the intricate technical steps required for their completion. In a typical security operations center (SOC) scenario, this could involve an AI agent automatically examining a security alert, gathering crucial context from endpoint, cloud, identity, and network systems, assessing the activity's severity, and initiating an appropriate response workflow.

Palo Alto Networks intends to integrate Console's capabilities directly into its existing Cortex platform. The company envisions this combined offering enabling security analysts to move beyond traditional, dashboard-centric operations, where manual alert review and ticket creation precede any action. This shift is crucial for keeping pace with the evolving threat landscape. Nikesh Arora, Chairman and CEO of Palo Alto Networks, emphasized that security operations must evolve from merely helping analysts work faster to enabling truly autonomous security outcomes.

Console's "software-as-an-agent" approach allows customers to interact directly with enterprise data using natural language, creating "agentic workflows." Unlike traditional AI copilots that merely suggest next steps, these agentic systems can be configured to complete defined tasks autonomously. Such tasks include enriching alerts with threat intelligence, correlating disparate security events, opening or closing incident cases, isolating compromised endpoints, or triggering automated remediation processes. This represents a significant leap towards proactive and efficient security management.

However, the successful implementation of autonomous security agents presents significant challenges, particularly concerning safety and governance. These powerful agents require controlled access to sensitive systems, comprehensive logging capabilities, human oversight for high-impact actions, and robust safeguards against inaccurate reasoning or unauthorized activities. Palo Alto Networks stated that Console's technology is designed to support the faster adoption and stronger governance of these agentic operations, addressing these critical concerns.

Console's co-founder and CEO, Andrei Serban, highlighted that their existing customers have already demonstrated the value of these agents in reducing operational overhead and improving business processes. He believes that joining Palo Alto Networks will provide Console with access to a broader cybersecurity ecosystem, extensive threat intelligence resources, and a global enterprise customer base. Palo Alto Networks, with its extensive reach serving over 70,000 customers across network security, cloud security, security operations, AI, and identity, is well-positioned to leverage this acquisition.

The integration of Console's technology into Palo Alto Networks' portfolio is expected to enhance its Unit 42 threat intelligence organization, providing a rich source of context for future AI-driven workflows. While the company acknowledges that the full benefits of the acquisition depend on successful integration, it signals a strong commitment to advancing autonomous security capabilities. This move aligns with the broader industry trend towards leveraging AI to automate and accelerate security operations in the face of increasingly complex and rapid cyber threats.

Synthesized by Vypr AI