IBM building
– Getty Images

IBM collaborated with Palo Alto Networks on a new framework designed to tackle AI security risks.

The Rapid AI Security Assessment is provided as a two-week assessment by IBM, offering an AI Infrastructure Discovery and Inventory (AI-BOM) which identifies AI models, agents, applications, and related components across targeted environments. The assessment also promises a prioritized, actionable roadmap with recommendations aligned to key governance and compliance frameworks such as the NIST AI RMF, EU AI Act, and ISO/IEC 42001.

Another major component is tackling the enterprise scourge of unauthorized, shadow AI, helping to detect non-compliant AI deployments and policy violations. According to IBM research, shadow AI can increase breach costs by $670,000, while 97% of enterprises reporting AI-related breaches lacked proper identity and access management (IAM) roles.

Palo Alto’s participation sees its Prisma AIRS site integrated with IBM’s delivery methodology, with IBM touting the assessment will be delivered by experts holding Palo Alto Networks certifications.

The theme of AI security has already come thick and fast in 2026. Recently released Palo Alto research claimed almost half (47%) of AI system breaches last year involved data exfiltration through assistants or plugins, due to AI agents relying heavily on APIs to operate – thus expanding the attack surface for enterprises.

IBM has already begun staking its claim in AI-centered security, with last week seeing the tech giant add model context protocol (MCP) to its governance software platform OpenPages. Released in late 2024 by AI firm Anthropic, MCP is an open standard designed to standardize the way AI systems, particularly large language models (LLMs), integrate and communicate with external data sources, tools, and systems.

IBM said the move provided “a standardized, secure interface for MCP-compatible AI agents to read, reason on and act with data and operations in the platform, describing it as “an early, controlled step toward agentic GRC.”