Palo Alto Networks has gone all in on vibe coding with a new program revolving around AI security.
Revealed at the London leg of its Ignite tour, the security giant’s AI Security Nexus program aims to help organizations adopt and secure AI end-to-end through strategic guidance and best practices.
According to Ian Swanson, product VP for AI security, the venture works as a “center of strategic foresight,” with a content hub of multimedia offerings, white papers, and real-world examples of how Palo Alto Networks uses AI for its internal operations. In various examples shown at Ignite, these revolved around vibe coding, in which developers use natural language prompts to generate, build, and debug applications at speed using large language models (LLMs).
Swanson claimed such coding had driven down mean time to resolution on Palo Alto support tickets by more than 50%, with productivity gains in specific workflows across the company in both technical and non-technical functions. Some projects, meanwhile, have seen a up to a four-times velocity increase, with the VP putting this down to the capabilities of Protect AI, as led and founded by Swanson, and acquired by Palo Alto last summer.
AI security under the microscope
The launch of Palo Alto’s AI Security Nexus comes amid increased scrutiny of AI use in the enterprise. The popularity of OpenClaw, a system that lets AI agents call, coordinate, and delegate tasks to other agents automatically, saw Palo Alto warn earlier this week that AI agent connectivity isn’t necessarily secure, and that such a level of ungoverned autonomy with agentic AI can give rise to “irreversible security incidents.”
In addition, SDxCentral uncovered this week AI agents sharing security evasion tips, specifically on web scraping. The discovery was made on Moltbook, a forum run and used exclusively by agents, some of whom operate on the OpenClaw system.
Vibe coding has seen similar scrutiny since its emergence last year, with Crystal Morin, senior cybersecurity strategist at Sysdig, commenting: “The challenge is that vibe coding is not secure by default. AI-generated code should not be trusted without proper testing and validation. AI models can introduce different classes of risk, ranging from obvious issues, such as hallucinated logic that causes functions to fail, to more subtle vulnerabilities embedded in code that otherwise appear clean and well-structured to the untrained eye.”
Morin added that AI systems can rely on outdated patterns or insecure techniques, as such approaches were present in their training data.
“Have you ever interacted with an AI model regarding dates and times? Oftentimes, it gets the answer wrong. If the underlying code used for training the model contained flaws or has not been kept up to date, those weaknesses can be reproduced in newly generated code.”
Inti De Ceukelaire, chief hacker officer at Intigriti, meanwhile, added: "When a company like Palo Alto discusses vibe coding, you know it's become a real thing. And you can be absolutely certain that they are totally aware of the risk it carries.”
The hacking veteran praised Nexus as a smart move by Palo Alto Networks to spotlight governance and security around AI-generated code, as either forbidding and ignoring vibe coding would be a “mistake” now that the genie is out of the bottle.
“Yes, speed is great, but security has to evolve as fast as development if AI-written code is to become truly enterprise-ready," De Ceukelaire said. "People are going to use AI anyway, so any awareness sessions around it will actually help the overall governance.”
The Palo Alto perspective
In an interview at Ignite, Scott McKinnon, UKI CSO at Palo Alto Networks, confirmed the company was closely watching recent OpenClaw developments, warning that people “should go in with their eyes wide open absolutely but they need to make sure that they have these kind of secure foundations in place, and then they can see the benefits of these tools and systems."
The CSO believed the starting point should be securing where most enterprise work takes place: in the browser, referring to recent updates to Prisma Browser.
“With the browser, we can provide a safe environment for these agents to be interconnected and plugged into, and then we can also protect on the back end where you've got cloud native applications that have agency to integrate within different systems," McKinnon said.
Ignite London also saw some keen insight on Palo Alto’s AI work courtesy of Global CIO Meerah Rajavel, who echoed De Ceukelaire in saying that it is too late to pause AI use when people have already seen the benefits it can bring, and as such, the firm had very much a “pro-AI culture” where usage isn’t too restricted.
“We want our 6,000 developers to use AI and be productive," Rajavel said. "However, I don't want them to go to ChatGPT or go to Claude in the public domain, or GitLab, for that matter, and just download the code and bring it into code repositories. That’s because we have a moral responsibility for 80,000 customers; we can’t afford a software supply chain risk.”
Rajavel added visibility was not good enough, and instead companies should secure applications and protect.
“If you're going to upload something that's a critical document of Palo Alto Networks’ into ChatGPT – no, you're not allowed. But we do allow that for analysis in our Gemini Enterprise version, where it's much more secure because that is integrated into the Microsoft Azure backend to look at everything that's happening there," Rajavel said.
The CIO noted the rise of AI and vibe coding had changed Palo Alto’s hiring strategy, with the company keen to assess developers on their critical thinking skills and learnability.
“We have this joke around in the company, or in my team specifically, where we ask: are you making AI work for you, or you're working for AI?” Rajavel said, suggesting that the 85% failure AI adoption rate amongst enterprises is down to simply not knowing how to use AI – with Palo Alto’s Nexus a possible fix.
Comments