AI
Two Rival AI Labs Just Joined the Same Security Team, and the Overlap Came In Under 10 Percent
The most honest sentence in cybersecurity this week came from a company with something to sell. Palo Alto Networks announced a new AI security service on Tuesday and led with its own testing data, which showed that a single AI model catches roughly 40 percent of vulnerabilities in a complex corporate network, while two frontier models built for cyber work overlap on less than 10 percent of what they find. That is a striking admission to print on launch day, and it explains the entire product.
The service is called Unit 42 Continuous Frontier AI Defense. It probes web applications, programming interfaces, and cloud infrastructure around the clock, hunting for vulnerabilities and mapping possible attack paths as customer systems change. When it finds something, it hands over guidance for fixing the gap, including code level repairs and virtual patching options. The engine underneath is a proprietary harness that routes each offensive testing task to the model best suited for it, one tuned for application security here, another tuned for cloud misconfiguration there.
The model roster is where the story gets its edge. Palo Alto put Anthropic's Claude Mythos 5 and OpenAI's GPT 5.6 Cyber on the same team, alongside open weight models, which means two labs that compete fiercely for enterprise deals are now cooperating inside a single security product. According to Unit 42's internal evaluations, that cooperation is the point. Each engine on its own covered too little ground, and the leading cyber models surfaced almost entirely different exposures, so the harness farms each task out to the specialist most likely to catch it while keeping compute spend manageable.
The commercial wrapper is equally deliberate. The service sells worldwide on annual subscriptions, with pricing set by the mix of OpenAI, Anthropic, and open source models each customer selects. Buyers are effectively assembling their own AI security cabinet and paying per brain. It arrives as attackers run the same playbook in reverse, using agentic tools and open weight models to discover and chain exposures at machine speed. Hackers are increasingly using AI to find and exploit weaknesses in corporate networks, which is exactly the pressure this product is built to answer.
There is also a privacy sweetener aimed squarely at enterprise buyers. The service runs on a zero data retention architecture, so customer source code and telemetry stay out of storage and out of public model training. For companies that spent the last two years wondering whether AI vendors were quietly drinking from their codebases, that guarantee does real selling work. It also sets a bar. Every AI assisted security vendor will now get asked the retention question in every deal.
The bigger story here is the end of the single model era in security. Palo Alto just told the market, in numbers, that coverage comes from orchestration, and published the math to prove it. Expect rivals to answer with their own coverage figures, and expect buyers to start asking every vendor the question Palo Alto already answered, namely what your model misses and who catches the rest. For anyone running corporate systems, the practical move is simple. Continuous AI driven testing is becoming table stakes, and the vendors being honest about their blind spots are the ones worth a second meeting.
Quick answers
What is this story about?
The most honest sentence in cybersecurity this week came from a company with something to sell. Palo Alto Networks announced a new AI security service on Tuesday and led with its own testing data, which showed that a single AI model catches roughly 40 percent of vulnerabilities in a complex corporate network, while two frontier models built for cyber work overlap on less than 10 percent of what they find. That is a striking admission to print on launch day, and it explains the entire product.
Why does this story matter?
The bigger story here is the end of the single model era in security. Palo Alto just told the market, in numbers, that coverage comes from orchestration, and published the math to prove it. Expect rivals to answer with their own coverage figures, and expect buyers to start asking every vendor the question Palo Alto already answered, namely what your model misses and who catches the rest. For anyone running corporate systems, the practical move is simple. Continuous AI driven testing is becoming table stakes, and the vendors being honest about their blind spots are the ones worth a second meeting.
Sources
New to crypto? Read the crypto glossary, browse frequent questions, read our story, or explore the story archive.