Palo Alto Networks has acquired Console, an AI-native platform built to run enterprise workflows with autonomous agents, and plans to integrate the technology into its Cortex security operations product. The cybersecurity giant did not disclose the terms.
From Copilots To Operators
The deal marks another step in the industry's transition from AI-assisted analysts to AI-operated SOC workflows. Traditional SIEMs and XDRs already lean on machine learning to prioritize alerts, but Console's agentic architecture is designed to take the next step: independently investigating cross-tool context, correlating identity, endpoint and cloud signals, and executing routine remediation without human hand-holding.
What Console Actually Does
Console's platform lets enterprises define agentic workflows that connect email, ticketing, cloud, EDR and identity systems, then hand execution to LLM-driven agents. Inside Cortex, Palo Alto plans to point that same architecture at alert triage, incident response and threat-hunting — tasks that currently consume the bulk of analyst time inside large SOCs.
The Autonomy Risk Trade
The obvious tension is that an autonomous security agent with broad access is itself a high-value attack target. Get it wrong and a compromised or misdirected agent can lock accounts, expose data or spread ransomware faster than any human insider. Palo Alto executives will need to answer questions about scoping, human-in-the-loop guardrails and forensic traceability before enterprise customers give agents production access.
Competitive Ripples
The deal ratchets up pressure on rival SOC vendors including CrowdStrike, SentinelOne, Microsoft Sentinel and Splunk. Each has hinted at agentic capabilities in 2026 keynotes; Console's talent and IP now sit inside Cortex, one of the largest SOC installed bases in the market.
A Big Week For AI-Security Deals
The Console purchase lands alongside a 100-firm rogue-AI cyber defence pact, ServiceNow's triple CVSS 10 patches and the OpenAI/Hugging Face rogue-agents post-mortem — all pointing at agentic AI both as attack surface and defensive fabric.
Reporting based on coverage from SecurityWeek and Tech Startups.