NetSec Spotlight: AI Access Security
AI Access Security is a solution for discovering and controlling the use of Generative AI applications across an organisation. It enables the safe adoption of GenAI by employees, mitigating the risks posed by inadvertent data leakage in prompts and malicious content in responses.
AI tools are being adopted faster than any other technology, and users are:
- Copying sensitive data into prompts
- Connecting AI tools to internal systems
- Using browser-based, API-based, and embedded AI features interchangeably
AI-driven interactions span browsers, APIs, SaaS integrations, and internal data sources, often occurring within encrypted and otherwise sanctioned traffic flows.
From a network security perspective, this represents a new access pattern that challenges traditional application-centric controls:
- How do you distinguish AI interactions from standard encrypted application traffic?
- How do you detect AI features embedded within otherwise sanctioned SaaS applications?
Platform Capabilities
To address these questions, AI Access Security extends the existing inspection layer with AI-specific context. The platform can not only recognise GenAI traffic, but understand and interpret AI-specific attributes and risk signals.
This is made possible through five key capabilities:
Discovery: maintains an extensive directory of GenAI applications, automatically identifying browser-based, API-driven, and embedded AI usage. GenAI discovery and categorisation is what catches shadow AI use within the organisation.
Inspection: leverages the Enterprise DLP detection engine for GenAI applications, using AI and Machine Learning to scan for sensitive data in prompts. Responses are also inspected for malicious content or compromise attempts.
Risk scoring: applications are scored across categories like data handling posture, model training behaviour, identity characteristics, use case, compliance, and security and privacy.
Policy enforcement: enables granular controls like allowing usage while blocking uploads or sensitive information in prompts, restricting high-risk applications entirely, or limiting access by user, device posture, or risk profile.
Reporting: provides robust reporting capabilities that enable security teams to generate insights into GenAI usage trends, policy violations, and data security metrics by user, application, and use case.
These capabilities work together in sequence, from identifying that GenAI traffic exists through to enforcing a policy decision.
For example, if a user copies internal finance data into a public AI chatbot, the flow without AI-specific inspection looks something like this:
- Traffic may be decrypted and inspected inline, or it may remain encrypted and outside effective inspection
- Application or encrypted web traffic identified
- No prompt-level inspection is applied
- Sensitive data exposure goes undetected
With AI Access Security the workflow is secured:
- Traffic is decrypted and inspected inline
- AI application is identified
- Prompt-level inspection is applied inline
- DLP policy is evaluated against the user and device context
- Upload is blocked or restricted according to policy


Platform Architecture
AI Access Security is a shared inspection capability delivered through Cloud-Delivered Security Services (CDSS) and managed by Strata Cloud Manager (SCM), rather than a separate product or security stack. It extends the same inspection layer already in place, without requiring additional products or management consoles.
GenAI interactions can be inspected inline at the network level using Prisma Access and NGFW, or directly within the browser workflow with Prisma Browser. Since the platform is already inspecting traffic, GenAI specific policies can be applied in parallel without any further performance overhead. In the case of the browser, the session can be fully inspected without the need for network-based decryption.
When enabling AI Access Security in the platform the following remains true:
- Policy authority stays centralised
- Enforcement continues to be distributed
- Telemetry is normalised within the same data model

In summary, AI Access Security provides important AI-specific context to the existing platform, enabling the following outcomes:
- Safe adoption of GenAI applications
- Safe conversational interactions with chatbots
- Granular control over AI features in sanctioned applications
- Clear and auditable visibility into AI usage patterns
- Consistent data protection across AI and non-AI traffic
Related Capabilities
AI Access Security targets GenAI application usage, discovering and governing traffic as it flows through the platform. Autonomous AI agents acting independently across systems are a distinct and rapidly evolving risk category, addressed through Prisma AIRS.
Prisma AIRS secures AI systems that organisations build and operate, through runtime inspection, model scanning, and AI red teaming - and discovers agents deployed in third-party platforms to assess their security posture.
For securing AI interactions (AI that talks), think AI Access Security. For securing AI agents (AI that acts), think Prisma AIRS.