Best AI Security markBest AI Security

Tool review · Checked against vendor sites, September 2026

Koi review (2026): Palo Alto Networks Cortex Agentic Endpoint Security

The verdict

Koi, now sold by Palo Alto Networks as Cortex Agentic Endpoint Security, is the natural choice for Cortex XDR customers: it adds visibility into models, MCPs, extensions and packages on the endpoint, risk scoring and prevention. It ties Bay for top visibility, but it is agent-based and its public pages do not describe how it tells agent actions from human ones.

Rank =5 of 9

Best for Palo Alto Cortex customers

Owner: Palo Alto Networks (acquisition completed 14 April 2026)

Visit Koi

What does Koi do?

  • Visibility into AI models, MCPs and extensions across the enterprise, with risk scoring.
  • Out-of-the-box policies for agent interactions and one-click removal of insecure packages, extensions and AI tools.
  • Stops malicious actions, blocks unsafe AI application interactions and prevents prompt injections.
  • Palo Alto Networks describes Koi as "a unique solution to securing vibe coding agents and autonomous endpoint tools".
  • Palo Alto Networks completed the acquisition on 14 April 2026. It is integrating Koi with Prisma AIRS, adding a new Cortex XDR module, and keeping Koi available as a standalone offering.

Source: Cortex Agentic Endpoint Security · Press release, 14 April 2026 · Reviewed Sep 2026

How does Koi deploy?

Integrates with Cortex XDR as a module and is also available standalone as an agent-based deployment. If you run Cortex XDR, this is the lowest-friction path; if you run another EDR, expect a separate agent.

Source: Cortex Agentic Endpoint Security · Press release, 14 April 2026 · Reviewed Sep 2026

How does Koi score?

HIGHEST IN GUIDE
Endpoint and agent visibilityWeight 22%9/10

Visibility into models, MCPs, extensions and packages on the endpoint, with risk scoring.

MCP and tool-call controlWeight 20%7/10

Blocks unsafe AI application interactions and prevents prompt injections; tool-call level mechanics not published.

LOWEST IN GUIDE
Policy granularityWeight 15%7/10

Out-of-the-box policies and one-click removal of insecure packages, extensions and AI tools.

Agent vs human identity and auditWeight 12%5/10

Agent vs human attribution not described on the pages we reviewed.

Deployment footprintWeight 13%6/10

Agent-based; offered as a Cortex XDR module and as a standalone offering.

Coverage beyond the endpointWeight 8%7/10

Palo Alto Networks is integrating Koi with Prisma AIRS for wider AI coverage.

Maturity and transparencyWeight 10%7/10

Acquisition completed 14 April 2026 by Palo Alto Networks; pricing not published.

Total

How we score

Where is Koi strongest?

  • Visibility into packages and extensions as well as AI tools (9 out of 10, tied highest).
  • Backing and roadmap of Palo Alto Networks, with Prisma AIRS integration.
  • Fits existing Cortex operations.

What should buyers check before choosing Koi?

  • Agent vs human attribution is not described on public pages.
  • Tool-call level decision mechanics are not published.
  • Product naming and packaging are changing after the acquisition; confirm what is in the Cortex module versus standalone.
  • Pricing is not published.

Who should shortlist Koi?

Shortlist Koi if your security operations already run on Palo Alto Networks Cortex and you want AI agent and extension control inside the same console.

What does Koi cost?

Contact sales. Pricing is not published.

Frequently asked questions

Is Koi still a separate company?

No. Palo Alto Networks completed its acquisition of Koi on 14 April 2026. Koi's website now redirects to Cortex Agentic Endpoint Security.

Do I need Cortex XDR to use Koi?

No. Palo Alto Networks says Koi remains available as a standalone offering.

Related

Head to head

Sources