AI Security, Governance and Assurance · Identity and Access Management · Data Security and Protection

Palo Alto's Portkey Buy Stakes the Gateway, Not the Product

Palo Alto Networks is buying Portkey for a reported $700M. The platforms aren't buying AI security. They're staking primitives. Two are now spoken for.

By Tal Eliyahu · · 9 min read

Editorial technical diagram for Palo Alto's Portkey Buy Stakes the Gateway, Not the Product
A clean runtime access control showing Workload, Credential Broker, Vault, Policy, and Audit Trail as connected parts of the story. CyberBiz

Palo Alto Networks is not buying an AI security product. It is staking a primitive.

On April 30, 2026, Palo Alto announced its intent to acquire Portkey — an AI Gateway company whose platform routes and policies traffic across more than 3,000 large language models for enterprise customers. The deal value was not officially disclosed. Trade press reporting puts it in the $700 million range. Read together with Cisco's Astrix Security acquisition five days later, the cybersecurity platform layer is being redrawn around the AI agent — and the redrawing is happening one primitive at a time.

There are three primitives in the AI-agent stack. Identity. Gateway. Data access. Two are now spoken for. The third is in motion.

Palo Alto pays for the chokepoint, not the product

Portkey provides what the company calls an AI Gateway: a control plane that sits between agentic applications and the language models, vector databases, and tools they call. Every prompt, response, and tool invocation passes through the gateway, where customers apply routing rules, rate limits, redaction, audit logging, and policy.

Workflow diagram for Palo Alto's Portkey Buy Stakes the Gateway, Not the Product
Workflow view of the control path, market pressure, and buyer impact behind Palo Alto's Portkey Buy Stakes the Gateway, Not the Product. CyberBiz

Portkey's customer base reportedly includes more than a thousand enterprises, processing trillions of tokens per month, per the company's own description. Palo Alto Networks plans to integrate Portkey into Prisma AIRS, the company's AI runtime security platform launched earlier this year.

The interesting move is not adding a product to the portfolio. It is acquiring the chokepoint.

Why the gateway is the natural enforcement layer

The enterprise problem Portkey solves is that AI agents talk to too many things. A single internal copilot might fan out to OpenAI, Anthropic, several open-source models, three vector databases, and a handful of internal APIs in the course of answering one question. Without a gateway, every team builds bespoke routing, falls back manually, and ships code that hard-codes provider keys. That is not a state any large enterprise can stay in for long.

For a cybersecurity platform, the gateway is the natural place to enforce policy. Block the agent from sending personally identifiable information to a third-party model. Force a guardrail check on responses before they reach the user. Audit every tool call. Rate-limit per agent identity. The gateway is the single chokepoint that makes those controls enforceable rather than aspirational.

Palo Alto already had an AI security product line in Prisma AIRS, focused on protecting AI applications from prompt injection, data leakage, and model abuse. Portkey adds the missing primitive: the routing and policy layer through which all the agent's calls actually flow. Without that layer, AI security is a series of bolt-on detections. With it, AI security becomes inline enforcement. That is the difference between a feature and a category.

Three primitives, two now spoken for

Cisco's planned acquisition of Astrix Security, analyzed previously, staked a different primitive: non-human identity. Astrix provides discovery, governance, and lifecycle management for the credentials AI agents use — API keys, OAuth tokens, service accounts, secrets.

Put the two deals next to each other and the architecture becomes clear.

  • Identity. Who or what is acting. Cisco bought into this layer with Astrix.
  • Gateway. Which calls go where, with what policy. Palo Alto Networks is buying into this layer with Portkey.
  • Data access. What the agent can read and write. This layer is still being contested by security platforms and data-governance vendors.

The cybersecurity platform layer for AI agents is converging on those three primitives. Hyperscaler-backed and large-cap security vendors are now buying — not building — those primitives. That changes the timeline for independent AI-security startups in the same categories. The independent gateway thesis is closing. The independent identity thesis is closing. The independent data-access thesis is being contested in real time.

We have seen this before. When the cybersecurity industry settles on the structural primitives of a new platform layer, the platforms acquire those primitives within a 12-to-24-month window. Cloud security ran this playbook between 2019 and 2022 — CSPM, CWPP, CIEM, and CNAPP went from independent categories to platform-owned in less than three years. The AI-agent stack is on the same arc, faster.

Palo Alto's 18-month lead in AI-runtime enforcement

For Palo Alto Networks specifically, this acquisition extends Prisma AIRS from a detection product to an enforcement product. Customers running Portkey already integrate it into their AI applications. Once the integration with Prisma is live, those customers get an AI security platform without changing what is in their application code. That is the hardest part of an enterprise security rollout, and Palo Alto bought past it.

The deal also gives Palo Alto Networks a defensible position in the agentic AI market. Routing and policy data is sticky. Once an enterprise's agents flow through Portkey, switching gateways means re-validating every routing rule, every fallback, and every audit trail. That switching cost is what makes gateway businesses durable.

Cisco does not yet have a comparable AI Gateway asset. CrowdStrike's recent agentic moves are detection-side. Microsoft is building gateway capabilities into Azure AI Foundry, but that is a hyperscaler-platform play rather than a security-platform play. The Portkey acquisition gives Palo Alto Networks roughly an 18-month lead over the other large-cap pure-play security vendors on AI-runtime enforcement. That lead is real, and it will only widen until one of the others picks a primitive of its own.

Buyers should expect AI Gateway and AI security to consolidate into one product

If you are buying AI security tooling in 2026, the acquisition has two practical implications.

The first is that AI Gateway and AI Security Posture Management are about to become a single product, not two product categories. Palo Alto Networks will package Portkey routing with Prisma AIRS detection. CrowdStrike, SentinelOne, and others will do the same once they pick their gateway partner or build internally. Procurement teams that signed standalone gateway contracts in 2025 should expect their renewal cycles to align with platform consolidation pressure. That pressure is structural — it is not a sales tactic.

The second is that model and tool fragmentation makes inline enforcement increasingly important. The number of LLMs, agents, and tools an enterprise integrates is growing faster than the number of security teams. Inline enforcement at the gateway is the only design that scales across that complexity. Detection-only AI security products are about to become a partial solution. Buyers who built their AI security strategy around detection alone should re-open the question.

The remaining AI-security primitives are not yet spoken for

For AI-security founders still building independently, the deal narrows the window in the gateway category and sharpens the question of which adjacent primitives platforms have not yet bought.

Identity, gateway, and data access are now spoken for at the platform level. Adjacent primitives that are still open include agent observability, agent testing and red-teaming, policy authoring tools that work across multiple gateways, and agent-aware DLP. Founders raising in 2026 should map their cap tables against the AI-security categories that platforms have not yet claimed. The categories they have claimed will keep getting compressed.

The second move worth taking seriously is to build for two-platform integration from day one. The customers buying AI-security tooling in 2026 are going to consolidate to one or two platforms within 24 months. Building deep integration with the platform a customer is consolidating to is a higher-leverage product investment than horizontal portability across all platforms.

The third is to read strategic-investment patterns as forward acquisition signals. The Astrix deal and the Portkey deal both rhyme with the strategic-only round XBOW closed days later. Public security vendors investing in private AI-security companies are usually previewing future M&A. Founders raising now should structure the next round with that path in mind.

The signals that complete the three-primitive picture

Three signals over the next two quarters will tell us whether the platform-layer consolidation thesis holds.

CrowdStrike does not yet have a public AI Gateway position. The next agentic acquisition or partnership announcement from CrowdStrike will tell us which primitive they prioritize. Hyperscaler responses will reshape the buyer landscape; Microsoft, Google, and AWS each have an AI Gateway story building inside their platform divisions, and whether they accelerate, partner with security platforms, or stay in their lane is the second signal. The third is pricing on the next AI-security M&A deal. Astrix is reported around $400M. Portkey is reported around $700M. The next deal in any of the three primitives sets pricing comps and tells founders what valuation discipline platforms are willing to apply.

The AI agent is becoming the unit of cybersecurity work — the same way the endpoint became the unit of cybersecurity work in the 2010s. Watch which platform owns which layer of that agent. The next two years of cybersecurity M&A will largely be a story about completing the three-primitive picture.

Two down. One to go.

Frequently asked questions

What is an AI Gateway and why does it matter for cybersecurity?
An AI Gateway is a control plane that sits between agentic applications and the language models, vector databases, and tools they call. Every prompt, response, and tool invocation passes through the gateway. For cybersecurity, the gateway is the single chokepoint where policies — data redaction, model selection, rate-limiting, audit logging — can be enforced inline rather than as bolt-on detections. That is the difference between AI security as a feature and AI security as a category.
How does Palo Alto's Portkey deal compare to Cisco's Astrix acquisition?
The two deals stake different primitives in the same architecture. Cisco bought identity for AI agents (Astrix). Palo Alto Networks is buying the gateway layer (Portkey). A third primitive — data access — is still open. Together these three primitives are how the cybersecurity platform layer is being redrawn around the AI agent. The deals are not coincidence. They are the platforms picking corners.
What does Palo Alto Networks gain that it could not build itself?
Time and customer adoption. Portkey already processes trillions of tokens per month for over a thousand enterprise customers. Building that traction internally would have taken Palo Alto Networks 18 to 24 months and not guaranteed customer migration. The acquisition shortcuts both — it brings the gateway, the customer relationships, and the operational data needed to make the gateway smarter. That kind of head start is rarely available, and when it is, platforms pay for it.
What does this deal mean for independent AI-security startups in the gateway category?
The window for an independent AI Gateway company is closing. Identity, gateway, and data access are now spoken for at the cybersecurity platform layer. Founders building in the AI-security category should look at adjacent primitives that have not yet been bought — agent observability, agent red-teaming, cross-platform policy authoring, agent-aware DLP. The categories the platforms have claimed will keep getting compressed.

Sources

  1. Palo Alto Networks press release: Acquisition of Portkey — Palo Alto Networks
  2. Investor relations release — Palo Alto Networks IR
  3. Securing and Governing AI Agents at Scale Through a Unified AI Gateway — Palo Alto Networks Blog
  4. Palo Alto's $700M-class AI bet on Portkey gateway — The New Stack