Check Point Software recently announced the launch of what it claims to be the industry’s first AI Network Firewall. This innovative technology introduces AI-specific inspection and control directly into existing firewall infrastructures, negating the need for separate virtual appliances. By embedding these capabilities within their firewall software release R82.20, Check Point aims to address a significant vulnerability in corporate networks: the burgeoning volume of traffic generated by AI systems. This includes user prompts, model calls, and the automated actions of various agents, which often pass through traditional security measures undetected, masking themselves as standard web traffic.
Nataly Kremer, Check Point’s Chief Product Officer, expressed the transformative nature of this launch, stating, “AI is transforming the enterprise network, and with the AI Network Firewall, we are transforming the firewall to secure it.” She emphasized that the network is the converging point for every prompt, model call, and agent interaction. Historically, traditional firewalls have not been equipped to monitor or regulate such activities, creating a critical gap in enterprise security.
Addressing Three Core Areas of Exposure
The AI Network Firewall is designed to tackle three primary areas of potential exposure within organizations:
-
Employee AI Use: This feature enables the firewall to discover both sanctioned and shadow AI tools currently in use, classifying the intent behind different prompts. It has the capacity to block sensitive data from being transmitted outside the network based on those classifications, offering a more nuanced approach than traditional keyword or pattern-based data loss prevention methods.
-
AI Agents and MCP (Model Context Protocol) Traffic: By providing security teams with visibility into which servers and tools are being invoked, the firewall allows for the enforcement of access policies governing these interactions, enhancing overall security.
- AI Applications and Large Language Models: The firewall inspects traffic in real time to identify and block potential threats such as prompt injection and adversarial inputs before they can reach the AI model itself. This is achieved without necessitating any modifications to the application, aiming for seamless integration.
Check Point’s research arm provides data supporting the need for this technology. Their AI Security Report 2026 revealed that a significant portion—between 87% and 93%—of organizations encounter at least one high-risk generative-AI interaction monthly. Alarmingly, the incidence of prompts containing sensitive corporate, personal, or regulated data has doubled year-over-year, now affecting roughly one out of every 25 interactions. Moreover, the report identified security vulnerabilities in 40% of 10,000 MCP servers and unveiled over 15,000 indirect prompt-injection payloads dispersed across public web pages, with approximately 70% of these payloads hidden from human eyes.
Industry Reactions and Insights
The introduction of the AI Network Firewall has elicited varied reactions from industry analysts and partners. Pete Finalle, a research manager specializing in trusted access and network security at IDC, observed that organizations often find themselves compelled to deploy additional, isolated AI security tools, which can exacerbate existing complexities. He noted that the native integration of AI security into established enforcement points is relatively uncommon but leads to notable improvements in visibility, telemetry, security posture, and overall management simplicity.
Similarly, Chris Konrad, Vice President of Global Cyber at WWT, argued that simply instituting policies will not be sufficient to curb the use of shadow AI. Employees are likely to adopt AI tools before security teams can react. He posited that embedding AI visibility and enforcement within trusted infrastructure provides security teams with a practical control point, facilitating AI adoption without impediments.
A Component of a Comprehensive AI Defense Strategy
The AI Network Firewall is part of Check Point’s broader AI Defense Plane, which serves as a unified control layer aimed at managing AI discovery, governance, and protection. This initiative extends across various domains including networks, endpoints, cloud environments, applications, and APIs. Check Point plans to enhance centralized, agent-driven policy management for its SASE and SD-WAN products, along with integrations with third-party micro-segmentation tools like Illumio. The ultimate goal is to enable a singular console that offers consistent policy management and audit trails across on-premises firewalls, cloud firewalls, AWS-native firewalls, SD-WAN, and SASE deployments.
The AI Network Firewall is currently available, marking a significant stride in the field of cybersecurity as organizations navigate the complexities brought on by the increasing integration of AI technologies.