Check Point announced the AI Network Firewall on July 30, 2026, putting prompt- and agent-level inspection inside its firewall software release R82.20 and running it from the gateways customers already operate. The capability is available now.
The gap it targets is one enterprise security teams have lived with since generative AI reached the workplace. A conventional firewall can establish that an employee reached an AI service. It cannot establish what went into the session. Prompts, file uploads, model API calls and Model Context Protocol requests all cross the network as ordinary encrypted HTTPS traffic, so application identification stops at the destination while the contract text pasted into a chat window stays inside the session.
What the firewall now inspects
The AI Network Firewall covers three areas:
- Employee AI use: discovery of the AI applications, agents and tools running on the network, sanctioned or not, with visibility into what prompts are being used for and enforcement that stops sensitive data leaving based on the prompt’s use case.
- AI tools: discovery of Model Context Protocol traffic, an inventory of the servers and tools agents call, and access policy applied to each interaction.
- AI applications and models: inline blocking of prompt injection and adversarial input before it reaches the model, with no change to the application.
The third has the most independent research behind it. Prompt injection ranks first in OWASP’s Top 10 for large language model applications, which distinguishes direct injection from the indirect kind: instructions planted in a web page or document that a model reads later and acts on, in content a human need never see. OWASP’s assessment is that there is no fool-proof prevention for the class, because the behavior follows from the way models process input. Inline network filtering is mitigation applied to traffic the security team already controls.
Check Point Research supplies the demand-side numbers, and they are the company’s own: between 87% and 93% of organizations see at least one high-risk generative-AI interaction each month, the share of prompts carrying sensitive corporate, personal or regulated data doubled in a year to one in 25, and the average organization runs ten AI applications a month, many outside any formal process. The same research reports security weaknesses in 40% of 10,000 Model Context Protocol servers reviewed, and 15,300 indirect-injection payloads planted in public web pages, roughly 70% of them hidden in parts of a page no human reads. Check Point’s 2026 cloud security report made the same argument earlier in 2026 about governance trailing adoption, and shadow AI is the practical form the problem takes inside most companies.
Where it sits in the AI security market
Check Point says it is the first vendor to deliver AI security from the physical firewall itself. Competitors have been building the same controls as separate products: Palo Alto Networks (PANW ) made its Prisma AIRS AI Gateway generally available in July 2026 as a standalone control plane for enterprise AI activity, and venture money keeps landing on agent governance, including Hush Security’s $30 million raise. Model providers are adding equivalent controls at their own layer, with Google now letting developers block Gemini agents’ tool calls. IDC research manager Pete Finalle, quoted in Check Point’s announcement, called native integration of AI security into existing enforcement points “rare,” crediting it with gains in visibility, telemetry and management simplicity.
Coverage follows the gateway. Inspection happens where a Check Point firewall already sits in the traffic path, which is why the company is pairing the release with the other enforcement points in its AI Defense Plane: endpoint enforcement for employees, a containerized firewall for AI data centers, a standalone API for self-managed applications, and a web application firewall.
Why the enforcement point matters
Concentrating prompt inspection in the firewall raises what an attacker gains from owning one. On July 22, 2026, Check Point published a hotfix and advisory for CVE-2026-16232, an authentication bypass in its Security Management and Multi-Domain Management software rated 9.3 out of 10, which the company said it found exploited in the wild against a handful of customers whose management interface was reachable from the internet without IP restrictions. Two further management and gateway flaws were fixed in the same update, with no exploitation reported. That makes the management plane, not just the data path, part of the AI control surface.
Alongside the firewall release, Check Point is extending central policy management to its SASE and SD-WAN products, with zero-trust enforcement reaching across IT, operational-technology and micro-segmentation tools including Illumio, managed from one console with a single audit trail.

