Check Point Software Technologies announced the Check Point AI Network Firewall, delivered as part of Check Point firewall software release R82.20. AI has introduced a new class of network traffic — prompts, autonomous agent actions, and sensitive business context — that traditional firewalls were never designed to see or secure. The AI Network Firewall closes that gap from the Check Point firewall organizations already run, delivered through Check Point's AI Defense Plane with no new infrastructure and no rearchitecting.
“AI is transforming the enterprise network, and with the AI Network Firewall, we are transforming the firewall to secure it,” said Nataly Kremer, Chief Product Officer at Check Point. “The network is where every prompt, model call, and agent interaction already converges, yet traditional firewalls were never built to see or govern that activity. By bringing AI security into the firewall organizations already run, we give security teams the visibility and control to enable AI adoption safely, in real time.”
“Organizations are challenged to deploy dedicated AI security solutions, which are additive to their existing security architecture – contributing to the sprawl of dis-jointed, siloed security tools and agents,” said Pete Finalle, Research Manager, Trusted Access and Network Security at IDC. “While rare, the native integration of AI security across existing enforcement points, provides improvements to visibility, telemetry effectiveness, security posture, and management simplicity.”
Turning existing firewalls into immediate AI protection
Unlike alternatives that require a separate virtual firewall deployed alongside existing infrastructure, Check Point delivers this protection directly from the physical or virtual firewalls customers already operate and scales across branches, data centers, cloud, and multi-cloud environments. For Check Point firewall customers, the AI Network Firewall turns existing firewall investments into immediate AI protection across three domains:
· Employee AI use: Discover AI apps, agents, and tools in use — both shadow and sanctioned — gain visibility into how AI is being used and prompt use-cases and intents, govern access to safe and sanctioned tools, and stop sensitive data from leaving the network based on the prompt's use case. Check Point Research found organizations now run an average of ten AI applications per month, many outside any formal process
· AI Tools (MCP): Discover Model Context Protocol (MCP) communication, gain full visibility into servers and used tools, and enforce policies to control access across every interaction. Check Point Research found security weaknesses in 40% of 10,000 MCP servers reviewed
· AI Application and LLM: Prevent prompt injection and adversarial inputs, blocking malicious prompts before they reach the LLM. This happens inline, with no application changes required. Check Point Research identified 15,300 indirect-injection payloads planted in public web pages, roughly 70% of them hidden in parts of the page no human ever sees
Part of the AI Defense Plane: one architecture across the enterprise
The AI Network Firewall becomes part of Check Point's AI Defense Plane, a unified control plane for discovering, governing, and protecting AI across the network, endpoints, cloud, applications, and APIs. Together, the AI Defense Plane delivers:
· Discovery, governance, and protection for AI across web, desktop, coding assistants, and AI agents
· Local AI agent discovery and control
· SaaS AI agent discovery and control
· Runtime protection and governance for AI applications
· Risk detection and guardrails to protect homegrown and deployed AI
Additional enforcement points across the AI Defense Plane span standalone API for self-managed applications, endpoint for employees, containerized firewall for AI data centers, and WAF - giving organizations consistent AI security across public and private clouds, branch offices, remote users, and data centers.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




