By NHI Mgmt Group Editorial TeamBased on Palo Alto Networks: “Palo Alto Networks to Acquire Portkey to Secure the Rise of AI Agents” (April 30, 2026)

TL;DR: Centralized routing, runtime policy enforcement, audit logs, and least-privilege controls are being positioned as core safeguards for autonomous agents that process trillions of tokens per month, according to Palo Alto Networks, with Portkey set to become the AI Gateway for Prisma AIRS. The move signals that AI agent governance is shifting from pilot oversight to production identity control.


At a glance

What this is: This is a product acquisition announcement that frames AI gateways as the control plane for autonomous agents, with the core claim that runtime policy, routing, and least-privilege enforcement must move into the AI transaction path.

Why it matters: It matters because IAM, PAM, and NHI teams will increasingly be asked to govern agent identity, tool use, and transaction-level authorization rather than treating agents as just another application tier.

By the numbers:

  • Palo Alto Networks says Portkey can achieve 99.99% uptime for autonomous workloads through semantic routing and automated failovers.
  • Palo Alto Networks says enterprises can access over 3,000 LLMs and MCP tools via a unified interface.

Context

AI agent governance is becoming an identity and control-plane problem rather than a feature added at the edge of existing security tools. In this announcement, Palo Alto Networks describes Portkey as a centralized AI Gateway for autonomous agents, with runtime enforcement, routing, telemetry, and least-privilege access positioned as the core mechanisms for production use.

The practical issue is that agentic systems do not behave like static workloads. They make repeated decisions, invoke tools, and touch internal and external systems at runtime, which means governance has to move closer to the transaction path if enterprises want visibility, authorization, and auditability without slowing delivery.

For identity teams, the important shift is not the acquisition itself but the architecture it points to. Agent identity, tool access, and policy enforcement are converging into a single operational layer, which is exactly where NHI, IAM, and PAM boundaries start to blur.


Key questions

Q: How should teams govern an open-source AI agent that can execute tools and touch internal systems?

A: Teams should treat an agent harness as privileged software, not a chat interface. That means defining who can connect tools, which actions require approval, how prompts and tool calls are logged, and where execution is allowed. If the agent can edit code or reach internal systems, governance must cover identity, authorization, auditability, and rollback before broad deployment.

Q: Why do autonomous AI systems create more identity risk than normal automation?

A: Normal automation follows a fixed path, but autonomous systems can interpret goals, choose actions, and continue without waiting for a person. That makes intent less predictable and review cycles less useful. The risk increases when the system can broaden scope or trigger actions that affect data, money, or compliance.

Q: What failure mode does an AI gateway help prevent in production agent deployments?

A: It helps prevent unrestricted agent reach into tools, models, and data sources by putting policy checks and logging in the execution path. Without that control point, organizations often discover the problem only after an agent has already taken the wrong action or accessed the wrong system.

Q: What should organisations do when AI agents become part of the production control plane?

A: They should assign clear identity ownership, define which actions require runtime authorization, and make auditability part of the architecture rather than an afterthought. In practice, that means treating agent access like privileged access with lifecycle controls, not like a simple app integration.


How it works in practice

AI gateway control planes for autonomous agents

An AI gateway sits between agent requests and the model, tools, and data sources they consume. In this announcement, Palo Alto Networks describes Portkey as a centralized control plane that can inspect AI traffic, route requests, enforce policy at runtime, and collect audit telemetry. That pattern matters because autonomous agents are not one-off queries. They repeatedly select tools, pass context, and continue execution across systems. The gateway becomes the point where authorisation, data protection, and observability are applied before the agent reaches downstream services.

Practical implication: Treat the gateway as a governance boundary and define which agent actions must be mediated there, not scattered across individual apps.

Least privilege for AI identities and tool access

The article frames autonomous agents as highly privileged insiders, which is the right mental model for risk analysis. An agent that can call tools, move data, and chain actions across systems is effectively holding a non-human identity with a broad blast radius unless access is constrained. Least privilege in this context is not only about model prompts or API scopes. It also includes which tools are exposed, which contexts persist, and whether the agent can reach high-impact actions without step-up control or transaction-level policy checks.

Practical implication: Map every exposed tool and action to an explicit approval or entitlement model before agents reach production systems.

Runtime policy enforcement and audit logs for agentic traffic

Static reviews are too late for agentic systems because many decisions happen during execution, not before it. Runtime policy enforcement is the mechanism that checks behaviour as the transaction unfolds, while audit logs create the trace needed to reconstruct what the agent did, what it touched, and what it was allowed to access. Without those controls, governance is reduced to post-hoc inference from prompts and logs that may not capture the full delegation chain. For AI operations, observability and policy become inseparable.

Practical implication: Design logging and policy so every agent action can be traced to an authorization decision and a specific tool invocation.


NHI Mgmt Group analysis

Agent governance is becoming identity governance. Once AI systems can call tools, move data, and chain decisions across environments, the governance question stops being model quality and becomes authorisation scope. That means the relevant control surface is no longer just the application layer but the identity and transaction layer where access is granted, inspected, and constrained. Practitioners should read this as a shift from AI usage policy to operational access control.

Least privilege loses precision when the actor is an autonomous agent. The article describes agents as highly privileged insiders, and that framing matters because an agent can change its path at runtime in ways a provisioning-time role model cannot fully predict. Access can no longer be assumed to remain stable long enough to be reviewed in the way human and workload identities are reviewed. The implication is that governance has to measure action boundaries, not just assigned entitlements.

Identity security for AI will converge with gateway architecture. If an AI gateway is where routing, telemetry, and runtime policy all meet, then the gateway becomes the practical control plane for AI identity. That convergence will push IAM, PAM, and NHI teams into shared ownership of agent access, because the same request may involve model invocation, tool use, and data retrieval in one transaction. Practitioners should expect control ownership to shift toward runtime mediation rather than static configuration alone.

Ephemeral model access does not eliminate persistent governance debt. A system can hide complexity behind low-latency routing and still leave unresolved questions about who owns agent credentials, which tools are exposed, and how delegated actions are revoked. That is the governance debt this announcement highlights: faster agent deployment increases the number of identity decisions that must be controlled, audited, and offboarded cleanly. Practitioners should treat AI scale as an identity lifecycle problem, not merely an infrastructure one.

From our research library:

What this signals

AI gateways will become the mediation layer for agentic access. Once agents are allowed to reach internal and external systems, the useful governance question is no longer whether the model is safe in isolation. It is whether the gateway can mediate every tool call, enforce policy before execution, and preserve enough trace data for identity review and incident reconstruction.

Ephemeral access will not solve autonomous behaviour. Even when agent sessions are short-lived, the governance challenge remains because the risky event is the decision itself, not just the duration of the credential. The control target shifts from long-lived secrets to runtime authorization, which is why identity teams should expect deeper involvement in AI architecture decisions.


For practitioners

  • Define an AI agent authorisation boundary List every tool, data source, and action an autonomous agent can reach, then decide which ones require runtime enforcement at the gateway versus downstream controls.
  • Classify agents as non-human identities Assign ownership, lifecycle, and revocation responsibility to each agent identity so access does not survive beyond the task or deployment that justified it.
  • Instrument transaction-level audit trails Capture the agent request, tool invocation, routing decision, and policy outcome in logs that can support incident review and access attestation.
  • Separate developer speed from privileged access Use quota, approval, and step-up controls for high-impact tools so rapid iteration does not become unrestricted production authority.

Key takeaways

  • Autonomous agents create an identity governance problem because they can combine access, tool use, and execution timing at runtime rather than following a fixed workflow.
  • The announcement points to AI gateways becoming the place where runtime policy, telemetry, and least-privilege enforcement meet for production agent traffic.
  • IAM and PAM teams should prepare to govern agent identity, not just model access, because the control surface now includes every AI transaction.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centers on autonomous agents acting with privileged access and runtime authority.
Recommendation — Constrain agent identity, privilege, and tool access at the runtime mediation layer.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe announcement frames AI agents as privileged insiders with broad access scope.
NHI-04 — Insecure AuthenticationAgent-to-tool transactions depend on how the AI identity is authenticated and authorised.
Recommendation — Review every agent entitlement for overprivilege before allowing production access. Require strong authentication and explicit trust boundaries for every agent identity.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementAgent credentials and tokens need lifecycle management and revocation discipline.
Recommendation — Apply authenticator lifecycle controls to AI agent credentials and revoke unused access.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementOver-privileged agent access can enable broad credential exposure and movement across systems.
Recommendation — Map agent abuse paths to credential access and lateral movement to improve detection.

Key terms

  • AI Gateway: A control point that sits between AI applications and the models, tools, or data they call. In practice, it can authenticate requests, enforce policy, inspect runtime behaviour, and stop unsafe actions before they spread into connected systems.
  • Agent Identity: An agent identity is the set of attributes, credentials and permissions assigned to an autonomous software entity. It is treated as a non-human identity because it can authenticate, act on systems and accumulate access over time, which creates governance, audit and lifecycle obligations similar to other production identities.
  • Runtime Policy Enforcement: Runtime policy enforcement evaluates a request at the moment it is executed instead of relying only on preconfigured permissions. For AI agents, this allows decisions to reflect current context, target sensitivity, and behavioural signals rather than static assumptions.
  • Agentic Traffic: Traffic generated by software that can act on behalf of a user or process with some degree of independent decision-making. In fraud prevention, it includes both legitimate assistants and malicious automation, so the control question becomes intent and behaviour, not automation alone.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org