TL;DR: Centralized routing, runtime policy enforcement, audit logs, and least-privilege controls are being positioned as core safeguards for autonomous agents that process trillions of tokens per month, according to Palo Alto Networks, with Portkey set to become the AI Gateway for Prisma AIRS. The move signals that AI agent governance is shifting from pilot oversight to production identity control.
Editorial analysis by NHI Mgmt Group, based on content published by Palo Alto Networks: “Palo Alto Networks to Acquire Portkey to Secure the Rise of AI Agents”.
By the numbers:
- Palo Alto Networks says Portkey can achieve 99.99% uptime for autonomous workloads through semantic routing and automated failovers.
- Palo Alto Networks says enterprises can access over 3,000 LLMs and MCP tools via a unified interface.
Key questions
Q: How should teams govern an open-source AI agent that can execute tools and touch internal systems?
A: Teams should treat an agent harness as privileged software, not a chat interface.
Q: Why do autonomous AI systems create more identity risk than normal automation?
A: Normal automation follows a fixed path, but autonomous systems can interpret goals, choose actions, and continue without waiting for a person.
Q: What failure mode does an AI gateway help prevent in production agent deployments?
A: It helps prevent unrestricted agent reach into tools, models, and data sources by putting policy checks and logging in the execution path.
Practitioner guidance
- Define an AI agent authorisation boundary List every tool, data source, and action an autonomous agent can reach, then decide which ones require runtime enforcement at the gateway versus downstream controls.
- Classify agents as non-human identities Assign ownership, lifecycle, and revocation responsibility to each agent identity so access does not survive beyond the task or deployment that justified it.
- Instrument transaction-level audit trails Capture the agent request, tool invocation, routing decision, and policy outcome in logs that can support incident review and access attestation.
Bottom line: Autonomous agents create an identity governance problem because they can combine access, tool use, and execution timing at runtime rather than following a fixed workflow.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agent governance is becoming identity governance. Once AI systems can call tools, move data, and chain decisions across environments, the governance question stops being model quality and becomes authorisation scope. That means the relevant control surface is no longer just the application layer but the identity and transaction layer where access is granted, inspected, and constrained. Practitioners should read this as a shift from AI usage policy to operational access control.
A few things that frame the scale:
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What should organisations do when AI agents become part of the production control plane?
A: They should assign clear identity ownership, define which actions require runtime authorization, and make auditability part of the architecture rather than an afterthought. In practice, that means treating agent access like privileged access with lifecycle controls, not like a simple app integration.
👉 Read our full editorial: Palo Alto Networks Portkey acquisition raises the bar for AI agent governance