Opens in a new tab

Why AI agent traffic is invisible to most enterprise firewalls

  • Home
  • Blog
  • Why AI agent traffic is invisible to most enterprise firewalls
Glowing blue data streams of AI agent traffic crashing through an enterprise firewall shield

Security teams can now see what their AI agents are doing across connected systems, because a new class of network firewalls is starting to inspect agent traffic inside the infrastructure enterprises already run. A recent study found that 48.9% of organizations have no visibility at all into the machine-to-machine traffic their AI agents produce, a gap that matters as agents handle purchasing, customer interactions and multi-step tasks without a person approving every move.

Why traditional firewalls cannot read agent traffic

Legacy web application firewalls and basic API gateways were built around attack signatures, rate limits and predictable human sessions. An autonomous agent can improvise a new sequence of otherwise legitimate requests without matching any known signature, so these tools have no rule to fire on. A log entry showing that one service contacted another cannot, on its own, explain whether the agent was following the company’s instructions.

Encryption makes the problem worse. Agent traffic traveling over HTTPS is encrypted, so a firewall needs the right certificates and policies in place to decrypt it before any inspection is possible. Even after decryption, exposing the text of a prompt is not the same as understanding whether the instructions are safe. A readable prompt and an understood prompt are different things.

Two meanings of AI firewall

The term covers two very different products. An AI-powered firewall uses machine learning to detect ordinary network threats, such as malware and intrusion attempts. A firewall built to protect AI inspects prompts and agent interactions for AI-specific harm, including prompt injection, where a document or webpage is crafted to give an agent instructions its owner did not intend.

That second category is where the visibility gap sits. Prompt injection has been used in recent attacks against coding agents, where a hostile input embedded in source code or documentation steers the model off course. Catching that requires looking inside the prompt, not just at the connection.

What Check Point’s AI Network Firewall does

Announced in July 2026, Check Point’s AI Network Firewall adds AI-specific inspection to a company’s existing firewall deployment. The company says it discovers and classifies employee use of generative-AI tools, AI agent activity and Model Context Protocol traffic, then applies real-time inspection to that activity. Model Context Protocol, or MCP, is the industry standard for connecting agents to external tools and data sources.

The product is designed to flag sensitive data heading toward a public AI tool and to catch manipulated prompts that try to trigger unintended behavior. Its broader AI security stack pulls in technology from Lakera, the AI security startup Check Point acquired in 2025, which supplies runtime protection against prompt attacks.

The deployment model is the differentiator. Customers can use their existing firewall infrastructure without adding new hardware or software, which means security teams can start governing AI traffic without standing up a separate system.

What Nightfall AI’s Firewall for AI does differently

Nightfall AI’s Firewall for AI takes a standalone approach. The company describes it as a client wrapper around generative-AI interactions, using APIs and software development kits to inspect content before it reaches a model. It scans for personally identifiable information, payment-card details, health information and secrets, and removes sensitive material before the application forwards a prompt. Nightfall also offers prompt-injection protection and conversational guardrails as separate products.

Those checks look at conversation content and at signals such as model-response refusals, rather than only at sensitive-data categories. Finding a payment card number and recognizing an attempt to redirect a model are different security tasks, so the two products end up reading agent activity in different places.

What the difference means in practice

The two approaches are not in a race to be more advanced. Check Point’s view is that AI-specific protection belongs inside infrastructure a company already runs. Nightfall’s view is that AI interactions warrant a dedicated layer within application workflows. For security teams choosing between them, the practical questions concern coverage, intervention and policy enforcement.

An integrated control suits established operations, and an application-level wrapper offers developers a specific point for filtering model-bound data.

Tooling that connects an instruction to an action and applies policy before harm occurs is the meaningful advance.

FAQ

What percentage of organizations cannot see their AI agent traffic?

According to a recent study cited in the source material, 48.9% of organizations have zero visibility into the machine-to-machine traffic their AI agents generate.

How is a firewall built to protect AI different from an AI-powered firewall?

An AI-powered firewall uses machine learning to detect conventional network threats like malware and intrusion attempts. A firewall built to protect AI inspects prompts and agent interactions for AI-specific harm, including prompt injection, where crafted input turns a document or webpage into instructions an agent follows.

What is Model Context Protocol?

Model Context Protocol, or MCP, is the industry standard for connecting agents to external tools and data sources. Check Point’s AI Network Firewall classifies MCP traffic alongside other agent activity so it can apply real-time inspection.


This article summarizes reporting from thenextweb.com.

← All Articles