What It Takes to Secure Claude Cowork Across the AI Enterprise
Palo Alto Networks introduces Prisma AIRS AI Gateway to secure Anthropic’s Claude Cowork and other AI tools across enterprises, addressing runtime risks and governance gaps not covered by built-in access controls.
AI agents like Anthropic’s Claude Cowork are now performing multi-step workflows across enterprise systems without human oversight, prompting organizations to prioritize deployment. While Anthropic provides role-based permissions, spend limits, and connector restrictions for Cowork, these controls only govern who can use the tool and what they can connect to, not the safety of actions taken during a session. This leaves gaps in data protection and runtime security, as demonstrated by scenarios where sensitive data is exposed or automated workflows are hijacked by malicious instructions embedded in web content. Traditional access controls are insufficient because AI systems dynamically combine models, tools, and data sources at runtime, making it difficult to predict or control outcomes after access is granted.
To address these gaps, Palo Alto Networks’ Prisma AIRS AI Gateway acts as a runtime security layer between enterprise teams and AI model providers such as Anthropic, AWS Bedrock, or Google Vertex. The gateway inspects every request and tool call, detecting sensitive data like financial projections or contract terms, and enforces agent identity controls to ensure traceability of automated actions. It provides audit trails for CISOs and observability for CIOs, including consolidated spending reports and the ability to reroute traffic between providers without disrupting workflows, addressing procurement and compliance needs.
The gateway is designed to scale governance across the entire AI enterprise, not just individual tools like Claude Cowork. As organizations adopt multiple AI assistants—coding tools, SaaS-integrated AI, and custom agents—the challenge shifts from securing one application to managing AI activity uniformly. Palo Alto Networks positions the gateway as a centralized control plane that enforces security policies consistently across all AI interactions, eliminating the need to configure controls separately for each tool.
By deploying Claude Cowork behind the Prisma AIRS AI Gateway, organizations gain runtime security, data protection, and full visibility without altering how teams use the tool. The same gateway secures other AI tools in the environment under identical policies, enabling enterprises to scale AI adoption while maintaining control. Palo Alto Networks emphasizes that the gateway is intended to bridge the gap between pilot-stage AI deployments and secure, organization-wide rollouts.