Q&A below the video.
Slides are available below the Q&A.
Can we compare AI Firewall Lakera based to Sandblast sandbox in terms of analysis flow?
The analysis flows are quite similar. The main difference is that they inspect and analyze different parts of the connection—Lakera focuses on AI prompts and MCP responses, while SandBlast focuses on files.
How much is possible without SSL-Inspection?
The Workforce AI Security solution requires SSL-Inspection to ensure the HTTPS traffic (default for most popular GenAI apps) is protected. Otherwise without it only HTTP traffic will be protected.
How are the functionalities of AI Network Firewall different from the offerings we have in the AI Security offering ? Or is the same?
The idea is that the firewall is an additional surface where we can provide AI security that complement our offering. So for customers who prefer not to install an agent for example, they will still be able to use the firewall that they already have for prompt content inspection coverage as one example.
How would this work with websites that have ai chatbots? would it block the website?
Actually only the AI chatbot will be blocked! (if matched according to policy). The protection inspects GenAI traffic only, and not the entire website as a whole.
Will it be a new category under URL filtering?
Such a category already exists. However, this is done with Application Control, not URL Filtering.
How is certificate for self-signed AI Sites handled?
It is handled the same way as any other self-signed site today - the certificate must be added to the HTTPS Inspection trusted certificates list.
We need a license for this product?
You will need a license for:
- AI Workforce Security - for securing employee AI tools and DLP
- AI Agent Security - for securing autonomous agents and AI applications
You need at least an NGFW subscription for:
- Discover and control employee usage of Gen-AI Apps
- Protect from malicious usage of Tools (MCP)
What exactly is required to enable AI Security at the firewall level?
The slides below should have enough to get you started. Full documentation is expected with R82.20 goes GA (expected end of August 2026, subject to change).
Does this run on Spark appliances?
These features are only present in R82.20 and above. Spark appliances do not support such versions currently.
The firewall control is only in the access via browser or can control the AI application installed in the user computer? The customer will need extra license for that?
It can capture content from certain desktop apps as well. To be able to see the content within Workforce AI, the customer needs to purchase Workforce AI. This will also allow them to use the discovery scanner, the browser extension, the agent etc.
Do we know if all AI applications are made through https traffic that we can inspect? Is there any *proprietary* traffic we will not be able to see?
The number of supported AI applications is growing by the day, and will be automatically available with on-going updates 🙂
All major AI applications are supported of course.
How will it be licensed?
Hi - For AI Workforce Security - per seat license, same as we currently license it. AI Agent security -per tens of millions of prompts - again same licensing we currently offer. The licensing structure is the same. And customers can use multiple enforcement points with the same license, so you have a lot of flexibility
For the AI security blade is this only for inbound traffic to an application?
It's not really a blade since this is being done in the context of Application Control.
Guardrails protect the apps and AI agents that the org manages itself - whether in SaaS or in the data center. Which means we support inbound and outbound to/from your agents and apps.
If a customer purchases for example lakera, they will be able to use it from platform.lakera.ai as well as on the firewall right?
The Lakera offering does not include these features, you would need to purchase AI Workforce Security and/or AI Agent Security.
I expect the AI vendors to use cert pinning in the future. Do you see this also coming?
It's something we are tracking.
Can this follow people who are connected via Harmony SASE?
Yes, as SASE Internet Access
Now IPS often blocks connections from users using Claude Code or OpenAI Codex because it sees it als code injection. Will this be smarter and will it prevent IPS from blocking it?
These are separate inspection engines. The AI Firewall performs AI-specific prompt analysis, while IPS continues to apply its own protections independently, so this capability will not directly change or suppress IPS detections. Either exclude them or reach out to TAC to see whether the relevant protections can be refined.
Network firewalls work on real-time flows. What about batch AI jobs, scheduled inference, or async processing? Are we blind to those?
At some point the jobs, even if batched, will reach the LLM. At this point the AI Firewall will see the traffic and be able to inspect it.
Can i block chatbot free version but allow enterprise version? example ChatGPT
Yes!