
Readers can now see what their AI agents actually do across connected systems, because a growing class of AI-specific firewalls is starting to inspect prompts and agent traffic inside the infrastructure enterprises already run. Nearly half of organizations (48.9%, according to one recent study) have zero visibility into the machine-to-machine traffic their autonomous agents generate, leaving security teams unable to confirm whether agents are staying within their instructions.
Why traditional firewalls miss agent traffic
Legacy web application firewalls and standard API gateways were built around attack signatures, rate limits, and predictable human sessions. An AI agent can improvise a new sequence of legitimate-looking requests without matching any known signature, so those tools never trip an alarm. The result is a blind spot that grows as agents take on purchasing access to data and online services, customer interactions, and multi-step tasks that no person approves in real time.
Encryption makes the problem worse. AI traffic traveling over HTTPS cannot be inspected without the right certificates and decryption policies in place. Even after decryption, a readable prompt is not the same as an understood one: exposing the text does not confirm whether the instructions are safe.
Two different meanings of “AI firewall”
The term covers two unrelated products, and confusing them costs organizations time.
- An AI-powered firewall uses machine learning to detect conventional network threats.
- A firewall built to protect AI inspects prompts and agent interactions for AI-specific harm, such as prompt injection that turns a document or webpage into instructions an agent will follow.
The gap that matters for agent oversight sits in the second category, because prompt injection can hijack an agent through otherwise legitimate inputs, the same mechanism used in recent attacks against coding agents.
Check Point’s approach: inspection inside existing infrastructure
Announced in July, Check Point’s AI Network Firewall adds AI-specific inspection to the firewall infrastructure enterprises already operate. The product discovers and classifies employee use of generative-AI tools, AI agent and Model Context Protocol (MCP) activity, and traffic to and from AI applications. MCP is the industry standard for connecting agents to tools and data. It then applies real-time inspection to flag sensitive data heading toward a public AI tool or a manipulated prompt attempting to trigger unintended behavior.
Check Point’s broader AI security stack incorporates technology from Lakera, the AI security startup acquired in 2025, which supplies runtime protection against prompt attacks. The deployment model is the differentiator: customers use their existing firewall infrastructure without new hardware or software, bringing AI controls into the management environment security teams already run.
Nightfall’s approach: a wrapper at the application layer
Nightfall AI’s Firewall for AI takes a different route. It is a standalone client wrapper around generative-AI interactions, using APIs and software development kits to inspect content before it reaches a model. The product scans for personally identifiable information, payment-card details, health information, and secrets, allowing sensitive material to be removed before an application forwards a prompt. Nightfall separately offers prompt-injection protection and conversational guardrails, which address conversation content and signals such as model-response refusals rather than sensitive-data categories alone.
Finding a payment card number and recognizing an attempt to redirect a model are different security tasks, which is why the two vendors package them separately.
What the two approaches mean for buyers
Check Point’s position is that AI-specific protection belongs inside infrastructure a company already runs, while Nightfall’s position is that AI interactions warrant a dedicated layer within application workflows. Neither placement, by itself, guarantees that every relevant interaction will be inspected. For organizations that need to protect AI systems, the practical questions concern coverage, intervention, and policy enforcement, not which product approach seems freshest.
An integrated control may fit established operations, while an application-level wrapper gives developers a specific point at which to filter model-bound data. A business that cannot observe its agents’ interactions cannot confidently assess whether those agents are staying within their remit. The meaningful advance will be tooling that connects an instruction to an action and applies policy before harm occurs, rather than logging the traffic after the fact.
FAQ
What percentage of organizations cannot see their AI agent traffic?
One recent study found that 48.9% of organizations have zero visibility into the machine-to-machine traffic their AI agents generate.
Why can’t traditional firewalls monitor AI agents?
Legacy web application firewalls and API gateways were built around signatures, rate limits, and predictable human sessions. Agents can improvise new sequences of legitimate requests without matching a known attack signature, and encrypted HTTPS traffic requires decryption before any inspection is possible.
How does Check Point’s AI Network Firewall work?
Announced in July, the AI Network Firewall adds AI-specific inspection to existing firewall infrastructure. It classifies generative-AI use, AI agent and Model Context Protocol (MCP) activity, and traffic to and from AI applications, then inspects that traffic in real time. It incorporates technology from Lakera, which Check Point acquired in 2025 for runtime prompt-attack protection.
This article summarizes reporting from thenextweb.com. See our editorial disclaimer for how our articles are produced.
Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.