Palo Alto Networks
Responses
In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?
The first Global Dialogue on AI Governance will succeed if it establishes Secure AI by Design as a foundational governance principle. Seventy-eight percent of organizations are transforming with AI, but only six percent have strategies in place to do so securely. This gap is not merely a technical shortcoming but a governance failure that the Dialogue should address. While global policy discussions, such as within the G7 HAIP, are largely focused on AI safety and usage risk, they significantly lag in addressing the rapidly escalating cybersecurity threat driven by the malicious use of AI. This growing gap presents a clear risk to safe, secure and sustainable AI adoption. The evolving attack surface of AI systems and agentic tools underscores the critical need for a Secure AI by Design approach. AI governance cannot be credible if it does not account for the cybersecurity of AI adoption, including autonomous attack cycles compressing timelines from days to minutes, with adversaries weaponizing vulnerabilities within fifteen minutes of disclosure. The Dialogue should also commit to a standing workstream on AI cybersecurity governance that bridges existing efforts, including the NIST AI Risk Management Framework, the OWASP Top 10 for Agentic Applications, MITRE ATLAS, ISO/IEC standard, and ETSI EN 304 223 to promote harmonization with relevant frameworks and standards. The Dialogue is uniquely positioned to bridge the exploitable gaps caused by fragmented governance. Finally, the Dialogue should formally acknowledge the unique governance challenges posed by autonomous AI agents, which can access sensitive data, invoke tools, and trigger automated workflows. A successful Dialogue must lay the groundwork for international norms addressing agent identity, accountability, and oversight. If these outcomes are achieved, the Dialogue will signal that the international community is serious about governing AI not only for fairness and transparency, but for security and resilience.
From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?
- Safe, secure and trustworthy AI
- Interoperability of governance approaches
- Transparency, accountability, and human oversight
Please briefly explain your selection.
4
The four selected priorities below most directly address the structural cybersecurity and governance challenges accompanying AI adoption at scale. Safe, secure and trustworthy AI is our foremost priority. Promoting Secure AI by Design requires integrating security controls at every phase of the AI lifecycle. Addressing security in just one phase leaves critical vulnerabilities elsewhere, making it essential to embed safeguards from initial scoping through to continuous monitoring during runtime. AI models are non-deterministic and constantly evolving. This means the threat surface is no longer static; it expands and changes in ways that traditional, rule-based security tools simply cannot match. Interoperability of governance approaches is essential because fragmented regimes create security gaps. The Dialogue should drive alignment across the NIST AI-RMF, OWASP, MITRE ATLAS, and ISO/IEC standards, while harmonizing information sharing requirements that currently consume critical bandwidth from incident responders. Transparency, accountability, and human oversight is critical in the context of agentic AI. As autonomous and semi-autonomous agents proliferate, organizations' security must center on identity-first controls, least-privilege access, scoped tool permissions, separation of duties, and governance over agent-to-agent and agent-to-system communications.
In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.
3
A critical gap in the current thematic framing is the absence of dedicated attention to the cybersecurity of AI itself, and specifically, the governance challenges posed by autonomous AI agents operating across organizational and national boundaries. AI agent systems face fundamentally different security challenges than traditional software due to their autonomous nature and ability to take independent actions. These challenges include prompt injection, which represents a critical difference from traditional systems by blending untrusted data and executable instructions, allowing attackers to manipulate agent behavior using natural language; dynamic tool chaining, where agents select and chain tools at runtime, meaning static policies and predefined allowlists struggle to keep pace; and hallucination-driven actions, where agents can act on incorrect or fabricated information, resulting in flawed decisions and unintended consequences. The multi-agent dimension compounds these risks. Research shows that a single compromised agent can poison eighty-seven percent of downstream decision-making within four hours, and cascading failures propagate faster than traditional incident response can contain them. These are not hypothetical scenarios; they represent emergent risks that no single existing governance theme adequately captures. Additionally, the current themes do not address the unique supply chain risks of AI. Nearly all commercial software incorporates open-source components, and this transparency creates a heightened risk of compromise, with adversaries compromising the AI supply chain and bypassing conventional prevention layers to land inside infrastructure directly. The Dialogue should elevate AI cybersecurity and agentic AI governance as a distinct cross-cutting theme, ensuring that new capabilities around cybersecurity and agentic workflows are secured by design.
How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.
The cybersecurity sector sits at the epicenter of AI governance gaps. In less than three weeks of testing frontier AI models, Palo Alto Networks accomplished the equivalent of a full year's worth of penetration testing effort. These models can analyze the full exposure surface of applications, including logic-based vulnerabilities that traditional tools miss, and can function as full-spectrum security researchers autonomously. This capability is transformative for defenders but equally available to adversaries. Without internationally coordinated governance, organizations face a patchwork of obligations that diverts resources from defense. Incident reporting regimes should strive for reciprocity, avoiding duplicative reports to multiple agencies, and be complementary with existing incident response best practices utilized by industry. The same capabilities that create risk also offer transformative defensive potential. The very models that find and exploit vulnerabilities can also be deployed in defense, but only if they are integrated into comprehensive cybersecurity platforms. We are entering a transition period, and the ultimate goal is a future where AI models identify and fix vulnerabilities faster and earlier than threat actors can exploit them. The Dialogue has an opportunity to accelerate this defensive advantage by establishing governance norms that incentivize Secure AI by Design, harmonize incident reporting, and promote the responsible deployment of frontier AI for defense.
What role can the AI Dialogue play in advancing international cooperation on AI governance?
The Dialogue can serve as the connective tissue between fragmented national and sectoral AI governance initiatives. It should establish shared baseline expectations anchored in four critical security imperatives: securing underlying AI infrastructure and data, safely building and deploying AI applications, securing the use of external AI tools, and monitoring and controlling AI agents. These imperatives are universal regardless of jurisdiction and provide a basis for international alignment. Second, the Dialogue should promote interoperability by encouraging nations to adopt peer-reviewed, industry-validated frameworks rather than creating duplicative regimes. Third, the Dialogue must address the transnational nature of AI agent operations. A key challenge unique to agentic architectures is the "on behalf of" flow, in which an AI agent acts as a delegate of a human user or another agent, often across borders. International norms for agent identity, delegation, and accountability are urgently needed. Finally, the Dialogue should champion information sharing that aligns with best security practices. Descriptions of tactics, techniques, and procedures, and indicators of compromise could help covered entities prevent or mitigate cyber incidents, but this requires trusted, reciprocal mechanisms operating at the international level. The Dialogue can catalyze these mechanisms.
What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?
The Dialogue should build upon established cybersecurity and AI governance initiatives rather than duplicating them. Palo Alto Networks is a founding member of the Joint Cyber Defense Collaborative (JCDC), the U.S. government's primary forum for bringing together public and private sectors to coordinate defensive actions and drive down risk in advance of cyber incidents. The JCDC model is multi-stakeholder, operationally focused, and built on reciprocal information sharing , offering a template for international AI cybersecurity cooperation. Similarly, through the ENISA Cyber Partnership Programme (CPP), Palo Alto Networks participates in a strategic public-private initiative to strengthen cyber resilience across the EU through enhanced information sharing, situational awareness, and coordinated incident response. This partnership supports closer operational cooperation between Member States, EU institutions, and industry, and positions the company at the center of Europe's evolving cyber defense ecosystem. The Dialogue could serve as a neutral venue for public-private collaboration on AI security modeled on these complementary approaches. The Dialogue should also connect with peer-reviewed technical frameworks that already enjoy broad industry adoption to encourage universal adoption.
How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.
The Dialogue should be structured to ensure that cybersecurity expertise, a prerequisite for credible AI governance, is represented at every level. Industry stakeholders should contribute operational threat intelligence and real-world security expertise, and government stakeholders should contribute by harmonizing national AI governance frameworks and information sharing requirements.
Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?
Two communities are critically underrepresented in global AI governance discussions: cybersecurity practitioners and the operators of critical infrastructure who are most exposed to AI-enabled threats.Cybersecurity practitioners — the engineers, researchers, and incident responders who defend organizations daily — possess irreplaceable operational knowledge about AI risks. The key advantage for defenders is the ability to use AI models to swiftly identify, validate, and patch vulnerabilities in near real time. However, these models are not effective as standalone defense systems since they require supporting infrastructure, including sensor networks, AI-enabled data lakes, and consolidated platforms. This operational reality is often absent from high-level governance discussions, which tend to focus on principles rather than implementation. Critical infrastructure operators face the most acute consequences of AI governance gaps. Palo Alto Networks' Unit 42 research team predicts an increase in large-scale supply chain compromises of open-source projects, and critical infrastructure is disproportionately affected by such attacks. These operators must have a seat at the table. Additionally, governance must reflect the perspectives of the full spectrum of AI adopters, not only large enterprises and technologically advanced nations.
What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?
The most effective engagement format for the Dialogue would be operationally grounded exercises that move beyond declarative principles to test governance frameworks against real-world AI threat scenarios. Tabletop exercises simulating AI-enabled cyber incidents should be a cornerstone. Palo Alto Networks' research mapped a realistic end-to-end AI-enabled attack path — from reconnaissance through exfiltration — illustrating how autonomous agents could conduct an entire campaign with minimal human involvement, at a speed and scale that manual triage cannot match. Running multi-stakeholder tabletops based on such scenarios would expose governance gaps in real time and generate actionable recommendations. Red team/blue team demonstrations using frontier AI models would vividly illustrate the stakes. Palo Alto Networks has conducted early testing of the latest frontier AI models through programs such as Anthropic's Project Glasswing and OpenAI's Trusted Access for Cyber program. Sharing findings from these programs in structured Dialogue sessions would ground discussions in empirical evidence rather than speculation. Finally, interoperability hackathons could bring together participants from different jurisdictions to test the compatibility of their AI governance frameworks by identifying gaps, conflicts, and opportunities for harmonization in a practical, collaborative setting.
Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.
2
Secure AI by Design is a comprehensive framework that operationalizes security at every phase of the AI lifecycle, from development through runtime, rather than treating it as an afterthought. The framework is structured around four critical security imperatives: securing underlying AI infrastructure and data through automated posture management and adversarial testing; safely building and deploying AI applications via red teaming and guardrails; securing the use of external AI tools, including shadow AI; and monitoring and controlling AI agents through identity-first controls and least-privilege access.