Check Point Software launches Check Point AI Network Firewall, a new feature in firewall software R82.20 that gives security teams greater visibility and control over how AI is used in an organization’s network. The solution builds on the company’s AI Defense Plane and requires no new infrastructure.
The rapid evolution of AI has given rise to a new type of network traffic that traditional firewalls were never designed to handle. Prompts, autonomous agent actions, and sensitive business information now move between users, applications, and AI services. The new software protects this traffic directly within the firewalls that organizations already use, without the need to rebuild their infrastructure or implement separate systems.
– AI is changing the corporate network and with AI Network Firewall we are changing the firewall so that it can protect it, says Nataly Kremer, Product Manager at Check Point. The network is the common hub for prompts, model calls, and agent interactions. The problem is that traditional firewalls are not built to identify or control this type of traffic. By building AI security into the firewall that organizations already use, we give security teams the visibility and control they need to safely deploy the technology in real time.
The background is a rapidly growing risk picture. According to Check Point Research The AI Security Report 2026 finds that between 87 and 93 percent of organizations experience at least one high-risk interaction with generative AI each month. Meanwhile, the proportion of prompts containing sensitive corporate data, personal data, or regulated information has doubled in a year to 1 in 25 interactions.

AI Network Firewall becomes part of Check Point's comprehensive AI Defense Plane, providing unified protection for AI across networks, endpoints, clouds, applications and APIs. For customers with Check Point Firewalls This means protection in three areas: employee AI use, AI tools like Model Context Protocol, and AI applications and large language models where attempts at prompt injection and other malicious input can be stopped before they reach the model.

Together with Check Point's central policy management for SASE and SD-WAN, the solution will provide unified protection in hybrid, multi-vendor environments.








