Check Point Software has announced AI Network Firewall, a new generation of firewall integrated into their R82.20 platform that includes specific capabilities to protect the use of artificial intelligence in corporate networks. The company argues that traditional firewalls were not designed to inspect traffic generated by AI models, autonomous agents, or protocols like Model Context Protocol (MCP), a gap they aim to fill without deploying new infrastructure.
The key points of Check Point’s AI Network Firewall in 20 seconds
- Check Point adds AI-specific protection to its firewall platform R82.20.
- The solution identifies AI applications, agents, MCP servers, and traffic associated with large language models (LLMs).
- The company states it works on existing firewalls deployed by its clients, without the need for new hardware.
- The launch is part of the AI Defense Plane strategy to protect networks, endpoints, applications, and APIs.
- Check Point warns that 87% to 93% of organizations record at least one high-risk interaction with generative AI each month.
The rapid adoption of tools like ChatGPT, Microsoft Copilot, Claude, Gemini, or internal assistants is changing the traffic moving through corporate networks. Users now do more than browse web pages or use SaaS applications—they send prompts, share documents with AI models, run autonomous agents, and connect applications via protocols like MCP.
For cybersecurity manufacturers, this evolution opens a new front: inspecting this traffic without blocking organizations from leveraging AI’s advantages.
The firewall aims to become the AI control point
The main change proposed by Check Point is utilizing the firewall itself as the inspection point for traffic related to artificial intelligence.
Instead of deploying a dedicated AI gateway or an additional firewall, the company ensures that its clients can add these capabilities directly on existing physical or virtual devices, whether in data centers, branch offices, cloud environments, or multi-cloud architectures.
According to the company, the system enables control over three main areas:
- AI usage by employees, identifying authorized applications and shadow AI tools, as well as enforcing policies to prevent leakage of sensitive information.
- MCP servers and tools, providing visibility into communications and controlling access to these environments.
- Applications based on large language models (LLMs), with mechanisms to detect prompt injection attempts and other attacks before they reach the model.
The goal is to provide a single point from which to apply security policies to the increasing volume of traffic generated by AI applications.
Check Point focuses on MCP and the growth of AI agents
One of the highlights of the announcement is the addition of specific capabilities for Model Context Protocol (MCP), initially driven by Anthropic and adopted by an increasing number of platforms to connect AI models with external tools and data sources.
According to Check Point Research, 40% of the 10,000 MCP servers analyzed by the company had some security weakness.
The company also states that organizations currently use an average of ten different AI applications each month, many of which are unmanaged by security teams.
This phenomenon, known as shadow AI, is becoming a major concern for cybersecurity leaders, as employees and departments adopt new tools without following usual validation processes.
From firewall to AI Defense Plane
The new firewall is part of a broader strategy called AI Defense Plane, presented by Check Point as a unified platform to protect AI across various levels of the infrastructure.
Along with the firewall, the architecture includes other control points for:
- Endpoints.
- APIs.
- AI applications.
- Containers.
- Public and private cloud environments.
- Local and SaaS AI agents.
The company aims to deliver consistent security policies regardless of where models or agents run.
Centralized management for hybrid environments
Coinciding with this launch, Check Point is also expanding its centralized security policy management capabilities.
The platform will enable management from a single console of:
- On-premises firewalls.
- Cloud-deployed firewalls.
- Natively cloud firewalls (e.g., AWS Firewalls).
- SD-WAN infrastructures.
- SASE services.
Additionally, integrations with micro-segmentation solutions like Illumio will help keep access policies up to date across hybrid environments.
The goal is to reduce fragmentation often seen when organizations manage separate tools for networking, connectivity, and security.
Rethinking the firewall’s role in the AI era
This announcement reflects a market shift. While firewalls previously evolved to inspect applications, encrypted traffic, or cloud services, vendors now strive to adapt to the growth of generative AI.
Organizations increasingly need to control which virtual assistants their employees use, what data they share with external models, which autonomous agents interact with their systems, and which MCP servers are involved.
Check Point argues that the firewall remains the convergence point for all these communications, making it the most suitable place for security controls. However, once deployed in real environments, it will be interesting to see how effectively these capabilities maintain visibility over the rapidly evolving AI ecosystem, with new models, agents, and protocols emerging almost weekly.
Frequently asked questions
What is AI Network Firewall?
It is a new feature integrated into Check Point’s firewall platform that adds specific controls to protect the use of artificial intelligence within corporate networks.
What threats does it aim to detect?
The solution aims to identify unauthorized AI applications, MCP communications, prompt injection attempts, the leakage of sensitive information, and other risks related to large language models.
Is it necessary to install new devices?
According to Check Point, AI Network Firewall runs on existing physical and virtual firewalls, without requiring additional infrastructure.
What is the AI Defense Plane?
It is Check Point’s security architecture for AI, integrating protection across network, endpoints, applications, APIs, containers, and cloud environments through unified management.
via: checkpoint

