The security boundary moves from words to actions
Check Point introduced AI Defense Plane in March 2026 as a control layer for AI used by employees, applications and agents. Traditional protection focused on harmful input or an unsuitable reply; an agent can open a database, call a tool, change a record and start another workflow. The questions now include what it may do, with which data and under whose responsibility.
The architecture combines discovery, policy, runtime monitoring, continuous assessment and offensive testing. Employee chat, a public AI application and an autonomous agent's permissions are distinct problems with different data, response times and owners despite the common product name.
First discover where AI is running
Employees may use unapproved web services while teams deploy their own models and frameworks. This shadow AI hides the paths by which information leaves an organisation. An inventory needs the model, application, owner, data, tools and identities or policy covers only what is already known.
Discovery also needs priorities: a harmless experiment differs from an agent accessing customer or financial data. Value depends on integrations with clouds, identity, endpoints and networks, while avoiding a new repository that concentrates sensitive prompts and content.
Prompt injection may arrive in a document
An email, web page or file read by an agent may contain an attacker's instruction that the model mistakes for a legitimate command. Simple banned-word lists cannot solve this indirect prompt injection; systems must distinguish instructions from untrusted data and separately authorise subsequent actions.
Runtime protection inspects input, output and tool calls. Check Point cites decisions in tens of milliseconds and multilingual support, but customers must measure latency, accuracy and false alarms in their own integration, understand why something was blocked and maintain a safe exception process.
Permissions are stronger than a model's promise
No model is infallible, so design must contain the consequences of error. A sales-proposal agent may read approved materials but should not rewrite prices or export the customer database. Every tool must verify identity, scope and context; critical steps need approval, volume limits and an audit trail. Text guardrails complement rather than replace access control.
Multi-agent chains can lose the original human intent and expand authority. A platform must follow the relationship among user, agent, tool and final action across clouds and applications in rules administrators can understand.
Red teaming must be continuous
An AI system changes with its model, prompt, tools and data, so a one-time penetration test expires quickly. Continuous adversarial testing should turn prompt, reasoning or tool-call findings into concrete policies, corrected permissions and regression tests in deployment.
Automation cannot foresee every business consequence. Domain experts must define scenarios such as changing a supplier's bank account or publishing a private document. The strongest programme combines automatic tests, human simulation and reviews of real incidents.
Start without adding another logo to the architecture
Choose one agent process, map its data and tools and define unacceptable actions. Then compare existing identity, cloud, gateway and audit controls with genuinely AI-specific gaps. A pilot should measure discovered systems, policy accuracy, latency and incident explainability so it does not become another console viewed only during audits.
Check Point brings a large customer base and acquisitions including Lakera and Cyata, but integration must be real. Czech customers will also need European data handling, local-system support and capable partners. Measurable risk reduction and manageable daily operation will determine value.
Sources and editorial note
The Jews.cz editorial team prepared this article from the public materials below, distinguishing company claims, independently documented facts and editorial interpretation.



