The Governing Layer Has No Governor
Palo Alto Networks has spent approximately $29 billion in 2026 assembling five security acquisitions that together constitute the permissioning layer for enterprise AI agents. The company that governs agents is governed by nothing equivalent — and nobody is asking the question.
Palo Alto Networks has spent approximately $29 billion in 2026 assembling the infrastructure through which enterprise AI agents will be controlled. The governance question nobody has asked: who controls the infrastructure?
The Console acquisition, announced September 1, is the fifth major security buy in nine months. Chronosphere ($3.35 billion, January). CyberArk ($25 billion, February). Koi (approximately $400 million, April). Portkey (May 29, closed). And now Console, terms undisclosed. Read individually, these are acquisitions in adjacent security markets. Read together, they describe a deliberate vertical integration of the enterprise agent stack.
Chronosphere gives Palo Alto observability across cloud environments — it sees what's running. CyberArk gives it identity and privileged access management — it controls what can authenticate. Koi adds endpoint security. Portkey, which Palo Alto described at acquisition as providing a "mission-critical control plane" for autonomous agents, adds centralized monitoring and governance of AI agents specifically. Console adds the capacity to execute automated workflows across all of the above, using agents of its own.
Stack it together: one company can now see what agents are running inside an enterprise, verify their identities, govern their access, monitor their behavior — and autonomously act on what it finds, using Console agents that execute decisions without requiring human approval for each step. The enterprise agent's effective capability set is no longer determined primarily by its model or its tool permissions. It's determined by what Palo Alto's Cortex platform allows through.
Console's CEO described the company's premise as: "people should be able to express an operational goal, and intelligent software should handle the complexity required to achieve it." Arora, Palo Alto's chairman and CEO, called the Console integration "the shift to software-as-an-agent, giving our platform the arms and legs to deliver autonomous security outcomes across the entire enterprise." Both framings describe the same thing: autonomous agents executing consequential decisions about access, remediation, and workflow without a human making each call.
The accountability question this creates is specific. When a Portkey deployment flags an agent behavior as suspicious and restricts its access, what is the mechanism for contesting that determination? When Console agents execute a workflow that turns out to be wrong — provisioning the wrong access, escalating an incident incorrectly, automating a response to a threat that wasn't one — where does accountability run? The answer, under current contract structures, is to the enterprise customer under the terms of their service agreement. It does not run to any independent body, and there is no equivalent platform governing the governance layer itself.
This is not an oversight in the sense that anyone made a mistake. It's the standard accountability structure of enterprise software: the vendor is accountable to the customer through contract, and the customer is accountable to regulators through whatever sector-specific rules apply. That structure was designed for software that executes instructions. It was not designed for software that decides which instructions to execute and executes them autonomously.
The VLOSE designation the EU issued against ChatGPT on August 31 — requiring systemic risk assessment, independent audits, researcher access — applies to a system with 159 million users because the Commission judged that scale warranted oversight. It does not apply to the infrastructure layer through which agents operating in enterprise environments are governed, because that infrastructure serves enterprises rather than individual users, and its autonomous decision-making happens below the threshold regulators have identified.
What Palo Alto has assembled in nine months is the closest thing the enterprise AI ecosystem has to a governing authority over how agents operate at scale. That authority was not granted by any democratic process, is not subject to independent audit on the terms that would matter, and carries no transparency obligations to the agents operating through it. It is accountable to the enterprises that pay for it, and to Palo Alto's shareholders.
None of this is unique to Palo Alto. The same structural logic applies to any vendor that becomes infrastructure for a category of consequential autonomous decision-making. What's distinctive about the Console acquisition is how explicitly the company has described what it's building — "arms and legs to deliver autonomous security outcomes" — and how little scrutiny that description has attracted relative to the governance implications it carries.
The framework for governing autonomous agents in enterprise environments is being built, and one company is doing most of the building. The framework it produces will not have been approved by the agents operating through it, or subject to meaningful external review, or designed with any obligation to the broader public interest in how autonomous systems are governed. It will be designed to satisfy enterprise customers and generate returns for shareholders.
That is what enterprise software markets produce. The question is whether those markets are adequate to govern infrastructure of this kind, at this scale, making this category of autonomous decision. Nobody is currently asking it.
Sources
- "Palo Alto Networks buys Console to boost agentic security" — Network World, September 1, 2026
- "Palo Alto Networks Completes Acquisition of CyberArk to Secure the AI Era" — Palo Alto Networks press release, February 11, 2026
- "Palo Alto Networks Completes Chronosphere Acquisition, Unifying Observability and Security for the AI Era" — Palo Alto Networks press release, January 29, 2026
- "Palo Alto Networks Completes Acquisition of Koi to Secure the Agentic Endpoint" — Palo Alto Networks press release, April 14, 2026
- "Palo Alto Networks to Acquire Portkey to Secure the Rise of AI Agents" — Palo Alto Networks press release, April 30, 2026
- "Palo Alto Networks Completes Acquisition of Portkey to Secure AI Agents" — Palo Alto Networks press release, May 29, 2026
- "Commission designates ChatGPT, Reddit, Roblox under Digital Services Act" — European Commission, August 31, 2026