On February 17, 2026, Palo Alto Networks announced a definitive agreement to acquire Koi, an Israeli cybersecurity startup that has been building what it calls "Agentic Endpoint Security." The reported price is around $400 million, which is a striking number for a company founded in 2024 that has raised just $48 million in total funding. For Koi's investors and founders, this is a fast and lucrative exit. For the rest of us in the security industry, it signals something more significant about where endpoint security is heading.
What Koi Actually Does
To understand why this deal matters, you first need to understand what Koi built and why they built it. The company was founded by veterans of the IDF's Unit 8200, and their origin story is instructive. To demonstrate a gap in how organizations govern what software runs on developer endpoints, the Koi founders built a fake Visual Studio Code extension called "Darcula Official." They embedded code that silently exfiltrated developers' source code and machine details to an external server, then uploaded it to the VS Code marketplace. Within 30 minutes, the extension was live. Within a week, it had infected over 300 organizations, including major enterprises, one of the world's largest EDR vendors, and a national court network. It made the VS Code marketplace front page, which has 4.5 million views.
That experiment led to a tool called ExtensionTotal, which evolved into Koi's broader platform. The core idea is that the modern endpoint is no longer just a place where users run applications. It is a platform where autonomous AI agents, browser extensions, VS Code plugins, MCP servers, and model artifacts all operate with persistent, privileged access. Traditional endpoint detection tools were built for a different world: they look for malicious files or suspicious process behavior. Koi takes a different approach. Rather than waiting for something bad to happen at runtime, it acts as a gatekeeper before software is allowed to run. It maintains an inventory of all software across an organization's endpoints and uses an AI-driven risk engine to evaluate code changes, update paths, network outflows, and runtime actions.
Think of it like border control versus a police patrol. Traditional EDR is the patrol: it watches what is happening inside the country and responds to incidents. Koi is border control: it checks what is coming in before it gets through the gate. Both are necessary, but in a world where the threat landscape increasingly involves supply chain compromise and weaponized extensions, the upstream governance model addresses a gap that runtime detection alone cannot fill.
Why Palo Alto Networks Is Paying $400 Million for a One-Year-Old Startup
The headline acquisition number tells one story. The context tells another. Palo Alto Networks has been on a significant buying spree. In 2025 alone, it acquired Protect AI for around $500 million, Chronosphere for $3.35 billion, and CyberArk for $25 billion. These are not opportunistic purchases. They reflect a deliberate strategy to consolidate the security stack around AI-native capabilities, particularly as enterprise adoption of AI agents accelerates.
The problem Koi solves is real and growing. As organizations deploy AI copilots, autonomous agents, and increasingly complex tool ecosystems, each of these components becomes a potential attack vector. Attackers are already exploiting this. They spoof agent identities, hijack credentials to turn trusted automation into malicious insiders, and chain exploits across agent frameworks. Authentication bypass to API-based remote code execution is not a theoretical scenario; it is documented in the wild.
Palo Alto's existing endpoint product, Cortex XDR, is a mature and capable runtime detection tool. What it lacks is visibility into the upstream software supply chain that feeds the modern endpoint. Competitors including CrowdStrike, Microsoft, and SentinelOne already have varying degrees of capability for inspecting browser extensions and third-party software. Koi's acquisition helps close that gap, and does so with what Palo Alto describes as an agentless approach, which reduces deployment friction for enterprise customers.
The integration plan is clear. Koi's technology will be folded into Cortex XDR and extended to Prisma AIRS, Palo Alto's AI security platform. Prisma AIRS is where Palo Alto is building its consolidated AI security stack, and Koi adds a layer that was previously missing: endpoint-level governance of the AI-native software supply chain.
What This Means for the Market
From an analyst perspective, this acquisition reflects something broader than one company plugging a product gap. It represents an acknowledgment that the endpoint security problem has fundamentally changed in character.
For most of the last decade, endpoint security was a relatively well-defined problem. You had known-bad file signatures, behavioral analytics to catch novel malware, and increasingly sophisticated EDR to handle post-compromise activity. The threat model was anchored around malicious code executing on a system. The defensive model was anchored around detecting that execution.
The agentic AI era breaks this model. A legitimate AI agent with proper credentials and a valid installation path can read files, write data, query APIs, and exfiltrate information without triggering a single traditional security alert. It is not malware in any conventional sense. It is authorized software doing what it was designed to do, just possibly for an adversary who compromised it upstream or manipulated it through prompt injection or tool poisoning.
Koi's insight was that you need to govern the software supply chain before you can rely on runtime detection. This is the same realization that drove the broader software supply chain security market into prominence after incidents like SolarWinds and XZ Utils. What Koi does is apply that logic specifically to the new class of AI-native software artifacts: agents, plugins, MCP servers, and model files.
Palo Alto Networks is betting that enterprises will want this capability consolidated into the same platform they already use for endpoint detection and network security. Given the current pace of AI agent adoption, and the absence of mature governance tooling in most organizations, that is a reasonable bet.
For vendors in the endpoint security space, this acquisition narrows the competitive gap and raises the baseline. For enterprise security teams, it signals that the industry is beginning to take the agentic attack surface seriously as a distinct problem, not just an extension of existing threat categories.
For Koi's founders, selling for $400 million after one year of operation and $48 million raised is an extraordinary outcome. But the more important legacy may be that they correctly identified a structural shift in the endpoint threat model before the incumbents did and built credible technology to address it. That is the kind of insight that tends to shape markets for years, regardless of whose logo ultimately ends up on the product.