We’re pleased to announce that after two months in public preview, Cortex Data Security is now generally available. And we’re already looking ahead to the comprehensive platform’s next stage: Our October release will include two new capabilities, DLP Harmonization and Unified DDR, further advancing our vision for unified data protection across cloud, legacy, and AI infrastructure.
Updating the Data Security Paradigm for the AI-Enabled Enterprise
AI transformation is still top of mind for the organizations we help protect. Autonomous agents are becoming further embedded into operational processes – from coding, through business automation, to customer-facing interfaces. And with this proliferation of agents, data flows are far less predictable and exponentially faster. As such, to prevent sensitive data exposure, security must adapt.
In this new era, visibility is not enough. What’s needed is a unified operating model for protecting data across posture, prevention, and response. With a unified paradigm in place, policies, detection, automation, and AI-powered remediation all feed from a single source of truth – updated in real time and faithful to the organization’s reality. Teams can then proactively monitor and respond to data security incidents at agent speed and with end-to-end context.
Cortex Data Security was designed to provide that foundation at a scale that’s needed to support the world's largest, most data-intensive organizations. As a unified platform, it brings together core data security capabilities – discovery, classification, posture and compliance, remediation, and more – applying them universally wherever data is stored, accessed, or used by human actors or AI agents.
Bolstering Platform Capabilities
After positive feedback during its public preview period, Cortex Data Security, as mentioned earlier, is now generally available.
In our public preview announcement, we introduced the platform’s initial set of features and capabilities. These included DSPM-powered discovery and classification of sensitive data across cloud, SaaS, AI, and on-premises environments; a unified DLP and DDR experience for Cortex XDR customers; AI lifecycle security that maps and monitors models, agents, and the data flows between them; agentic automation with integrated SOAR, including natural language investigation and remediation through XSOAR and AgentiX; and access governance for every identity that interacts with sensitive data – be it human or nonhuman, including AI agents.
The October addition of two new strategic capabilities – DLP Harmonization and Unified DDR – will significantly expand how Cortex Data Security unifies policy visibility and detects and responds to data threats.
DLP Policy Harmonization
Data loss prevention (DLP) is one of the main sources of policy sprawl and repetitive work for security teams. DLP policies tend to multiply across every surface that needs to be protected – legacy tools used in on-premises environments, point solutions for web browsers and email clients, and modern tooling adopted during the cloud transformation era. Each tool might support different conventions and levels of automation, and keeping policies aligned and up to date is a labor-intensive activity that often falls by the wayside. Policy inflation also leads to alert inflation, making remediation more difficult than necessary.
Cortex Data Security aims to be the single source of policy truth for an organization, regardless of where the rules were originally defined. As a first step in that direction, users will be able to view, normalize, and enrich policies from Microsoft Purview and from Cortex Endpoint DLP. This will enable them to spot duplicate policies, optimize rules, and identify gaps in data protection across their organization.

Unified DDR
Pioneered by Palo Alto Networks, data detection and response (DDR) has become an industry standard for data security products. With the upcoming October release, Cortex Data Security will include Unified DDR to enable near-real-time detection and response to data security incidents across cloud data stores, SaaS, and AI infrastructure.
The platform will centralize a host of DDR alerts – including anomalous logins, training data poisoning, data exfiltration, and dozens of other detections – in a unified dashboard across SaaS, cloud, and AI infrastructure. Each alert will be enriched and contextualized with the insights generated by Cortex Cloud DSPM (posture and data classification) and by identity data via IdP integrations. Powered by our proprietary AI and ML models, Cortex will use this entire context to surface the most relevant incidents within seconds, or minutes, without overwhelming security and ops teams with false positives.
More to Come
General availability marks an important milestone for Cortex Data Security, but it’s only the beginning. With DLP Harmonization and Unified DDR coming in October, we’re continuing to expand the platform’s coverage, integrations, and ability to help security teams detect and respond to data risk faster. As the AI transformation continues to gain momentum, data will remain a major focus for organizations. The Cortex platform plays a key role in enabling this transformation and in reducing the risks of AI adoption.