AI Agent Security
AI Agent Security is a Threat Prevention blade that protects your organization’s AI applications from prompt injection attacks and provides content moderation capabilities.
Prompt Injection
Prompt injection occurs when attackers manipulate user input to alter AI behavior, bypass safeguards, or extract sensitive data. Because AI models interpret input as instructions, such attacks can result in unintended actions, including data exposure, service disruption, or application misuse. Prompt injection protection is configured on the Threat Prevention profile. See Configuration of Prompt Injection Protection.
AI Agent Security mitigates these risks using:
-
Advanced filtering and security policy enforcement: Blocks malicious inputs before they reach the LLM and reduces the risk of exploitation.
-
Comprehensive logging: Tracks and audits all interactions for visibility and compliance.
Example Use Case
A bank operates an internal AI-powered assistant that uses the OpenAI API to process customer requests. An attacker attempts to manipulate the assistant with a crafted prompt designed to bypass business rules and obtain unauthorized loan approval. AI Agent Security inspects the prompt, detects the prompt injection attempt, and enforces policy controls to prevent the malicious request from reaching the LLM.
Content Moderation
Content moderation is the process of automatically identifying potentially harmful, sensitive, or unsafe content in AI prompts and interactions. It helps detect topics such as violence, weapons, criminal activities, and other content that may violate organizational policies or safety guidelines. Content moderation is configured directly on the Security Gateway. See Content Moderation.
Scope and Operation
AI Agent Security secures internally developed AI applications that use external Large Language Model (LLM) services, such as OpenAI, Claude and Gemini through developer APIs.
Unlike solutions for public AI web applications, AI Agent Security secures the organization's own AI applications and services. It provides protection for general-purpose consumer LLM web interfaces.
Supported Applications
AI Agent Security supports these applications:
-
OpenAI - Chat Completions, Conversation API, Responses API
-
Azure AI -
services.ai.azure.com -
Azure OpenAI -
openai.azure.com -
Azure API Management - azure-api.net
-
Groq - api.groq.com
-
Mistral AI - api.mistral.ai
-
Together AI - api.together.xyz
-
Fireworks AI - api.fireworks.ai
-
Anthropic - api.anthropic.com
-
Google Gemini - generativelanguage.googleapis.com
-
Cohere - api.cohere.com
-
Perplexity AI - api.perplexity.ai
Limitations
-
AI Agent Security supports text prompts only.
-
AI Agent Security supports a maximum prompt length of 512 KB.
Prerequisites
- Connect your Security Management Server
Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. to the Check Point Portal. See Connecting On-Premises Management Servers and Security Gateways to the Check Point Portal - AI Guardrails license.
- Enable HTTPS Inspection
Feature on a Check Point Firewall that inspects traffic encrypted by the Secure Sockets Layer (SSL) protocol for malware or suspicious patterns. Synonym: SSL Inspection. Acronyms: HTTPSI, HTTPSi. on the Security Gateway. See HTTPS Inspection.
Configuration of Prompt Injection Protection
Step 1: Create an API Key and a Project in the Check Point Portal
-
Log in to the Check Point Portal.
-
From the main menu
, go to AI Security > AI Guardrails. -
In the left navigation pane, go to Settings > AI Guardrails.
The API Access page opens.
-
In Guard API keys, and click Create new API key.
The API key secures the communication between your Security Management Server
Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. and the Check Point Portal.
Note - Make sure you select Guard API key and NOT Platform API key.
-
In the left navigation pane, go to AI Guardrails > Projects, and select New Project.
A project is a logical container for AI applications or integrations. It helps you track performance, monitor security, and compare different AI-powered applications, environments, or components. Projects can help reduce false positives for the AI Agent Security.
The Create project window opens.
-
Enter a name for the project and the relevant tags to identify it.
-
In Policy Details > Assign a policy, select Lakera Default Policy.
Step 2: Configure AI Agent Security in SmartConsole
-
In SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., go to Security Policies > Threat Prevention > Custom Threat Prevention. -
Open the applicable Threat Prevention profile.
-
In the left navigation pane, go to General Policy. In the AI Security section, select AI Agent Security.
The AI Agent Security blade is enabled in the profile. -
In the left navigation pane, go to AI Agent Security.
-
In the AI Agent Security API Key section > API Key field:
-
Enter the new API key that you created.
-
Click Check Key to verify the API key is correct.
-
-
In the Project section:
-
Enter the applicable Project ID.
-
Click Check Project to verify the Project ID is correct.
If the Project ID is correct, you receive a notification that the Project ID matches the API Key.
-
-
Click OK.
-
Install policy.
AI Agent Security is now integrated into the Threat Prevention profile. The Threat Prevention profile now automatically enforces protection against prompt injection threats based on the profile's defined levels of Confidence, Severity, and Performance Impact.
Policy Enforcement
AI Agent Security integrates with the Threat Prevention profiles. After enabling AI Agent Security in a Threat Prevention profile, the profile automatically enforces protections against prompt injection threats based on the profile's defined levels of Confidence, Severity, and Performance Impact.
Content Moderation
To configure content moderation inspection, on the Security Gateway, run:
-
For IPv4:
confp_cli set -p firewall.ipv4.prompt_injection.prompt_injection_moderated_content_enable -v true -
For IPv6:
confp_cli set -p firewall.ipv6.prompt_injection.prompt_injection_moderated_content_enable -v true
Logs
You can view the AI Agent Security logs both in SmartConsole and in the Check Point Portal > AI Security > AI Guardrails > Logs.
The logs in the Check Point Portal provide more detailed information. They include the user prompt and indicate whether the prompt was identified as a potential attack.
Analytics
The Analytics dashboard provides an overview of your AI Guardrails project activity for a selected time period. It includes detailed metrics, trends, and insights that help you monitor application usage, identify threats, and evaluate security posture.
The dashboard presents information such as the total number of requests by type, the number and percentage of requests flagged as suspicious, API request latency, detection activity, and other relevant analytics.
Interactive charts help you identify trends, detection patterns, attack spikes, and changes in suspicious behavior over time.
The dashboard also includes project-level insights, helping you determine which GenAI applications, environments, or components are most exposed to threats.
For more information, see the Analytics documentation.

