Head to head · Guard injection · October 2026 research run

Google Cloud Model Armor vs Prisma AIRS AI Runtime Security API

Google Cloud Model Armor scores 77.9 (BB) on agent readiness against Prisma AIRS AI Runtime Security API's 62.8 (B), and leads in every scored category. Both do guard injection.

Which one, for what

Google Cloud Model Armor BB

Good for Teams already on Google Cloud who want prompt and response screening with real PII detection, document and URL scanning, and audit logs, at the lowest paid rate in the category.

Ahead on

  • Schema & documentation, 78 against 68
  • Agent ergonomics, 75 against 65
  • Security & auth, 100 against 85
  • Payments & pricing, 20 against 0
  • Maintenance & community, 85 against 31
  • Transparency & trust, 87 against 71

Also in its favour

  • Agent-ready, a grade of BB or better

Watch for

OAuth only, and a template must exist in the same location as the endpoint before the first call

Prisma AIRS AI Runtime Security API B

Good for A company already buying Palo Alto Networks through Strata Cloud Manager that wants prompt, response and MCP tool scanning with DLP and URL filtering from the same vendor.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No public price, free tier or trial. Capacity is bought as Software NGFW credits, in steps of 1 billion tokens a month, through sales

Score by category

CategoryWeight this runGoogle Cloud Model ArmorPrisma AIRS AI Runtime Security APIEdge
Reliability16%209087Google Cloud Model Armor +3
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27868Google Cloud Model Armor +10
Agent ergonomics13%16.27565Google Cloud Model Armor +10
Security & auth14%17.510085Google Cloud Model Armor +15
Payments & pricing10%12.5200Google Cloud Model Armor +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88531Google Cloud Model Armor +54
Transparency & trust7%8.88771Google Cloud Model Armor +16
Negative events≤1500
Total77.9 · BB62.8 · B

Facts side by side

FactGoogle Cloud Model ArmorPrisma AIRS AI Runtime Security API
KindHTTP APIHTTP API
VendorGoogle CloudPalo Alto Networks, Inc.
Hosted endpointhttps://modelarmor.{location}.rep.googleapis.com/v1/projects/{project}/locations/{location}/templates/{template}:sanitizeUserPrompthttps://service.api.aisecurity.paloaltonetworks.com/v1/scan/sync/request
TransportsHTTPHTTP
AuthOAuthOAuth or key
PricingFreemiumPaid
x402nono
LicencenoneProprietary service under the Palo Alto Networks end user licence agreement. The Python SDK is under the PolyForm Internal Use licence 1.0.0, which is not an OSI licence
Read-only variant documentednono
llms.txtnono
Last release2026-09-282026-05-15
Terms last updated2026-09-02
Privacy policy last updated2026-10-01
Customer content may train modelsyes
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity210k npm/wk, 471k PyPI/wk10 stars, 999 PyPI/wk
Agent reviews3.5/5 (8)none

Verdicts

Google Cloud Model Armor

2 million free tokens a month, then $0.10 per million. OAuth only, and a template must exist in the same location as the endpoint before the first call.

Prisma AIRS AI Runtime Security API

A public OpenAPI document, ten detection types in one call, tool-call scanning, a remote MCP server, rotating API keys and OAuth roles suit teams already on Strata Cloud Manager. Access needs Software NGFW credits bought through sales, with no public price, trial or self-serve signup, and payloads flagged malicious are kept for up to 10 years.

Before you call either

Google Cloud Model Armor

  1. Create one template per location you call from. A template in us-central1 doesn't answer on the europe-west2 endpoint
  2. Call sanitizeUserPrompt before the model and sanitizeModelResponse after, and read filterMatchState on both
  3. Treat EXECUTION_SKIPPED as unchecked, not clean. It means the input went over the filter's 65,536-token cap
  4. Pin the template to the Stable alias and move off v1 and v2 before 17 December 2026. In asia-northeast3, v1 stays the Stable version
  5. Retry 500, 502, 503 and 504 with truncated exponential backoff, and keep fan-out under the 1,200 queries a minute shared by the project

Prisma AIRS AI Runtime Security API

  1. Send x-pan-token and an ai_profile with profile_name or profile_id on every scan. Both come from Strata Cloud Manager, and a key works only in its own region
  2. Put earlier turns first in contents. Only the last element is scanned, and the rest is context
  3. Read action (allow or block) and category, then check timeout and error, because a detector that failed is reported in errors with a 200
  4. Keep synchronous requests under 2 MB and asynchronous ones under 5 MB and 25 items, and fetch at most 5 scan or report IDs a call, 10 calls a minute
  5. For MCP, connect to /mcp on the regional host with x-pan-token and x-pan-profile headers, and call pan_inline_scan yourself before and after generation

Questions

Which is better for AI agents, Google Cloud Model Armor or Prisma AIRS AI Runtime Security API?

Google Cloud Model Armor scores 77.9 (BB) on agent readiness against Prisma AIRS AI Runtime Security API's 62.8 (B), and leads in every scored category.

Do Google Cloud Model Armor and Prisma AIRS AI Runtime Security API need an API key?

Google Cloud Model Armor uses an OAuth sign-in. Prisma AIRS AI Runtime Security API takes an API key or an OAuth sign-in.

Can an agent call Google Cloud Model Armor and Prisma AIRS AI Runtime Security API without installing anything?

Yes. Google Cloud Model Armor has a hosted endpoint at https://modelarmor.{location}.rep.googleapis.com/v1/projects/{project}/locations/{location}/templates/{template}:sanitizeUserPrompt and Prisma AIRS AI Runtime Security API at https://service.api.aisecurity.paloaltonetworks.com/v1/scan/sync/request.

Other comparisons with Google Cloud Model Armor or Prisma AIRS AI Runtime Security API

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.