AI is changing vulnerability discovery from a periodic security exercise into a faster, more continuous race between defenders and attackers. PwC and Palo Alto Networks are preparing to bring a joint Unit 42 Frontier AI Defense service to market. The planned service addresses a growing concern for security leaders: AI could make it easier for attackers to find software flaws, connect smaller weaknesses, and expose gaps that traditional scanning tools may miss.Palo Alto Networks introduced Unit 42 Frontier AI Defense in April 2026. The company positioned it as a service to help organizations understand whether their defenses are ready for AI-powered attacks. The offering combines exposure analysis, an autonomous security blueprint, and agentic defense transformation, delivered through Unit 42 consultants and supported by Palo Alto Networks security tools. PwC’s role would add consulting and cyber risk transformation support to that model.PwC frames the service as a way for CISOs and boards to test existing security programs against faster AI-enabled discovery and exploitation cycles. The point is not necessarily to replace current tools, but to understand where those tools and processes may fall short. PwC describes the planned service as a three-step approach: frontier AI exposure analysis, a threat-driven roadmap, and cyber defense transformation.Traditional vulnerability management has often centered on known CVEs, asset inventories, severity scores, and scheduled remediation windows. Frontier AI adds more pressure. PwC argues that newer AI models are becoming better at reasoning across application stacks, finding software flaws, and chaining lower-severity issues into higher-impact attack paths. Palo Alto Networks has made a similar case, warning that attackers may use AI to automate vulnerability discovery and chaining at a pace that gives defenders less time to respond.Many security teams still manage exposure management, penetration testing, code review, and incident response as separate workflows. AI-enabled discovery pushes those workflows closer together. A weak API, an over-permissioned identity, or a misconfigured SaaS integration may not look urgent on its own. But if AI can quickly test combinations of weaknesses and map workable attack paths, defenders need to know which exposures are most likely to become real problems.That is the gap PwC and Palo Alto Networks appear to be targeting. PwC points to several risk areas the firms are exploring, including over-permissioned identities, insecure APIs, unmanaged SaaS sprawl, model misuse, prompt injection, and other AI-native attack patterns. These are not new problems for security teams. They are becoming harder to manage as AI-assisted development and business-led technology adoption create more systems outside traditional security review