Your Most Valuable Infrastructure Is Also Your Most Exposed.
AI factories with private GPU clusters, LLM training pipelines, and high-throughput inference APIs are the most valuable and vulnerable infrastructure enterprises deploy today. But, today’s legacy data center security systems were never designed to understand AI semantics, or inspect and protect this new and much larger AI attack surface.
The attack surface is scaling with it
Attacks on AI Systems
- Prompt injection & manipulation
- Model theft via API enumeration
- Training data poisoning
- Adversarial input attacks
AI Misuse & Data Risk
- Sensitive data exposed in prompts
- Policy violations & toxicity
- Unintended data exfiltration
- Hallucination in critical workflows
Infrastructure Threats
- Lateral movement inside GPU clusters
- Supply chain & container compromise
- Malicious code in model weights
- Ransomware targeting training data
Secured from Day One. Not Retrofitted Later.
Every layer of the AI factory, from identity to data integrity, is designed secure from day one, not bolted on as an afterthought.
Zero Trust Everywhere
Every user, API call, agent workflow, and non-human identity authenticated, authorized, and continuously validated, including across GPU cluster east-west traffic.
AI-Native Controls
Semantic inspection that understands the intent behind prompts, not just keyword pattern matching. Built into every enforcement point.
Data & Model Integrity
Signed models, monitored training pipelines, and isolated data zones protect proprietary datasets and inference outputs from manipulation.
Red Team AI Stress Testing
AI runtime inspection, automated red teaming, and GPU memory forensics catch new AI vulnerabilities before attackers can exploit them.
AI Factory Security Blueprint: 4 Critical Insights
AI traffic and agents break the assumptions that data center security is built on.
These four insights from Check Point’s Security Blueprint show exactly where, and how to close the gap.
- Rethink the AI threat modelPrivate AI systems will be open to internal systems by design, connected to everything, and never rest. A traditional security stack wasn’t built for that. The risk isn’t just someone breaking in. It’s the AI being turned against the business from the inside.
- Protect internal LLMs, GPU clusters, RAG pipelinesAI agents, private LLMs, RAG pipelines, GPU clusters, and MCP gateways are each autonomous, semantically manipulable, and capable of cascading action. They need protection built for them, not bolted on.
- Extend zero trust to AINever trust, always verify. Least privilege. Assume breach. The principles haven’t changed – but the attack surface has. Check Point extends AI Zero Trust enforcement natively across every layer of the AI stack, from network perimeter to prompt to AI workloads, with no gaps between enforcement points.
- Enforce defense-in-depth across five layersSecure everything. Users. Applications and agents. Network perimeter. AI factory infrastructure. Even your AI workloads and containers — with zero impact on AI performance, because host security runs on the dedicated NVIDIA BlueField DPUs, not on the GPUs.

Check Point Lays the Groundwork with NVIDIA
Learn about the latest advancements in AI Factory security for enterprise private AI systems and internal LLMs
One Security Fabric. Every Layer of the AI Factory Protected.
From the network perimeter to inside each GPU server, five integrated security layers that catch what each other misses and respond as one. Managed centrally via a single control plane with no fragmentation.
Layer 1: AI-Native Application Security
Semantic inspection that understands the intent behind LLM prompts and API calls, not just keywords. Runs natively across Check Point firewalls, WAF, and Workforce AI Security. Embedded, not bolted on.
- API and LLM guardrail enforcement. Blocks exfiltration and policy violations
- Consistent policy across firewall, WAF, and Workforce AI Security with no fragmentation
- MCP traffic visibility for agentic AI workloads

AI Runtime Protection:
Stop AI Threats in Real Time Across Every Prompt, Response, and Agent Action. Enforce inline protection across every interaction without retraining models or slowing performance.
Layer 2: Perimeter & Network Security
Maestro Hyperscale Firewall enforces Zero Trust Network Access at the AI data center edge. Separate Security Groups isolate management, private API, and public inference traffic, so traffic can never cross zones without inspection.
- 1 Tbps network security throughput
- 99.999% system resilience

AI Data Centers Need Maximum Network Security
Maestro Hyperscale is built for the most demanding AI Factories. Provides full redundancy, resilience, and maximum security required for today’s 24×7 high-performance AI workloads.
Layer 3: Host-Level Security on the DPU
AI Factory Firewall runs natively on NVIDIA BlueField DPUs, embedded inside each DGX/HGX server.* Security enforcement at the hardware level, fully offloaded from CPU and GPU.
- Zero impact on token throughput or AI workload performance
- Enforcement runs inside the server before traffic reaches compute resources
- 40 Gbps firewall throughput; 3.2M concurrent connections

Secure Internal AI GPU Server Infrastructure
Our strategic partnership enables enterprises and neocloud providers to securely deploy private LLMs and internal AI systems across AI factories and AI data centers.
Layer 4: Hardware-Accelerated AI Threat Detection
NVIDIA DOCA Argus with Check Point ThreatCloud AI performs real-time GPU memory forensics, detecting supply chain compromise, reverse shell activity, and anomalous behavior without any host-side agent.
- Invisible to attackers even if the host OS is compromised
- No performance overhead. No blind spots.
- 3.3 Gbps threat prevention; 61,000 connections per second

Protect training & inference workloads.
Prevent supply chain breaches and illicit behavior with GPU-server onboard security forensics working in unison with Check Point real-time global threat intelligence.
Layer 5: AI Workload & Kubernetes Container Security
Illumio delivers micro-segmentation visibility across Kubernetes (K8s) namespaces, pods, and services. In turn, Check Point firewalls enforce policy via APIs, to block lateral movement and quarantine compromised workloads automatically.
- Open platform integrated with best-of-breed partners. No vendor lock-in
- East-west traffic visibility across training and inference namespaces

Microsegmentation
Learn how Check Point + illumio deliver microsegmentation for AI workloads and Kubernetes environments:
AI Zero Trust Extends to Every Agent, API, and Non-Human Identity
Agentic AI will query private LLMs autonomously, at volumes 100x to 1,000x higher than human users. Service accounts, API keys, and automated pipelines are everywhere across the AI data center. Every one is a potential attack vector if left uncontrolled.
What AI Zero Trust Covers
Check Point extends AI Zero Trust across the entire AI stack: every user, every agent, every API call, every model interaction. Access is context-aware, tied to data sensitivity and model risk classification.
- Every user and external API call
- Every agentic workflow and pipeline
- Every non-human identity and service account
- Every model interaction and inference request

Your Architecture. Your Security Management Model. Your Choice.
Three deployment models. One Check Point policy engine. A national government agency has different requirements than a Neocloud provider.
Check Point’s security management adapts to your architecture. Not the other way around.
| Check Point Product | Smart-1 Appliances | Security Management Software | Smart-1 Cloud |
|---|---|---|---|
| Deployment | On-premises, purpose-built hardware appliances | Run software on your own hardware or virtual appliances | Cloud-based SaaS. No hardware required |
| Best For | Maximum control, air-gap, sovereign AI | Software flexibility, air-gap | Ops simplicity, cloud-first orgs |
| Air-Gap Ready | YES | YES | NO |
| Sovereign AI | YES | YES | Verify by cloud region |
Built for Multi-Tenancy. From the Ground Up.
Large enterprises segment their GPU resources across divisions or business functions. Neocloud providers serve dozens of enterprise customers simultaneously on shared infrastructure. Check Point has been solving multi-tenant data center security for over 30 years.
Large Enterprise AI Factory
Segment GPU clusters by division, business unit, or cost center, each with independent security policies, access controls, and audit trails. IT chargeback models supported natively.
Neocloud / GPU-as-a-Service
Serve multiple enterprise customers on shared GPU infrastructure with complete tenant isolation. Each customer’s workloads, data, and policies are separated at the security layer, not just compute.
Managed Security Providers
Deliver AI factory security-as-a-service across multiple clients from a single management platform: centralized visibility, per-tenant enforcement, and consolidated reporting.
Designed Better. For AI.
Check Point took an innovative path: by delivering AI runtime inspection, and embedding protection at the hardware layer, inside the NVIDIA GPU server itself, with no negative impact on AI GPU performance. Built on three decades of securing the most demanding data centers around the world.
Security on the DPU, Not in Software
AI Factory Firewall runs natively on NVIDIA BlueField DPUs, fully offloaded from CPU and GPU. No latency. No throughput impact. GPU clusters run at full capacity. Always.
AI-Native Intelligence at Every Layer
Check Point provides native AI runtime inspection and protection, across firewalls, WAF, Workforce AI Security, and private AI infrastructure. From prompt to AI workload, the coverage doesn’t stop. Same semantic understanding everywhere.
Open Ecosystem, No Lock-In
Check Point enforces. Best-of-breed partners like Illumio provide specialized capabilities. One open platform integrated with third-party solutions. No vendor lock-in.
Maestro Hyperscale for AI Factory Scale
The elastic, load-sharing firewall cluster that secures the world’s most demanding data centers, now purpose-built for AI factory throughput and resilience requirements.
ThreatCloud AI: Real-Time Global Threat Intelligence
Real-time threat intelligence from more than 100,000 protected organizations worldwide. Global scale applied to your AI environment from day one.
30+ Years of Multi-Tenant Architecture
AI infrastructure is new. The cyber security discipline that protects it is not. A 30-year foundation extended into the AI era, with DPU-embedded enforcement and AI Zero Trust.
Trusted by the World’s Most Demanding Environments
Regulatory Realities. Compliance by Design.
The EU AI Act is in force. GDPR’s right to explanation applies today. U.S. sector mandates are tightening. Check Point’s centralized policy management and unified audit trails give security teams the traceability regulators require, as a byproduct of good architecture, not a separate workstream.
Governance
- Centralized policy across training, inference, and management planes
- Unified visibility across all five security layers
- Single control plane, consistent enforcement everywhere
Traceability
- Full audit trails for API calls and model access
- Container and pipeline behavior monitoring
- End-to-end visibility from data ingestion to inference
Framework Alignment
- NIST AI RMF & Gartner AI TRiSM
- EU AI Act & GDPR
- HIPAA, PCI-DSS, ISO 42001
AI at Full Speed. Security at the Foundation.
The organizations that get AI factory security right from the start don’t just avoid breaches. They move faster, deploying AI broadly without stopping for case-by-case risk reviews every time a new use case emerges.
Confident Enterprise AI
Security and governance in place from day one means AI can be deployed broadly across departments, without case-by-case risk reviews slowing every new initiative.
Maximum GPU Performance, Always
Security offloaded to DPU hardware means zero impact on GPU throughput or token production. Your AI factory runs at full speed. Always.
Lock Down Intellectual Property
Proprietary models, training datasets, and inference outputs are among the most valuable assets your organization will ever own. Protect them accordingly.
Scale Team Productivity
Every employee with access to well-governed private AI becomes more productive. Removing barriers to adoption creates a compounding effect across the organization.
Compliance Assured
Audit trails, governance controls, and policy enforcement aligned to global AI regulations, built into the architecture rather than retrofitted as a separate workstream.
Faster AI Deployment
Teams that trust their security foundation move faster. New AI use cases deploy in weeks instead of quarters. That speed compounds into competitive advantage.
The Numbers Behind the Architecture
Resource for Every Audience

AI Data Center & AI Factory Security Blueprint
The complete technical reference: architecture diagrams, use cases, security components, and governance alignment.
77% Have an AI Strategy.
Only 26% Can Enforce It.
AI is scaling across users, applications, and autonomous agents—faster than security architecture can keep up. This gap is exposing enterprises to new risks across data, identities, cloud and hybrid environments.
Frequently Asked Questions
This applies to any enterprise deploying an internal, local AI system: a private LLM running on GPU servers, whether in their own data center or off-site with a Neocloud (GPU-as-a-Service) provider. Introducing private, local large language models and agentic applications into a data center exposes a very sophisticated and large attack surface.
Securing a private LLM or AI factory takes a layered approach, not a single product. Check Point’s architecture secures five layers end to end: AI-native application security for prompts and API traffic, perimeter and network security at the data center edge, host-level security running on the NVIDIA BlueField DPU, hardware-accelerated AI threat detection for GPU memory forensics, and AI workload and Kubernetes container security for training and inference environments.
On top of these layers, AI Zero Trust extends to every user, agent, API call, and non-human identity, since agentic AI queries private LLMs at volumes 100x to 1,000x higher than human users. All of it runs through whichever deployment model that fits your environment: on-premises appliances, security management software running on your own physical/virtual appliances, or our cloud-based SaaS solution. With one consistent policy engine regardless of deployment model.
No. Securing an internal AI system/LLM requires multiple layers of defense-in-depth to enforce AI-native protection across every step of the AI lifecycle: from the network perimeter and user/agent prompts, to the AI workloads themselves (training/inference), to the GPU server infrastructure.
Introducing private, local AI systems exposes an enterprise to a completely different class of vulnerability than legacy tools were built to catch. Traditional firewalls and gateways inspect ports, protocols, and known signatures. But an AI agent’s most dangerous actions travel as ordinary API calls and natural-language prompts that look identical to legitimate traffic until their intent is understood.
That risk exists in what is being asked, not how it’s being sent. This is a distinction conventional network controls were never designed to make. A compromised agent can also execute in seconds what once took months of human effort, raising the stakes further. This is why AI-native security, AI runtime inspection, and AI Zero Trust are critical today.
An AI Network Firewall is the central enforcement layer for prompt protection, AI-enabled application traffic inspection, access control for RAG and agentic AI security, telemetry, and management, enabling safer, faster enterprise AI adoption.
The Check Point AI Factory Firewall (AIFF) is an infrastructure-native Next-Generation Firewall that runs directly inside the server chassis, as a container embedded on the NVIDIA BlueField DPU, rather than as an external perimeter box.
It does not touch, inspect, or interfere with any GPU traffic, including processing within a single GPU or high-speed East-West traffic between GPUs during training or cluster synchronization. That layer is entirely bypassed, so running AIFF on the BlueField DPU introduces zero latency to the core AI training fabric.
NVIDIA BlueField DPUs act as “servers within a server.” Check Point’s AI Factory Firewall runs natively on the DPU as a container firewall, offloading security, networking, and storage tasks from the main server’s CPU, freeing up GPU resources and improving the efficiency, security, and scalability of AI factories and Neoclouds.
This isolates traffic by design: North-South storage and management traffic passes through the DPU’s security mechanisms, including AIFF for traditional and AI-specific threat prevention, while East-West GPU-to-GPU data bypasses it entirely for maximum performance.
No. Check Point’s security architecture is an open platform that supports many vendors across a wide range of domains, including GPU infrastructure, micro-segmentation, identity services, all major cloud providers, and more.
Check Point’s AI-native security platform, built on the 2025 Lakera acquisition and subsequent innovations, provides full-stack AI runtime inspection integrated across Check Point’s enterprise solutions.
It supports fully air-gapped and sovereign AI deployments for regulated and sensitive markets. AI runtime inspection, AI Factory security, and policy management can all run locally with no public internet connection required.
Check Point’s AI Factory Firewall features include securing access control, system management, administrative traffic, and access control for RAG and agentic AI:
- Identity-based threat prevention and virtual patching: blocks unauthorized access, exploits, and zero-days targeting the AI infrastructure.
- Runtime protection against AI-specific threats: detects prompt injection, data exfiltration, adversarial queries, and API abuse.
- Host-level DMA auditing via NVIDIA DOCA Argus: inspects host system memory directly, without burdening the host OS, to flag compromised or poisoned code in downloaded AI models.
- Performance: 40 Gbps firewall throughput per DPU, 3.2M concurrent connections, 3.3 Gbps threat prevention, 99.9% block rate, 61,000 connections per second.
- Eliminates the performance-vs-security tradeoff: DPU silicon offloading delivers full-stack security at wire speed with zero GPU/CPU overhead.
- Enables secure multi-tenant architecture: Neocloud providers and large enterprises can isolate and manage per-tenant security policies on shared GPU infrastructure.
- Secures persistent AI agent working contexts: protects credentials, tool-call flows, and memory states, not just data packets, preventing lateral damage from a compromised agent.
- Provides access control for RAG and agentic AI, telemetry, and management, enabling safer enterprise AI adoption.


