August 20, 2026 7m read

Three Years as a Leader. Built for Where the Market Is Going.

Jaime Romero
Jaime Romero

Table of Contents

Wondering where to begin your SASE journey?

We've got you covered!
Listen to post:
🔊 This audio player requires that "Preferences" cookies be accepted

Why AI Is Raising the Architectural Standard for SASE

Being recognized as a Leader in the Gartner® Magic Quadrant™ for SASE Platforms for the third consecutive year is an important milestone for Cato Networks. We believe it reflects more than consistent execution. It comes at a time when enterprise networking and security are entering another architectural transition, one driven by AI.

The first generation of SASE unified networking and security to reduce complexity and improve resilience. AI is raising the bar again. Enterprises now need an architecture that can understand not only users, applications, devices, and data, but also AI agents that operate autonomously across environments. We believe SASE is no longer simply the destination for convergence. It is the foundation for securing the AI era.

AI Raises the Architectural Standard

AI is not simply introducing another application category or another security control. It is changing how employees work, how applications interact, how decisions are made, and how attacks unfold.

Enterprises must now secure the AI applications employees use, protect the data moving into and out of those applications, and govern a rapidly growing population of AI agents and other nonhuman identities (NHI). Those agents will access data, invoke APIs, execute workflows, and make decisions across enterprise environments at a speed and scale traditional and legacy network and security architectures were not designed to handle. Consider an AI agent that accesses enterprise data, invokes an API, interacts with a SaaS application, triggers another agent, and takes an action on behalf of a user. Securing that workflow requires more than identifying each individual connection. The enterprise must understand the identity behind the activity, the applications and data involved, the actions being taken, and the relationships among them, all while the workflow unfolds at machine speed.

This shift raises the architectural standard for SASE. The issue is not how many networking, security, data, and AI products a vendor can place beneath a common name or expose through a common console. The architectural test is whether those capabilities share users, applications, devices, data, visibility, context, policy, and enforcement without recreating the fragmentation SASE was designed to eliminate.

Gartner predicts: “By 2029, 60% of large organizations with expiring SASE contracts will consolidate to a single, AI-native SASE platform specifically to secure complex, multistep workflows initiated by AI agents, abandoning fragmented dual-vendor solutions that lack NHI and visibility.”¹ That is the transition now underway. The question is no longer whether networking and security products can be connected. It is whether users, applications, data, devices, and AI agents can be understood and governed through one architecture, one data context, and one policy framework.

Convergence must exist below the interface.

Nearly every technology portfolio can be presented through a common console. That consolidation can improve the user experience, but a common interface is not the same as a common architecture.

When networking and security operate through separate engines, separate data models, and separate policy frameworks, customers still carry much of the complexity beneath the surface. Their teams must reconcile policies, normalize data, maintain integrations, and investigate activity across systems that do not share complete context.

True convergence happens in the enforcement path. Traffic should be inspected once, relevant networking and security controls applied through a shared enforcement engine, and the resulting context made available across the platform. The system must understand not only that a connection occurred, but who or what initiated it, which application and data were involved, what action was attempted, and how that activity relates to the broader environment.

Cato was built on this principle. SPACE, our Single-Pass Cloud Engine, operates with single management, a single policy framework, a single data lake, and a global private backbone as one cloud-native system, not as separate products held together by integrations. This foundation allows networking, security, operations, data protection, and AI security to use the same context and enforcement path.

In the AI era, that shared context becomes essential. Defending against an AI-powered attack or governing an autonomous agent cannot depend on a chain of loosely integrated tools exchanging partial information after the fact. Protection must operate at the speed of the interaction. In that sense, SASE is not the endpoint of the platform. It is the architectural foundation for the next era of network security.

Extending SASE for the AI Era

Over the past year, Cato has made significant investments to extend this architectural foundation. Cato’s acquisition of Aim Security brought advanced AI security capabilities into the Cato SASE Platform. Cato AI Security helps enterprises discover and govern employee AI usage, protect private AI applications, and gain visibility into AI agents and their interactions with tools, while extending the platform toward increasingly autonomous protection.

Cato also introduced Cato Neural Edge, bringing GPU-powered inspection into our global cloud infrastructure. This provides the computational foundation required to apply advanced AI models directly to enterprise traffic while preserving the simplicity of a cloud-delivered platform. Cato’s work in agentic threat prevention extends the same principle to cyber defense: using AI agents to analyze emerging threats, determine how they apply to a specific environment, and accelerate the creation and delivery of relevant protections. In Q2, Cato demonstrated what that full architecture makes possible by reducing time-to-protect for newly discovered vulnerabilities to 45 minutes with full Agentic CVE mitigation. These are not separate AI products placed beside SASE. They are capabilities that gain value from the platform’s existing traffic visibility, data, policy, and global enforcement architecture.

At the same time, enterprises do not all transform in one step. They may begin with SD-WAN, SSE, Universal ZTNA, or AI Security based on their most immediate priorities. Cato’s modular adoption model allows customers to start where the business need is greatest and expand over time, without creating another fragmented architecture that must eventually be consolidated.

Platform value must be measured across the operating model.

The shift to a unified platform is also an economic decision. Comparing individual license prices tells only part of the story. Fragmentation creates costs that rarely appear in a product comparison: infrastructure to maintain, integrations to build, policies to reconcile, data to normalize, consoles to operate, and specialized workflows required to keep the environment secure and available. The value of consolidation should therefore be measured not only by the number of products replaced, but by the operational burden removed. Can the enterprise deploy new capabilities without adding infrastructure? Can a small team manage a global environment? Can networking and security teams work from the same data and policy framework? Can the organization respond faster when the business or threat landscape changes? Those outcomes determine the real economics of a platform.

Sustained recognition and continued responsibility.

Cato’s momentum continues to accelerate. We recently surpassed $415 million in annual recurring revenue, growing 42% year over year, and now serve more than 4,800 customers worldwide. Enterprise momentum accelerated in Q2, with material growth among Fortune 500 and Global 2000 organizations, including several multi-million-dollar ARR contracts.

We view that momentum, together with continued recognition from Gartner, as evidence that enterprises increasingly see native convergence as an operating model, not simply a technology category. But leadership is not a destination. Each wave of change raises the standard. The next era of network security will not be defined by how many capabilities a vendor can place beneath a common logo. It will be defined by whether those capabilities operate as one system, sharing visibility and context, applying consistent policy, and adapting at machine speed.

That is the platform Cato set out to build. It is the platform we continue to advance for the AI era. And we believe being named a Leader in the Gartner Magic Quadrant for SASE Platforms for the third consecutive year reflects the strength of that commitment.

Download the 2026 Gartner Magic Quadrant for SASE Platforms to learn more.

¹ Gartner, Forecast Analysis: Secure Access Service Edge, Worldwide, 2025–2030, 15 May 2026, By Charanpal Bhogal, Neil MacDonald, Andrew Lerner, Jonathan Forest, Charlie Winckless

Gartner, Magic Quadrant for SASE Platforms, 28 July 2026, By Jonathan Forest, Andrew Lerner, John Watts

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

Related Topics

Wondering where to begin your SASE journey?

We've got you covered!
Jaime Romero

Jaime Romero

Chief Marketing Officer

Jaime Romero is the chief marketing officer at Cato Networks. Jaime leads Cato’s global marketing organization, driving the company’s growth and market presence. Prior to joining Cato in 2026, Jaime was EVP and head of marketing at Fortinet. He brings deep experience in modernizing go-to-market strategy, building high-performing teams, and driving operational discipline at global scale. Jaime holds a Master of Business Administration (M.B.A.) and a Bachelor of Science (B.S.) in Marketing from Manhattan University.

Read More