WatchGuard is expanding its Rai agentic AI platform with new capabilities designed to automate more security operations work for MSPs, as the company pushes to consolidate network, identity, access, and threat management within its Unified Security Platform.
Announced at WatchGuard’s IMPACT North America conference, the updates add new AI-driven investigation, auditing, customer risk assessment, and natural-language capabilities to Rai, as well as expanded shadow AI visibility, firewall tools, and secure access features.
For MSPs, the broader strategy aims to reduce operational complexity and help partners scale security services without adding tools or staff at the same rate.
WatchGuard expands Rai agentic AI capabilities
Headlining the announcements is an expansion of Rai, WatchGuard’s agentic AI system designed to perform security operations tasks across customer environments.
Unlike a traditional AI assistant that primarily helps an analyst complete tasks, WatchGuard said Rai can handle assessment, investigation, prioritization, reporting, and other security workflows.
New capabilities include:
- Hey Rai: A natural-language interface for interacting with the Rai Workforce
- Rai Analyst enhancements: AI-driven incident investigation, analysis, and prioritization
- Rai Auditor: Continuous security posture and compliance assessment
- Rai Customer Success: Tools for identifying customer risks and potential areas for stronger protection
- MCP integration: Support for bringing WatchGuard security intelligence and capabilities into external AI platforms
“We’ve been led to believe that the answer to every security challenge is another product,” said Joe Smolarski, chief executive officer of WatchGuard Technologies. “But more products don’t create better security. AI-native integrated platforms do.”
The latest updates build on a broader strategy Smolarski outlined to Channel Insider earlier this year, when he said WatchGuard was continuing to evolve its platform around MSP needs while increasing its focus on AI and security innovation.
WatchGuard is positioning Rai as a way for MSPs to expand security operations capacity without increasing staffing at the same rate, although the company did not provide specific staffing or cost-reduction figures in its announcement.
WatchGuard also announced several updates across its network security portfolio as it continues to position the firewall as part of a broader security platform.
Shadow AI and firewall tools broaden platform visibility
New additions include:
- Firebox T175: A new appliance with full-scan security performance, 10G connectivity, and multigigabit networking
- WatchGuard Prime Security Suite: A new mid-tier offering designed to give MSPs another option for matching security coverage to customer requirements
- WatchGuard Network Management: Expanded visibility and monitoring capabilities
- Application Risk Assessments: Tools for identifying potentially vulnerable or risky applications
- Vulnerability scanning: New scanning capabilities available through WatchGuard MDR
WatchGuard is also expanding shadow AI discovery across its platform. Customers using Prime Security Suite or Total Security Suite will receive access to the Network Shadow AI dashboard at no additional licensing charge, according to the company.
The dashboard and related capabilities include:
- Combined data from OAuth grants, email metadata, FireCloud work-device telemetry, and Firebox network visibility in a single discovered applications inventory
- Visibility into users, permissions, and application risk levels, with controls to grant or revoke access
- Identification of misconfigurations and risky settings through CloudDR
- Detection and response for suspicious sign-ins and identity-based threats through CloudDR’s identity threat detection and response capabilities
WatchGuard combines identity and secure access tools
WatchGuard also introduced the WatchGuard Access App, which combines AuthPoint and FireCloud capabilities through a single client, sign-in, and management portal. The approach is intended to simplify users’ access to applications and private resources while providing MSPs with centralized deployment, management, and visibility through WatchGuard Cloud.
WatchGuard cited its 2026 Cyber Hygiene Report, which found that 22% of employees use multifactor authentication everywhere it is available, as part of the rationale for reducing friction around secure access.
The company described the Access App as combining identity security and SASE capabilities into a single experience rather than treating authentication and connectivity as separate workflows.
“The real power of a platform is what happens when every capability makes every other capability smarter and more streamlined,” said Vincent Hwang, chief product officer at WatchGuard Technologies.
“Rai can act on broader platform intelligence, security teams gain deeper visibility into networks, applications, and vulnerabilities, and users get a simpler, more seamless access experience. The result is stronger security, less operational overhead, and better outcomes for our partners and customers.”
WatchGuard said the new capabilities will become available beginning in October through its Unified Security Platform.
What the updates mean for MSP operations
For MSPs already using WatchGuard, the biggest takeaway is consolidation. Rai, firewall management, shadow AI discovery, MDR, identity security, and secure access are increasingly being consolidated into a single platform, which could reduce the number of separate tools partners need to manage across customer environments.
That could be especially relevant for providers trying to scale services without adding operational overhead at the same rate. If capabilities such as incident investigation, posture assessment, access management, and application risk visibility can be handled through a more unified workflow, partners may be able to simplify both technician processes and customer management.
That also aligns with Smolarski’s earlier comments to Channel Insider that WatchGuard intends to keep evolving around MSP needs.
The practical question for partners will be whether tighter integration actually delivers simpler operations while still preserving enough flexibility to work with other tools and vendors already embedded in their security stacks.
Read more: Gorilla Logic joined Anthropic’s Claude Partner Network as a Select Services Partner, expanding its work around enterprise engineering, AI agents, and automated workflows. Read more about the partnership and how Gorilla Logic plans to bring Claude into production customer environments.



