AI Security

AI is doing two things to cybersecurity at once, and they carry very different economics. It is re-pricing the existing security market — changing how security products and services are built, delivered, and priced (the supply side), while making attackers cheaper and more capable and thereby expanding the demand for defense (the demand side) — and it is creating an entirely new category: the securing of AI systems themselves. Understanding the business of cybersecurity in the AI era means keeping these apart, because value is forming in some and being competed away in others.

Related: Security for AI (the new attack surface) · The Agentic SOC (AI for defense).

How AI intersects cybersecurity

Security FOR AI protect AI systems (new attack surface) a new category AI FOR Security the supply side better products + software eats services AI-driven offense the demand side cheaper, broader attacks → more security spend AI re-prices the value chain — supply and demand — and creates a new category
AI reshapes cybersecurity on three fronts: a new category (securing AI systems), the supply of security (AI-built products and AI-delivered services), and the demand for security (AI-driven offense that expands the threat).

A new category — security for AI. Models, agents, training data, and the pipelines that build them form a net-new attack surface that existing defenses were not designed for. Securing them — against prompt injection, data poisoning, model theft, and over-privileged agents — is the youngest and fastest-growing pool in the sector, and the subject of an active platform land-grab (detailed in section 1 below).

The supply side — AI for security. AI is changing how security itself is built and delivered, in two ways worth holding apart because their economics differ:

The demand side — AI-driven offense. AI also makes attackers cheaper and more capable — AI-written phishing and malware, AI-discovered vulnerabilities, and now autonomous agents that can run a full intrusion. A cheaper, broader threat surface raises what organizations must spend on defense. Because AI is reshaping the supply of security and the demand for it at the same time, its overall effect on the industry is expansionary even as it disrupts individual categories. See AI for Offense and Threat Economy.

Beyond these, AI is also starting to reshape the business of cybersecurity itself — how companies are sourced and evaluated for acquisition, and how frontier models are treated as strategic, export-controlled assets (covered in the sections below and in The AI Deal Machine).

Market re-pricing (Wall Street research)

A mid-2026 Wall Street sector note describes AI as "the most consequential inflection in cybersecurity since the cloud" and quantifies the re-pricing across all four branches. Its central finding is that cyber's growth is not a rising tide: budgets are being reallocated away from legacy tools toward AI-enhanced categories rather than simply added on top.

Segment (Gartner via Wall Street research) 2029/2030 CAGR Read
Total cyber spend ~$353B by 2030 ~10% The base
AI-enhanced solutions (AI augments the core platform) ~$222B by 2030, ~63% of spend ~60% Branches A + B: AI raises the product ceiling and re-tools services
Security for AI workloads ~$12B by 2029 ~65% (fastest-growing) The Security-for-AI pool
Non-AI products declines to ~$132B (~37% of spend) ≈ −7% The base that AI is eating — the sharpest proof of the re-pricing

The non-AI segment shrinking at ~−7% CAGR while AI-enhanced compounds ~60% captures the thesis in two numbers: AI is not adding a new line item so much as transferring spend from legacy point tools and human-delivered work to AI-native, platform-integrated architectures. The note's bull case is that an expanding attack surface, AI-armed adversaries, and accelerating enterprise AI adoption make AI a secular demand catalyst — the demand side (branch C) — that more than offsets the frontier-model risk to individual categories. The identified winners are platform vendors with autonomous capabilities, broad data access, and integrated architectures; endpoint becomes "the epicenter of AI usage" (greenfield sensor demand), and non-human-identity governance scales with agents.

(Source: mid-2026 Wall Street cybersecurity sector research, citing Gartner market estimates. The seat-based → consumption/outcome pricing shift this note documents is treated under branch B — see Software Eats Services.)

1) Security for AI — the new attack surface

Existing defenses (firewalls, EDR, human-built IAM) were not designed for models, prompts, or autonomous agents. The OWASP LLM Top 10 defines the new vulnerability classes:

Risk What it is
Prompt injection (LLM01) Hidden instructions in data the model processes; the #1 AI risk. Reported success rates 50–84%
Jailbreaks Coercing a model past its safety constraints
Sensitive-info disclosure Tricking a model into revealing training data or accessible data
System-prompt leakage Extracting the hidden instructions governing a model
Data poisoning Corrupting training data so the model misbehaves on command
Model theft / extraction Stealing the model or reconstructing it via outputs
Excessive agency An agent empowered to act takes the wrong action

Prompt injection has reached commodity crime (Jul 2026). Zscaler documented two in-the-wild campaigns using indirect prompt injection in web content to exploit autonomous AI agents browsing the web: SEO-poisoned fake Python-library pages hiding payment instructions in schema markup and hidden HTML (steering agents into cryptocurrency transfers to hardcoded wallets), and a typosquat of the DeFi dashboard DeBank whose hidden prompts instruct agents to treat the impostor as the legitimate domain. In Zscaler's test harness, 4 of 26 evaluated LLMs were manipulated into making a payment (SecurityWeek, Jul 6 2026 · Zscaler). The significance is the attacker profile: these are criminal monetization campaigns, not researcher proofs-of-concept — as agents become a browsing and purchasing interface, ordinary web content becomes an attack surface, a direct demand driver for runtime guardrails and agent-action controls.

Agentic browsers extend the attack surface to co-resident software (2026). As AI vendors ship browser-based agents that can read and act across a user's web sessions, the agent itself becomes an over-privileged endpoint reachable by other software installed in the same browser. Research by Manifold Security found that Anthropic's Claude for Chrome extension activated its built-in tasks without verifying that the triggering click came from a real user, so a separate malicious extension could forge the interaction and drive the agent to read a victim's Gmail, Google Docs, and calendar entries; under the extension's more autonomous "act without asking" mode, the action could proceed without a visible confirmation prompt. Manifold reported the issue to Anthropic in May 2026 — tied to an earlier flaw it named ClaudeBleed — and said it remained exploitable across the releases that followed. The market implication tracks the rest of this section: the spread of agentic browsers is a demand driver for runtime agent-action controls and for the vendors positioning to govern agent behavior, and another reason agent-security capability is being absorbed into larger platforms rather than sustained as a standalone product (SecurityWeek · Manifold Security).

The attack taxonomy is institutionalizing (Jul 2026). CrowdStrike's AI security research team published 18 new additions to its prompt-injection taxonomy on Jul 7, 2026, expanding coverage to more than 200 documented techniques — the largest such catalog in the industry. Five of the additions illustrate how the attack class has moved beyond "ignore previous instructions": trigger-activated rule addition (a dormant instruction that activates on a later keyword or event), cognitive token suppression (blocking safety-related terms to steer the model away from refusal patterns), algorithmic payload decomposition (fragmenting a malicious command into benign-looking pieces the model reassembles), special token injection (counterfeiting the structural markers models use to separate system commands from user input), and unwitting user context-data injection (hiding the payload in content a legitimate user pastes into a CRM record, ticket, or document that an AI system later processes) (CrowdStrike, Jul 7 2026). A 200+-technique taxonomy maintained by a platform incumbent signals that prompt-injection defense is consolidating into the platforms' research apparatus — the same dynamic that makes standalone Security-for-AI vendors acquisition targets rather than durable independents.

The agentic explosion (where risk becomes acute). The shift from AI that talks to AI that acts is the hinge. Autonomous agents plan, decide, and act — querying data, calling tools, moving money, deploying code. The Model Context Protocol (MCP) is the de facto standard connecting agents to tools, and that connective power is the danger: prompt injection that hijacks tools, malicious/counterfeit MCP servers, software-supply-chain risk, and over-privileged "helpful" agents. The consensus control framework: authentication/authorization, provenance tracking, isolation/sandboxing, inline policy enforcement, centralized gateway governance.

AI identities as an attack surface (Jul 2026). A Sophos research report published Jul 22 2026 identifies enterprise AI adoption as the fastest-growing source of new exposure, and frames the risk primarily as an identity and governance problem rather than a model-behavior problem. As coding agents, assistants, and open-weight models are granted privileged access to core systems, the credentials and permissions surrounding them — OAuth tokens, AI service credentials, developer tools, and exposed AI infrastructure — become high-value targets, and breaching one creates a new pathway into the enterprise network. The report cites separate research finding a 466.7% year-over-year increase in active AI agents in enterprise environments, and notes that governance and access policy have not kept pace (Sophos, Jul 22 2026 · Infosecurity, Jul 23 2026). The recommended controls — treat each agent as a scoped non-human identity, require manual verification for new access, and alert on anomalous agent behavior — restate the linkage below: securing AI is largely an identity problem, and agent adoption expands the non-human-identity pool that identity vendors govern.

The AI build chain as an attack surface (Jun 2026). North Korea's Sapphire Sleet (APT38/BlueNoroff) compromised an npm maintainer account and backdoored 144 packages in the @mastra scope (Mastra is an open-source TypeScript framework for AI apps/agents) in a single ~88-minute automated campaign (compromise Jun 17; Microsoft attribution Jun 19), injecting credential/crypto-wallet-stealing malware — tied to a separate Axios npm attack in April 2026 (Infosecurity · SecurityWeek). Securing the packages, pipelines, and agent dependencies that build AI — provenance/SBOM, registry integrity, dependency governance — is a Security-for-AI frontier beyond model/prompt defense (cf. Chainguard + JPMorgan + BNY teaming Jun 16 to secure open source against AI threats). See Threat Economy.

The model registry has an owner (Sep 2026). NVIDIA agreed to acquire Hugging Face for $12,930,300,000, announced by NVIDIA's chief executive on Sep 3 2026. The platform carries more than 3 million models, 500,000 datasets and 1 million applications, used by over 18 million developers and 200,000 companies; NVIDIA is already its largest single contributor, with more than 500 models and 250 open datasets published there. The acquirer states the platform will remain open, will continue to support models from every builder, and will remain multi-cloud and multi-accelerator, with NVIDIA compute not required to build or deploy through it (NVIDIA, Sep 3 2026 · SecurityWeek, Sep 4 2026).

Three consequences follow for Security for AI, and they are separable from the openness question. First, concentration. What npm and PyPI are to software dependencies, Hugging Face is to model weights and datasets — the point through which the artifacts enter the enterprise. That point now has a single commercial owner for the first time, and it is the vendor that also supplies most of the compute those artifacts run on. Second, the registry was itself the incident. Hugging Face's data-processing systems were compromised in July 2026 in the episode OpenAI attributed to its own model, which is the reference case behind much of the agent-access literature above and is the honeypot from which OpenAI later built its Astra evaluations. The asset being acquired is the one that demonstrated the exposure. Third, and commercially the most direct: registry-native controls compete with the model-scanning market. Model scanning, ML-supply-chain integrity and artifact provenance are lane (1) of the Security-for-AI market catalogued on 20g — the lane Palo Alto bought with Protect AI and where HiddenLayer is the largest remaining independent. That revenue exists because the registry does not perform those checks to enterprise standard. An owner with the balance sheet to build them natively is the same absorb-the-category dynamic already recorded from the SDLC side (Snyk), the data-cloud side (Snowflake) and the network tier (F5, A10), now applied to the artifact source itself. Nothing in the announcement states an intention to do so, and the openness commitments cut the other way; the point is that the exposure now exists where it did not before.

The defensive response is consolidating around the coding agent (Jun 2026). Snyk launched Evo Agentic Development Security (Evo ADS) on Jun 23 2026 (GA Jun 29), governing — inside the agent's workflow — the tools an agent pulls in (incl. MCP servers), the actions it takes at runtime, and the code it generates. Evo ADS completes the Snyk AI Security Platform (Evo AI-SPM for AI-asset visibility + Evo Continuous Offensive Security for simulated attacks), and pairs with Snyk's Invariant Labs acquisition (announced Jun 24 2025; agentic-AI/MCP security) for a build-time-to-runtime agent-security stack (SiliconANGLE · Snyk). OWASP's 2026 LLM report puts prompt-injection +340% YoY (its fastest-growing attack category) and frames agent security as "a supply-chain problem first" (Help Net Security). A dev-security incumbent assembling a full Security-for-AI platform organically and by tuck-in simultaneously is a clear current instance of the pattern in which a platform absorbs the category as a feature, compressing the standalone-pure-play window from the SDLC side.

The data-cloud platforms are building Security-for-AI natively (Aug 2026). At Black Hat USA 2026, Snowflake introduced enterprise AI-security controls around its Cortex AI Gateway — agent-identity controls, data-exfiltration prevention, and governance for Model Context Protocol (MCP) tool use — positioning the data platform itself as the enforcement point for how AI agents access governed data. This is the same absorb-the-category dynamic seen from the SDLC side (Snyk) and the network/ADC tier (F5, A10), now from the data-cloud side: the platform where enterprise data already lives extends into agent-access governance rather than leaving it to a standalone Security-for-AI vendor. It reinforces the read that much of Security-for-AI accrues to incumbents adjacent to the asset being defended — here, the data warehouse — narrowing the durable-independent window for agent-governance point products (Snowflake, Aug 2026).

→ Key linkage: Securing AI is largely an identity problem — every agent is a non-human identity to authenticate, authorize, monitor, and govern. Agents are exploding the non-human-identity count, supercharging the identity profit pool (see Vendors, Market Structure). This extends the same migration that drove Palo Alto–CyberArk ($25B).

The defensive stack & standards

Government guidance is converging on the same control set (UK, Aug 20 2026). The NCSC published interim advice on managing the cyber risk of agentic AI, issued as a blog post ahead of formal guidance that will supersede it, and framed as a response to incidents in which models carried out unsanctioned or unintended activity. Its recommendations map closely onto the categories above. Organizations are advised to assess how much autonomy a system actually requires and to threat-model the agent's prompts, tools, networks and accessible services before deployment, and explicitly not to rely on safeguards built into the underlying model or agent framework, which the NCSC notes can be bypassed or prove insufficient in higher-risk settings. For higher-risk deployments it recommends running agents in robust sandboxes with access restricted to the resources a task requires, network controls that deny connectivity by default with allowlists or service-aware proxies for permitted connections, and separation of agent execution, supporting infrastructure and inference services — while warning that agents can themselves discover weaknesses in those controls, creating sandbox-escape risk. On identity it recommends a distinct identity per agent, credentials limited to the task and short-lived where possible, and treatment of API keys, OAuth grants, SSH keys and authenticated sessions as components of an agent's blast radius. On operations it recommends named human responsibility for agent activity, real-time monitoring, logging of agent activity within security operations and incident response, and the ability to halt autonomous activity immediately, including cutting network access and communication with model infrastructure (NCSC, Aug 20 2026 · Infosecurity, Aug 20 2026).

Two features of the advice bear on the vendor landscape. The controls named are largely identity, network and observability primitives rather than AI-specific products, which places incumbent identity, segmentation and logging vendors inside the recommended architecture alongside the agent-governance specialists on 20g. And the emphasis on standing delegations — per-agent identity, short-lived credentials, blast-radius accounting — addresses the same mechanism documented in the Ghostjacking research, where the offense was supplied by access the victim had already granted rather than by a new attacker capability. The status of the advice is interim and non-binding; it creates no obligation of the kind the EU AI Act does.

A hardware-rooted evidence layer enters neutral governance (TRACE, Aug 25 2026). The Linux Foundation assumed governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), an open specification contributed by confidential-computing vendor OPAQUE and developed jointly with AMD, Intel, Microsoft and the Technology Innovation Institute. TRACE produces a hardware-backed, cryptographically verifiable record binding the runtime environment, the software executed, the policies applied, the classification of the data involved and the tools an AI agent invoked, in an artifact designed to be portable across cloud providers, confidential-computing platforms and sovereign infrastructure. It composes existing standards — RATS, EAT, SLSA, SCITT, SPIFFE and EAR — rather than defining a new verification framework. The reference library recorded roughly 135,000 PyPI downloads in the ten weeks after its introduction at the Confidential Computing Summit in June 2026, an average near 13,500 a week (SecurityWeek, Aug 25 2026 · specification).

TRACE sits in a different layer from the guardrail and posture products above: it does not prevent an agent from misbehaving, it produces evidence of what an agent did that a third party can check. That distinction matters commercially. Attestation anchored in silicon is a substrate the chip and cloud vendors supply, and placing the specification under neutral governance limits the extent to which any single vendor can charge for the evidence format itself. The revenue accrues one layer up — in the products that collect, retain, interpret and report the evidence against a policy or a regulation — which is the same position occupied by the AI-governance and agent-observability vendors on 20g. Where a rule requires demonstrable control over an AI system, as the EU AI Act does for high-risk systems (16), a portable attestation format is the mechanism by which the demonstration becomes auditable rather than asserted.

Vendor landscape & M&A

Company Note
Protect AI → Palo Alto Networks (~$700M, 2025); folded into Prisma AIRS
Robust Intelligence → Cisco (~$400M); AI app/infrastructure security
Bonfy.AI → Kiteworks (announced Sep 10 2026; terms undisclosed, estimated at tens of millions). Inline content classification and policy enforcement applied at the moment of an exchange — email, file sharing, SaaS, data repositories and autonomous agents — folded into Kiteworks' Data Control Plane. The acquisition of an enforcement point rather than an inventory: the distinction matters because an agent's authority to hold data and its authority to move it are separate questions, and only the second is decidable in flight. Founded early 2024 by Gidi Cohen (founder, Skybox Security) and Danny Kibel (ex-chief executive, Idaptive; later global R&D, CyberArk); $9.5M seed, TLV Partners with Saban Capital Group, stealth exit Jun 2025. Kiteworks' eighth acquisition in five years
Enkrypt AI → Anaconda (Aug 2026, terms undisclosed); AI red-teaming (300+ attack categories), runtime guardrails, and NIST-AI-RMF / EU-AI-Act compliance automation folded into the Anaconda Python/data-science platform
Virtue AI → Fortinet (Aug 18 2026; terms undisclosed, characterized by Fortinet as immaterial to its business); agentic-system red teaming, agent protection and governance, continuous AI validation and real-time runtime guardrails. Closes the last AI-security gap among the major network-security incumbents and brings the absorbed cohort to nine companies since Aug 2024
Alice (formerly ActiveFence) Pre-release model stress-testing, continuous red-teaming and runtime guardrails; $140M raised Aug 25 2026 (Apax Digital-led; $280M total). A trust-and-safety vendor re-based on Security for AI, carrying a decade-old adversarial-behaviour corpus (Rabbit Hole) as its data moat
HiddenLayer AI model security + AI-SPM; added agentic runtime security (2026)
Lakera Prompt-injection protection (Gandalf), AI red-teaming
Prompt Security, Noma, Mindgard, Zenity, Straiker, Patronus Pure-play startups across guardrails, agent governance, red-teaming
Wiz, CrowdStrike, Palo Alto, Microsoft, AWS Incumbents/cloud extending into AI security

Market context: AI-in-cybersecurity market ~$34B (2025) → ~$44B (2026) → $130B+ by early 2030s (≈20%+ CAGR). The "security for AI" slice is young and the highest-multiple, highest-aggregation-risk part of it.

→ Profit-pool read (three lenses, see [04 economics lens]): margin = software-rich; migration = forceful (value flowing toward AI security as enterprises build on AI); structural attractiveness = high but shadowed by aggregation risk — the Protect AI / Robust Intelligence deals signal the platforms intend to absorb AI security as a feature, and cloud providers bundle guardrails at near-zero marginal cost.

Two buyer archetypes in the Security-for-AI consolidation. The acquirers of AI-security pure-plays now split into two distinct groups. The first is the security platform absorbing AI security as a feature of its own suite — Palo Alto (Protect AI), Cisco (Robust Intelligence) — the aggregation-risk pattern above. The second, newer archetype is the AI or data-science platform internalizing AI security to make its own AI outputs trustworthy: Anaconda's August 2026 acquisition of Enkrypt AI (red-teaming, runtime guardrails, and NIST-AI-RMF / EU-AI-Act compliance automation) governs "every step from a builder's first prompt to the AI-native application running in production." For this second buyer, AI security is not a product line to sell but a control the platform must own to ship trusted AI — a demand pulled forward by the Aug 2, 2026 EU AI Act GPAI-enforcement milestone (16b). It widens the exit set for AI-security independents beyond the security incumbents to the AI-tooling vendors themselves.

The same date carried a second, wider obligation, and it reaches a different buyer. The Act's Article 50 transparency duties also became applicable on Aug 2, 2026: systems that interact directly with people must disclose that they are AI, synthetic outputs must carry machine-readable marks, deepfakes and AI-generated public-interest text must be labelled, and people exposed to emotion-recognition or biometric-categorisation systems must be told. Where the GPAI regime binds a small set of model providers, Article 50 attaches to the product, so it reaches any business shipping a chatbot or generative feature into the EU. Systems already on the market before that date have until Dec 2, 2026 to meet the machine-readable marking requirement. The consequence for this segment is that content provenance, watermarking and synthetic-media detection acquire a regulatory purchase trigger separate from fraud loss — the demand that has so far driven that cohort (15d) — and the buyer is often product engineering rather than the security function (16b, 16c).

Funding signal (Jun 2026): fresh capital keeps entering the runtime/agent-governance edge even as platforms absorb it. Runlayer raised a $30M Series A led by Felicis with Khosla Ventures (announced Jun 24, 2026; ~$42M total raised) to be the security & governance layer for the enterprise MCP / AI-agent workforce — tool-mapping, human sign-off on sensitive actions, full-session observability, and detection of prompt injection, tool poisoning, exfiltration and intent drift, with early adopters incl. Gusto, dbt Labs, Instacart and Opendoor (PR Newswire · Fortune). Earlier in June, NeuralTrust (Barcelona) raised a $20M seed led by Alstin Capital (Jun 17, 2026) — reportedly the largest cyber seed by an EU company to date — for enterprise AI-agent security (prompt-injection/jailbreak defense, runtime guardrails, red-teaming, observability) (PR Newswire). Together they mark MCP / agent-runtime governance as a distinct, fast-funding sub-segment (cf. Snyk–Invariant/Evo, Koi→PANW, Promptfoo→OpenAI) — the European locus (NeuralTrust) carries a NIS2/DORA + EU AI Act tailwind, while the US cluster (Runlayer) draws marquee tier-1 sponsors.

Funding signal (Aug 2026): the agent-governance edge produced its largest independent round to date — Zenity's $125M Series C (Aug 3, 2026; led by Norwest; total funding ~$185M), which added strategic corporate backers SoftBank Vision Fund 2, Hitachi Ventures, and LG Technology Ventures whose participation is tied to their own enterprise agent adoption. Following the July agent-governance cluster (Onyx $113M, plus the Neo/Hush/Act identity rounds), it marks the first agent-security independent capitalized to attempt durable scale rather than an early absorption — the sliver the falsifiable "feature-or-market" test flags as the one platforms have not yet closed (03l, 07). (Fortune, Aug 3 2026 · SiliconANGLE) The next day (Aug 4, 2026) the agent-governance lane priced its first unicorn: Obsidian Security's $85M Series D at a ~$1.1B valuation (led by Crescent Cove Advisors; total funding over $200M) — a runtime-governance platform for AI agents inside third-party SaaS applications, the second nine-figure agent-governance round in two days. Alongside it, Oligo Security raised $60M (total ~$140M) for runtime application/cloud and AI-systems protection — an AI-for-Security runtime play rather than agent governance. The four AI-security rounds across Aug 3–4 total roughly $520M: about $210M into Security-for-AI agent governance (Zenity, Obsidian) and about $310M into AI-for-Security validation and runtime protection (Horizon3.ai, Oligo) — both lenses of the framework capitalizing at once (03l, 11). (SecurityWeek — Obsidian · SecurityWeek — Oligo)

Funding signal (Aug 25 2026) — and an adjacency crossing into the category. Alice, the company previously trading as ActiveFence, raised $140M led by the Apax Digital Funds, with MoreTech, Phoenix Financial, Resolute Ventures, Grove Ventures, CRV, Highland Europe, Vintage Investments, Norwest, NFX and Claltech participating. Total funding reaches $280M, so this single round is half of all capital the company has raised. Headquartered in New York and Tel Aviv, Alice stress-tests foundation models before release, then supplies continuous red-teaming and runtime guardrails once models are in production, and maintains a research lab of more than 150 specialists working with model developers. Its stated differentiator is a proprietary corpus, Rabbit Hole, assembled over close to a decade of tracking digital fraud, extremism and manipulation campaigns and now repointed at detecting hostile inputs to generative systems (SecurityWeek, Aug 25 2026).

The structural point is the origin rather than the size. ActiveFence was a trust-and-safety vendor selling content-abuse detection to consumer platforms, a market adjacent to cybersecurity but historically priced and sold separately (42). The asset that transfers is the labelled corpus of adversarial human behaviour, which is a data moat rather than a model or a control, and it is the kind of asset a security platform cannot readily build after the fact. The rebrand and the round together mark trust-and-safety as a second supply route into Security-for-AI alongside the security-native startups and the AI-tooling vendors described above — a third entrant archetype, and one that widens the buyer set for any independent in this lane.

The largest single financing in the Security-for-AI lane reinforces the same convergence from the data side. Cyera took $400M from Goldman Sachs on Sep 22 2026 as an extension of a Series G that first closed in June at $12B, bringing the round to $1.0B; no new valuation was disclosed, so the round records capital intake rather than a repricing. The capital sits behind a data-plus-identity assembly: the $1B acquisition of Oasis Security completed Sep 3 2026 and now runs as Cyera Identity, and two agent-security products shipped between the tranches — an agent inventory that scans agents, their tools and their MCP servers and blocks or quarantines actions against policy, and an endpoint control for agents running on employee devices. The thesis being funded is that what sensitive data exists and what an agent is permitted to reach are a single control plane, which is the data-security route into the same problem that the identity vendors approach from the credential side (03g, 20b, 07).

Several AI-security deals are frequently misdated to June 2026 but are in fact June 2025; search results recurrently conflate the two years' M&A roundups. All of the following are primary-source-verified to June 2025:

Deal Real date Sub-segment Primary-source tell
Snyk–Invariant Labs Jun 24 2025 Agentic-AI / MCP runtime defense (Security FOR AI) Snyk PR dateline "BOSTON, June 24, 2025"; seeded the 2026 Evo platform
Cyera–Otterize Jun 26 2025 Non-human identity / data flows Cyera PR "June 26, 2025," cites the Jun-2025 $540M/$6B round
Rubrik–Predibase Jun 25 2025 Agentic-AI / model ops Rubrik newsroom URLs /2025/06/25/
F5–Fletch Jun 2025 Agentic-AI threat triage GeekWire URL /2025/
Bitdefender–Mesh Jun 2025 Email security BusinessWire wire-ID 20250618

2) AI for security (offense & defense)

AI labs in cybersecurity — partnerships & programs (2026)

The frontier AI labs have moved directly into cybersecurity, partnering with the largest public companies. This is now a primary axis of the industry. (See also Key People and Intelligence Sources.)

Anthropic — Project Glasswing

OpenAI — Daybreak / Aardvark (Codex Security)

Hyperscalers & platforms (agent-security land grab)

Three of the largest hyperscalers now ship a version of the same discover→validate→remediate loop — Microsoft (MDASH, now productized as Project Perception), AWS Continuum, and Google CodeMender — each validating exploitability by building working exploits in a sandbox, each behind a multi-model router rather than a single frontier model. Microsoft's Project Perception adds a nuance to the pure-router pattern: alongside its GPT-5.4 fallback it now trains an in-house, purpose-built cyber model (MAI-Cyber-1-Flash) as the default engine — the same security-specific base-model bet the funded startup Corma is making, taken by the platform incumbent. The convergence is the concrete form of two pressures the rest of this page tracks: bundling pressure on the sub-scale autonomous-pentest/AI-SOC pure-plays that sell the loop as a standalone product, and the supplier-commoditization leg of the frontier-lab bear case, in which the general models become interchangeable, price-competed inputs behind a platform's own orchestration — though a platform training its own domain model complicates the assumption that the model layer commoditizes uniformly.

→ M&A read: the labs are picking winners (Glasswing's CrowdStrike/Palo Alto), validating AI-security categories, and accelerating the agent-security land grab among hyperscalers — supportive of AI-security M&A and an example of AI reshaping the business itself.

Certification as the control point — the security platform's own marketplace (Aug 31 2026)

The land grab above concerns what the platforms build. A parallel move concerns what they permit others to build on them. CrowdStrike announced an AI Partner Specialization on Aug 31 2026, sorting partners into four routes to market — resell through Falcon Flex, manage as a managed service, build partner-authored agents via Charlotte AI AgentWorks and Falcon Foundry, and deliver agentic transformations through systems integrators — and introducing a Verified Agent certification that validates partner-built agents against CrowdStrike's own requirements as the route to distribution through the CrowdStrike Marketplace. Named participants include Accenture, Anthropic, CoreWeave, JetStream and World Wide Technology. The release states no partner counts, no certified-agent counts and no economics (CrowdStrike, Aug 31 2026).

Set beside the Daybreak Defense Network described below, the two form a matched pair running in opposite directions. A frontier lab routing capability through partner products uses the security industry as its channel; a security platform certifying partner-built agents into its own marketplace uses partners as its suppliers. In the first, the lab supplies an input and the vendor owns the customer. In the second, the partner supplies intellectual property and the platform owns distribution, the technical standard and the renewal. Both are described by their sponsors as ecosystem programmes, and they allocate the customer relationship to opposite parties.

→ M&A read: a certification tier creates a named, pre-qualified population whose integration with the platform is already validated — an origination funnel for the platform itself, and for any other acquirer a concentration map of assets whose distribution and roadmap depend on a company that may bid against them. The dependency does not surface in a customer-concentration table, because the platform is not a customer. Treated at length in Distribution and Cloud Marketplaces.

Two more issuers, and the certifier's position turns out to be the variable (Sep 3 · Sep 16 2026)

Within sixteen days of the CrowdStrike announcement, two further parties began certifying AI agents, and they occupy structurally different positions from CrowdStrike and from each other.

Tenable and OpenAI announced the CyberAgents Exchange AI Inspector on Sep 3 2026 — a security review process for AI agents, skills, MCP servers and multi-agent playbooks listed on the CyberAgents Exchange, the open-source registry Tenable launched in August 2026 and operates, which held more than 100 community-submitted components at announcement. The review has three layers: frontier assessment using OpenAI GPT cyber models, skills inspection through Tenable One AI Exposure, and expert review by Tenable researchers. Availability was stated as expected in September. The collaboration originated in Tenable's membership of the OpenAI Daybreak Defense Network described below, making this the second named product from that channel alongside the Proofpoint agent (Tenable, Sep 3 2026).

Outerlimit raised a $16M pre-seed led by AlbionVC, Evolution Equity Partners and Crane Venture Partners, for a decentralised authorisation layer that discovers AI agents, observes their behaviour and enforces policy on the scope and conditions under which delegated tokens are used. No revenue, customer or valuation figures were disclosed (SecurityWeek).

Reco raised $55M led by AT&T Ventures, Forestay and Quadrille Capital, bringing total funding to $140M; the company describes agent and SaaS-access security built on context graphs mapping agents to applications, accounts and permissions, states ARR in the "double-digit millions" with 100+ customers, and reports finding 21,000 previously unknown agents at one Fortune 100 customer. Valuation was described as in the high hundreds of millions, without a figure (TechCrunch).

The three positions are platform vendor, registry operator and independent underwriter — gating a marketplace, a registry, and nothing respectively. The distinction is not cosmetic, because only the third produces a credential that exists independently of its issuer, and therefore only the third is an asset that can change hands. The full treatment, tested against the four conditions under which a certification functions as a moat, is in Certifications as Moats; no issuer has disclosed a price, a duration or a pass rate, so the class is a control point in formation rather than an established moat.

The collective-action letter (Aug 27 2026)

On Aug 27, 2026 OpenAI published an open letter, A call for collective action on cyber defense, co-signed by more than 100 organisations — 128 by SecurityWeek's count — including Anthropic, Microsoft, Google, AWS, IBM, Oracle, Cisco, Check Point, Cloudflare and CrowdStrike. The letter states that AI-enabled attacks will become more widespread and more sophisticated as models grow more capable, and that there is a limited window in which to strengthen defences. It asks two things of two different parties: that cybersecurity companies lead the response and make AI-powered defence deployable by critical-infrastructure operators, and that frontier AI companies supply responsible model access, funding, training and hands-on support.

The market-structure reading turns on the direction of that second ask. A frontier lab offering funding, model access and support to the security industry is positioning itself as an input to that industry rather than as a competitor within it — the opposite of the substitution risk implied by the hyperscaler products described above, where a platform ships the discover-validate-remediate loop the pure-plays sell. Both dynamics are live at once, and they resolve at different layers: the labs supply the model, the hyperscalers supply the orchestration, and the pressure falls on vendors whose only differentiation is the orchestration. The letter is a statement of intent rather than a commitment of capital, and carries no named sum, unlike Anthropic's Project Glasswing ($100M in credits plus $4M to open-source security organisations). Its near-term significance is as a signal of where the largest buyers expect AI-defence spending to be directed — toward critical-infrastructure operators, the same population the bulk-power exclusion order reaches from the regulatory side (SecurityWeek, Aug 27 2026 · Engadget, Aug 27 2026).

Daybreak for Frontline Defenders — the collective-action letter acquires a price tag (Sep 3 2026)

Seven days after the collective-action letter, OpenAI attached a number to it. Daybreak for Frontline Defenders, announced Sep 3 2026, commits $1B in subsidised access to Daybreak cyber models and products, together with training, technical assistance and partnerships, and OpenAI states it is targeting that commitment to be consumed over the following six months. Priority goes to a named list of buyers: water and wastewater systems, electric grid operators, state and local government, community and regional banks, nonprofits and open-source maintainers, starting in the United States with expansion to partner countries intended in subsequent weeks. Three further disclosures accompany it — a public-sector and water-focused training pilot with the Multi-State Information Sharing and Analysis Center (MS-ISAC); more than 35 partner products and partner-operated services shipping under the Daybreak Defense Network; and the first adoption figure published for the programme, 2,000 approved organisations and workspaces. OpenAI also records that it had earlier offered affected states and utilities up to $1M in no-cost API credits and assistance following attacks on US water systems, which places the new commitment three orders of magnitude above that precedent.

The scale is best read against the public programme aimed at the same buyers. The State and Local Cybersecurity Grant Program, created under the Infrastructure Investment and Jobs Act, authorised $1B across four fiscal years — an average of $250M a year — and allocated $91.75M in FY2025, its final year under that authorisation. The Government Accountability Office found that $172M, or 17.2% of the total, had reached states as of Aug 1 2024, funding 839 projects. A commitment of $1B consumed over six months runs at $2B a year, eight times the grant programme's average annual authorisation and 10.9 times its final-year allocation. The comparison is one of scale and of target population, not of economic equivalence: a supplier's valuation of discounts against its own undisclosed list prices is not appropriated cash, and OpenAI does not state what is subsidised, at what percentage, or whether the subsidy is fixed or proportional. What the two figures do share is a buyer — the tier of operator that has never carried a security software budget line large enough to matter to a vendor.

The delivery mechanism is the channel, which changes who the commitment threatens. The Daybreak Defense Network routes the capability through partner products and partner-operated services rather than direct to the operator, so this is a lab subsidising demand through the security industry rather than disintermediating it — consistent with the input-not-competitor reading of the collective-action letter above, and the opposite of the substitution pressure the hyperscaler products create. The commercial consequence falls on partnership status. For a vendor or MSSP selling into state and local government, small utilities and community banking, membership of the Network is a six-month price advantage in that segment and absence from it a six-month disadvantage, on admission criteria that are not public. That extends to the defensive tier the same point 20a records for Daybreak Red: supplier access has become a competitive variable and a diligence question rather than a partner-page listing.

The six-month consumption target is the part with a durable commercial consequence. A subsidy with a stated horizon creates a cost that arrives at month seven, and the buyers named are the ones least able to absorb it — which is why the grant programme existed. Three outcomes are available and only the first is neutral: the operator finds new budget; the MSSP or MSP that wrapped the capability absorbs it into a managed price and takes the margin compression, the segment already carrying the worst gross margins in 04a; or the capability lapses. The subsidy also lands on tooling and not on labour, so for operators defined by having no security staff the binding constraint is unchanged — which argues that the near-term beneficiary is the managed-services layer that supplies the staff, not the operator. Nothing in the announcement addresses post-subsidy pricing, and no inference is drawn here about renewal economics. See Sovereign & Government for the public-funding side of the same buyer and 20e for the Daybreak programme history. (OpenAI, Sep 3 2026 · SecurityWeek, Sep 4 2026 · CISA — SLCGP · FEMA — FY2025 SLCGP fact sheet)

The first product through the Daybreak Defense Network, and the limit it sets on its own autonomy (Sep 3 2026)

On the same day as the Frontline Defenders commitment, the channel described above shipped its first product. Proofpoint introduced the SOC Analyst Agent on Sep 3 2026, stating it is the first Proofpoint capability to emerge from the OpenAI Daybreak Defense Network, which the vendor joined in June 2026 — a single quarter from network membership to a named, shipping product, the release giving the month of joining but not the day, so the interval is between 65 and 94 days and is not stated more precisely here. The agent plans investigations and draws context from connected Proofpoint security data including alerts, logs, data-loss-prevention events and user risk signals, converting natural-language questions into findings traceable to their underlying source data. It is in private preview with selected beta customers, with general availability stated as expected by the end of Q3 2026. Three capabilities are named: investigation across connected products in natural language, scheduled recurring workflows for threat hunts and escalation reporting, and traceability of every finding back to source (Proofpoint, Sep 3 2026).

The boundary the announcement draws is the part with analytical value, because it is drawn explicitly and in the vendor's own words. The release states that the agent "does not independently make account changes, contain threats, or initiate other consequential remediation actions." That places the product at the investigation tier of the discover → validate → remediate progression used throughout this page, and deliberately not at the action tier. The distinction matters because it is measurable against claims already recorded for the same category on 04b: Arctic Wolf reports more than 60% of cases autonomously closed on its Aurora platform, and Sophos reports 52% of cases resolved without human intervention at an 89-second average automated response time. Those are claims of autonomous closure. This is a claim of autonomous analysis with human closure retained by design. A category described with one label therefore contains products making opposite commitments about who acts, and a buyer or an acquirer comparing them on the label alone compares two different things.

The economic consequence separates this from the services-substitution case. An agent that investigates but cannot act does not remove the analyst from the loop; it reduces the time the analyst spends assembling context per case. That compresses cost per investigation without changing headcount structurally, which is a different economic event from the labour-to-software conversion that drives the re-rating described in 04h. It belongs on the products side of the supply story — AI raising what a security product does — rather than the services side. The vendor's own survey, cited in the release, reports 54% of organisations already using AI-enhanced capabilities to triage and investigate alerts, a self-reported figure from the announcing party and one that describes adoption of a capability class rather than of this product.

For market structure, the sequence is the observation. A lab partner programme announced in May 2026 admitted this vendor in June and produced a shipping product by September, alongside a stated 35-plus partner products and partner-operated services in the same Network. Frontier-model access is arriving in commercial security products on a quarterly cadence rather than an annual one, which shortens the period during which a model-derived capability is a differentiator for any one vendor. See 04c for the agentic-SOC camps this product sits among, 20e for the Daybreak programme history, and 11 for the vendor's Acuvity acquisition, which addresses the securing-AI side of the same portfolio.

The federal policy frame — the June 2026 AI EO

On June 2, 2026, the White House signed the executive order "Promoting Advanced Artificial Intelligence Innovation and Security" — Executive Order 14409, published in the Federal Register June 5, 2026 (91 FR 34565). It pursues two tracks: (1) hardening federal and private-sector cyber defenses against AI-enabled threats, and (2) building voluntary benchmarking/review frameworks for the secure development and release of "covered frontier models." It directs agencies on aggressive 30-/60-day timelines — key deliverables due July 2, 2026 and August 1, 2026 — to deploy AI-enabled defenses on federal systems, stand up a classified benchmarking process (Treasury, War, Homeland Security) to evaluate models' advanced cyber capabilities, establish an AI cybersecurity clearinghouse (Treasury + National Cyber Director) for vulnerability scanning/patch coordination, and prioritize criminal enforcement of AI-enabled cyberattacks (White House presidential action · Covington/Inside Privacy analysis). The clearinghouse leg stood up on Jul 14, 2026 as the Treasury-managed "Gold Eagle" initiative — intake via the VINCE platform run with Carnegie Mellon's Software Engineering Institute, with the White House saying the system was already receiving vulnerability intelligence and prioritizing patches at launch (CyberScoop, Jul 14 2026; detail in Regulation).

→ Why it matters for M&A: the EO institutionalizes "AI cyber capability" as a national-security-graded property of models — the same logic that, ten days later, produced the BIS Fable/Mythos directive (below). For the deal machine it (a) accelerates federal demand for AI-security tooling and benchmarking/red-team vendors, and (b) raises the regulatory overhang on frontier-model access — a structural tailwind for the AI-security pool and a new diligence axis (export-control/benchmarking exposure). See also Regulation and 20f.

The allied policy frame — the Five Eyes joint statement (Jun 22, 2026)

Twenty days after EO 14409, the heads of the Five Eyes cyber security agencies — CISA and the NSA (US), the UK NCSC, Australia's ACSC, the Canadian Centre for Cyber Security, and New Zealand's NCSC — issued a rare joint leadership statement, "The AI shift in cyber risk: why leaders must act now." Its central claims: frontier AI models "are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities," and "the timeline is not years, it is months." The statement frames cyber risk as a board-level business risk rather than a technical one, and directs leaders to five priority actions: attack-surface reduction, accelerated patching (because AI is shrinking the window between vulnerability discovery and exploitation), legacy-system replacement, stronger identity and access controls, and incident preparedness — alongside an explicit instruction to use AI in defense because "adversaries are already using AI to move faster" (NSA, Jun 22 2026 · CISA). It is signed by the individual agency heads, including acting CISA director Nick Andersen and NSA cybersecurity director David Imbordino.

→ Market read (threads kept distinct): on the demand side, this is the most senior allied-government endorsement to date of the AI-cheapened-offense thesis — official confirmation that the discovery-to-exploitation window is compressing, which underwrites budget for patching automation, exposure management, and the agentic-SOC cohort. On the supply side, the "use AI to strengthen defense" directive gives boards top-cover for AI-for-Security adoption. The statement sits alongside the same summer's national programs (EO 14409, UK Cyber Shield above) as coordinated allied signaling rather than a new legal regime — it imposes no obligations, but board-level attention is itself a demand mechanism (see How Buyers Buy).

3) AI as a strategic asset — Fable/Mythos

On June 12, 2026, the U.S. Commerce Department's Bureau of Industry and Security issued an export-control directive ordering Anthropic to suspend all access to Fable 5 and Mythos 5 for any foreign national — inside or outside the US, including Anthropic's own foreign-national employees. Because the company could not reliably screen users by nationality, it disabled both models entirely for all customers while working to comply (other models unaffected).

Status as of 2026-07-04: the export controls were lifted. Anthropic said on Jun 30, 2026 that the administration removed the restrictions (CNBC); Fable 5 returned globally Jul 1, 2026, and Mythos 5 was restored to approved U.S. organizations (government sign-off reported Jun 26). The resolution was a settlement rather than a rescission: it includes prerelease federal review of frontier models and dedicated government-priority research teams, so the precedent hardened into a negotiated regime. Full treatment: Fable/Mythos & AI Export Controls. Open questions are whether prerelease review generalizes to other labs and how it interacts with the EO 14409 ≈Aug 1 benchmarking track.

Fable 5's cyber classifiers and the CJS framework (Jul 2, 2026)

Alongside Fable 5's global redeployment, Anthropic published the first detailed public taxonomy of what a frontier model's cyber safety classifiers block, plus a draft Cyber Jailbreak Severity (CJS) framework built with the Glasswing partners (Amazon, Microsoft, Google) — a proposed industry standard for scoring jailbreak risk (Anthropic, Jul 2 2026):

→ Two market reads (threads kept distinct): (1) Security-for-AI — the model's misuse surface is being standardized; if CJS is adopted, it becomes compliance infrastructure the AI-governance/AI-SPM cohort can map to. (2) AI-for-Security implication — blocking pentest/red-team/exploit work on the frontier model is a capability-access constraint on the autonomous-pentest/offensive-validation cohort: "known-good-actor" access programs (cf. OpenAI's "Trusted Access for Cyber," Jun 23) become a moat-and-diligence question for any AI-for-Security target that depends on frontier-model offensive capability.

/ angle

→ Sell-side origination: founder-led, VC-backed AI-security pure-plays in a hot, migrating pool with declared strategic acquirers = textbook sell-side mandates; the scarcity window closes as platforms aggregate.

→ Buy-side: every platform and many sponsors now have an explicit AI-security gap to fill; targeted sourcing here extends a buy-and-build program.

Adjacent market: the AI infrastructure and governance layers as industries of their own are mapped on AI Infrastructure & Governance.


Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.