What AI security means — three sub-markets
A common analytical error is treating "AI security" as one thing. It is three, and they map to different products, buyers, and acquirers:
- Security for AI (AI-SPM / model & data security) — protecting the models, training data, and pipelines an enterprise builds or fine-tunes. Think model scanning, ML-supply-chain integrity, AI asset inventory, posture management. Buyer: the AI/platform team. (Protect AI, HiddenLayer, Robust Intelligence.)
- Runtime / GenAI-app security (the AI firewall) — guarding live LLM applications and agents against prompt injection, data leakage, jailbreaks, and toxic output at inference time. Buyer: the AppSec / SecOps team. (Lakera, Prompt Security, Lasso, CalypsoAI, Noma.)
- Agentic / non-human identity security — governing the exploding population of agents, MCP connections, and machine identities. Buyer: the IAM team. This overlaps 20b (Astrix, Entro, Token, Noma).
Most "AI security" startups began in one lane and are sprinting to cover all three, because the platform acquirers want a full stack, not a feature.
The platform land-grab — who bought what
The acquired cohort (now inside platforms)
| Target | Acquirer | Announced | Est. value | What it brought |
|---|---|---|---|---|
| Robust Intelligence | Cisco | Aug 2024 | undisclosed | Model/app testing, AI firewall → folded into Cisco AI Defense |
| Protect AI | Palo Alto Networks | Apr 28 2025 | ~$650–700M (est.) | AI-SPM, model scanning, the open-source projects (ModelScan, NB Defense, Garak); anchors Prisma AIRS |
| Prompt Security | SentinelOne | Aug 5 2025 | ~$250M (cash+stock) | Runtime GenAI/agent visibility & enforcement; "security for AI" to pair with S1's "AI for security" |
| Lakera | Check Point | Sep 16 2025 | ~$300M | Runtime LLM guardrails + red-teaming (Gandalf); becomes Check Point's AI-security Center of Excellence |
| CalypsoAI | F5 | Jan 2026 | undisclosed | Inference-layer red-teaming & runtime defense; fits F5's app-delivery/app-security stack |
| Promptfoo | OpenAI | Mar 9 2026 | undisclosed | Red-teaming / LLM-&-agent evaluation (prompt-injection, jailbreak, data-leak testing); → OpenAI Frontier. First frontier-lab buyer in the land-grab — the labs move from validating partners (Glasswing/Daybreak) to buying the harness |
A new kind of buyer joined the land-grab. Every acquirer above through January 2026 was a platform/strategic (Cisco, Palo Alto, SentinelOne, Check Point, F5). On March 9, 2026, OpenAI agreed to acquire Promptfoo (OpenAI · TechCrunch) — the first time a frontier lab bought an independent AI-security pure-play outright rather than merely partnering with one (cf. Project Glasswing/Daybreak). It is the cleanest live evidence for the bear case below — the labs themselves are the best-positioned builders of the operational harness — and the anchor for book Ch 26's "aggregation clock" exhibit (seven pure-plays absorbed in ~21 months, the cadence tightening toward one a quarter).
The independents still standing
| Company | Lane | Funding signal | M&A read |
|---|---|---|---|
| HiddenLayer | Security-for-AI / MLDR (model detection & response) | $50M Series A (Sep 2023, M12/Moore) | Pure-play AI-SPM leader; logical platform target if it doesn't raise growth capital |
| Noma Security | Agentic-AI + AI-SPM full lifecycle | $100M Series B (Jul 2025, Evolution Equity; 1,300%+ ARR growth claimed) | Fastest-scaling independent; could go either way (scale or premium exit) |
| Neo | Agentic / non-human identity + runtime (real-time control layer over AI agents) | $100M total — $75M Series A (Jul 2026, Andreessen Horowitz + Bessemer; Craft, Merlin) plus a $25M seed completed 2025 | Best-funded new entrant in lane (3); founded by ex-SentinelOne (COO Nick Warner, detection-engineering lead Shlomi Salem) with ex-Wiz/Palo Alto staff; inventories and enforces policy on AI agents, MCP servers, and browser extensions; launched from stealth Jul 20 2026 |
| Hush Security | Agentic / non-human identity — machine-access platform governing AI agents and their infrastructure | $30M Series A (Jul 2026, total $41M; Akamai strategic investor + Battery, YL Ventures) | Founded 2024 by ex-Meta Networks team; strategic acquirer (Akamai) already on the cap table — a classic invest-then-absorb setup in lane (3) |
| Act Security | Agentic access / cloud-access-surface reduction — enforces boundaries for humans, workloads, and AI agents | $60M total (Jul 2026; $20M seed Team8 + Bessemer, $40M Series A Notable Capital) | Founded by the Medigate team (sold to Claroty for $400M); repeat AI-security backers; overlaps exposure management / CTEM |
| Onyx Security | Agentic governance — enterprise "AI control plane" that discovers, monitors and remediates risks from AI agents accessing corporate systems | $113M Series B (Jul 2026) at $640M; total ~$153M (Bessemer led; Cyberstarts, TCV, Conviction, FirstMark) | Founded 2024 (Bar Kogan, Elbaz); Fortune 500 customers, revenue quadrupled in ~4 months from stealth; largest AI-agent-governance round of the July cluster — governs what agents may do rather than issuing their identities |
| Lasso Security | Runtime GenAI / agent security | Seed/Series A (Israeli) | Runtime lane; acquisition candidate for a SecOps platform without one |
| Apex / PromptArmor / Aim / Knostic | GenAI governance, DLP-for-AI, access | Early-stage | Feature-companies; absorbed into broader DSPM/CASB platforms |
| Pillar Security, Operant, Aurascape | Agentic runtime / AI-native SOC adjacencies | Early-stage | Watch list; agentic-identity overlap with 20b |
The named landscape is unusually Israeli- and Seattle/SF-concentrated (Lakera is the Zurich outlier), reflecting the Israeli foundry and the frontier-lab talent pools. Funding for the category surged into 2026 — RSAC-2026 coverage counted ~$3.6B of Crunchbase funding flowing to agentic-AI-security names, against a ~$96B cyber-M&A backdrop. Mid-2026 rounds continued at scale: Neo's $100M launch (Andreessen Horowitz and Bessemer, Jul 2026) is the largest new-entrant round to date in the agentic-identity lane, and turns on the same demand thesis Gartner frames as agentic adoption rising from ~5% of enterprise applications in 2025 toward ~40% by the end of 2026. Late July 2026 firmed the lane into a cluster: Hush Security ($30M Series A, with Akamai as a strategic investor) and Act Security ($60M out of stealth, Team8 + Bessemer) both closed on Jul 28, concentrating fresh capital in governing the AI-agent / non-human-identity population — and, in Hush's case, placing a strategic acquirer on the cap table before scale.
Why it matters for M&A — and the bear case
The investable insight is timing and lane. Security-for-AI buyers pay platform multiples for a capability they can cross-sell to an installed base tomorrow, not for standalone ARR — which is why sub-$10M-ARR companies cleared $250–700M. The acquirer screen is every name in the land-grab chart plus the platforms that still lack a story (CrowdStrike, Zscaler, Fortinet, Microsoft's organic build, Okta on the identity edge).
The falsifiable bear case has three legs. (1) Feature, not platform — if AI-security collapses into a checkbox inside DSPM/CNAPP/IAM suites, independents get commoditized before they scale and exits compress. (2) The buyer is the model provider — if OpenAI/Anthropic/Google ship "good-enough" native guardrails, the third-party runtime-firewall thesis erodes from below. (3) Demand is ahead of spend — enterprises are still piloting GenAI; if budgets lag the hype, the 2025–26 valuations look like a vintage peak rather than a floor. The counter: regulation (20d, EU AI Act), the agent explosion (20b), and the offense curve (20a) all push the demand floor up, not down.
Sources: Palo Alto–Protect AI (PANW press, Apr 28 2025) · CNBC on PANW–Protect AI · SentinelOne–Prompt Security (Aug 5 2025) · Yahoo Finance: ~$250M deal · Check Point–Lakera (~$300M, Sep 16 2025) · Cisco–Robust Intelligence (Aug 2024) · Noma Security $100M (Jul 2025) · HiddenLayer $50M (Sep 2023) · F5–CalypsoAI (announced Jan 2026, per market coverage; deal-value undisclosed) · Neo $100M launch (GlobeNewswire, Jul 20 2026) · CTech on Neo (Jul 20 2026) · Hush Security $30M (SecurityWeek, Jul 28 2026) · Hush Security $30M (PR Newswire, Jul 28 2026) · Act Security emerges from stealth (SecurityWeek, Jul 28 2026) · Act Security $60M (SiliconANGLE, Jul 28 2026).
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.