The Business of Cyber Security

What AI security means — three sub-markets

A common analytical error is treating "AI security" as one thing. It is three, and they map to different products, buyers, and acquirers:

  1. Security for AI (AI-SPM / model & data security) — protecting the models, training data, and pipelines an enterprise builds or fine-tunes. Think model scanning, ML-supply-chain integrity, AI asset inventory, posture management. Buyer: the AI/platform team. (Protect AI, HiddenLayer, Robust Intelligence.)
  2. Runtime / GenAI-app security (the AI firewall) — guarding live LLM applications and agents against prompt injection, data leakage, jailbreaks, and toxic output at inference time. Buyer: the AppSec / SecOps team. (Lakera, Prompt Security, Lasso, CalypsoAI, Noma.)
  3. Agentic / non-human identity security — governing the exploding population of agents, MCP connections, and machine identities. Buyer: the IAM team. This overlaps 20b (Astrix, Entro, Token, Noma).

Most "AI security" startups began in one lane and are sprinting to cover all three, because the platform acquirers want a full stack, not a feature.

The platform land-grab — who bought what

In 18 months, every major platform bought its way into AI security Announced acquisitions of security-for-AI / GenAI-app-security startups, 2024–2026 (est. values; several undisclosed) Aug 2024 Apr 2025 Aug–Sep 2025 Jan 2026 $250M $500M $700M Cisco N/D PANW ~$700M S1 ~$250M Check Pt ~$300M F5 N/D Robust Intel. Protect AI Prompt Sec. Lakera CalypsoAI Sources: company press releases / 8-Ks, Apr 2025–Jan 2026. Values estimated where undisclosed (N/D). Exhibit: The Business of Cyber Security.
The pattern is a classic platform "feature-ization" sweep: each network/endpoint/AppSec leader needed an AI-security story for the 2026 selling season, and building organically was slower than buying a 2–4-year-old startup. That compresses the independents' window — the exit is increasingly "be acquired in 18 months" rather than "scale to IPO." See the consolidation logic on [02d](02d-consolidation-aggregation.md).

The acquired cohort (now inside platforms)

Target Acquirer Announced Est. value What it brought
Robust Intelligence Cisco Aug 2024 undisclosed Model/app testing, AI firewall → folded into Cisco AI Defense
Protect AI Palo Alto Networks Apr 28 2025 ~$650–700M (est.) AI-SPM, model scanning, the open-source projects (ModelScan, NB Defense, Garak); anchors Prisma AIRS
Prompt Security SentinelOne Aug 5 2025 ~$250M (cash+stock) Runtime GenAI/agent visibility & enforcement; "security for AI" to pair with S1's "AI for security"
Lakera Check Point Sep 16 2025 ~$300M Runtime LLM guardrails + red-teaming (Gandalf); becomes Check Point's AI-security Center of Excellence
CalypsoAI F5 Jan 2026 undisclosed Inference-layer red-teaming & runtime defense; fits F5's app-delivery/app-security stack
Promptfoo OpenAI Mar 9 2026 undisclosed Red-teaming / LLM-&-agent evaluation (prompt-injection, jailbreak, data-leak testing); → OpenAI Frontier. First frontier-lab buyer in the land-grab — the labs move from validating partners (Glasswing/Daybreak) to buying the harness

A new kind of buyer joined the land-grab. Every acquirer above through January 2026 was a platform/strategic (Cisco, Palo Alto, SentinelOne, Check Point, F5). On March 9, 2026, OpenAI agreed to acquire Promptfoo (OpenAI · TechCrunch) — the first time a frontier lab bought an independent AI-security pure-play outright rather than merely partnering with one (cf. Project Glasswing/Daybreak). It is the cleanest live evidence for the bear case below — the labs themselves are the best-positioned builders of the operational harness — and the anchor for book Ch 26's "aggregation clock" exhibit (seven pure-plays absorbed in ~21 months, the cadence tightening toward one a quarter).

The independents still standing

Company Lane Funding signal M&A read
HiddenLayer Security-for-AI / MLDR (model detection & response) $50M Series A (Sep 2023, M12/Moore) Pure-play AI-SPM leader; logical platform target if it doesn't raise growth capital
Noma Security Agentic-AI + AI-SPM full lifecycle $100M Series B (Jul 2025, Evolution Equity; 1,300%+ ARR growth claimed) Fastest-scaling independent; could go either way (scale or premium exit)
Neo Agentic / non-human identity + runtime (real-time control layer over AI agents) $100M total — $75M Series A (Jul 2026, Andreessen Horowitz + Bessemer; Craft, Merlin) plus a $25M seed completed 2025 Best-funded new entrant in lane (3); founded by ex-SentinelOne (COO Nick Warner, detection-engineering lead Shlomi Salem) with ex-Wiz/Palo Alto staff; inventories and enforces policy on AI agents, MCP servers, and browser extensions; launched from stealth Jul 20 2026
Hush Security Agentic / non-human identity — machine-access platform governing AI agents and their infrastructure $30M Series A (Jul 2026, total $41M; Akamai strategic investor + Battery, YL Ventures) Founded 2024 by ex-Meta Networks team; strategic acquirer (Akamai) already on the cap table — a classic invest-then-absorb setup in lane (3)
Act Security Agentic access / cloud-access-surface reduction — enforces boundaries for humans, workloads, and AI agents $60M total (Jul 2026; $20M seed Team8 + Bessemer, $40M Series A Notable Capital) Founded by the Medigate team (sold to Claroty for $400M); repeat AI-security backers; overlaps exposure management / CTEM
Onyx Security Agentic governance — enterprise "AI control plane" that discovers, monitors and remediates risks from AI agents accessing corporate systems $113M Series B (Jul 2026) at $640M; total ~$153M (Bessemer led; Cyberstarts, TCV, Conviction, FirstMark) Founded 2024 (Bar Kogan, Elbaz); Fortune 500 customers, revenue quadrupled in ~4 months from stealth; largest AI-agent-governance round of the July cluster — governs what agents may do rather than issuing their identities
Lasso Security Runtime GenAI / agent security Seed/Series A (Israeli) Runtime lane; acquisition candidate for a SecOps platform without one
Apex / PromptArmor / Aim / Knostic GenAI governance, DLP-for-AI, access Early-stage Feature-companies; absorbed into broader DSPM/CASB platforms
Pillar Security, Operant, Aurascape Agentic runtime / AI-native SOC adjacencies Early-stage Watch list; agentic-identity overlap with 20b

The named landscape is unusually Israeli- and Seattle/SF-concentrated (Lakera is the Zurich outlier), reflecting the Israeli foundry and the frontier-lab talent pools. Funding for the category surged into 2026 — RSAC-2026 coverage counted ~$3.6B of Crunchbase funding flowing to agentic-AI-security names, against a ~$96B cyber-M&A backdrop. Mid-2026 rounds continued at scale: Neo's $100M launch (Andreessen Horowitz and Bessemer, Jul 2026) is the largest new-entrant round to date in the agentic-identity lane, and turns on the same demand thesis Gartner frames as agentic adoption rising from ~5% of enterprise applications in 2025 toward ~40% by the end of 2026. Late July 2026 firmed the lane into a cluster: Hush Security ($30M Series A, with Akamai as a strategic investor) and Act Security ($60M out of stealth, Team8 + Bessemer) both closed on Jul 28, concentrating fresh capital in governing the AI-agent / non-human-identity population — and, in Hush's case, placing a strategic acquirer on the cap table before scale.

Why it matters for M&A — and the bear case

The investable insight is timing and lane. Security-for-AI buyers pay platform multiples for a capability they can cross-sell to an installed base tomorrow, not for standalone ARR — which is why sub-$10M-ARR companies cleared $250–700M. The acquirer screen is every name in the land-grab chart plus the platforms that still lack a story (CrowdStrike, Zscaler, Fortinet, Microsoft's organic build, Okta on the identity edge).

The falsifiable bear case has three legs. (1) Feature, not platform — if AI-security collapses into a checkbox inside DSPM/CNAPP/IAM suites, independents get commoditized before they scale and exits compress. (2) The buyer is the model provider — if OpenAI/Anthropic/Google ship "good-enough" native guardrails, the third-party runtime-firewall thesis erodes from below. (3) Demand is ahead of spend — enterprises are still piloting GenAI; if budgets lag the hype, the 2025–26 valuations look like a vintage peak rather than a floor. The counter: regulation (20d, EU AI Act), the agent explosion (20b), and the offense curve (20a) all push the demand floor up, not down.


Sources: Palo Alto–Protect AI (PANW press, Apr 28 2025) · CNBC on PANW–Protect AI · SentinelOne–Prompt Security (Aug 5 2025) · Yahoo Finance: ~$250M deal · Check Point–Lakera (~$300M, Sep 16 2025) · Cisco–Robust Intelligence (Aug 2024) · Noma Security $100M (Jul 2025) · HiddenLayer $50M (Sep 2023) · F5–CalypsoAI (announced Jan 2026, per market coverage; deal-value undisclosed) · Neo $100M launch (GlobeNewswire, Jul 20 2026) · CTech on Neo (Jul 20 2026) · Hush Security $30M (SecurityWeek, Jul 28 2026) · Hush Security $30M (PR Newswire, Jul 28 2026) · Act Security emerges from stealth (SecurityWeek, Jul 28 2026) · Act Security $60M (SiliconANGLE, Jul 28 2026).


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.