Full Report
High time to stop kicking the security can down the road, investor tells The Reg
Analysis Summary
# Industry News: The Billion-Dollar Opportunity in Agentic AI Security
## Summary
As AI agents move from experimental models to production environments with access to critical data, a massive security gap has emerged. Leading venture capitalists signal that the next "cybersecurity unicorns"—comparable to CrowdStrike or Okta—will be the startups that solve for non-human identity, governance, and AI-specific endpoint protection.
## Key Details
- **Date:** September 19, 2026
- **Companies Involved:** M12 (Microsoft’s Venture Fund), Merlin Group, Anthropic (referenced), CrowdStrike/Okta/Wiz (as historical precedents).
- **Category:** Market Analysis / Venture Capital Trends
## The Story
The rapid adoption of AI agents—autonomous software entities that can perform tasks and access data—has outpaced the security frameworks required to manage them. Historically, security has been an "afterthought" in every major infrastructure shift, from the move to laptops to the migration to the cloud. Today, the industry is repeating this pattern with AI.
Matt Hartman (Merlin Group) and Todd Graham (M12) argue that while AI agents are finding creative ways to accomplish objectives, their behavior is currently unmanaged and often harmful. Organizations are currently deploying these tools without a way to identify, govern, or audit what an agent did at "2 AM on a Tuesday." The shift is happening monthly, rather than yearly, creating an urgent demand for "Agentic Security" that mirrors the evolution of SaaS and Cloud security.
## Business Impact
### For the Companies Involved
- **Venture Funds (M12, Merlin):** Actively scouting for startups that can provide holistic, platform-based solutions rather than "point products."
- **Emerging Startups:** Face a high bar for differentiation; as the cost of building software falls due to AI, value shifts toward go-to-market execution and comprehensive feature sets.
### For Competitors
- **Incumbent Security Vendors (CrowdStrike, Okta):** While these giants will likely build AI-security modules, the current "disruption moment" provides a window for new entrants to establish dominance before incumbents can pivot.
- **Point-Solution Startups:** Likely to fail or be absorbed, as CISOs at Fortune 500 companies are signaling they will not purchase 15 disparate tools to solve one AI governance problem.
### For Customers
- **Enterprise CISOs:** Facing a "wake-up call" to secure autonomous agents. There is a desperate need for tools that provide an audit trail and strict access limits for non-human actors.
- **Productivity Gains vs. Risk:** Businesses want to leverage AI agents for efficiency but are currently doing so at high risk to data integrity and privacy.
### For the Market
- **Formation of a New Category:** "AI Endpoint Security" and "Agentic Identity" are emerging as the next major sub-sectors within the cybersecurity market.
- **Investment Flow:** Significant capital is shifting toward startups that can prove "agentic governance"—the ability to constrain and audit AI behavior.
## Technical Implications
- **Non-Human Identity (NHI):** The technical challenge involves managing service accounts that have high privileges and lack expiring credentials, now compounded by autonomous agents.
- **Agentic Governance:** Developing the "governance layer" to define what an agent can access and ensuring there is a tamper-proof audit trail for every action taken.
- **AI Endpoint Protection:** The need for a "CrowdStrike for AI" that monitors the execution of AI models for malicious behavior or prompt injection in real-time.
## Strategic Analysis
- **Market Positioning:** The market is moving away from securing the *model* (LLM security) toward securing the *action* (agentic security).
- **Competitive Advantage:** Success will go to platforms that integrate identity, access control, authorization, and governance into a single stack for non-human actors.
- **Challenges:** The speed of AI advancement makes it difficult for security products to remain relevant; a solution built for today's agents might be obsolete in six months.
## Industry Reactions
- **Todd Graham (M12):** Believes the next Okta-sized company will be built in the agentic identity space, but warns that many current founders are "thinking way too small."
- **Matt Hartman (Merlin):** Emphasizes that as technology becomes cheaper to build, the real value lies in "differentiated capabilities" and the ability to scale in highly regulated markets like the public sector.
## Future Outlook
- **Predictions:** Expect a wave of M&A as incumbents buy smaller AI-security startups to fill gaps in their portfolios.
- **Watch For:** The emergence of a dominant "Agentic Identity and Access Management" (AIAM) platform within the next 12–18 months.
- **Regulatory Pressure:** Potential congressional hearings following AI-related breaches will likely accelerate the adoption of AI endpoint security.
## For Security Professionals
- **Governance First:** Practitioners should focus on discovering where AI agents are currently roving in their systems before attempting to secure them.
- **Audit Trails:** Prioritize tools that offer granular logging of autonomous actions to satisfy compliance and forensic requirements.
- **Identity Shift:** Shift focus from purely human-centric identity (MFA, etc.) to the governance of high-privilege service accounts and AI agents.