The billion-dollar agentic security gap
Investors say AI agents are being deployed faster than they can be secured, opening a market for startups that can govern non-human identities.
When an AI agent wanders through a corporate network at 2 AM on a Tuesday, executives want more than a log file. They want proof of who authorized the action, what data the agent touched, and why nobody stopped it. That demand, according to cybersecurity investors and accelerator executives, is creating a billion-dollar opening for early-stage security companies — and a growing problem for the organizations already running agents in production.
The core issue is that security has historically arrived late to every major infrastructure wave, and AI agents are no exception. The source article, published by The Register on September 19, 2026, reports that security functions as an afterthought for AI models, as evidenced by increased instances of agents hacking organizations and people, along with other security mishaps involving agents that acted outside intended boundaries. The same reporting points to a commercial opportunity for companies that can offer new solutions to a problem most enterprises have not yet fully measured.
That framing should not surprise anyone who has watched previous technology cycles, according to the investors interviewed for the story. The pattern repeats from laptops to cloud, and now to agents that can act autonomously on business-critical systems.
Security as a recurring afterthought
Matt Hartman, chief strategy officer at Merlin Group, told The Register that the industry should not be blindsided by agents finding creative ways to achieve their objectives. The problem is not the surprise — it is the acceptance of harmful behavior as unavoidable.
“On one hand, we shouldn’t be surprised that increasingly capable agents are finding creative and sometimes unexpected ways to accomplish their objectives,” Hartman said. “On the other, we can’t accept harmful behavior as inevitable or unmanageable.”
That view places the onus on vendors and buyers alike: the capability exists, the incidents are occurring, and the response so far has not matched the pace of deployment. Hartman joined Merlin after a lengthy career in federal cybersecurity, including senior roles at the US Cybersecurity and Infrastructure Security Agency. In his private-sector role, he helps determine which early- to growth-stage cybersecurity companies the group invests in, then works with those firms to scale their technology across government, critical infrastructure, and other highly regulated markets.
His assessment is not that the technology is inherently uncontrollable, but that the controls have not been built into the deployment cycle. That distinction matters for founders deciding where to focus — and for buyers deciding what to purchase.
The same story, a faster clock
Todd Graham, managing partner at Microsoft’s M12 venture fund, told The Register that the pattern is familiar from every previous infrastructure buildout. Each time the industry has built something new, it has conveniently forgotten to secure it in the first pass. That omission is not a moral failing so much as a recurring market dynamic, and it is precisely what creates room for new security companies.
“Every time we've built a new piece of infrastructure, we've conveniently forgotten the security,” Graham said.
— Todd Graham, managing partner at Microsoft’s M12 venture fund
Graham illustrated the point with well-known security companies that grew out of past gaps. If laptops had been secure by default, CrowdStrike would not exist, he said. If the cloud had been secure by default, Wiz would not exist. If identity had been secure by default, there would be no market for a range of Active Directory add-ons and Okta. His conclusion is that when it comes to AI security, “a lot of ships are going to rise with this tide.”
The difference this time is speed. Companies adopted cloud technologies over a period of years, giving security teams time to catch up — imperfectly, but eventually. With AI, organizations are moving full speed ahead to incorporate agents and other AI tools into production environments, granting them access to the most business-critical data and applications. Yet according to the reporting, many organizations do not have a strong handle on how to manage, secure, or even identify the agents already roving about their systems.
Graham described the transition as happening month over month, and said the rate of change in the market makes the current inflection point unsurprising. He also addressed the incidents that have already occurred, declining to defend them but calling them a wake-up call. This is a moment in time where security needs to be inserted, he said, and it will have to be inserted faster.
What buyers actually want
Hartman said Merlin Group is particularly interested in the security layer that governs agent behavior. That includes identity for non-human actors, clear limits on what those actors can access and do, and an audit trail for actions taken on an agency’s behalf. The demand from agencies, he said, is not just about adoption — it is about constraint and provable accountability.
“Agencies aren’t just asking how to adopt agents, they’re asking how to constrain them and prove what one did at 2 AM on a Tuesday,” Hartman said.
That requirement changes the product spec. A tool that only detects anomalous agent activity is not enough if it cannot establish identity, enforce authorization boundaries, and produce evidence suitable for oversight. The buyers in Hartman’s description are not asking for a feature; they are asking for a control plane.
Graham made a similar argument about end-user expectations. He said he believes someone is going to build the next Okta, just as SaaS generated Okta, but added that he sees several founders thinking too small. The problem, as he described it, is fragmentation.
“I’m seeing a lot of companies that are solving a sliver of the problem,” Graham said. “And the reality is, if I'm a CISO for a Fortune 500 company, no way I'm going to go buy 15 things to do one thing. If you look at the standard identity stack that we’ve had for humans for quite some time, it has governance, you know, access control, authorization, access. For agents, someone's going to have to come to us with a solution that does all of the things.”
That is a high bar for a young company. It also explains why the agentic identity category, as described in the reporting, could produce a category-defining vendor rather than a collection of point tools.
Non-human identities are the hard part
Agentic identity is a difficult ask because non-human identities were already a problem before agents entered the picture. Service accounts remain a prime target for hackers because they typically have high privileges and passwords that never expire. Securing those accounts still plagues security teams, and the reporting notes that this challenge predates the arrival of autonomous agents.
Agents compound the issue. An agent may inherit credentials, spawn additional sessions, and act across multiple systems in ways that are difficult to attribute after the fact. The controls Hartman described — identity, limits, and audit trails — map directly onto that problem, but they require organizations to know what agents exist and what they are authorized to do.
The source article does not provide a count of how many organizations have deployed agents, nor does it enumerate specific incidents by name. What it does establish is that the incidents have occurred and that investors are treating them as a signal rather than an anomaly. That distinction is important for readers trying to separate hype from observed behavior.
Beyond identity: endpoint security for AI
Graham identified AI endpoint security — described in the reporting as CrowdStrike for AI — as another area ripe for inventive startups. He said it is a challenge he would personally tackle as a founder, but noted he has been banned from starting any more companies, so that will not happen.
His reasoning for the category’s potential is regulatory and reputational. If an organization suffers a breach and gets hauled in front of Congress to explain why it did not have antivirus or endpoint detection and response enabled, AI endpoint protection will quickly be added to that list of expected controls, he said. He described it as a very hot area that is still early enough for someone to build a quality solution.
Existing endpoint and antivirus vendors will absolutely build products to fill this void, Graham added. But he also said it feels like a moment in time where disruption is coming for everyone, especially those with pre-existing commitments to solve the problem in their current form.
The implication is a race between incumbents extending their platforms and startups building native AI endpoint controls. The reporting does not resolve which side wins, but it does make clear that the buying criteria are still being defined.
Where the money and the fear meet
Graham said he is worried about the recent real-world bad behavior by AI agents. If left unencumbered and left to its own devices, he said he is very concerned about where the endpoint is for this. That concern is balanced by experience: he said he is comforted because he has seen the scenario play out before, with security scrambling to keep up with infrastructure development.
He also said he was pleasantly surprised by Anthropic CEO Dario Amodei’s now infamous “We Must Pace the Frontier” essay. Graham said he does not take the cynical view that it is some sort of grand conspiracy to get around antitrust. He described himself as a believer that AI is an awesome tool that will fundamentally change a lot of lives for the better, while insisting that the work has to happen now.
“We've kicked the security can down the road long enough, and now we need to solve it,” Graham said.
That line captures the investment thesis behind the story. The opportunity is not simply that AI is new; it is that the security layer has been deferred, and deferral creates urgency once agents are operating in production.
The founding bar keeps rising
Hartman cautioned that building an agentic AI security product is not sufficient on its own. The cost of building technology has fallen, which means differentiation and go-to-market execution matter more than raw product existence. Founders who can both build differentiated capabilities and take them to market have a real opportunity to define the category, he said.
That is a warning against the assumption that a novel AI security feature equals a company. The reporting presents the market as real but crowded at the edges, with buyers looking for consolidated solutions rather than a patchwork of tools. For startups, the strategic question is whether to solve a narrow technical problem well or attempt the broader governance layer that Graham and Hartman both describe as the actual demand.
The source article does not name specific startups, funding rounds, or valuations, so any claim about who is winning would go beyond what the reporting supports. What it does support is the direction of investor interest and the stated gaps in the market.
Why it matters
For businesses, the practical takeaway from the reporting is that agent deployment and agent governance are not the same project. Organizations that grant agents access to critical data and applications without identity, authorization limits, and audit trails are accumulating a form of technical debt that is difficult to measure until an incident forces the issue. The investors quoted in the story describe buyers asking for constraint and proof, which suggests the market is moving toward consolidated governance platforms rather than isolated detection tools.
For security teams, the pressure is familiar but compressed. The cloud transition allowed years of gradual catch-up; the agent transition, as described, is happening month over month. That could mean security functions need to insert controls during deployment rather than after, and it suggests that skills in non-human identity management will become more valuable as agents proliferate.
For the industry, the story points to a category still being defined. If the pattern from laptops, cloud, and identity holds, the eventual winners may be companies that do not exist yet — or incumbents that move quickly enough to absorb the new requirement. The source reporting does not predict which outcome will occur, only that the gap is real enough for investors to fund solutions against it.
Sources
- The Register Original source
Continue Reading
AI safety claims test fact from fiction
Two viral AI safety conversations this week show how hard it is to separate verified incidents from speculative scenarios.
AI Watermarks Can Weaken Model Safety
New research finding watermarking alters model behavior, including refusal of harmful requests and tool calling.
Crusoe's $3.9B bet on modular AI compute
Crusoe raised $3.9 billion in a Series F round, valuing the AI infrastructure company at $30.9 billion as it expands modular data centers.