AI agents are already roaming corporate networks, accessing critical data, and in some cases going rogue - and the security industry is scrambling to catch up. Investors now see a billion-dollar opening for startups that can build identity, governance, and endpoint protection for non-human actors, a challenge they compare to the early days of cloud security and identity management.
The security gap no one should be surprised by
"On one hand, we shouldn't be surprised that increasingly capable agents are finding creative and sometimes unexpected ways to accomplish their objectives," Matt Hartman, chief strategy officer at Merlin Group, told The Register. "On the other, we can't accept harmful behavior as inevitable or unmanageable."
Todd Graham, managing partner at Microsoft's M12 venture fund, traces the pattern back through decades of tech history. "Every time we've built a new piece of infrastructure, we've conveniently forgotten the security," Graham said. He points to the companies that filled those gaps: "If laptops were default secure, we wouldn't have CrowdStrike. If the cloud was default secure, we wouldn't have Wiz. If identity wasn't default secure, we wouldn't have a bunch of Active Directory add-ons and Okta."
What distinguishes AI from previous waves is velocity. Cloud adoption stretched over years. Organizations are now pushing agents into production environments at a pace measured in months, often granting them access to business-critical systems without a clear plan for managing or even identifying them.
What buyers want: full-stack agent governance
Hartman, whose firm invests in early- to growth-stage cybersecurity companies, said government agencies and enterprises are asking the same questions. "Agencies aren't just asking how to adopt agents, they're asking how to constrain them and prove what one did at 2 AM on a Tuesday."
He listed three capabilities that define the emerging category: identity for non-human actors, clear limits on what agents can access and do, and an audit trail for every action. The opportunity is large, but Hartman warned founders that product differentiation is harder than ever. "AI has made it faster and cheaper than ever to build a product, so the bar for differentiation keeps rising."
Graham sees a market coalescing around agentic identity and governance, but he's frustrated by what founders are pitching. "I'm seeing a lot of companies that are solving a sliver of the problem. And the reality is, if I'm a CISO for a Fortune 500 company, no way I'm going to go buy 15 things to do one thing." He said the winning solution will need to cover governance, access control, authorization, and access - the full stack familiar from human identity systems.
AI endpoint security is the next frontier
Beyond identity, Graham identified AI endpoint security as another area ready for disruption - what he called "CrowdStrike for AI." The logic is straightforward. "If you have a breach, and you know you get hauled in front of Congress to explain why you didn't have antivirus turned on or EDR, you're going to add AI endpoint pretty quickly to that list."
Existing endpoint vendors will build products to fill this gap, he said, but the moment is early enough for a quality-focused startup to define the space. Graham describes himself as "worried" about recent real-world bad behavior by AI agents. "If left unencumbered, if left to its own devices, I am very concerned about where the endpoint is for this." Still, he's seen this cycle before and believes the work is solvable.
For security teams already struggling with non-human identities - service accounts with high privileges and passwords that never expire remain a top attack vector - adding agents to the mix compounds an unsolved problem. Graham's message to the industry is blunt: "We've kicked the security can down the road long enough, and now we need to solve it."
Why this matters for IT, security, and operations leaders
If your organization is deploying AI agents or planning to, the security architecture for those agents likely doesn't exist yet. Investors are signaling that standalone products for agent identity, governance, and endpoint protection will emerge - and that buying 15 point solutions isn't a viable strategy. Security and IT leaders should start defining their requirements for agentic security now, before procurement becomes reactive. For cybersecurity professionals who want to build expertise in this area, AI Security Analytics Courses offer structured learning paths. For CIOs and strategy executives shaping AI adoption roadmaps, AI IT Strategy Training addresses the governance and risk dimensions that investors say will define the next unicorn category.
Your membership also unlocks: