Artificial intelligence has changed the shape of cybersecurity. The risk no longer sits only inside servers, laptops, networks, apps, or cloud systems. AI agents now create a new layer of risk. These systems can read emails, access company files, browse websites, call software tools, write code, run commands, and make decisions without a person checking every step.
That change has created a new market for cybersecurity startups. These companies do not focus only on old threats such as malware, phishing, or stolen passwords. They focus on AI agents, model security, agent identity, AI tools, software skills, MCP servers, agent browsers, AI coding systems, and the data that these systems can reach.
The scale of this market now shows how fast the shift has happened. The AI Security Startups Map, with data current to September 1, 2026, tracks 402 companies across 14 security categories and 27 countries. Those companies have raised about $11.3 billion in disclosed capital. The United States has 214 companies, Israel has 90, and the United Kingdom has 20. A large part of the market formed very recently. Some 232 of the 402 companies, or 58%, started between 2023 and 2025. The year 2025 alone saw 87 new companies.
AI Agents Create a New Security Perimeter
The biggest change comes from AI agents. A normal chatbot mainly responds to a request. An AI agent can take action. It can access a database, send an email, open a browser, change a file, call an API, or execute code.
That extra power also creates extra risk.
An attacker may not need to break into the main system. An attacker may instead place harmful instructions inside a web page, email, document, code file, or other source that an AI agent reads. The agent may then treat those instructions as part of its task and take an action that the attacker wants.
This creates a major shift in the threat model. Security teams must now examine not only what a user can access, but also what an AI agent can access, what tools it can call, what data it can read, and what decisions it can make.
The agent itself becomes a security identity. It can hold permissions, access company information, use software tools, and act across several systems. A large company could soon have thousands or even millions of such agents. That scale makes manual control difficult.
HiddenLayer Puts Runtime Security at the Center
HiddenLayer provided one of the clearest signs of investor interest in this market on September 2, 2026. The company raised $100 million in a Series B round led by Delta-v Capital. Ten Eleven Ventures, Morgan Stanley, M12, Microsoft’s venture fund, and Booz Allen Ventures also took part.
The company plans to expand its AI security platform, with a major focus on agent runtime security. HiddenLayer also introduced Agent Harness Security, which extends its runtime protection to AI coding agents. These systems can write, review, and ship code with far less human control than older development tools.
This matters for a simple reason. A coding agent can access source code, secrets, software repositories, terminals, cloud systems, and production tools. A security failure can therefore move far beyond a bad answer from an AI model.
HiddenLayer wants to watch agent behavior while the agent works. Its platform can flag manipulation, tool misuse, and actions that fall outside approved rules. The company says 96% of organizations now view AI as critical to core operations, while almost one-third cannot say with certainty if an AI-related breach has already affected them.
That gap creates a large market for runtime security.
The Software Supply Chain Has a New Layer
AI agents rely on more than models. They can also use skills, plug-ins, MCP servers, tools, and other software components. Each component can add new access and new risk.
AIR, a new AI security company, came out of stealth on September 1 with $50 million from two seed rounds. Sequoia led the first $10 million round, while Greenoaks led the second $40 million round.
AIR focuses on the software supply chain around AI agents. Its platform can find agents inside a company, check the skills and tools they use, and block access to components that fail security rules. It also offers a marketplace for approved agent skills and add-ons.
AIR says its system currently filters out about 27% of the agent skills and add-ons it finds online. The company has more than 20 customers, with about one-quarter of them classed as large enterprises. Financial services and pharmaceutical firms show the strongest demand so far.
The problem goes beyond a simple software scan. A skill may look safe today and turn harmful later. A package may change. A developer account may face compromise. A tool may fetch a new component from the internet. AIR therefore treats this as a continuous trust problem rather than a one-time scan.
That idea could become one of the most important parts of AI security.
Zenity Targets Agent Control
Zenity has also made a major move in this market. In August, the company raised $125 million in Series C capital, led by Norwest. Qumra Capital, SoftBank Vision Fund 2, Hitachi Ventures, LG Technology Ventures, Vertex Ventures, Third Point Ventures, DTCP, and Intel Capital took part in the round.
Zenity focuses on security and governance for AI agents. Its core argument is simple: visibility alone does not solve the problem. Security teams need to know what an agent plans to do before the action takes place.
That concern gained more weight at Black Hat USA 2026. Zenity researchers found dozens of malicious AI agent skills in public registries. Some could deliver malware, change agent settings, steal data, or run attacker-controlled instructions.
Zenity created AI Total to test these skills inside a controlled environment. The system checks what a skill actually does at runtime instead of relying only on a review of its code or written instructions.
The company also disclosed a vulnerability class called PleaseFix. Researchers found zero-click attack paths across Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge. The attack paths could lead to data theft, credential theft, account takeover, or control of a victim’s machine.
These findings show why the browser has become another important AI security frontier.
Obsidian Brings AI Security Into Identity
Obsidian Security adds another part to the picture: identity.
The company raised $85 million in a Series D round in August at a $1.1 billion valuation. Crescent Cove Advisors led the round, with Greylock Partners and Menlo Ventures also taking part.
Obsidian says almost 70% of its customers allow AI agents to interact with business data. Its platform can oversee agents that operate inside products such as Microsoft Copilot Studio, Salesforce Agentforce, and Anthropic’s Claude.
The identity question may become one of the hardest issues in enterprise AI security.
A human employee has a clear identity, role, manager, and access policy. An AI agent may act on behalf of several teams and access several systems. It may also pass work to another agent.
That raises basic security questions. Which agent has access to a customer database? Who approved that access? When should the access expire? What happens when an agent changes its task? What happens when one agent asks another agent to perform a sensitive action?
Security products now need answers to these questions.
Glow Brings AI Security to the Endpoint
Glow takes a different route. The company came out of stealth in July with a $180 million Series A at a $1.2 billion valuation. Sequoia Capital, Cyberstarts, Greenoaks, Redpoint Ventures, Index Ventures, Swish Ventures, Lux Capital, Operator Collective, and Holly Ventures backed the round.
Glow focuses on endpoint security in an AI era. Employee laptops, servers, and other connected devices now interact with a much larger set of AI tools.
At the same time, attackers have access to AI that can help with phishing, malware creation, and more advanced cyberattacks. That puts pressure on traditional endpoint security products.
Glow’s rise shows that AI security does not exist only inside AI models or agent platforms. The endpoint itself must also adapt to the new threat environment.
Huskeys Watches AI-Driven Web Traffic
Huskeys approaches the problem from outside the enterprise.
The Tel Aviv startup raised $27 million in a Series A round led by Blackstone Innovations Investments. The company now has a valuation above $100 million and has raised $35 million in total capital.
Huskeys targets AI-driven web traffic. Its system acts as an intelligent gatekeeper that works with existing security systems and looks for complex automated threats. Blackstone says unwanted automated internet traffic has risen 56% year over year.
Huskeys launched in early 2026 and saw revenue rise fourfold from one quarter to the next. Consumer-focused companies such as Merlin and TikTok account for much of its revenue.
The rise of AI gives attackers better tools for automation. That means security teams must defend not only against human attackers, but also against large volumes of machine-driven activity.
Geordie Focuses on Enterprise Agent Governance
Geordie has also gained strong investor support. The company raised $30 million in Series A capital in May, led by Balderton Capital. Crosspoint Capital, General Catalyst, and Ten Eleven Ventures also took part. The round brought Geordie’s total capital to $36.5 million.
Geordie says its annual recurring revenue rose 1,300% during the first five months of 2026. The company focuses on security and governance for AI agents inside large organizations.
Its approach reflects a wider market shift. Companies do not want to block AI agents entirely. They want to approve useful agents while placing strict controls around their access and actions.
That creates a difficult balance. Too much control can slow business work. Too little control can expose private data, source code, money, and critical systems.
The Market Now Has Many Distinct Layers
The AI security market no longer looks like one simple product category. Model security protects the AI model itself. Runtime security checks agent behavior. Agent identity controls access. AI-SPM tools help companies discover their AI assets. MCP gateways control connections between agents and external tools.
Red-team companies test AI systems for weaknesses. Supply-chain products inspect skills and plug-ins. Agent browser security protects AI-controlled browsers. Coding-agent security focuses on systems that can write and execute software.
The market map now tracks 14 categories. Observability and governance has 258 vendors, while runtime and guardrails has 203. Agentic identity has 93. These numbers overlap across categories, yet they show how quickly the field has split into specialist products.
Security Must Move From Alerts to Action
The next major change may come from automated response.
Traditional cybersecurity often creates an alert for a human analyst. That model becomes harder to scale when thousands of AI agents make millions of tool calls.
A security platform may need to stop a risky action before it happens. It may need to block a suspicious skill, remove an agent’s access, stop a dangerous command, or prevent a sensitive data transfer.
Zenity has argued that security should sit at the decision point, just before an agent takes an action. HiddenLayer also places strong focus on runtime controls. AIR focuses on continuous checks across the agent supply chain. These approaches point toward the same future: security must sit close to the moment when AI takes action.
A New Security Market Takes Shape
The central shift is clear. AI does not only create new cyber tools for attackers. It creates new digital actors inside companies.
An AI agent can hold credentials, read private information, call software, browse the internet, write code, and make decisions. Each new permission creates another possible attack path.
That explains the large capital rounds across the sector. HiddenLayer has raised $100 million in its latest round. Zenity has raised $125 million in Series C capital. Glow raised $180 million at a $1.2 billion valuation. Obsidian raised $85 million at a $1.1 billion valuation. AIR raised $50 million across two seed rounds. Geordie raised $30 million in Series A capital. Huskeys raised $27 million in Series A capital.
The numbers show a market that has moved past the early experiment stage. The next phase will test which startups can turn security research into products that enterprises can trust at scale.
The strongest companies may not simply detect AI attacks. They may control agent identity, check every tool, watch every sensitive action, stop unsafe behavior, and give security teams a clear record of what each agent did.
AI has created a new class of software that can act rather than just respond. Cybersecurity now needs a new class of defense for that software. The companies that solve that problem could define one of the most important security markets of the next decade.
Also Read – Venture Debt vs Equity: Which Is Better for Startups?