
What happened
Strategic adviser Itay Sagie argues AI agent security will not become one broad category, but will split into control points. Kiteworks acquired Bonfy.AI, and Huskeys raised a $27 million Series A led by Blackstone.
Why it matters
Agent identity is becoming a new layer of cybersecurity, and the real value sits in what a company controls — identity, data access, prompts or auditability — so 'AI security' is likely too broad a positioning for startups.
What to watch
The test is whether distinct control points consolidate into platforms or remain standalone tools. M&A activity around agent identity, data access, and traffic security is the signal to track.
WHO IT HITSCybersecurity startup founders and M&A teams need to define their control point precisely, as enterprise security vendors and cloud platforms look to embed agent-security capabilities into their products.
Summaries like this, in your inbox every morning.
As AI agents browse the web, write code, access files, trigger APIs and interact with internal systems, they are becoming a new class of enterprise identity. Unlike traditional users or service accounts, these identities are not passive: they can move between systems, invoke tools and make decisions, which makes controlling them more complex. Companies will need to know which agent accessed what information, which systems it connected to, and whether its actions were authorized.
The article suggests this market will not develop as one broad category called 'AI security.' Instead, the real opportunity will be around specific control points — one company may protect agent identity, another may control the data an agent can access, while others may focus on prompts, MCP servers, plug-ins, traffic or auditability. Existing activity supports this view: Kiteworks acquired Bonfy.AI for real-time data classification and policy enforcement, while Huskeys raised a $27 million Series A led by Blackstone to secure complex internet traffic, including traffic generated by autonomous systems.
For entrepreneurs, this means 'AI security' may already be too broad a positioning. The more important question is what exactly the company controls. The stakes hinge on whether these control points consolidate into broader platforms or remain standalone tools, and on whether identity providers, data-security vendors, cybersecurity platforms, cloud companies and enterprise software vendors embed agent-security capabilities directly into their products. How that plays out will determine which startups become acquisition targets and which become features of larger platforms.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Rabbit Inc. unveiled OS3, a cloud personal AI agent installed via a single command on up to five machines, wor…
At Snapdragon Summit 2026, Qualcomm CEO Cristiano Amon hosted Google SVP Rick Osterloh to discuss the past yea…

On September 21, SoftBank launched more than $11 billion in dollar and euro bonds ahead of a $10 billion OpenA…

Advanced Micro Devices crossed a $1 trillion market value for the first time on September 21 after shares jump…

Redis launched LangCache, a managed semantic cache that stores full question-response pairs outside the model…

Trump told the UN General Assembly AI oversight is a 'globalist scheme,' while Sam Altman and Dario Amodei are…
