AI agents are quickly becoming part of the enterprise. They browse the web, write code, access files, trigger APIs and interact with internal systems.
That creates enormous productivity potential, but it also creates a new security problem: Companies now need to protect not only users, devices and applications, but software actors that can take actions on their behalf.
AI agents are becoming a new class of enterprise identity
An agent may access corporate files, query databases, send emails or execute code. Once it has that level of access, it needs permissions, monitoring and governance. Companies will need to know which agent accessed what information, which systems it connected to, and whether the actions it took were authorized.
As enterprises move from experimenting with a few agents to deploying hundreds of them, agent identity will become another important layer of cybersecurity. The challenge is that these identities are not passive. Agents can move between systems, invoke tools and make decisions, which makes controlling them more complex than managing traditional users or service accounts.
The value will sit in specific control points
This market will probably not develop as one broad category called “AI security.” The real opportunity will be around specific control points.
One company may protect agent identity, another may control the data an agent can access, while others may focus on prompts, MCP servers, plug-ins, traffic or auditability.
We are already seeing activity around these areas. Kiteworks recently acquired Israeli startup Bonfy.AI, which focuses on real-time data classification and policy enforcement. Israeli cybersecurity startup Huskeys, meanwhile, raised a $27 million Series A led by Blackstone and focuses on understanding and securing increasingly complex internet traffic, including traffic generated by autonomous systems.
These companies are solving different problems, but together they show how the market may begin to separate into distinct security layers.
These control points are creating a new M&A map
Identity providers may extend identity governance to autonomous agents. Data-security vendors may need to control what information agents can access. Cybersecurity platforms, cloud companies and enterprise software vendors may eventually need agent-security capabilities embedded directly into their products.
For entrepreneurs, this means that “AI security” may already be too broad a positioning. The more important question is what exactly the company controls.
Itay Sagie is a strategic adviser to tech companies, investors, CEOs and boards, specializing in strategy, growth and M&A. He is a guest contributor to Crunchbase News and a university lecturer on strategy, finance and entrepreneurship. Learn more at SagieCapital.com and connect with him on LinkedIn.
Related Crunchbase queries:
- Global M&A In 2026 For Venture-Backed Companies
- Global Venture Funding To AI Startups In 2026
- Global Cybersecurity Venture Funding In 2026
Illustration: Dom Guzman


