Security remains an afterthought when it comes to AI models, as demonstrated by rising cases of agents hacking organizations and individuals alongside other security failures involving rogue agents, according to a report published by The Register on September 19. Cybersecurity investors and accelerator executives say this pattern mirrors every previous technology wave, from laptops to cloud computing, where security was conveniently overlooked during the initial infrastructure buildout. Yet the gap presents a significant opening for early-stage security firms to create new solutions.
What sets AI apart is how quickly models are progressing, according to Todd Graham, managing partner at Microsoft's M12 venture fund. While cloud technology adoption unfolded over several years, companies are now racing at full speed to embed agents and other AI tools into production environments and granting them access to their most business-critical data and applications. Organizations lack a firm grasp on how to manage, secure, or even locate the agents already moving through their systems. This shift happens month over month, and given the pace of market change, Graham says the issue has surfaced in a rather dramatic way. The incidents that have taken place should serve as a wake-up call that security needs to be inserted now, and it must happen faster than before.
Matt Hartman, chief strategy officer at Merlin Group and a former senior official at the US Cybersecurity and Infrastructure Security Agency, told The Register that increasingly capable agents are discovering creative and sometimes unexpected methods to achieve their objectives, which shouldn't surprise anyone. However, harmful behavior can't be accepted as inevitable or impossible to control. Merlin Group focuses particularly on the security layer that governs agent behavior, including identity for non-human actors, clear boundaries on what they can access and do, and an audit trail for actions taken on an agency's behalf. Government agencies aren't just asking how to adopt agents but how to constrain them and prove what one did at 2 AM on a Tuesday, Hartman said.
The opportunity is enormous, Hartman noted, but startup founders must go beyond simply building an agentic AI security product. AI has made building products faster and cheaper than ever, so the threshold for differentiation keeps climbing. As the cost of creating technology drops, value shifts toward differentiated capabilities and the ability to bring them to market. Graham points to several areas ripe for disruption, including agentic identity and governance products—he believes someone will build the next Okta just as SaaS generated Okta—and AI endpoint security, which he describes as CrowdStrike for AI. If a breach occurs and executives get called before Congress to explain why they didn't have antivirus or endpoint detection and response enabled, they'll add AI endpoint protection quickly to that list, Graham said. Service accounts remain a prime hacking target because they typically carry high privileges and passwords that never expire, and securing these non-human accounts still plagues security teams even before agents entered the picture.
Graham admits he's worried about recent real-world bad behavior by AI agents and is very concerned about where the endpoint is if agents are left unencumbered and to their own devices. Still, he finds comfort in having seen this scenario before, with security scrambling to keep up with infrastructure development. Graham also expressed pleasant surprise at Anthropic CEO Dario Amodei's "We Must Pace the Frontier" essay, saying he's not taking the cynical view that it's some grand conspiracy to evade antitrust scrutiny. He believes AI is an awesome tool that will fundamentally change many lives for the better, but the work must happen now—the security can has been kicked down the road long enough, and now it needs to be solved. The window for founders who can deliver both differentiated capabilities and market execution represents a real chance to define this category, though end-users want comprehensive solutions rather than buying 15 separate things to accomplish one task. For enterprises already moving at breakneck speed to deploy agents, the choice between slowing adoption and accepting unmanaged risk grows starker by the month, while the vendors who solve identity, governance, and endpoint protection holistically stand to capture disproportionate value in a market where piecemeal tools won't satisfy chief information security officers at Fortune 500 companies.

