Urgent.News

What's breaking now, across thousands of outlets.

AI

The Emerging M&A Map For AI Agent Security

As AI agents gain access to enterprise data, systems and tools, they are emerging as a new class of active identity requiring specialized permissions, monitoring and governance, writes guest author Itay Sagie. He believes the market, and its M&A opportunities, will likely form around specific control points, making precise positioning crucial for startups.

The Emerging M&A Map For AI Agent Security

AI agents are becoming integral to enterprises, capable of browsing the web, writing code, accessing files, triggering APIs and interacting with internal systems. This expansion brings about a fresh security challenge: protecting not just users, devices and applications, but also software actors that can act on behalf of companies.

AI agents represent a new class of enterprise identity, granting them access to corporate files, databases, email, and even the ability to execute code. To secure these agents, companies must implement permissions, monitoring, and governance. As businesses transition from testing a few agents to deploying hundreds, agent identity will emerge as a crucial layer of cybersecurity.

However, these identities are not static; agents can traverse systems, invoke tools, and make decisions, making their control more intricate than traditional users or service accounts. The opportunity lies in specific control points rather than a broad "AI security" category. Companies may specialize in protecting agent identity, managing data access, handling prompts, MCP servers, plug-ins, traffic, or ensuring auditability.

Recent developments include Kiteworks acquiring Bonfy.AI, an Israeli startup specializing in real-time data classification and policy enforcement, and Huskeys, an Israeli cybersecurity firm that raised $27 million in Series A funding to secure complex internet traffic, including that generated by autonomous systems. These acquisitions and investments indicate a potential separation of the market into distinct security layers.

Identity providers may extend identity governance to autonomous agents, data-security vendors may need to control the access agents have to information, and cybersecurity platforms, cloud companies, and enterprise software vendors might embed agent-security capabilities directly into their products. For entrepreneurs, this suggests that "AI security" may be too broad a market positioning.

The more critical question is what specific aspect the company controls. Itay Sagie, a strategic adviser to tech companies, investors, CEOs, and boards, emphasizes that the focus should be on the exact control the company holds.

Written by urgent.news from Crunchbase News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at news.crunchbase.com →

More in AI

More from Wednesday 23 September →