AI is reinventing every category of software infrastructure and cybersecurity is no exception. AI agents coming online opens a net new threat vector for all enterprises, giving birth to a new layer of AI security products that protects against this net new risk.

AI security as a big opportunity is fairly market consensus – a number of early companies have been acquired by the incumbents and a set of other companies have been kingmade with large rounds out the gates. But despite the innovation over the past 4 years since the launch of ChatGPT, history as a guide shows us that the defining cybersecurity company of this generation likely hasn’t been started yet.

Cybersecurity markets tend to evolve in waves, with the first few waves absorbing the chaos around new terrain and unanswered questions (what does an ideal product look like? What needs to be built? What is the right form factor?) before it ultimately produces a generational business.

Cloud Security as a Case Study

Wiz was acquired by Google last year for $32B. It was the largest cybersecurity acquisition in the history of the industry, indicative of both the magic of the Wiz product (they are wizards after all!) and the enormity of the cloud opportunity. But it’s worth remembering that Wiz was founded in 2020, ~14 years after the advent of EC2 and S3. The canonical cloud security platform emerged 14 years after the inception of the cloud. And Wiz certainly wasn’t the first to identify that cloud security would be important – a number of cloud security companies were founded in that 14 year window.

Why did it take a decade plus for the category defining company to be started, let alone crowned?

The first generation of cloud security businesses were companies like Dome9, Evident.io, and Redlock among others. They were all started in the early 2010s (Dome9 in 2010, Evident in 2013, Redlock in 2015), in an era where the shift to cloud wasn’t fully certain and, hence, the language to define cloud security wasn’t fully there yet.

If you go back and look at the messaging of these companies in the early days, it’s clear that there wasn’t a coherent vocabulary to understand what cloud security meant.

Take the Dome9 website circa 2014 for example. The cloud wasn’t mainstream enough for “cloud security” to be a surefire budget line item for CISOs, hence Dome9 had to approach messaging by porting vocabulary from a previous era. Bulletproof firewall security for cloud servers. Even when seeing how they described their product (“keep ALL administrative ports closed on your servers without losing access and control, dynamically open any port on-demand”) reveals an on-prem network security mental model of the world vs a cloud one.

Dome9 website circa 2014

Evident.io and RedLock were both steps in the right direction on a product level. When you look at the product specs for both companies, there’s a lot of similarities with Wiz (complete and continuous visibility, agentless deployment, etc). And again, it’s impossible to run the counterfactual - both Evident.io and RedLock sold to Palo Alto Networks in 2018 (Evident.io had been around for 5 years, RedLock had been around for 3), so it’s hard to know if these two companies could’ve been longstanding billion dollar businesses had they stayed private.

But aside from the overwhelming tailwind of cloud demand which catapulted Wiz when they started in 2020, both Evident and RedLock were still subject to the inherent chaotic dynamics of cloud in the mid-2010s, which influenced their positioning.

On Evident’s website circa 2016, they clearly positioned themselves as security and compliance automation. RedLock’s website in 2017 emphasized compliance in addition to secure cloud migrations. So much of this is timing dependent: this was at a time where convincing large enterprises to migrate workloads to the cloud was still a large undertaking, and hence infrastructure companies had to attach themselves to those narratives accordingly. When Palo Alto bought both companies in 2018, they were seen as complements - the compliance capabilities of Evident with the analytical capabilities of RedLock.

Evident.io website circa 2016
RedLock website circa 2017

Much ink has been spilled on why Wiz was able to win in the 2020s. Their revenue growth curve was one of the fastest in software history, reaching $100M of ARR in 18 months (this was pre ChatGPT and pre AI!), getting to 25% of the Fortune 100 in this first 1.5 years alone. What sticks out to me:

  • At a technical level, Wiz differentiated from competitors like Orca Security and Lacework by having an agent-less, graph-based approach which made deployment incredibly simple and time-to-value orders of magnitude faster than existing solutions.
  • They also benefited from operating in an environment where the uncertainty around cloud as a secular trend had dissipated, and every enterprise’s focus had shifted to real visibility of these workloads as quickly as possible. Total cloud spend in 2015 was $20B annually. AWS just announced a $40B quarter.  
  • But so much of their magic was in the marketing and positioning too– owning the category fully and unequivocally (their tagline being “secure everything you build and run in the cloud”), brand consistency around the Wizard persona, and just messaging in a way that was crystal clear and digestible by anyone (easy to say, hard to do).

The AI security wave cycle has only just begun

AI is obviously evolving faster than the cloud did, as shown by the rapid revenue ramps of the the large model labs and a number of AI companies (both inference and app layer!). And there is a certain element of early AI security that rhymes with early cloud security: a lot of M&A.

Just in the last few years:

  • Cisco bought Robust Intelligence (August 2024)
  • Palo Alto Networks bought Protect AI (July 2025)
  • SentinelOne bought Prompt Security (August 2025)
  • Cato Networks bought Aim Security (2025)
  • F5 bought Calypso AI (September 2025)
  • Check Point bought Lakera (September 2025)
  • Crowdstrike bought Pangea Security (September 2025)

What’s crazy is that 6/7 of these acquisitions happened in a 56 day span (July 22nd, 2025 to September 16, 2025), and 4 of them happened in September alone.

All these players approached AI security from different angles: scanning machine learning models, detecting AI tools used within an organization, establishing an MCP gateway to monitor tool invocations, and guardrails to prevent sensitive data leakage among other product functionality. Much like cloud security in 2015, the language around AI security hasn’t fully stabilized yet. What it means to secure the AI applications you’re building (and how that differs from securing the AI applications you’re using, a la CASB) isn’t wholly agreed upon.

The AI problem surface itself is in a state of rapid evolution and change.

The first generation focused on securing the model, but to stop there would be to ignore where the risk truly sits: in the agent. MCP went from developer convenience to critical infrastructure almost overnight, with the vulnerabilities following just as fast: roughly thirty MCP-related CVEs in the first sixty days of 2026. It’s hard to standardize a vocabulary for a target that is still changing shape.

If the pattern holds, then the defining AI security company is likely yet to be started. And it will likely originate from a team that will do to AI security what Wiz did to cloud: show up at the exact moment the market finally knows what it wants, ship the product that looks obvious only in hindsight, and own the category so completely that they get to name it.

The company that wins AI security will be the one that gets to define what AI security means.

We don’t know who they are yet, and that is exactly why this is the most exciting time to be looking.

If you’re building a System of Action or have ideas about how we can move toward fully autonomous systems, I’d love to chat. Please reach out to me at proby@work-bench.com.