{"id":776256,"date":"2026-09-19T23:34:09","date_gmt":"2026-09-19T23:34:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/776256\/"},"modified":"2026-09-19T23:34:09","modified_gmt":"2026-09-19T23:34:09","slug":"agentic-security-is-the-billion-dollar-challenge-for-some-clever-startup-to-solve","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/776256\/","title":{"rendered":"Agentic security is the billion-dollar challenge for some clever startup to solve"},"content":{"rendered":"<p>When it comes to AI models, security functions as an afterthought, as evidenced by <a href=\"https:\/\/www.theregister.com\/security\/2026\/09\/18\/researchers-used-claude-to-hack-openai-employees-chatgpt-accounts\/5297517\" rel=\"nofollow noopener\" target=\"_blank\">increased instances<\/a> of\u00a0<a href=\"https:\/\/www.theregister.com\/security\/2026\/09\/14\/openais-malicious-bot-swarm-attacked-rubygems\/5296356\" rel=\"nofollow noopener\" target=\"_blank\">agents hacking<\/a>\u00a0<a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/09\/10\/anthropic-reveals-fourth-likely-crime-committed-by-its-ai\/5295412\" rel=\"nofollow noopener\" target=\"_blank\">organizations<\/a> and <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/27\/openai-explains-how-its-naughty-ai-agents-attacked-hugging-face\/5292780\" rel=\"nofollow noopener\" target=\"_blank\">people<\/a>, and <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/09\/10\/latest-anthropic-horror-story-chills-with-tales-of-kamikaze-drone-swarms-and-bioweapons-research\/5295702\" rel=\"nofollow noopener\" target=\"_blank\">other<\/a> <a href=\"https:\/\/www.theregister.com\/security\/2026\/09\/16\/ai-agents-can-modify-themselves-without-humans-telling-them-to-do-so\/5296991\" rel=\"nofollow noopener\" target=\"_blank\">security mishaps<\/a> with <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/06\/openai-reveals-its-rogue-agent-swarm-went-a-little-bit-borg-ahead-of-hugging-face-hack\/5283741\" rel=\"nofollow noopener\" target=\"_blank\">agents gone rogue<\/a>. There&#8217;s also an opportunity here for companies to offer new solutions.<\/p>\n<p>This should not come as a shock to anyone, according to cybersecurity investors and accelerator executives.<\/p>\n<p>\u201cOn one hand, we shouldn\u2019t be surprised that increasingly capable agents are finding creative and sometimes unexpected ways to accomplish their objectives,\u201d Matt Hartman, chief strategy officer at Merlin Group, told The Register. \u201cOn the other, we can\u2019t accept harmful behavior as inevitable or unmanageable.\u201d\u00a0<\/p>\n<p>It\u2019s the same story that plays out with every emerging technology, from laptops to cloud, said Todd Graham, managing partner at Microsoft\u2019s M12 venture fund.<\/p>\n<p>\u201cEvery time we&#8217;ve built a new piece of infrastructure, we&#8217;ve conveniently forgotten the security,\u201d Graham told The Register.\u00a0<\/p>\n<p>Herein lies the opportunity for early-stage security companies.<\/p>\n<p>\u201cIf laptops were default secure, we wouldn&#8217;t have CrowdStrike,\u201d Graham said. \u201cIf the cloud was default secure, we wouldn&#8217;t have Wiz. If identity wasn&#8217;t default secure, we wouldn&#8217;t have a bunch of Active Directory add-ons and Okta.\u201d<\/p>\n<p>When it comes to AI security, \u201ca lot of ships are going to rise with this tide,\u201d he added.<\/p>\n<p>What\u2019s different with AI is the speed at which models are advancing. While companies adopted cloud technologies over a period of years, organizations are <a href=\"https:\/\/www.theregister.com\/special-features\/2026\/01\/29\/unaccounted-for-ai-agents-are-being-handed-wide-access\/5120939\" rel=\"nofollow noopener\" target=\"_blank\">moving full speed ahead<\/a> to incorporate agents and other AI tools into their production environments and allow them to access the most business-critical data and applications. Yet they don\u2019t have a strong handle on how to manage, secure, or even identify the agents that are already roving about their systems.<\/p>\n<p>\u201cThis is a transition happening month over month, and given the rate of change we\u2019re seeing in the market, I\u2019m in no way or shape surprised that this issue has come to a head in a rather dramatic fashion,\u201d Graham said. \u201cThe incidents that have occurred &#8211; I\u2019m not going to defend them, but they should be a wake up call. This is a moment in time where we need to insert security, and we&#8217;re just going to have to insert it faster.\u201d<\/p>\n<p>&#8216;Ships are going to rise&#8217; with the AI tide<\/p>\n<p>Hartman joined Merlin after a lengthy career in federal cybersecurity, including senior roles at the US Cybersecurity and Infrastructure Security Agency. In his private-sector role, he helps determine which early- to growth-stage cybersecurity companies the group invests in, and then works with these firms to scale their technology across government, critical infrastructure, and other highly regulated markets.\u00a0<\/p>\n<p>\u201cWe\u2019re particularly interested in the security layer that governs agent behavior: identity for non-human actors, clear limits on what they can access and do, and an audit trail for actions taken on an agency\u2019s behalf,\u201d he said. \u201cAgencies aren\u2019t just asking how to adopt agents, they\u2019re asking how to constrain them and prove what one did at 2 AM on a Tuesday.\u201d<\/p>\n<p>But while \u201cthe opportunity is enormous,\u201d startup founders need to do more than just build an agentic AI security product. \u201cAI has made it faster and cheaper than ever to build a product, so the bar for differentiation keeps rising,\u201d Hartman said. \u201cAs the cost of building technology falls, the value shifts toward differentiated capabilities and the ability to take them to market. Founders who can do both have a real opportunity to define this category.\u201d<\/p>\n<p>            This is a moment in time where we need to insert security, and we&#8217;re just going to have to insert it faster<\/p>\n<p>Graham also says that end-users are looking for agentic identity and governance products &#8211; \u201cI truly believe someone is going to build the next Okta, just as SaaS generated Okta,\u201d &#8211; but adds he sees several founders \u201cthinking way too small.\u201d<\/p>\n<p>\u201cI\u2019m seeing a lot of companies that are solving a sliver of the problem,\u201d Graham said. \u201cAnd the reality is, if I&#8217;m a CISO for a Fortune 500 company, no way I&#8217;m going to go buy 15 things to do one thing. If you look at the standard identity stack that we\u2019ve had for humans for quite some time, it has governance, you know, access control, authorization, access. For agents, someone&#8217;s going to have to come to us with a solution that does all of the things.\u201d<\/p>\n<p>Agentic identity is the next unicorn<\/p>\n<p>When it comes to non-human identities, however, that\u2019s a really big, tough ask. Service accounts remain a prime target for hackers because they typically have high privileges and passwords that never expire. Securing these non-human accounts still plagues security teams &#8211; and that\u2019s even before agents entered the mix.<\/p>\n<p>Beyond agentic identity, AI endpoint security &#8211; think of this as CrowdStrike for AI &#8211; is another area ripe for inventive startups, Graham said.\u00a0<\/p>\n<p>He says it\u2019s a challenge he would personally tackle as a founder, but he\u2019s been banned from starting any more companies, so that\u2019s not going to happen.<\/p>\n<p>\u201cIf you have a breach, and you know you get hauled in front of Congress to explain why you didn&#8217;t have antivirus turned on [or] EDR, you\u2019re going to add AI endpoint pretty quickly to that list,\u201d Graham said. \u201cIt feels like a very hot area that is still early enough, if someone wanted to build a quality solution.\u201d<\/p>\n<p>Existing endpoint and antivirus vendors \u201cwill absolutely\u201d build products to fill this void, he added. \u201cBut it does feel like again a moment in time where disruption is coming for everyone, especially those that have you know pre-existing commitments to go solve.\u201d<\/p>\n<p>Graham admits he is \u201cworried\u201d about the recent real-world bad behavior by AI agents. \u201cIf left unencumbered, if left to its own devices, I am very concerned about where the endpoint is for this,\u201d he said.\u00a0<\/p>\n<p>Still, he\u2019s \u201ccomforted\u201d because he\u2019s seen this scenario play out before, with security scrambling to keep up with infrastructure development. Graham also was &#8220;pleasantly surprised\u201d by Anthropic CEO Dario Amodei\u2019s <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/09\/15\/anthropic-and-openai-look-to-uncle-sam-to-make-them-too-big-to-fail\/5296403\" target=\"_blank\" rel=\"nofollow noopener\">now infamous \u201cWe Must Pace the Frontier\u201d essay<\/a>.<\/p>\n<p>\u201cI&#8217;m not taking the cynical view that it&#8217;s some sort of grand conspiracy to get around antitrust,\u201d he told us.\u00a0<\/p>\n<p>\u201cI&#8217;m a believer that AI is this awesome tool that is going to fundamentally change a lot of lives for the better. But we\u2019ve got to put in the work now,\u201d Graham said. \u201cWe&#8217;ve kicked the security can down the road long enough, and now we need to solve it.\u201d\u00a0\u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"When it comes to AI models, security functions as an afterthought, as evidenced by increased instances of\u00a0agents hacking\u00a0organizations&hellip;\n","protected":false},"author":2,"featured_media":776257,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-776256","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/776256","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=776256"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/776256\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/776257"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=776256"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=776256"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=776256"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}