8 segments · 154 companies · as of Sep 18, 2026
AI Security & Trust
Protecting AI systems, identities and data while using AI to detect attacks and fraud
Where it sits
Fed by: Models & Platforms
AI expands the attack surface through agents, machine identities, model inputs and sensitive data. Security platforms automate investigation while specialists secure runtime behavior, recover compromised data and detect impersonation. Durable value depends on enforceable controls and reliable evidence, not the presence of a chatbot.
Why now
Consolidation accelerates: CyberArk, Wiz, Armis, Astrix and Oasis now sit inside broader platforms. August deals add Virtue AI to Fortinet and Permiso to Okta. Agent permissions, prompt attacks and synthetic identities are moving security budgets beyond endpoint and network protection.
Security Platforms & AI SOC
Large security vendors combine telemetry, detection, investigation and response. Enterprise buyers compare coverage and operational accuracy; platform consolidation and existing endpoint or network distribution shape share.
Falcon and Charlotte AI automate SOC investigation; acquired Onum telemetry pipelines strengthen AI SIEM
leaderCortex XSIAM consolidates security telemetry, AI investigation and automated response across enterprise estates
leaderSecurity Copilot agents work with Sentinel and Defender telemetry to triage incidents and automate response
majorGoogle SecOps and Mandiant add Gemini investigation; Wiz cloud-security acquisition closes March 2026
majorVia Splunk, Enterprise Security and AI assistance correlate security events; XDR links network and endpoint signals
majorFortiAI and Security Fabric combine network detection, SOC assistance and automated security operations
majorZero Trust Exchange plus Red Canary, acquired August 2025, connect access signals to managed AI-driven response
majorInfinity AI Copilot supports threat analysis and response across network, cloud and endpoint security
majorVision One and Companion apply AI across endpoint, cloud and network detection and investigation
majorMDR and Taegis, via Secureworks acquired February 2025, combine analyst services with AI detection
majorAurora and managed detection combine AI alert handling with human-led investigation and response
majorExposure platform combines Vulcan risk prioritization and Apex AI exposure capabilities, both acquired in 2025
majorEnterprise TruRisk and TotalAI inventory vulnerabilities and AI exposures for risk-based remediation
majorPurple AI and Singularity AI SIEM investigate threats; Observo, acquired September 2025, prepares telemetry
challengerVia Cloudflare One, combines zero-trust access and network telemetry to detect and contain enterprise threats
challengerActiveAI Security Platform learns normal behavior and coordinates autonomous threat detection and response
challengerInsightIDR and managed response use AI to consolidate alerts, exposure context and investigation workflows
challengerSecurity analytics and AI Assistant search telemetry and guide investigations within SIEM workflows
challengerCloud SIEM and Security Inbox connect cloud detections with AI-assisted investigation and observability context
challengerArmis, acquired April 2026, adds asset exposure intelligence to security incident and remediation workflows
challengerManaged Security Platform combines threat analytics and a 24/7 human SOC for SMB and midmarket security teams
challengerCloud SIEM SOC Analyst Agent delivers evidence-backed investigations; generally available since August 2026
challengerWorkbench detection agents propose rules and summarize alerts for analyst-reviewed managed response
challengerAtlas Preempt feeds continuous AI attack testing into 24/7 managed detection and human-controlled response
challenger
Sources: paloaltonetworks.com, cloud.google.com, ir.crowdstrike.com, newsroom.servicenow.com, sophos.com, wisdominterface.com
Specialist & Regional Security Operations
Autonomous investigation specialists and regional security suppliers serve buyers with existing tools, local threat intelligence or data-residency requirements. Coverage, language and practical response integrations determine adoption.
HyperSOC and agentic workflows investigate alerts and orchestrate response across existing security tools
majorWorkbench and security workflows connect AI reasoning with approved response actions and human checkpoints
majorNew-Scale SIEM and LogRhythm apply behavioral analytics and AI investigation across hybrid security estates
majorBehavioral AI detects email impersonation and collaboration threats; renamed from Abnormal Security in 2025
majorAI PLUS agents connect XDR, SOAR and threat intelligence for Korean enterprise security operations
majorManaged security operations use threat analysis and AI guardrails for Korean enterprise cloud and agent deployments
majorSecudium managed security operations combine Korean threat intelligence, analysts and automated detection
majorQ-GPT and intelligent SOC tools assist Chinese enterprise security analysis and threat response
majorAI SOC and Security GPT combine endpoint and network signals for automated alert investigation
majorSecurity AI models and enterprise security operations use local threat intelligence for Chinese customers
majorCyber threat intelligence and managed SOC services apply AI to investigation for regulated European customers
majorAI SOC analysts investigate alerts and return evidence-backed conclusions for human escalation
challengerHyperStream SIEM and attack-tracing AI support high-volume enterprise SOC investigation across cloud data
challengerSOC platform correlates telemetry into investigation stories and automates threat detection for enterprise security teams
challengerMulti-data-platform SIEM automates detection engineering and triage while retaining customers' security data lakes
challengerManaged detection uses AI-driven triage with human analysts; automation also compresses its own staffing requirements
challengerElements security and managed detection serve European midmarket firms; delisted under Diana BidCo in March 2026
nicheAI-assisted threat analysis complements anti-DDoS and network-security operations for carriers and enterprises
nicheTaihe security models assist threat analysis and response within Chinese enterprise SOC deployments
nicheHengnao security AI assists alert analysis, data-risk investigation and response for Chinese enterprises
nicheVia Protect, secures Apple fleets and supplies device trust; AI remains an adjunct to endpoint management
nicheSIEM, Automation and AgentX support European SOC detection and response; local deployment anchors its regional position
nicheAutonomous agents gather evidence and investigate security alerts across an enterprise's existing toolset
emergingAI SOC platform automates triage, evidence collection and investigation rather than adding a separate SIEM
emerging
Sources: torq.io, ahnlab.com, samsungsds.com, abnormal.ai, sec.gov, investegate.co.uk
Identity for Humans & Agents
Identity controls decide which humans, workloads and agents may act on sensitive systems. Growth shifts toward machine credentials, continuous authorization and privileged actions; an AI agent needs narrower rights than its human sponsor.
Entra Agent ID inventories and governs agent identities alongside workforce and workload authentication
leaderVia CyberArk, acquired February 2026, governs privileged human, machine and agent credentials, including Venafi
leaderWorkforce Identity and Axiom secure access; agent identities create demand while fewer human logins threaten seat fees
majorIdentity Security Cloud and Entro govern workforce and agent access; fewer employees can pressure human-identity licenses
majorFalcon identity protection adds SGNL continuous authorization and Seraphic browser controls, acquired February 2026
majorDuo and Identity Intelligence add Astrix non-human identity discovery and controls, acquired June 2026
majorVia HashiCorp Vault, acquired February 2025, manages secrets and short-lived credentials for agent workloads
majorPingOne and ForgeRock unify customer and workforce access; machine identities must offset any decline in human-seat demand
majorPassword Safe and Identity Security Insights control privileged access and expose risky machine permissions
majorSecret Server plus StrongDM, acquired March 2026, enforce privileged access and continuous authorization
majorPKI, certificates and identity orchestration secure human and machine access; fewer workforce seats can pressure fees
majorVia Veza, acquired March 2026, maps permissions and access paths across humans, machines and AI agents
challengerExtended Access Management and agent credentials extend workforce security; human-seat compression is a pricing risk
challengerIdentity Cloud governs human, machine and AI-agent permissions across cloud applications and infrastructure
challengerUnified identity protection applies authentication and runtime policies across legacy and cloud access paths
challengerVia Oasis, acquired September 3, 2026, governs machine and agent access through the new Identity product
challengerAgentic Identity and authentication flows authorize customer and agent access to applications and tools
challengerInfrastructure Identity replaces standing credentials with audited, short-lived access for people and workloads
challengerKeeperPAM and secrets management protect agent credentials; machine usage must offset any lost human seats
challengerDirectory and device access policies govern enterprise users; agent substitution threatens per-user licensing growth
challengerVia Stytch, acquired November 2025, supplies developer authentication and identity controls for AI agents
nicheYubiKey phishing-resistant authentication secures human approvals and account recovery against impersonation
nichePortalGuard adds biometric MFA and passkeys for workforce access; small scale and fewer human logins limit AI upside
nicheWorkload IAM brokers policy-controlled, short-lived access for services and AI agents without static secrets
emerging
Sources: okta.com, investor.sailpoint.com, blogs.cisco.com, cyera.com, twilio.com, delinea.com
Data Security, Governance & Resilience
Sensitive-data discovery, access policy, governance and recoverable copies make enterprise AI usable. Buyers must prevent agents from exposing restricted information and recover trustworthy data or identities after attacks and mistakes.
Data Platform + Securiti AI, acquired December 2025, connect backup, DSPM, privacy and AI governance
leaderSecurity Cloud and Agent Cloud protect data and reverse agent mistakes; FY27 Q2 subscription ARR reaches $1.66B
leaderCloud Cleanroom Recovery and identity resilience restore trusted data and applications after cyber incidents
majorDataProtect, acquired Veritas enterprise backup assets and Gaia combine resilient copies with governed AI search
majorDSPM and automated permissions remediation reduce AI oversharing; SlashNext adds phishing defense
majorAI data discovery and classification map sensitive information; Oasis adds identity context after September close
majorAI Governance inventories models and use cases, runs assessments and connects privacy and compliance workflows
majorNewEdge and Netskope One apply DLP and access controls to enterprise SaaS, web and generative-AI traffic
majorData Security and Zero Trust Exchange prevent sensitive information escaping through applications and AI tools
majorPurview classifies sensitive information and enforces data-loss and access policies around Copilot and agents
majorNormalyze DSPM and Hornetsecurity, acquired December 2025, extend enterprise data and Microsoft 365 protection
majorData Security Everywhere discovers sensitive information and enforces DLP across endpoints, cloud and AI use
majorData protection, content governance and security products protect enterprise information used by AI workflows
majorGuardium AI Security discovers AI deployments and sensitive-data risks; governance connects to watsonx controls
majorCipherTrust and Imperva protect sensitive data, encryption keys and databases feeding enterprise AI
majorAI Governance and data lineage connect model use cases to trusted enterprise data and accountable owners
majorVia Own and Informatica, completed acquisitions add SaaS recovery, lineage and governance for agent-accessible business data
majorCyber Protect combines endpoint backup, recovery and threat protection for MSPs and enterprise customers
majorDiscovers and classifies sensitive data, then applies access, privacy and AI-governance policies across stores
challengerCloud backup and AI-assisted cyber recovery protect SaaS and enterprise data without customer-managed appliances
challengerConfidence Platform governs and protects collaboration data before organizations expose it to AI assistants
challengerDynamic data-access policies and monitoring restrict what analytics tools and AI workloads can retrieve
challengerActive metadata, lineage and governance give AI agents trusted enterprise data context and access controls
challengerComputer Backup restores endpoints and B2 Object Lock supports immutable recovery; direct AI-security exposure is modest
niche
Sources: veeam.com, cyera.com, proofpoint.com, rubrik.com, varonis.com
AI Security Platforms & Controls
These products discover AI assets, test models and enforce runtime guardrails against prompt attacks, data leakage and unsafe tool calls. Buyers need coverage across models and agents; recent acquisitions are rapidly changing vendor ownership.
Prisma AIRS 3.0 combines Protect AI model scanning, red teaming and runtime guardrails for agents
leaderAI Defense, built on acquired Robust Intelligence, tests models and blocks malicious AI inputs and outputs
majorVia Lakera, acquired October 2025, adds prompt-injection defense and runtime guardrails to Infinity
majorVia Prompt Security, acquired September 2025, discovers AI use and protects model and agent runtime interactions
majorFalcon AI Detection and Response incorporates Pangea guardrails for prompts, sensitive data and agent interactions
majorVia SPLX, acquired 2025, adds AI asset discovery, automated red teaming and prompt hardening
majorFortiAIGate plus Virtue AI, acquired August 2026, add agent red teaming, validation and runtime protection
majorAI Guardrails and AI Red Team use CalypsoAI, acquired September 2025, to secure inference and agent interactions
majorDefender and Azure AI Content Safety provide AI posture, prompt-attack detection and model-output controls
majorVia Wiz, acquired March 2026, maps AI cloud assets and exposure; Model Armor filters malicious AI interactions
majorAI Trust Platform and Invariant Labs, acquired June 2025, test agent tools and defend against MCP attack paths
majorFirewall for AI and AI Gateway apply network-delivered controls to prompts, model traffic and sensitive data
challengerAI application and API security defend inference endpoints and agent-facing services against malicious requests
challengerAI Security Fabric and Imperva AI Application Security protect runtime prompts, data access and agent interactions
challengerVia Aim Security, acquired September 2025, governs enterprise AI use and protects agent and application traffic
challengerEnterprise Browser enforces policies on AI web sessions, data movement and access to business applications
challengerHardened container images and open-source artifacts reduce software supply-chain exposure in AI application workloads
challengerEPIC-AI, Cloud WAF, API security and Bot Manager defend enterprise applications; AI SOC automates attack response
challenger
Sources: paloaltonetworks.com, cisco.com, checkpoint.com, f5.com, fortinet.com, island.io
Fraud & Risk Decisioning
Financial institutions and merchants use identity, device, behavioral and transaction data to reject fraud without rejecting good customers. AI-generated scams increase demand; data networks and feedback on real losses are durable advantages.
Decision Intelligence, Brighterion and Recorded Future threat intelligence score payment and digital-fraud risk
leaderAdvanced Authorization and Featurespace, acquired December 2024, detect payment fraud; BioCatch deal is pending
leaderFalcon Fraud Manager applies adaptive models to transaction streams and account behavior for financial institutions
majorVia Actimize, X-Sight and financial-crime AI detect fraud and support AML investigations
majorLexisNexis Risk Solutions combines ThreatMetrix device intelligence and IDVerse identity checks against fraud
majorCrossCore combines identity signals; ClearSale, KYC360 and AtData expand fraud and financial-crime coverage
majorTruValidate combines device reputation, identity and behavioral signals to assess digital transaction risk
majorVia Kount, applies identity networks and AI scores to merchant fraud, account takeover and payment decisions
majorVia Verafin, AI and shared banking intelligence detect fraud, scams and suspicious money movement
majorRisk Intelligence and World-Check support entity screening, sanctions checks and financial-crime investigations
majorEntity data and AI-enabled screening connect ownership networks to fraud, AML and counterparty risk assessments
majorBehavioral biometrics detect scams and account takeover; agreed $2.4B Visa acquisition remains pending
majorRiskOps and AI transaction models detect payment fraud and scams for banks and payment providers
majorDigital Trust & Safety uses shared transaction feedback to score payment fraud and account abuse
majorTrust Platform automates ecommerce approvals, account protection and policy-abuse decisions
majorCLEAR and Risk Inform connect identity and public-record signals for enterprise fraud investigations and due diligence
majorRiskOS combines Effectiv decisioning and Fravity agents, acquired August 2026, for fraud and compliance operations
challengerDevice intelligence and behavioral models combine fraud detection, AML and automated risk investigations
challengerDigital identity and device signals enrich fraud scores and AML decisions across online transactions
challengerAI chargeback-guarantee models approve legitimate ecommerce orders while absorbing covered fraud losses
challengerEntity resolution and Decision Intelligence connect customer networks for bank AML and financial-crime investigations
challengerSensa AML uses AI to prioritize suspicious activity and support bank financial-crime investigations
challengerFraud Management applies machine learning to bank and merchant payment streams in real time
nicheAI credit-network decisions route loan applications for lending partners; credit losses remain a risk beyond model accuracy
niche
Sources: investor.mastercard.com, investor.visa.com, usa.visa.com, socure.com, experianplc.com, feedzai.com
Identity, Deepfakes & Authenticity
Verification vendors establish who is present, while forensic tools identify synthetic media and provenance systems record origin. Banks, marketplaces and employers compare false accepts, user friction and resistance to injection attacks.
ID+ and document verification combine identity graphs, biometrics and fraud signals to resist synthetic identities
leaderIdentity verification and orchestration connect document, selfie and database checks for digital onboarding
majorVia Onfido, acquired April 2024, applies document AI, biometric liveness and workflow orchestration to identity checks
majorMiVIP and biometric liveness detect identity and deepfake attacks; check-fraud models extend document expertise
majorKyX identity platform combines document checks, face matching and liveness for remote customer onboarding
majorDocument verification, face matching and liveness detect synthetic identities and onboarding impersonation
majorIdentity verification and deepfake detection join transaction monitoring and compliance orchestration
majorPulse detects synthetic voices and video impersonation in contact centers, hiring and virtual meetings
majorContent Credentials and C2PA tools attach tamper-evident provenance to media used in business workflows
majorGBG Go, Reach and GoPlane connect identity checks to enterprise AI agents; GoPlane remains beta
majorOmni and Deepsight defend biometric verification; Identiq acquisition adds privacy-preserving fraud signals
challengerMultimodal detection flags synthetic voice, video and images; KPMG takes a minority stake in September 2026
challengerBiometric face and liveness checks protect remote onboarding, including government identity programs and synthetic attacks
challengerAutoIdent and VideoIdent combine automated document checks with human video verification for regulated onboarding
nicheReadID, VideoID and European eID integrations verify people and reduce document and impersonation fraud
nicheSecure camera capture and C2PA provenance record content origin; provenance does not prove a claim is true
nicheValidates government-issued IDs against authoritative records to detect manipulated documents and identity fraud
nicheCLEAR1 applies reusable biometric identity to enterprise access and digital verification beyond airports
nicheIDI and FOREWARN resolve identities and surface public-record risk signals for investigations and fraud prevention
nicheDigipass and digital identity verification secure high-risk transactions, authentication and remote agreements
nicheVia Liquid, LIQUID eKYC combines document checks, biometrics and liveness for Japanese digital onboarding
nicheVerified and PrivacyKey perform biometric proofing and authentication; microcap scale limits exposure to the AI security market
nicheVia AwareSDK and Intelligent Liveness, checks identities and presentation attacks for government and enterprise onboarding
nicheForensic analysis detects manipulated audio, video and images for enterprise investigations and verification
emerging
Sources: miteksystems.com, withpersona.com, entrust.com, pindrop.com, kpmg.com, elementsinc.jp
AI Security & Governance Specialists
Independent specialists test models, discover agents and enforce runtime or governance controls. Security teams buy defenses against prompt attacks, data leaks and unauthorized actions; adoption depends on measurable attack coverage and low operational friction.
Discovers AI assets and agent tools, evaluates posture and enforces runtime protection across the AI lifecycle
challengerAI-agent discovery and runtime governance inspect actions and permissions; raised $125M in August 2026
challengerAI Security Platform and Agent Harness Security test and protect model and coding-agent runtime behavior
challengerObserves enterprise AI usage and applies policy controls to prompts, sensitive information and model interactions
challengerLEAP applies CPU-based runtime guardrails to AI requests and actions; $30M funding announced September 2026
challengerAutomated adversarial testing discovers weaknesses in models and agents; August 2026 Series A funds deployment growth
challengerAI inventory, governance and runtime protection combine with Aiceberg, acquired May 2026
challengerMCP Gateway monitors agent behavior and blocks unauthorized actions or sensitive-data sharing across workplace AI
challengerKirin enforces least privilege and runtime policy for enterprise agents, tools and sensitive information access
challengerRuntime protection discovers AI applications and APIs, enforcing controls over live calls and data in use
challengerAdversarial testing and runtime defenses secure model behavior; frontier labs use its platform for AI evaluations
challengerAgent registries, policy controls and evidence workflows govern enterprise AI models, applications and vendors
challengerEvaluates frontier-model and agent capabilities to uncover exploitable behaviors before enterprise deployment
nicheInventories agents and MCP tools, red-teams their behavior and applies runtime data and action policies
emergingAutomated red teaming and AI guardrails test Korean enterprise models and agents for exploitable behavior
emerging
Sources: zenity.io, lasso.security, mindgard.ai, cranium.ai, grayswan.ai, credo.ai
Glossary
- SOC
- Security operations center: the team and systems that investigate threats and coordinate response.
- Non-human identity
- An account or credential used by software, workloads or AI agents rather than a person.
- DSPM
- Data security posture management: discovering sensitive data and identifying risky access or exposure.
- Prompt injection
- Malicious instructions embedded in data that try to redirect an AI system or misuse its tools.
- Cyber resilience
- The ability to preserve operations and restore trustworthy data and systems after an attack.
- Liveness
- Checks that distinguish a present person from a photo, replay, mask or synthetic impersonation.
Heat, spend, exposure and shares are editorial estimates. How to read the map ↗
