Skip to content
The Next Marketers
September 28, 2026
Bitcoin-0.92%
Ethereum-1.65%
Solana-0.59%
The Next Marketers
Artificial intelligence

Navigating Mergers and Acquisitions in AI Agent Security

As artificial intelligence agents integrate into enterprise operations, they introduce complex security challenges that are shaping a new mergers and acquisitions landscape focused on specific cybersecurity control points and agent identity governance.

Navigating Mergers and Acquisitions in AI Agent Security

Artificial intelligence agents are rapidly integrating into enterprise operations. These systems browse the web, write code, access files, trigger APIs, and interact directly with internal infrastructure.

While this unlocks massive productivity gains, it simultaneously introduces a novel security challenge: organizations must now safeguard not just human users, devices, and traditional applications, but software entities capable of executing actions on behalf of the company.

AI agents are becoming a new class of enterprise identity

Because an agent might query databases, review corporate files, execute code, or dispatch emails, it requires proper monitoring, governance, and permissions. Businesses will need absolute clarity regarding which agent accessed specific information, which systems it integrated with, and whether its actions were authorized.

As enterprises scale from testing a handful of agents to running hundreds simultaneously, agent identity will emerge as a vital layer of cybersecurity. Managing these identities is vastly more complicated than handling standard users or service accounts because agents are dynamic—they make autonomous decisions, invoke various tools, and navigate seamlessly between systems.

The value will sit in specific control points

Rather than developing into a single, monolithic category known as “AI security,” this market will likely fragment around precise control points.

Specialized firms will emerge to tackle different facets: one might secure agent identity, another might regulate the data an agent is permitted to view, while others concentrate on prompts, Model Context Protocol (MCP) servers, plug-ins, network traffic, or audit trails.

Activity within these niches is already underway. Kiteworks acquired Bonfy.AI, an Israeli startup specializing in real-time policy enforcement and data classification. Simultaneously, Huskeys—an Israeli cybersecurity startup that secured a $27 million Series A funding round led by Blackstone—concentrates on securing and interpreting complex internet traffic, encompassing traffic produced by autonomous systems.

Although these businesses address distinct challenges, collectively they illustrate how the sector is dividing into clear security layers.

These control points are creating a new M&A map

Identity governance providers are likely to broaden their scope to cover autonomous agents. Meanwhile, data-security vendors may find it necessary to govern the specific information agents can reach. Over time, enterprise software vendors, cloud providers, and broader cybersecurity platforms will likely need to integrate agent-security features natively into their offerings.

For startup founders, this indicates that positioning a business simply under the umbrella of “AI security” might already be too vague. The critical consideration is precisely what system asset or layer the enterprise controls.

Itay Sagie is a strategic adviser to tech companies, investors, CEOs and boards, specializing in strategy, growth and M&A. He is a guest contributor to Crunchbase News and a university lecturer on strategy, finance and entrepreneurship. Learn more at SagieCapital.com and connect with him on LinkedIn.

Related Crunchbase queries:

  • Global M&A In 2026 For Venture-Backed Companies
  • Global Venture Funding To AI Startups In 2026
  • Global Cybersecurity Venture Funding In 2026

Illustration: Dom Guzman

Frequently Asked Questions

Why are AI agents creating new cybersecurity challenges?

AI agents go beyond passive tasks by actively browsing the web, writing code, triggering APIs, and accessing corporate files. Because they can make decisions and move between systems independently, they require an entirely new approach to identity, monitoring, and governance compared to traditional user accounts.

What is an agent identity in enterprise cybersecurity?

An agent identity functions as a software-based entity profile that requires specific permissions, monitoring, and governance to track what corporate information it accesses and which systems it connects to.

How is the AI security market expected to develop?

Rather than forming a single broad category, the market is expected to center around specific control points such as agent identity, data access boundaries, prompts, plug-ins, traffic, and auditability.

What recent M&A and funding activity has occurred in this space?

Kiteworks acquired Israeli startup Bonfy.AI, which specializes in real-time data classification and policy enforcement. Additionally, Israeli cybersecurity startup Huskeys secured a $27 million Series A funding round led by Blackstone to focus on securing complex internet traffic, including autonomous system traffic.

What does this mean for cybersecurity startups and founders?

Founders may find that a broad “AI security” label is too generic, shifting the focus toward defining and mastering exact control points within the technology stack.

Related stories

Comments 0 responses

Join the discussion

Comments are moderated and appear after review.