Mapping the Mergers and Acquisitions in AI Agent Security
As AI agents gain access to enterprise data, systems and tools, they are emerging as a new class of active identity requiring specialized permissions, monitoring and governance, writes guest author Itay Sagie. He believes the market, and its M&A opportunities, will likely form around specific control points, making precise positioning crucial for startups.
Artificial intelligence agents are rapidly integrating into enterprise operations. These software tools browse the web, write code, access files, trigger APIs, and interact directly with internal systems.
While this delivers immense productivity gains, it simultaneously introduces a novel security challenge: organizations must now safeguard not just human users, devices, and traditional applications, but also autonomous software actors capable of executing actions on their behalf.
AI agents are becoming a new class of enterprise identity
Because an agent might query databases, access corporate files, send emails, or run code, it requires proper permissions, monitoring, and governance. Businesses will need visibility into which agent accessed specific data, which systems it connected with, and whether its actions were authorized.
As organizations transition from testing a handful of agents to implementing hundreds at scale, agent identity will emerge as a vital cybersecurity layer. Managing these identities is far more complex than handling conventional users or service accounts because agents are active participants—they can make decisions, invoke tools, and navigate seamlessly between different systems.
The value will sit in specific control points
Rather than evolving into a single, monolithic category known as “AI security,” this market is expected to center around distinct control points.
Different firms will specialize in different areas, with one securing agent identity, another governing the data an agent can view, and others concentrating on traffic, plug-ins, MCP servers, prompts, or auditability.
Market activity in these spaces is already visible. Kiteworks acquired Bonfy.AI, an Israeli startup specializing in real-time policy enforcement and data classification. Meanwhile, Huskeys, an Israeli cybersecurity startup focusing on securing and understanding complex internet traffic—including traffic produced by autonomous systems—secured a $27 million Series A funding round led by Blackstone.
Although these enterprises tackle different challenges, collectively they illustrate how the market is dividing into separate security layers.
These control points are creating a new M&A map
Identity providers could potentially expand their identity governance frameworks to cover autonomous agents. Similarly, data-security providers may require mechanisms to regulate the information agents are permitted to access. Over time, enterprise software vendors, cloud companies, and major cybersecurity platforms will likely need to integrate agent-security features natively into their offerings.
For entrepreneurs, this indicates that positioning a business simply under “AI security” is likely too broad. The critical consideration is defining the precise control point the company manages.
Itay Sagie is a strategic adviser to tech companies, investors, CEOs and boards, specializing in strategy, growth and M&A. He is a guest contributor to Crunchbase News and a university lecturer on strategy, finance and entrepreneurship. Learn more at SagieCapital.com and connect with him on LinkedIn.
Related Crunchbase queries:
- Global M&A In 2026 For Venture-Backed Companies
- Global Venture Funding To AI Startups In 2026
- Global Cybersecurity Venture Funding In 2026
Illustration: Dom Guzman
?Frequently Asked Questions
01Why are AI agents considered a new class of enterprise identity?
AI agents actively navigate systems, make decisions, and execute tasks like querying databases or writing code on behalf of users. Because they hold operational access, they require dedicated permissions, tracking, and governance just like human or service identities.
02How is the AI security market expected to develop?
Rather than forming a single broad category, the market is breaking down into specific control points. These include agent identity management, data access governance, prompt security, traffic monitoring, and auditability.
03What recent market activity highlights this trend?
Examples include Kiteworks acquiring the Israeli startup Bonfy.AI for real-time data classification and policy enforcement, and Israeli cybersecurity startup Huskeys raising a $27 million Series A led by Blackstone to secure complex internet traffic generated by autonomous systems.



