Money and M&A are catching up to a problem practitioners already see in incident timelines: autonomous and semi-autonomous AI agents can call tools, touch credentials, and reach production systems — and more than half of successful attacks on AI agents are expected to hinge on access control and prompt injection by 2029, per Gartner's August 2026 forecast. This post is a 2026 market snapshot: analyst sizing for "securing AI," the largest disclosed funding rounds and acquisitions tied to agent security, and an honest read on where Beam (local endpoint monitor) sits relative to enterprise platforms (runtime enforcement, discovery, governance).
TL;DR — questions this roundup answers
| Question | Short answer |
|---|---|
| How big is the market? | Gartner: ~$2.84B in 2026 → ~$4.78B in 2027 for securing AI (four segments below). |
| Is there a dedicated "agent-only" TAM line? | Not in Gartner's public table; agents are a driver inside usage control and application security. |
| Who raised nine figures recently? | Zenity ($125M Series C, Aug 2026), HiddenLayer ($100M Series B, Sep 2026). |
| Who bought whom? | F5/CalypsoAI, Check Point/Lakera, Palo Alto/Protect AI, Cisco/Robust Intelligence (details below). |
| Where does Beam fit? | Local endpoint monitor + pre-run skill/MCP scan — not an enterprise blocking platform. |
| What should I read next for buying advice? | AI agent security platforms: how to evaluate one and Compare. |
Gartner "securing AI" forecast (August 2026)
On August 26, 2026, Gartner published a forecast for the market for securing AI — software and platforms that help organizations use AI safely and meet regulatory expectations. The headline numbers from Gartner's press release:
| Metric | Figure |
|---|---|
| 2026 worldwide spending | $2,835 million (83.0% growth vs. prior year) |
| 2027 worldwide spending | $4,783 million (68.7% growth vs. 2026) |
| 2028 (directional) | ~$7.7 billion (per Gartner's release) |
Gartner splits the category into four segments. The following table reproduces Table 1 from the release (figures in millions of U.S. dollars):
| Segment | 2026 spending | 2026 growth (%) | 2027 spending | 2027 growth (%) |
|---|---|---|---|---|
| AI application security | 508 | 82.1 | 851 | 67.5 |
| AI usage control | 433 | 86.6 | 749 | 73.0 |
| AI governance platforms | 275 | 77.4 | 462 | 68.0 |
| AI gateway | 251 | 80.6 | 429 | 70.9 |
| Other securing AI | 1,368 | 83.9 | 2,292 | 67.5 |
| Total | 2,835 | 83.0 | 4,783 | 68.7 |
How to use this without overclaiming: Gartner's definition is broader than "AI agent security startups." It includes gateways, governance suites, and application-layer controls — not only agent runtime products. Still, Gartner explicitly ties growth to identifying, monitoring, and protecting AI models and agents from threats such as prompt injection, and notes that autonomous AI introduces vulnerabilities beyond traditional monitoring — language that matches how agent-focused vendors pitch today.
For practitioners, the useful takeaway is budget gravity: security teams are getting a named line item for AI-specific tooling, which is why platform vendors acquired guardrail startups (next section) and why standalone agent-security companies can raise $100M+ rounds without pretending to be full-stack SIEM replacements.
Funding rounds that defined the category in 2026
Venture dollars cluster on enterprise agent governance and runtime protection — blocking, posture, and visibility across many agents — not on single-developer laptop monitors.
| Company | Round | Date announced | Amount | Lead / notable participants | Primary source |
|---|---|---|---|---|---|
| Zenity | Series C | Aug 3, 2026 | $125M | Norwest; SoftBank Vision Fund 2, Hitachi Ventures, LG Technology Ventures, Qumra Capital | Zenity newsroom |
| HiddenLayer | Series B | Sep 2, 2026 | $100M | Delta-v Capital; Ten Eleven Ventures, Morgan Stanley, M12, Booz Allen Ventures | HiddenLayer announcement |
Zenity describes itself as an AI security and governance platform purpose-built for AI agents, with the Series C earmarked for global expansion and platform innovation. HiddenLayer emphasizes agentic runtime security and Agent Harness Security for autonomous coding agents in enterprise environments; it reported ARR up more than 10x and 50+ new enterprise customers in the year before the round (per its release).
Smaller but directionally important: several vendors raised capital for pre-runtime and supply-chain angles on agents (MCP servers, skills, plugins). Treat secondary round write-ups as signals, not audited financials, unless the company publishes terms.
M&A: guardrails roll into platform vendors
The pattern since 2024 is consistent: network and security platforms buy AI guardrail and model-security startups, then sell "AI security" as part of ADSP, Prisma AIRS, Infinity, or similar suites. That consolidation matters for buyers — procurement paths shift from best-of-breed startup contracts to existing vendor relationships.
| Target | Acquirer | Announced / closed | Disclosed consideration | What the acquirer said |
|---|---|---|---|---|
| Robust Intelligence | Cisco | Closed Sep 24, 2024 | Not disclosed in Cisco's close announcement | AI security for the AI lifecycle |
| Protect AI | Palo Alto Networks | Completed Jul 22, 2025 | Not disclosed in PANW press release | Folded into Prisma AIRS (model scanning, red teaming, runtime, agent security) |
| CalypsoAI | F5 | Intent Sep 11, 2025; closed Sep 26, 2025 | $145.2M cash in F5 SEC filing; $180M purchase consideration in F5 press release | Real-time threat defense, red teaming, data security for generative and agentic AI |
| Lakera | Check Point | Agreement Sep 16, 2025; completed Oct 22, 2025 | Not disclosed in Check Point's announcement; press reported ~$300M | Lakera Guard / Lakera Red for agentic and GenAI apps |
F5 completed CalypsoAI and shortly after introduced F5 AI Guardrails and F5 AI Red Team (F5 blog, Sep 29, 2025). Check Point positioned Lakera as the core of a global center of excellence for AI security (SecurityWeek, Sep 16, 2025).
Pricing caveat: Where acquirers did not file an exact price (Protect AI, Lakera in public PR), this post cites official completion announcements only — not rumored multiples — except where an SEC filing gives a cash figure (CalypsoAI).
Four product layers — and why the market map confuses buyers
The same phrase — "AI agent security platform" — covers four different architectures. Enterprise M&A and Gartner's "securing AI" spend mostly land in enterprise platforms and gateways; individual developers often need endpoint monitors and scanners first.
| Layer | Typical buyer | Representative 2026 signal | Blocks by default? |
|---|---|---|---|
| Enterprise AI security platform | CISO / platform security | HiddenLayer $100M B; Zenity $125M C; F5/CalypsoAI | Usually yes (runtime enforcement) |
| AI gateway / usage control | AI platform team | Gartner's fastest-growing segments (usage control, gateway) | Often yes (policy at the call path) |
| MCP / skill scanner | Developer / appsec | Crowded free tools; supply-chain incidents | No (pre-run check) |
| Local endpoint monitor | Individual engineer or small team | Beam, Numbat-class tools | No (observe and flag) |
Beam's own column in the compare pages is deliberate: local-first activity monitoring for coding agents, 11 heuristic scan patterns plus MCP version-pin check on skills and configs, no blocking in v1, no MDM/SSO/SOC 2, no central console. That is a different purchase from a $100M-funded runtime platform — and that gap is the point.
Where Beam fits (honest positioning)
Beam is not competing for the same budget line as Zenity or HiddenLayer. Those companies sell organization-scale agent governance and runtime protection to enterprises deploying agents in production workflows. Beam is an early local prototype spun out of on-device agent observability work: watch what Claude Code, Codex, Cursor, and similar harnesses do on your machine, redact credentials before persistence, and scan SKILL.md / MCP configs before you run them — per apps/sentinel-collector/README.md, scanning is heuristic, not semantic malware analysis, and nothing is blocked.
| Need | Better starting point |
|---|---|
| Block risky agent actions org-wide | Enterprise platform (compare HiddenLayer, Zenity, CalypsoAI via F5) |
| Runtime GenAI app protection (API path) | Lakera / Check Point class |
| Record what a coding agent did on one laptop | Agent runtime security / Beam |
| Check a skill or MCP file before connect | MCP security scanning |
| Pick the right layer before RFPs | How to evaluate AI agent security platforms |
If your threat model includes undisclosed agent swarms hitting package registries or autonomous agents scraping external sites, the fix is not only a laptop monitor — it is registry governance, sandboxing, and vendor disclosure — but local monitoring still answers the question "what did the agent on my machine attempt?" See the RubyGems / OpenAI agent incident and the AI agent security incidents timeline for grounded examples.
What the market momentum implies for practitioners
- Enterprise budgets are real. Gartner's ~$4.8B in 2027 figure is the citation-friendly anchor for "why is my CISO suddenly asking about agents?"
- Consolidation is ahead of standalone IPOs. F5, Check Point, Palo Alto, and Cisco have already bought AI guardrail companies; expect features to appear as modules, not greenfield SKUs.
- Agent harnesses are a stated product surface. HiddenLayer's Agent Harness Security naming matches what security researchers already document on coding agents — the same surface MCP security guide and securing coding assistants cover from a practitioner angle.
- Local-first tools remain complementary. Even a well-funded runtime platform does not automatically see unapproved skills on a contractor's laptop unless that machine is in scope. Endpoint monitors fill that blind spot; they do not replace SIEM, CASB, or AI gateways.
Related reading
- Compare Beam to endpoint monitors, scanners, enterprise platforms, and observability tools
- Beam vs HiddenLayer · Beam vs Zenity · Beam vs Lakera · Beam vs CalypsoAI
- AI agent security platforms: how to evaluate one
- What is AI agent monitoring?
- AI compliance and regulation for agent activity
- AI agent security incidents: a timeline (2025–2026)
- Introducing Beam: local-first AI agent security
Market sizes, funding amounts, and acquisition dates reflect public announcements and Gartner's August 26, 2026 press release as of publication. Gartner segments are analyst definitions, not Beam product categories. Beam v1 observes and flags; it does not block. Check each vendor's current documentation before purchasing.
