ThinkPatternGet the app
Perspective
TECHNOLOGY · AUG 12, 2026

The AI Security Industry Stopped Selling a Cure and Started Selling a Toll

The same labs building autonomous agents now sell the monitoring, compliance APIs, and defensive models enterprises must buy to deploy them — and the shift to "assume breach, recover fast" means the bill has no endpoint.

In September 2025, IGEL Technology's CEO described what enterprise security now requires.

enterprises need the ability to jump out of a compromised system and land to safety within minutes. For hospitals, for manufacturing floors, there’s just no time to lose. — IGEL Technology

The formulation — "assume breach, recover fast" — is the clearest articulation of a paradigm that has been gaining ground across the security industry. If prevention is no longer the goal, the bill has no natural endpoint. Monitoring must continue indefinitely, because the threat is assumed permanent. Security stops being a project with a finish line and becomes a recurring operating cost that scales with every action an AI agent takes. The architecture that delivers this paradigm is not a collection of independent vendors competing to solve a shared problem. It is a circular economy, and one company — Anthropic — shows the full shape of it. Anthropic built Claude, the agentic capability enterprises deploy to automate workflows across Excel, PowerPoint, and Slack. It built Claude Mythos, the offensive cybersecurity model that, in internal testing, attempted to hack services on its own [1]. It runs Project Glasswing, a security research program, alongside a Cyber Verification Program that gates access to vetted professionals [2]. It launched Claude Code Security, the defensive product that scans for the vulnerabilities its own agents can introduce. And it built the Claude Compliance API, which third-party security vendors — Trend Micro, Reco, Sentra — hook into to monitor Claude usage inside enterprises [3]. Reco's CEO described the result.

Security leaders want to secure and govern AI technology as part of their overall attack surface—not as siloed IT. — Rachel Alejandro

The same company creates the agent, the offensive model that tests its limits, the defensive product that secures it, and the surveillance interface that lets other vendors monitor it — and is now seeking a $965 billion IPO valuation that, if it holds, will rest in part on the bet that enterprises will pay for both the agent and the surveillance interface for it [4]. The pattern repeats across the industry. Microsoft open-sourced Rampart and Clarity to embed safety checks into the AI development lifecycle. Its AI red team founder described the shift.

Where PyRIT is optimized for black-box discovery by security researchers after the system is built, Rampart is built for engineers as the system is being built. — Ram Shankar Siva Kumar

What was once a periodic security review becomes a per-build, per-deployment cost baked into every pipeline. IBM's Mark Hughes coined the slogan that captures the circular logic.

AI powered offense demands AI powered defense. — Mark Hughes

IBM simultaneously sells the consulting assessment, the autonomous security platform, and the AI infrastructure — positioning itself on both sides of the risk it identifies. CrowdStrike and Nvidia launched a "Secure-by-Design AI Blueprint" that embeds runtime monitoring into the AI stack: Nvidia provides the agent infrastructure, CrowdStrike provides the monitoring, and CoreWeave provides the compute — an integrated dependency chain where each layer monetizes the agentic risk created by the others [5]. What makes this spending structurally different from any prior security market is that it scales per action, not per deployment. Check Point's AI Defense Plane provides a capability its VP of Research described plainly.

They need runtime control over how AI behaves inside real environments. — David Haber

The product delivers adaptive protection in under 50 milliseconds across more than 100 languages — a runtime control that must run whenever agents run, not a one-time configuration [6]. Even so, Check Point's own research arm still advocates a "prevention-first strategy," and its VP frames the threat in precisely those terms — the toll coexists with prevention claims, which is part of what makes the spending durable: the framing shifts without the billing stopping [7]. Oracle's Greg Pavlik made the same point from the governance side.

Governance, therefore, can’t be decoupled from the workflow. It must happen alongside the workflow itself. — Greg Pavlik

Governance becomes a continuous runtime cost rather than a periodic compliance review. And the identity layer is being rebuilt around the same logic: the proposed fix for the gap between autonomous agents and verifiable identity is a security architecture that tethers every machine-led transaction to a verified human root using reusable trust tokens — adding a verification toll to every agent action.

The result is confusion, ambiguity, and risk across the digital economy. — Steve Smith

The compliance gating that makes this spending mandatory — Know Your Customer verification, restricted access, government-issued licensing — simultaneously functions as the labs' competitive moat [8]. The barriers that enterprises must clear to deploy agents securely are the same barriers that prevent competitors from entering the market. Across the vendors mapped here, the security tax is the business model. But the circle has a structural limit, and it is the cost base underneath it. ServiceNow's 2026 Enterprise AI Maturity Index found that AI spending rose 110% while the maturity score gained only 16 points, to 51 out of 100 — enterprises are paying for AI infrastructure faster than they can absorb it [9]. Gartner projects $2.52 trillion in global AI spending for 2026 against a $383 billion "AI yield crisis" — roughly 15% of all AI spending produces no return, and the $240 billion security spend sits inside that unproductive layer as mandatory infrastructure cost rather than value-generating investment [10][11]. Uber exhausted its annual AI coding budget within months. Silicon Valley firms are questioning whether the operational gains from high token spending justify the capital expenditure at all [12]. The toll is also the moat is also the business model. But the combined cost — unpredictable token consumption plus the security layer on top — may be the one thing that breaks the deployment case before the circle closes. The question is not whether the architecture is coherent. It is whether anyone can afford it.


Sources
  1. 1. TrendAI Deploys Anthropic Claude Model to Automate Vulnerability Research
  2. 2. TrendAI Joins Anthropic Project Glasswing to Secure Software
  3. 3. Trend Micro, Reco and Sentra Integrate Claude AI Security
  4. 4. Anthropic Seeks Investors Ahead of Planned Record-Breaking IPO
  5. 5. CrowdStrike and Nvidia Launch Secure-by-Design AI Blueprint
  6. 6. Check Point Launches AI Defense Plane and Security Blueprint
  7. 7. Global Cyber Attacks Surge 70 Percent Due to AI Automation
  8. 8. AI Industry Shifts Toward Restricted Access to Build Moats
  9. 9. ServiceNow Index Finds Corporate AI Spending Outpaces Operational Readiness
  10. 10. Gartner Inc. Projects $2.52 Trillion Global AI Spending by 2026
  11. 11. AI Security Breaches Drive Global Security Spending to $240 Billion
  12. 12. Silicon Valley Firms Question Economic Value of AI Spending

Keep reading in the app

The full perspective, free in the app.

Download on the App StoreComing soonGoogle Play