AI Security, Governance and Assurance · Identity and Access Management · Incident Detection and Response · Application Security

Six Layers, Six Months: The Agentic Security Category Map

The agentic security stack has six layers. Most CISOs do not have a map. Here is one, with each layer's place in the 2026 consolidation cycle.

By Tal Eliyahu · · 12 min read

Editorial technical diagram for Six Layers, Six Months: The Agentic Security Category Map
A clean industry shift map showing Event, Market Shift, Buyer, Pressure, and Response as connected parts of the story. CyberBiz

The agentic security stack has six layers. Most CISOs we have spoken with do not have a map. Here is one.

In the past six months, cybersecurity platforms have spent more than $40 billion buying into a stack that did not exist as a procurement category in 2024. Identity, AI gateway, agentic endpoint, agentic browser, agent-ready data, agentic SOC. Each layer has named entrants. Each layer has a different consolidation status. Each layer has different open primitives.

The map matters because the cycle is shorter than any prior cybersecurity platform consolidation. Cloud security took four years. The agentic stack is consolidating in six to nine months. By the time most CISOs have written 2027 budgets, the layers below will be functionally closed for new procurement choices.

This is where each layer sits today.

The framework

The agentic security stack has six load-bearing layers and two adjacent ones.

Workflow diagram for Six Layers, Six Months: The Agentic Security Category Map
Workflow view of the control path, market pressure, and buyer impact behind Six Layers, Six Months: The Agentic Security Category Map. CyberBiz

Identity is who or what is acting. AI agents act on behalf of humans, on behalf of services, and increasingly on behalf of other agents. The identity layer answers: which entity is making this call, what is it allowed to do, and how does authorization stay current as the agent's behavior changes.

AI Gateway is which calls go where, with what policy. Every prompt, response, and tool invocation an agent emits passes through some routing layer. The gateway is the inline enforcement point.

Agentic Endpoint is where AI agents and AI-using tools run. Browser-resident AI tools, autonomous agents on developer laptops, and AI features inside enterprise SaaS apps all bypass traditional EDR. The agentic endpoint layer is where they get inspected.

Agentic Browser is where agents and AI tools meet the user's browser. Increasingly, the browser is the place enterprise work happens — and the place AI tools are most active. Agent-aware browser security is the inspection point for that traffic.

Agent-ready Data is what agents can read and write. Data security posture management was the prior-cycle category. Agent-ready data extends it to: what data can an agent access, under what authorization, with what audit trail.

Agentic SOC is how anomalies in agent behavior get detected and responded to. The SOC was already moving toward AI-driven analysis; agentic SOC platforms run agents that investigate, correlate, and remediate at machine speed.

Two adjacent layers complete the picture: autonomous offensive security (continuous AI-driven testing, the supply side of the agentic-defense funding wave) and agent observability and red-teaming (the still-emerging layer that watches, replays, and adversarially tests agent behavior).

Identity — the most consolidated layer

The identity layer is the cleanest example of how fast this consolidation moves.

Palo Alto Networks closed CyberArk in February for $25 billion, the largest deal in the company's history, and Nikesh Arora has framed identity as the *fourth pillar* of platformization. CrowdStrike spent $740 million on SGNL in January for continuous, runtime, agent-aware authorization. Cisco bought Astrix Security in May for a reported $400 million for non-human identity inventory and lifecycle management — analyzed in this companion piece. Silverfort acquiring Fabrix Security in late April and Delinea merging with StrongDM in January fill out the runtime, continuous, agent-aware authorization category.

The shared structural argument across these deals is the same. Standing privilege is dead. Session-time authentication is too coarse. AI agents act faster than humans can approve, and they act on behalf of humans whose authorizations were never designed to cover an autonomous proxy. The market is converging on runtime, continuous, agent-aware authorization as the new identity control plane.

What is closed: human identity, non-human identity, agent identity within a single organization. The platforms have bought.

What is still open: agent-to-agent identity in cross-organization meshes (federated identity for agents acting across company boundaries), agent identity for sovereign and government deployments where US platform stacks are not procurement targets, and standalone identity governance for highly regulated sectors that cannot consolidate inside a generalist platform.

AI Gateway — claimed by Palo Alto, contested by hyperscalers

The AI Gateway layer is more contested than identity, despite a clear early winner.

Palo Alto Networks announced its acquisition of Portkey in late April for a reported ~$700 million — analyzed in this companion piece. Portkey routes trillions of tokens monthly across more than 3,000 LLMs for over a thousand enterprise customers. Integrating it into Prisma AIRS gives PANW the routing and policy layer through which all of an agent's calls flow.

The contested part is that hyperscalers have parallel capabilities embedded in their own platforms. Microsoft's Azure AI Foundry includes routing and policy primitives. Google Cloud has model routing embedded in Vertex AI. Cloudflare has shipped an AI Gateway product in its Workers AI stack. AWS embeds guardrails in Bedrock. None of these are sold standalone as cybersecurity products. All of them compete with Portkey's positioning.

What is closed: the standalone AI Gateway category. PANW will set the cybersecurity-platform pricing.

What is still open: cross-platform agent routing where customers run agents across multiple hyperscalers and multiple model providers. Independent gateways that compete on neutrality, vendor independence, and cross-cloud flexibility have a window through 2026. The window will close once one hyperscaler ships a credible cross-cloud gateway or another platform vendor acquires a Portkey alternative.

Agentic Endpoint — newly named, structurally important

Palo Alto Networks named *agentic endpoint security* as a category when it acquired Koi Security in February for $400 million. The category did not exist as a procurement line item in 2025.

The structural argument is that browser-resident AI tools, autonomous agents on developer laptops, and AI features embedded in enterprise SaaS bypass the threat model traditional EDR products were built around. EDR vendors instrument the operating system for malware-shaped behavior. Agentic endpoint instruments for AI-specific behavior: which agent is running, what it is reading, what it is exfiltrating, what it is publishing.

What is closed at the platform level: PANW has established the category and the framing. Other public platforms will need an answer.

What is still open: the standalone vendor layer. Koi was the first material acquisition in this category. The next two to four entrants will define the procurement comparable set. Founders building here have a roughly twelve-month window before the category closes.

Agentic Browser — Seraphic, SquareX, and the pure-plays

The browser security layer fills out fastest among the public platforms. CrowdStrike acquired Seraphic Security in mid-January for $420 million and framed the deal alongside SGNL as a fused identity-to-browser-to-cloud control plane. Zscaler acquired SquareX in early February for an undisclosed amount in the same window.

The enterprise browser pure-plays — Island and the others still independent in 2026 — face a procurement question they can no longer ignore. CrowdStrike and Zscaler now ship browser security as part of their platform packages. The standalone enterprise-browser category has to compete on differentiation that platforms have not absorbed yet.

What is closed: browser security as a feature of the SASE/XDR platforms. Buyers running CrowdStrike or Zscaler get browser security as part of the contract.

What is still open: pure-play enterprise browsers that compete on user experience, dedicated browser features, and specific developer or contractor use cases. The category will support one or two independent leaders past 2027. The rest will be acquired or marginalized.

Agent-ready Data — earliest stage of consolidation

The data layer for AI agents is the earliest stage of any of the six.

Varonis acquired AllTrue.ai for $150 million in February for shadow-AI discovery and runtime guardrails. Check Point bought Cyata as part of its three-startup February announcement to add AI agent guardrails. The category boundaries are still being defined.

The structural argument: AI agents reading and writing enterprise data at machine speed need governance that cannot rely on human review. The agent-ready data layer is where data security posture management extends into runtime.

What is closed: the early platform positioning. Varonis and Check Point have staked claims.

What is still open: cross-platform agent-aware DLP, federated agent data access (across multiple organizations or multiple data domains), and standalone agent-data governance products. The category does not yet have a recognized leader. Founders raising in this space have leverage that the more-consolidated layers no longer offer.

Agentic SOC — most contested

Agentic SOC is the most crowded layer at the time of writing.

Rapid7 acquired Kenzo Security in late March; Cisco acquired Galileo in April for agentic monitoring inside Splunk. Standalone agentic SOC startups raised material rounds through 2026 — 7AI took $130 million in Series A for the largest cybersecurity Series A on record. Dropzone AI, Prophet Security, and Torq operate in the same space at varying stages of commercial maturity. XM Cyber and the broader CTEM specialists are adjacent.

The shared framing is *machine-speed investigation* — collapsing the dwell time between alert and response by running AI agents that triage, correlate, and remediate. The exact division of labor between AI and human varies by vendor.

What is closed at the platform level: Rapid7 and Cisco have made their initial bets. Other public platforms are still positioning.

What is still open: the category leader. Three to four vendors will reach durable scale; the rest will be acquired or marginalized within twelve to eighteen months. The selection event is the next material consolidation move in this layer — likely a public-platform acquisition of one of 7AI, Dropzone, Prophet, or Torq, or one of these companies announcing a Series C at premium valuation that establishes the standalone path. Expect that signal before Q1 2027.

The adjacent layers — autonomous offensive and observability

Two adjacent layers complete the agentic security map.

Autonomous offensive security — continuous AI-driven testing — is the supply side of the agentic-defense funding wave. XBOW raised a strategic-only $35 million Series C extension on May 6. Artemis raised $70 million in Series A on April 15 for AI-vs-AI defensive security. Variance closed $21.5 million in Series A in early April for autonomous AI compliance and fraud agents. The category is well-funded, agentic-native, and positioned to either become a platform feature (most likely path) or to consolidate around two to three leaders (less likely but plausible).

Agent observability and red-teaming is the most open layer. Tools that observe what agents do, replay agent sessions, red-team agentic workflows, and evaluate agent behavior under adversarial conditions exist as a class but do not yet have a recognized category leader. AI red-teaming startups, AI security guardrail vendors, and prompt-evaluation tooling sit here. The category is fragmented enough that we expect one to two material funding rounds and at least one acquisition before year-end to define the consolidation pattern.

How to read the map for buyers

For procurement teams, the map collapses into a small number of practical decisions.

Identity, AI gateway, agentic endpoint, and agentic browser are now platform-bought. If you are running a public security platform, you should expect those layers to ship as features inside your existing renewal. Standalone procurement of pure-play vendors in these layers will not survive the 2027 budget cycle in most enterprises.

Agent-ready data still has independent procurement options. The platforms have bought into the category but have not closed it. Buyers with strong data-security requirements should evaluate Varonis and the standalone agent-data governance entrants on technical merit rather than assume platform consolidation has resolved the choice.

Agentic SOC has multiple credible options. The category will select two to four leaders within twelve to eighteen months. Buyers committing to a vendor in this layer in 2026 should ask explicit questions about acquisition risk, integration roadmap with the buyer's existing platform stack, and what happens to the contract if the vendor is acquired by a competing platform.

The adjacent layers — autonomous offensive and agent observability — should be evaluated as specialist procurements with explicit acquisition risk. The vendors operating here are likely to be acquired within twelve to twenty-four months. Buy specifically for capability, not for category leadership.

How to read the map for founders

For founders building or raising in 2026, the map closes some doors and opens others.

Closed: identity (within a single organization), AI gateway (as a standalone category), agentic endpoint (as a category-leader play), agentic browser (as a horizontal play). Building in these layers requires a defensible niche the platforms have not bought into — sovereign deployments, regulated-edge environments, federated cross-organization use cases.

Contested: agent-ready data, agentic SOC. Both layers will support multiple credible vendors at scale. The defensibility is technical depth, customer concentration in a vertical the platforms have not prioritized, and the ability to integrate cleanly with whichever platform a customer is consolidating on.

Open: agent observability, agent red-teaming, cross-platform policy authoring, agent-aware DLP that works across multiple gateways and data stores, agent-to-agent identity (mesh), and federated agent identity across organizations. The recognized leader has not been declared in any of these. The window for category formation is open — but per the M&A pillar, the window is shorter than the prior cycle. Twelve to eighteen months, not three years.

The cap-table implication is also worth taking seriously. Per the Cloudsmith funding piece, generalist growth funds (TCV, Tiger, Coatue, ICONIQ, Stripes) are entering security infrastructure. Founders raising in the open layers should structure their pitch for both cybersecurity-specialist and generalist software audiences. The companies that do will see broader investor sets and better pricing.

What to watch for the rest of 2026

Four signals between now and December will tell us how the map redraws.

The first is the next agentic-SOC consolidation move. A public-platform acquisition of 7AI, Dropzone, Prophet, or Torq — or a Series C at premium valuation establishing the standalone path — sets the pattern for the most contested layer.

The second is the first major move in agent observability or red-teaming. Whether by funding round or acquisition, the first material event in this layer will define whether agent observability becomes a category or stays as features inside larger platforms.

The third is the cross-platform AI Gateway question. Whether a hyperscaler ships a credible cross-cloud gateway, or whether an independent vendor establishes neutrality as a defensible position, decides whether Portkey's PANW absorption was the start of consolidation or a one-time event.

The fourth is sovereign-deployment positioning. Allied governments and critical-infrastructure operators are increasingly unwilling to accept US-only stacks at the most sensitive layers. Sovereign-cyber agentic-security pure-plays — including the kind of hardware-PQC positioning we've seen from Sitehop — will produce material moves before year-end.

The map is not finished. The corners are filling fast. The next twelve months will tell which open primitives become categories and which fade into platform features.

Knowing which layer you are on is the first procurement, building, or investing decision. Most of the rest follows from there.

Frequently asked questions

What are the six layers of the agentic security stack?
Identity (who or what is acting), AI gateway (which calls go where with what policy), agentic endpoint (where AI agents and AI-using tools run), agentic browser (where agents meet the user's browser), agent-ready data (what agents can read and write), and agentic SOC (how anomalies in agent behavior get detected and responded to). Two adjacent layers complete the picture: autonomous offensive security and agent observability/red-teaming. Each layer has different consolidation status, different open primitives, and different procurement implications.
Which agentic security layers are already platform-bought, and which are still open?
Closed at the platform level: identity, AI gateway, agentic endpoint, and agentic browser. Major public security platforms have made acquisitions in each of these layers in the first five months of 2026. Contested: agent-ready data and agentic SOC — multiple platforms and standalone vendors are credible, and the category leader has not been selected. Open: agent observability and red-teaming, cross-platform policy authoring, agent-aware DLP, agent-to-agent identity, and federated agent identity. None of these have a recognized leader, and the window for category formation is roughly twelve to eighteen months.
How should procurement teams evaluate agentic security vendors in 2026?
Three practical questions. First, in closed layers (identity, gateway, endpoint, browser), expect the platforms to ship the capability inside existing renewals — standalone procurement is rarely durable. Second, in contested layers (agent-ready data, agentic SOC), evaluate vendors on technical merit but ask explicit questions about acquisition risk, integration roadmap with your existing platform stack, and what happens to the contract if the vendor is acquired by a competing platform. Third, in open layers, buy for capability rather than for category leadership — the vendors operating here are most likely to be acquired or to redefine themselves before procurement renewal.
Where should cybersecurity founders build in the agentic stack in 2026?
Closed layers (identity, AI gateway, agentic endpoint, agentic browser as horizontal plays) require a defensible niche the platforms have not bought into — sovereign deployments, regulated-edge environments, or federated cross-organization use cases. Contested layers (agent-ready data, agentic SOC) will support multiple credible vendors; defensibility comes from technical depth and vertical concentration. Open layers (agent observability, red-teaming, cross-platform policy authoring, agent-aware DLP, agent-to-agent identity) have no recognized leader yet — the window for category formation is open, but it is shorter than prior cycles. Twelve to eighteen months, not three years.

Sources

  1. Palo Alto Networks completes acquisition of CyberArk — Palo Alto Networks
  2. CrowdStrike to acquire SGNL — CrowdStrike
  3. Palo Alto Networks to acquire Portkey — Palo Alto Networks
  4. Cisco announces intent to acquire Astrix Security — Cisco
  5. Capstone Partners Q1 2026 Cybersecurity Market Update — Capstone Partners