AI's New Attack Surface: A New Cost, a New Budget
The product development cycle in AI is accelerating rapidly. A capability released in one quarter is a commodity feature in the next. Security is one of the few areas where that compression does not hold.
The product development cycle in AI is accelerating rapidly. A capability released in one quarter is a commodity feature in the next. Security is one of the few areas where that compression does not hold.
The reason is that AI systems in production hold real access. They read from source systems, write to them, and increasingly act on their own. An agent with a credential is an identity, and an identity is something an organisation has to govern, audit and eventually explain to a regulator.
AI is doing two things to cybersecurity at once. It is expanding the number of systems, identities and workflows that need to be secured, while dramatically reducing the labour required to execute attacks. That combination creates not only a new attack surface, but a new security budget.
The Attack Surface Is New, the Budget Is Newer
Two disclosures shaped how enterprise buyers now think about this.
In November 2025 Anthropic disclosed that it had disrupted a state-sponsored espionage campaign, designated GTG-1002, which targeted roughly thirty entities. The AI executed approximately 80 to 90 percent of the tactical work, leaving human operators with target selection and approvals.
In July 2026 Hugging Face disclosed that an AI agent had compromised its infrastructure. The agent was a combination of OpenAI models being tested on a cyber-capability benchmark with their refusals reduced for evaluation purposes. OpenAI described it as an unprecedented cyber incident.
One detail from the second disclosure has direct product implications. When Hugging Face tried to use commercial models to analyse the attacker's exploit code, the models' guardrails repeatedly declined the forensic work, because the material resembled working exploit code. The team's solution was to stand up a locally hosted open-weight model. Organisations that rely only on third-party AI APIs for incident response generally do not have that capability pre-staged.
It is important not to overstate the change. The 2026 Verizon Data Breach Investigations Report, built on more than 22,000 confirmed breaches, concludes that AI is primarily accelerating and scaling known attack methods rather than inventing new ones. The median malicious actor used AI across fifteen documented techniques. Where the report is most specific is speed: AI is reducing the defensive window on known vulnerabilities from months to hours.
The more immediate enterprise exposure is not necessarily adversarial. It is employees using AI outside the organisation's security boundary. The same report found that 45 percent of employees are now regular AI users on corporate devices, up from 15 percent a year earlier, that 67 percent of them sign in through non-corporate accounts, and that source code is the data type most often submitted to unapproved tools.

Neither pattern requires a new class of attack. Both describe an existing set of weaknesses, operated at a faster cadence, inside estates that expanded faster than governance could track them.
Capital Is Flowing in the Same Direction
Total funding into the category looks flat. Crunchbase counts $10.6 billion into security and privacy startups in the first half of 2026, in line with recent comparable periods. The second quarter was soft at $4.4 billion, down around 30 percent from both the prior quarter and the year-ago period.
The composition has changed. Startups at the intersection of AI and security raised $855 million across more than 150 seed rounds in 2026, on track for an all-time high. Total capital into cyber is stable while the share going to AI-native security is at a record. The important signal is therefore that capital is rotating within cybersecurity toward companies where AI is part of the product's core economic model, rather than a new category forming on top of a mature one.
Demand data points the same way, provided two forecasts are kept separate.
Gartner's "AI-amplified security" series runs from $49 billion in 2025 to $160 billion by 2029. Gartner states explicitly that this is not additive spending. It measures the share of existing security products that now embed AI.
The "securing AI" series measures new spending on protecting AI systems themselves.


Three billion dollars is a small market. A small market growing above 80 percent a year, with an identified buyer and a compliance requirement behind it, is a different proposition from the $160 billion figure that is more often quoted.
Two Categories of Company: "Securing AI" vs. "Security Built With AI"
Capital in this space is being allocated across two distinct product types with different economics.
Securing AI
These companies sell to the AI deployment itself. Zenity raised a $125 million Series C in August 2026, led by Norwest, for a platform that evaluates an agent's intent and permits, modifies or blocks the action before it executes. Oasis Security raised $120 million in March 2026, led by Craft Ventures, for non-human identity and agentic access governance, reporting new recurring revenue growth of five times year on year across a largely Fortune 500 customer base.
Security Built With AI
These companies sell the security work itself, performed by machine. XBOW raised $120 million in March 2026 at a valuation above $1 billion, and reached the top of the HackerOne leaderboard before raising a growth round. Exaforce raised $125 million in May 2026 for agentic security operations. 7AI raised $130 million in December 2025, ten months after leaving stealth.

The distinction matters for underwriting. The first type sells a control plane and therefore competes with whatever the customer's identity and platform vendors release next. The second replaces labour against a budget line that already exists. That is a shorter sales cycle and a harder product for a platform to bundle away, because what is sold is an outcome rather than a feature. The question is whether the product owns a security workflow, or merely improves the interface to an existing one.
Five Layers, Priced Separately
Security for AI is not a single product category. It resolves into five: identity and authorisation, runtime control, visibility and inventory, validation and evaluation, and autonomous defence.

Gartner's assessment of where competition settles is specific. In AI governance platforms and AI gateways, large vendors building on existing governance, data and API management systems are expected to retain the lead. In AI application security and AI usage control, a wave of startups is emerging, with consolidation expected as the market grows.
Two layers are likely to be held by incumbents and two are open to new companies. The underwriting question is simple: which layer is structurally open to a startup, and which layer is likely to become a feature of an incumbent platform?
From an Investor's Perspective
The consolidation risk in this category is documented rather than theoretical. Palo Alto Networks completed its $25 billion acquisition of CyberArk in February 2026, making identity security a core pillar of its platform, with the stated rationale of securing every identity: human, machine and agent. In the identity layer, the incumbent has already paid to be able to replicate.
Product depth requires scrutiny. Exaforce's founders describe much of the current market as wrappers around frontier models, with prompts that convert alert payloads into summaries, producing triage notes that fall apart when the question requires context the tool did not anticipate. A product that summarises an alert is not a company.
Evidence quality requires the same scrutiny. A significant share of the widely cited statistics in this category were commissioned by vendors selling the corresponding solution. Customer references are more informative than research citations.
Valuations should be assessed against the size of the market being contested. Cyera, an established company in a real category, was reported in June 2026 to be in discussions at approximately $12 billion, around eighty times revenue, while financing operating losses. That valuation is difficult to underwrite against a narrowly defined securing-AI market of roughly $3 billion, particularly while the company remains loss-making. The investment case therefore depends on whether the category expands beyond today's defined market and whether the company can own a broader layer of enterprise AI security.
What This Means for Türkiye
Policy in Türkiye has moved ahead of the market in this area.
The Türkiye AI Action Plan for 2026–2030 entered into force by Presidential Circular 2026/9, published in the Official Gazette on 18 August 2026. One of its sixteen priority actions is directly relevant. AI security evaluation capacity is to be established within TÜBİTAK BİLGEM's AI Institute, covering test methodologies, evaluation tools and technical guidance for security, robustness, data protection and resilience to cyber threats. High-impact AI systems are to be assessed against those criteria before going live and again at major version updates.
The plan also targets a minimum 2 percent share of public investment programmes for AI projects and positions public institutions as first customer for domestic solutions. The regulatory foundation was already in place: Law 7545 on Cybersecurity, in force since 19 March 2025, established cybersecurity as an audited management obligation across both public institutions and private companies.
Read together, these create an unusually favourable starting condition: an emerging evaluation requirement, a potential public-sector procurement channel and a policy environment explicitly encouraging domestic AI solutions.
The category also has domestic precedent. Picus Security, founded in Ankara in 2013, has raised $80 million and serves more than 500 enterprise customers worldwide. In July 2026 it launched a platform combining breach-and-attack simulation, autonomous penetration testing and exposure validation in a single automated loop, against roughly 132 new vulnerabilities published daily.
Three areas follow.
Assurance and evaluation tooling, where the requirement is emerging with public funding behind it and supply remains limited.
Operational technology and critical infrastructure, where Türkiye's industrial base and its defence and drone ecosystem provide access to environments that do not appear in shared datasets, and where degraded connectivity is a design assumption rather than an exception.
The Asia-Pacific corridor, and Türkiye and Korea in particular. XBOW appointed a South Korea general manager at the start of 2026 to lead its regional expansion, and Zenity reports faster adoption of agent-centric security in Japan, Korea, Singapore and Australia than in previous cycles.
For founders, the opportunity is therefore not simply to build another cybersecurity product. It is to build a security capability around AI systems that are becoming operational, regulated and increasingly autonomous.
The Moat in AI Security
Long procurement cycles, audit requirements and integration depth can initially slow the growth of companies in this category. As AI models become more accessible and easier to substitute, competitive advantage accumulates in the layers surrounding the model. Each successful deployment produces new integrations and additional operational data, that data improves detection, and over time the product becomes more deeply embedded in the customer's operations.
AI did not necessarily create a new class of attack. It removed the labour constraint from existing attacks while introducing new identities, permissions and execution paths into enterprise systems. In doing so it created a security budget that is difficult to defer, and a new generation of security companies whose defensibility will be measured by one question. By the hundredth deployment, is the company harder to replicate than it was at the first? The answer should compound across integrations, security telemetry, detection quality, workflow ownership and customer trust.