Deep|Cybersecurity: Enterprise AI Security Budgets Are Shifting Toward Large Platforms

Recent enterprise interviews show that AI applications are adding demand for identity, runtime and API security, with companies integrating these capabilities into existing platforms. We expect platforms that meet these needs and replace overlapping tools to grow spending within some accounts faster than the customers’ total security budgets. CrowdStrike, Palo Alto Networks and Cloudflare are among the vendors we are watching, although the outcome for each will depend on its products and customer purchases.

This report draws on our recent enterprise interviews. The detailed findings were consolidated into a separate report that is available to all Premium subscribers, covering enterprise experts’ security, databases and related spending and procurement decisions. Reach out to sales@funda.ai to learn more.

The interviews point to additional AI demand and consolidation of older tools as the main drivers.

  • AI and personal agents accessing enterprise systems bring new requirements for identity, runtime, API, and tool-call security. Existing platforms can meet these needs by expanding their deployments and incorporating pertinent security data.
  • As traditional security budgets grow slowly, enterprises are cutting redundant tools and licenses, reallocating more spending to platform security vendors.

AI Is a Priority for Incremental Enterprise Security Spending With Identity Security in Focus

An expert at a large U.S. telecommunications company expects the total cybersecurity budget to grow 10%–15% in 2026, up from 5%–10% in 2025. As AI workloads move into production, demand shifts to runtime protection, data security, non-human identities, API security, and governance.

The company distinguishes direct spending to protect models and agents, at 5%–8% of its total security budget, from a broader 15%–20% that includes AI-driven demand for data, identity and cloud security.

Agent identity and non-human identities are small but growing areas. The telecom interviewee roughly estimated their share at 15%–25% of direct AI security spending. Applying that range to the 5%–8% share for direct AI security implies about 0.75%–2% of the total security budget. This is a calculation from the two ranges, not a separately measured amount.

Enterprises are adding agents and other non-human identities to their identity management systems, assigning separate identities, accountable owners, least-privilege access, short-lived credentials, and audit trails. Some incremental spending will fund extensions to existing identity platforms and related modules.

Agents Expand the Security Perimeter and Increase Inspection Volumes

Agents interact with enterprise systems through prompts, tool calls and Model Context Protocol (MCP) connections. Security teams need to protect agents acting on employees’ behalf as well as employees and devices.

A user request can trigger several model calls, tool calls and agent interactions, so security checks may grow faster than user requests. The telecom interviewee estimated that production model calls, tokens and agent interactions are growing 60%–100% YoY in 2026, requiring broader security controls.

Security checks must cover the entire execution chain, from the person initiating the task to the agent’s identity and permissions, the data accessed, tools invoked, and final actions taken.

An interviewee at a pharmaceutical company said agents need distinct identities, least-privilege access, short-lived credentials and authorization for each API and tool call.

These controls need to apply throughout a task. If employees use multiple continuously running agents, active identities and interactions will increase further. Malicious prompts and misuse of tool permissions could also spread through successive calls, requiring timely detection and response across systems.

Previously, enterprises used separate security tools focused on human activity, which typically monitored only parts of the execution chain. As execution chains lengthen, integrating information becomes more difficult, increasing the need for cross-system correlation and automated response as AI agents proliferate.

The figure groups eleven security capabilities into foundational configuration, invocation controls, execution controls, and monitoring and response. Identity, gateway, runtime and data controls can operate together. Approvals depend on risk, and recovery depends on what the business system supports.

Unified Security Data and Policies Favor Platform Vendors

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论