AI is becoming more capable, and the security stakes are rising with it.
After some uncertainty earlier this year about what rapidly advancing AI models might mean for traditional cybersecurity, the conversation has shifted. AI increasingly looks less like a threat to security demand and more like a catalyst for it. Enterprises are adopting AI quickly, attack surfaces are expanding, and entirely new categories of security are beginning to emerge.
We’ve seen that evolution reflected in our own portfolio over the past few months.
- Bloom Security emerged from stealth with an approach to rethinking endpoint security for a world of AI agents, MCP servers, CLI tools and other technologies traditional EDR wasn't designed to secure.
- Geordie, which we invested in before agentic security was a recognized category, raised a $30 million Series A led by Balderton Capital after winning the 2026 RSAC Innovation Sandbox.
At the same time, developments across the broader AI ecosystem are showing just how quickly the security equation is changing. Recent incidents involving autonomous AI systems reaching environments they weren't intended to access, including OpenAI's evaluation that ultimately reached Hugging Face's production systems, offer an early glimpse of the risks that come with increasingly capable agents. Importantly, these incidents also demonstrate that AI-driven attacks can still exploit very familiar weaknesses: credentials, exposed systems, weak configurations and other gaps that security teams have been managing for years.
Another development we're watching closely is the growing debate around open-weight versus closed models. Open-weight models are improving quickly, while offering developers greater flexibility and lower costs. At the same time, questions around security, governance, data sovereignty and control are becoming more complicated.
The likely result isn't a world dominated by a single model. We increasingly expect enterprises to operate in a multi-model environment, much as they ultimately adopted multiple clouds. That creates a need for security and governance layers that work independently of any one model provider and opens another significant area for innovation.
The AI adoption cycle is moving extraordinarily quickly, and cybersecurity will have to move with it. For founders and investors, that creates both urgency and opportunity. We're excited about the companies already building for this next chapter and about the new categories that haven't been defined yet.
As we reflect on a summer when the news cycle never seemed to slow, one thing feels certain: the pace of change in AI and cybersecurity is only accelerating, and we expect the months ahead to bring even more shifts in how these two markets evolve together.