Mainstreaming of AI Security Through Industry M&A, Tools, and Enterprise Risk Strategies
Major security vendors have significantly increased their investments in artificial intelligence (AI) security, with a surge in mergers and acquisitions (M&A) aimed at strengthening their capabilities to protect AI systems, applications, and workflows. Cisco initiated this trend by acquiring Robust Intelligence for $400 million, followed by at least eleven more acquisitions involving companies such as Cato Networks, Check Point, CrowdStrike, F5, and SentinelOne, who collectively spent over $1.3 billion to enhance their AI security portfolios. These acquisitions reflect the growing recognition of AI as a critical area for cybersecurity, especially as generative AI technologies like ChatGPT 3.5 have driven public and enterprise adoption. The focus of these deals spans runtime protections, prompt injection defenses, agent identity management, and output validation, as vendors seek to address the unique risks posed by AI systems. Concurrently, the enterprise sector is grappling with the expanded attack surface introduced by integrating AI into business operations, necessitating a strategic shift from traditional patchwork defenses to comprehensive, built-in security and safety measures. Enterprises are now required to evaluate threats such as software vulnerabilities, misconfigurations, broken authentication, and prompt injection attacks, all of which can compromise the confidentiality, integrity, and availability of AI systems. The distinction between AI security and AI safety is becoming more pronounced: while security focuses on defending systems from external threats, safety is concerned with ensuring AI systems behave as intended and remain aligned with organizational values. To address the challenge of AI safety, Anthropic has released an open-source tool called Petri, which uses AI agents to simulate interactions with frontier models and assess their propensity for risky behaviors such as deception, sycophancy, and power-seeking. Early tests of Petri on leading models like Claude Sonnet 4.5 and GPT-5 revealed that, although some models are safer than others, the ability of AI to discern and avoid harmful actions remains imperfect. The tool provides a framework for measuring and triaging safety risks, highlighting the need for both technical and governance solutions. As organizations deploy AI at scale, regulatory compliance and data governance are becoming integral to their security strategies, with vendors and enterprises alike recognizing that robust AI security and safety are essential for trustworthy and resilient AI adoption. The convergence of industry investment, new safety tools, and evolving enterprise risk management practices marks a pivotal shift in how the cybersecurity community approaches the protection and alignment of AI technologies. This mainstreaming of AI security is expected to continue as both the threat landscape and regulatory expectations evolve, driving further innovation and collaboration across the sector.
Jun 29, 2026