Agentic AI Security: The New Battleground
Agentic AI adoption has exposed new security risks: tool poisoning, prompt injection, multi-agent vulnerabilities, and data leakage outside traditional security perimeters. In response, both established cybersecurity firms and cloud-first vendors have sought out specialist startups to accelerate their AI security capabilities. This blog post summarizes the recent acquisitions to see where the market is going.
2025 Acquisition Highlights
Here are the most notable agentic AI security and AI security startup acquisitions since early 2025:
Check Point acquired Lakera.AI (Sep 2025)
Lakera offers runtime protections for agentic deployments, LLM guardrails, and multi-agent control platforms (Check Point Press Release).
The $300M deal marks one of the sector’s highest price tags and signals how agent control is moving into mainstream enterprise focus (MSSP Alert).
SentinelOne acquired Prompt Security (Aug–Sep 2025)
Prompt Security delivers GenAI application visibility, prompt injection protection, and enterprise agent controls (SecurityWeek).
This $250M acquisition extends SentinelOne’s strategy from endpoint AI to generative and agentic AI environments, aiming to provide “real-time AI visibility, control, and protection across enterprises.”
Snyk acquired Invariant Labs (Jun 2025)
Invariant Labs specializes in deep research on agentic vulnerabilities (MCP, LLM toolchains, and poisoning) (ChannelInsider).
Snyk extends its AI Trust Platform, bringing runtime agentic guardrails to developer environments.
Cato Networks acquired Aim Security (Sep 2025)
Aim Security focuses on securing agent usage across hybrid networks and SASE architectures.
CalypsoAI integrates enterprise guardrails and agentic controls into F5’s application delivery stack.
Fletch’s agentic AI tech now powers the F5 Data Fabric, enabling real-time threat prioritization, context assignment to agents, and drift detection for ML models.
Palo Alto Networks acquired Protect AI (Jul 2025)
Protect AI’s agent-centric red teaming and runtime AI controls are now part of Prisma AIRS.
Zscaler acquired Red Canary (May 2025)
Zscaler cements its “AI-powered SOC of the future” with MDR and agentic detection at rumored multi-billion dollar scale.
Here is the summary table
Strategic Analysis & Insights
1. The Scale and Speed of Consolidation:
From midsize $50–100M talent-centric deals (Invariant Labs) to nine-figure platform acquisitions (Lakera, Prompt Security, Red Canary), incumbents are not just buying technology—they’re buying deep research talent and instant integration of complex agent and LLM controls into legacy product platforms
2. Moving Beyond Model Security:
While early AI security focused on ML/LLM supply chains (data poisoning, vuln disclosure), most recent acquisitions target runtime agentic protection: controlling prompt flow, agent actions, inter-agent communications, and emergent tool behaviors in distributed control planes and autonomous workflows
3. Full-Stack Vendor Play:
Major platforms like Check Point, SentinelOne, Palo Alto, F5, Zscaler, and Snyk aim to unify agentic AI security—beyond endpoints—to cloud workloads, SASE edges, developer tools, and enterprise AI adoption strategies. The integration challenge is immense: these platforms now juggle legacy SIEM, LLM agent interoperability, and AI trust as a product feature—not just an add-on.
4. Expect More Talent-Focused Acquisitions:
Acquirers increasingly target specialist teams who lead academic research or niche agentic open source, rather than just buying code/IP. Invariant Labs' researchers, Fletch's practitioners, and Prompt's domain architects all signal the scarcity of expertise required for next-phase agentic security evolution
Outlook for Agentic AI Security
This consolidation represents a tipping point. With multi-agent workflows, agentic control planes, and autonomous orchestration now mission-critical for enterprises, vendor offerings must deliver:
Context-aware protection for LLM/agent chains and applications
Controls for prompt injection, tool misuse, and agent drift
Real-time visibility into AI use, data flows, and “Shadow AI” risk
Multi-layer integration with SASE, cloud, OT, and developer stacks
Platform leaders are betting that agentic security will be as important—and challenging—as endpoint security was two decades ago. The race to acquire, integrate, and generalize these capabilities will define who wins the next decade of cybersecurity.


