Why Worries About Rogue AI Are Lifting Security Stocks

Cybersecurity stocks are rising because investors are worried about AI safety and rogue AI agents. That is the main point of a TechCrunch video published on September 23, 2026, which says the market move is a verdict on today's security tools.
The stock gains came first. On September 21, 2026, CrowdStrike rose 4% and Okta rose 4% after AI safety warnings, according to Yahoo Finance. Investors were buying established identity and endpoint companies. That same worry is now pulling venture capital into younger startups.
Venture investors are putting large sums into startups building security for an AI-native world, TechCrunch reports. That covers tools that secure AI systems themselves, and tools that defend companies where self-running software runs inside live business systems.
Two names illustrate the pricing. Startups Instinct and Simile have raised nine-figure funding rounds at valuations that would not have made sense a few years ago, according to the same TechCrunch report. No further terms were disclosed in the verified material, but nine figures means $100 million or more per round.
Those rounds sit inside other large AI and security financings. Obsidian Security raised $85 million in a Series D at a $1.1 billion valuation, reported on August 4, 2026 by Reuters. Positron AI raised $875 million in its latest round, reported on September 10, 2026. Israeli AI cybersecurity startup Dream raised $260 million at a $3 billion valuation, reported on June 18, 2026.
Earlier deals show the pipeline forming. Israeli cybersecurity startup Vega raised $65 million in early-stage financing at a $400 million valuation, reported in September 2025. Glilot Capital raised $500 million for new AI and cybersecurity investments, reported in September 2025, with each of its new funds planning to invest in 12 AI and cybersecurity startups. The first quarter of 2026 brought more cybersecurity startup funding than the second quarter of 2026, according to Crunchbase data published July 14, 2026.
Why investors say periodic controls fail
The investor TechCrunch uses to explain the shift is Shardul Shah, a partner at Index Ventures. Shah has spent nearly two decades investing in cybersecurity and enterprise software. He invested in six consecutive funding rounds in cloud security startup Wiz.
Wiz matters because Google acquired it for $32 billion, a deal TechCrunch describes as one of Google's largest acquisitions ever. That links Shah's work in the cloud security buildout to the current AI security cycle.
On TechCrunch's Equity podcast, Shah spoke with Rebecca Bellan about why periodic, human-in-the-loop security cannot keep up. Periodic means scans, audits, quarterly reviews and fixing problems by ticket. Human-in-the-loop means a person must approve or sort each action, like a guard who must stamp every pass. The argument is that this pace breaks when attackers and defenders both use fast automation.
What changes for practitioners
The broader context here is architectural, not only financial. Cloud computing moved work from fixed walls to online connections, digital IDs and short-lived computers. Security teams adjusted with posture management, runtime detection and identity controls. AI agents push that change further. Work runs all the time, software grants permissions on its own, and code, data and actions mix in one flow.
In my view, that is why public and private markets are moving together in this case. CrowdStrike and Okta gain when investors expect more spending on detection and identity. Startups gain when investors think current tools will not be enough for non-human workers at large scale. Both can be true at once. Large firms capture near-term budgets. New firms chase the larger rebuild.
Looking at what this means for working technologists, the question is less about one vendor than about control design. If checks happen on a schedule while AI works all the time, gaps grow. Teams will need rules that check during work, IDs that also cover software agents, and logs that show what an agent did, what data it touched and who gave permission. Much of this already exists in cloud practice. The hard part is using it at AI speed and volume without adding manual steps that slow automation.
Worth flagging is that high valuations for Instinct, Simile and peers raise the bar. A nine-figure round pays for hiring and sales reach. It also demands a product that can replace or sit above tools security chiefs already buy. Past history shows buyers test many tools during a shift, then cut spending to a few winners. Founders who saw the cloud wave know this pattern. Operators should plan for it.
The optimistic case here is simple and familiar. Each computing shift first looked like a security crisis, then led to better basic protections. PCs brought antivirus and regular updates. The internet brought TLS and network filters. The cloud brought identity-based controls and guardrails written in code. AI work could bring nonstop checking by default, with less need for after-the-fact review. That would help builders and users, if the tools arrive in time and are not too hard to run.
For now, the facts are narrow and consistent. Stocks moved on September 21. Venture rounds followed at nine-figure prices. A veteran cloud security investor says the old model of scheduled human checks does not fit the new workload. The rest is work for engineering and security teams to do.


