Technology

Cybersecurity Stocks Rise as AI Agents Strain Old Defenses

Martin HollowayPublished 2w ago4 min readBased on 8 sources
Reading level
Cybersecurity Stocks Rise as AI Agents Strain Old Defenses
Image by rupixen from Pixabay

Cybersecurity stocks are rising on fears about AI safety and rogue agents. That is the core signal from a TechCrunch video published on September 23, 2026, which frames the move as a verdict on the existing security stack.

The pricing action came first. On September 21, 2026, CrowdStrike rose 4% and Okta rose 4% amid AI safety warnings, according to Yahoo Finance. Investors in public markets were bidding up incumbent identity and endpoint names on the same headline risk that is now pulling venture capital into earlier-stage companies.

Venture investors are putting large sums into startups building security for an AI-native world, TechCrunch reports. The phrase covers two jobs: tooling that secures AI systems themselves, and tooling that defends companies where autonomous software, often called agents, operates inside live production systems.

Two names illustrate the pricing. Startups Instinct and Simile have raised nine-figure funding rounds at valuations that would not have made sense a few years ago, according to the same TechCrunch report. No terms beyond that description were disclosed in the verified material, but the nine-figure threshold puts both rounds at $100 million or more.

The two raises sit inside a wider run of AI and security financings. Obsidian Security raised $85 million in a Series D at a $1.1 billion valuation, reported on August 4, 2026 by Reuters. Positron AI raised $875 million in its latest round, reported on September 10, 2026. Israeli AI cybersecurity startup Dream raised $260 million at a $3 billion valuation, reported on June 18, 2026.

Earlier deals show the pipeline building. Israeli cybersecurity startup Vega raised $65 million in early-stage financing at a $400 million valuation, reported in September 2025. Glilot Capital raised $500 million for new AI and cybersecurity investments, reported in September 2025, with each of its new funds aimed at investing in 12 AI and cybersecurity startups. The first quarter of 2026 was a more robust period for cybersecurity startup funding than the second quarter of 2026, according to Crunchbase data published July 14, 2026.

Why investors say periodic controls fail

The voice TechCrunch uses to explain the shift is Shardul Shah, a partner at Index Ventures. Shah has spent nearly two decades investing in cybersecurity and enterprise software. He invested in six consecutive funding rounds in cloud security startup Wiz.

Wiz matters here because of its exit. Google acquired Wiz for $32 billion, a transaction TechCrunch describes as one of Google's largest acquisitions ever. That outcome connects Shah's work in the cloud security buildout to the current AI security cycle.

On TechCrunch's Equity podcast, Shah joined Rebecca Bellan to discuss why periodic, human-in-the-loop security cannot keep up. Periodic means scans, audits, quarterly reviews and ticket-driven fixes. Human-in-the-loop, a term for a system where a person must approve or review an action, means an analyst triages or gates each step. Like a building that gets inspected once a quarter while robots work inside around the clock, the argument is that this cadence breaks when attackers and defenders both operate with machine-speed automation.

What changes for practitioners

The broader context here is architectural, not only financial. Cloud moved workloads from fixed perimeters, the old walled network, to APIs, identities and short-lived infrastructure that appears and disappears on demand. Security teams adapted with posture management, runtime detection and identity controls. AI agents compress that transition further. Work happens continuously, privileges are granted by software, and code, data and actions blend in a single workflow.

In my view, that is why public and private markets are moving together in this instance. CrowdStrike and Okta reprice when investors expect more spend on detection and identity. Early-stage startups reprice when investors expect current detection and identity tools to be insufficient for non-human actors operating at scale. Both can be true at once. Incumbents capture near-term budget. New entrants capture the architectural rewrite.

Looking at what this means for working technologists, the practical question is less about any single vendor than about control design. If review cycles stay periodic while agent activity is continuous, gaps widen by default. Teams will need policy that evaluates at runtime, identity that extends cleanly to workloads and agents, and audit trails that record what an agent did, what data it touched and under whose authority. None of that is exotic. Much of it exists in cloud-native practice. The difficulty is applying it at agent speed and agent volume without adding manual gates that defeat automation.

Worth flagging is that high valuations for Instinct, Simile and peers raise the bar for execution. A nine-figure round buys hiring power and sales reach. It also requires a product that can displace or sit above systems of record that CISOs already pay for. History in enterprise security suggests buyers will fund parallel pilots during a platform shift, then consolidate spend. Founders who lived through the cloud security wave understand that pattern. Operators should plan for it.

The optimistic case here is straightforward and familiar from past shifts. Every major compute shift has first looked like a security crisis, then produced better defaults. The PC era produced antivirus and patching discipline. The internet produced TLS and network filtering. The cloud produced identity-centric controls and infrastructure as code with guardrails. An AI-native environment could produce continuous verification as a default, with less reliance on after-the-fact review. That would be a net gain for builders and users, if the tooling arrives in time and integrates without excessive operational load.

For now, the facts are narrow and consistent. Stocks moved on September 21. Venture rounds followed at nine-figure prices. A veteran cloud security investor says the old model of periodic human checks does not fit the new workload. The rest is work for engineering and security teams to do.