AI Agents Are Creating a New Market for Enterprise Security
As AI systems move from generating responses to taking actions across company networks, Rosenblatt Securities analyst Catharine Trebnick says enterprises need new ways to track agents, their permissions and their activity. She argues that this is creating a cybersecurity opportunity for established providers such as CrowdStrike and Palo Alto Networks—and that more capable frontier models are more likely to add value to those platforms than displace them.

AI agents have turned visibility into a security requirement
The shift from AI that talks to AI that acts has created a new security problem: companies need to know which agents are operating across their networks, what permissions they have, and what they are doing at runtime. Rosenblatt Securities analyst ? catharine-trebnick says enterprises cannot simply put off that work as agents become more capable.
Trebnick described one enterprise that believed it had 300 agents across its network and discovered it had 18,000. That gap matters because an agent’s presence is not enough to understand its risk: organizations also need to identify it, determine what it can access, and protect activity while it is happening.
The market’s view of AI and cybersecurity has shifted quickly, Trebnick said. In March, Anthropic’s suggestion that AI could handle vulnerability management weighed on cybersecurity stocks. After RSA, the message changed: Anthropic needed help, and CrowdStrike and Palo Alto Networks rallied. A more recent debate about pacing frontier models has brought another shift. Trebnick’s comments point to a growing focus on how enterprises will secure AI deployment.
She pointed to new products from both CrowdStrike and Palo Alto Networks that address agent tracking and protection. Palo Alto bought Prompt AI for “600 and some million” in February 2025, Trebnick said; its Prisma Access product tracks AI agents and is now the company’s fastest-scaling product. CrowdStrike acquired Pangea, which became the basis for a product category called Falcon Guardian. Trebnick said its AI DR product had surpassed $100 million in annual recurring revenue.
Demand is also showing up in how security budgets are being allocated. Trebnick said Rosenblatt interviews 16 to 17 chief information security officers and more than 20 resellers each quarter. What she hears is that spending is being directed toward protecting infrastructure and choosing the tools to do it. Established platforms are getting additional consideration, she said, in part because customers may already have products and procurement arrangements in place. CrowdStrike’s Falcon Flex, which lets customers add modules through an existing purchasing model, is one example.
Frontier models may strengthen security platforms rather than replace them
Ed Ludlow asked whether increasingly capable models could displace established cybersecurity companies, as some had feared in other software markets. Trebnick rejected that outcome. She recounted Anthropic appearing at CrowdStrike’s Fal.con event and saying it wanted to partner with cybersecurity companies rather than enter the business itself. The Anthropic representative, she said, described the value of leveraging CrowdStrike as the speed and scale the model company could not provide on its own.
For Trebnick, that distinction comes down to data and operational reach. Security platforms have accumulated telemetry—the information generated across the systems they protect—and built an understanding of enterprise infrastructure. Frontier models can add capability, but the data and context needed to protect a particular organization remain central to the service provided by companies such as Palo Alto Networks, CrowdStrike, Zscaler and Fortinet.
That is the basis for Trebnick’s view that more capable models are not automatically a substitute for existing security providers. The platform companies already operate across the infrastructure and hold the telemetry that can make model capabilities useful in an enterprise setting. In her account, the models’ progress raises the value of that layer rather than making it obsolete.
Misbehavior and misuse are distinct risks, and both matter
Ludlow separated two concerns: models behaving unpredictably, which he described as an alignment problem, and powerful models getting into the hands of bad actors. Trebnick said neither should be treated as the sole risk. The models are being tested and “you’re seeing these rogues,” she said; the possibility that capable systems could be misused is also serious.
Her answer was not that existing defenses eliminate either danger. Rather, she argued that security companies with visibility across infrastructure can provide a layer of protection for organizations deploying AI. She cited CrowdStrike’s coverage at runtime across endpoints, cloud workflows and identity as an example. With AI moving quickly, she said, companies that have been preparing to defend that infrastructure are important to both problems.
