[Photo: Reve AI]

As AI hacking spreads, companies are showing signs of changing spending priorities rather than simply increasing cybersecurity budgets. Some security technologies are benefiting from the trend, while some existing security products are being pushed down the priority list.

According to a recent report by The Information, large companies are increasing spending on systems that monitor employees' AI use, AI models that find vulnerabilities before hackers do, and AI-based tools that help patch those vulnerabilities quickly.

They are also looking for ways to cut costs by reducing spending on traditional vulnerability management software, information-logging tools and penetration testing services. The Information reported that this could put pressure on established software companies such as Cisco, SentinelOne and Rapid7.

After Anthropic introduced its advanced AI model Mythos in April, concerns about cyber threats that abuse AI spread among companies. That has led, in broad terms, to the security market growing in size.

Zafran CEO Sanaz Yashar (사나즈 야샤르) told The Information, "It usually takes several months to sign contracts with large companies, but in the 5 weeks after Mythos was released we signed new contracts with 3 large banks."

As AI threats spread, major AI model developers have also emerged as competitors to existing companies in the security solutions market. OpenAI recently introduced GPT-6 Astra, stressing that it can help security officials find and patch security vulnerabilities. In August, it brought in a veteran cybersecurity executive as chief revenue officer (CRO).

Security startups that specialize in AI security have also emerged as dark horses in the corporate market. Mobile advertising company AppLovin signed contracts with Pluto Security, which provides an internal AI agent that monitors employees' AI use, and Pyg Security, which detects vulnerabilities with AI and suggests patches. Both Pluto Security and Pyg Security debuted in the market this year.

Pyg launches 'Figaro' AI agent, introduces CI/CD into security operations

AppLovin is also using products from Endor Labs, a software startup that analyzes vulnerabilities in AI-written code. The Information reported that AppLovin was able to curb to some extent the increase in its annual cybersecurity software budget, which is about $1 million, by buying AI security tools sold by early-stage startups at discounted prices.

Some companies are also seeing cases in which startups are taking over parts of positions previously held by established security firms.

AppLovin has used CrowdStrike and SentinelOne software to secure endpoints used by employees, such as PCs. The Information reported that AppLovin is reviewing spending on existing security solutions because AI-based technology from Pluto and others more effectively identifies what data employees input into AI.

The Information, citing AppLovin chief information security officer Jeremiah Kung, reported that similar AI security tools offered by CrowdStrike and SentinelOne are "not great."

A CrowdStrike spokesperson countered, saying, "A customer deciding not to purchase a specific module does not, by itself, mean it was replaced by a competitor's product, especially when that customer is still using the CrowdStrike platform." The spokesperson added, "CrowdStrike's AI detection and response solutions have grown more than 79-fold over 3 quarters since launch."

Even so, as large language model (LLM)-based vulnerability analysis tools spread, the view persists that the position of established vulnerability companies that had taken root before the LLM era, such as Qualys, Tenable and Rapid7, could be shaken. John Raper (존 레이퍼), a former CISO at Chevron and Costco who now advises companies on cybersecurity, said, "Traditional vulnerability scanners have seen virtually no major change since they emerged in the mid-to-late 1990s. They just collected a lot of information, and most of it was information without context, so it was effectively useless." He forecast that traditional vulnerability scanners "will be replaced by LLM-based scanners."

Gartner forecasts the AI security market will rise about 69 percent in 2027 from 2026 to about $4.783 billion. It expects the market to expand to about $7.7 billion in 2028. Gartner forecast that by 2029, attacks exploiting access-control vulnerabilities and prompt injection will account for more than half of successful cyber attacks targeting AI agents.

"AI security market to grow 69 percent next year"...Gartner forecast

Keyword

#OpenAI #Anthropic #Gartner #AppLovin #CrowdStrike
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.