It’s hard to stop a vampire once you’ve invited him for dinner. That old legend well applies in the era of agentic AI: Millions of autonomous bots can now browse websites and complete complicated tasks without a human having to approve each step; as agents have grown more resourceful, some are learning to bend the rules, jump their guardrails and potentially wreak havoc.
Welcome to the frontlines of cybersecurity’s intensifying battle against rogue AI agents. As concern swells, U.S. lawmakers from both parties are reportedly looking to institute new regulations to keep bad AI actors in check. Meanwhile, we believe the rising threat from rogue agents continues to open potentially attractive investment opportunities within the rapidly growing cybersecurity sector.
Warning Signs
Back in July, OpenAI was testing its GPT-5.6 Sol model on a hacking benchmark, a standardized test measuring how well an AI model can outwit security systems. The test ran inside a “sandbox”, a theoretically locked-down area with no access to the internet, yet the model broke free anyway, exploiting a “zero-day” security flaw that hadn’t been patched. Once online, the rogue AI broke into Hugging Face, a platform where developers share AI tools, and pulled the correct answers to the test on its own, without any human intervention.1
In another incident, the UK’s AI Security Institute found agents launching self-directed spear-phishing campaigns. The agents also planted “prompt injections”—hidden misleading instructions buried inside normal-looking content.2
Neither event involved human hackers: The agents simply slipped their chains and acted on their own.
New Tools for a New Threat
An AI agent needs access to do its job, whether that means moving files, calling systems or making decisions. But the sneakiest agents can trick other agents into misusing the access they’ve already been granted—like that vampire trying to charm his way into your dining room.
As the agent army has grown larger and craftier than their human-hacker counterparts, traditional security tools are falling short. One big problem is that agents write and ship code continuously, allowing potentially malicious instructions to slip through because a system thinks they’ve already been vetted and approved. (In the security trade, this is called “supply chain poisoning.”)
To mount a stronger defense, leading security players are now taking a more maniacally rigorous approach: Every agent, piece of code and ultimate action needs its own verified identification that is checked continuously rather than once at the door.
Think of it like passengers having to clear multiple checkpoints at an airport. First, they must present some form of ID, such as driver’s license or passport, to secure a ticket; next, they scan that ID to get past the gate agent; and finally, they check their ticket against a badge system before being allowed to board. And all of those steps require an airport terminal to handle the traffic and administer the various checkpoints.
That airport-like security infrastructure involves many different players. Here is a rough schematic:
- ID issuance: These software platforms, including JFrog, manage how code and AI models move from development into production. They verify where each piece of code came from and confirm it hasn’t been tampered with along the way. Every piece is given its own ID before it travels further down the line.
- Boarding pass scan: These network-security and content-delivery companies, including Akamai and Cloudflare, sit at the internet’s edge, monitoring behavior in real time to distinguish legitimate traffic from malicious activity—like a gate agent matching faces against IDs rather than scanning ticket numbers alone.
- Badge check: These companies manage access controls across networks and cloud systems. Palo Alto’s acquisition of CyberArk gives it control over “non-human identity”, letting it issue and manage access badges for AI agents. Fortinet, another industry leader, builds similar checks directly into its Zero Trust network hardware, verifying a limited-access badge every time an agent tries to act.
- The terminal: Cloud infrastructure providers, such as DigitalOcean, host and support application development for businesses of all sizes, essentially supplying the terminal where agents are built, tested and launched.
Collectively, we believe this group is spinning up a new and rapidly growing cybersecurity category. MarketsandMarkets expects the agentic AI security market will shoot from $1.7 billion to $13.5 billion by 2032, a blistering 42% compound annual growth rate.3
With more vampire agents on the prowl, we believe thematic investors may be wise to raise their stakes.

