NEW YORK — Corporate America is rewriting its cybersecurity budget playbook as artificial intelligence moves from an experimental technology into a core business tool, creating a new opportunity for cybersecurity software companies while forcing enterprises to rethink where their security dollars deliver the most protection.
Companies are spending more on cybersecurity overall, but the biggest change is happening inside those budgets. Businesses are increasingly directing money toward AI-specific protection, identity controls, cloud security, threat detection and systems designed to monitor autonomous AI agents.
That shift is putting cybersecurity software companies in a relatively strong position at a time when parts of the broader enterprise software market are facing questions about whether AI could disrupt traditional subscription-based products.
Recent market moves have highlighted the contrast. Cybersecurity companies such as CrowdStrike have attracted investor attention as businesses look for tools capable of defending increasingly complex AI-driven environments.
AI Is Changing the Cybersecurity Budget
Artificial intelligence is creating a two-sided problem for corporate security teams.
On one side, companies are using AI to automate operations, analyze data, write software and assist employees.
On the other, attackers are using AI to develop more convincing phishing campaigns, identify vulnerabilities faster and automate parts of cyberattacks.
That combination is pushing security executives to rethink spending priorities.
A June study from Information Services Group found that 74% of surveyed enterprises had increased investment in AI-specific security tools and solutions, while 69% had increased budgets for monitoring and detecting AI-specific threats. AI-related cybersecurity spending represented more than 11% of total cybersecurity budgets among the organizations surveyed.
The message from corporate security departments is increasingly clear: AI is becoming both a business opportunity and a security problem.
Cybersecurity Spending Is Still Growing
The broader cybersecurity market remains resilient even as companies scrutinize technology spending.
A recent BCG survey found that 83% of cybersecurity leaders are spending more on cybersecurity, while nearly nine in 10 respondents reported experiencing cyberattacks during the previous year.
That spending is not necessarily flowing evenly across the market.
Security executives are prioritizing areas where they believe AI is creating the greatest new risks, including cloud environments, data protection, threat intelligence and AI governance.
BCG said more than half of surveyed CISOs planned to increase spending on cloud, data and threat-intelligence security.
AI Security Is Becoming Its Own Market
The emergence of AI is creating demand for an entirely new category of security software.
Gartner estimates that worldwide spending on products specifically designed to secure AI will reach approximately $4.8 billion in 2027, up from about $2.8 billion in 2026.
The market includes several categories:
- AI application security
- AI usage controls
- AI governance platforms
- AI gateways
- AI runtime protection
- AI agent security
- AI data protection
These products are designed to address risks that conventional security tools may not fully understand.
Traditional Security Tools Face a New Challenge
For years, cybersecurity products focused on protecting networks, endpoints, applications and data.
AI introduces another layer.
An AI agent can interact with applications, access corporate information, call external services and make decisions based on instructions and data.
That means security teams increasingly have to monitor not just machines and employees, but also software agents acting on behalf of employees.
Gartner says traditional security tools often need significant updates to address AI-specific threats, driving demand for specialized AI-security products.
The Rise of AI Agents Is Changing Identity Security
The expansion of agentic AI may be one of the most important reasons security budgets are being redirected.
An AI agent can potentially receive permissions similar to those held by an employee.
It may access files, send messages, query databases or interact with enterprise software.
That creates a new identity problem.
Security teams need to know not only who is accessing a system, but also which AI agent is acting, what it is authorized to do and whether its behavior remains within company policy.
McKinsey estimates that spending on technologies designed specifically to govern AI agents could eventually account for roughly 15% of enterprise cybersecurity budgets, with identity, governance and data security among the areas receiving significant attention.
Companies Are Looking for Better Visibility
One of the biggest problems is that companies do not always know where AI is being used.
Employees may adopt generative AI tools without going through formal IT approval.
Developers may connect AI models to internal applications.
Business teams may create automated workflows using AI agents.
This phenomenon is often described as shadow AI.
BCG found that only 41% of surveyed organizations had formal AI governance policies, while just 23% had implemented monitoring or logging for AI agents.
That gap represents a significant opportunity for cybersecurity vendors.
AI Governance Becomes a Spending Priority
AI governance tools are designed to help companies establish rules around how employees and AI agents use models.
These systems can monitor which models are being accessed, what information is being shared and whether AI applications comply with internal policies.
As companies move from experimentation to widespread deployment, governance is becoming increasingly important.
The objective is not necessarily to stop employees from using AI.
Instead, companies want to make AI use visible, controlled and auditable.
CrowdStrike Benefits From the Shift
CrowdStrike has become one of the cybersecurity companies attracting significant attention as AI reshapes enterprise technology spending.
Recent financial results showed strong growth, while investors responded positively to the company’s ability to position cybersecurity as a beneficiary of AI adoption rather than a victim of it.
That distinction matters.
Some software companies face concerns that AI agents could replace portions of the work their applications perform.
Cybersecurity companies face the opposite dynamic.
The more AI companies deploy, the more security infrastructure they may need.
AI Could Increase the Attack Surface
Every new AI application creates another potential entry point.
A company might connect a model to customer records, internal documents or software-development systems.
If permissions are poorly configured, an attacker could exploit that connection.
Prompt injection is one example.
An attacker can place malicious instructions inside data that an AI system processes, potentially influencing the model’s behavior.
The risk becomes greater when AI agents can take actions rather than simply produce text.
Security Spending Is Moving From Prevention to Continuous Monitoring
The rise of AI is also changing how companies think about security.
Traditional cybersecurity often focused on preventing unauthorized access.
Modern AI security increasingly requires continuous monitoring.
Companies need to know what AI systems are doing in real time.
They may need to detect unusual agent behavior, unauthorized data access or attempts to bypass security controls.
This is helping drive demand for AI gateways, runtime protection and behavioral monitoring.
Gartner expects AI gateway spending to grow rapidly as organizations seek additional control over AI interactions.
Cybersecurity Companies Are Also Using AI
The spending shift is not limited to protecting AI.
Security vendors are increasingly using AI themselves.
AI can analyze enormous amounts of security data, identify unusual activity and help security analysts investigate alerts.
It can also automate routine tasks.
That can be especially valuable for companies struggling with cybersecurity staffing shortages.
The result is a feedback loop.
AI creates new security risks while simultaneously becoming one of the primary tools used to defend against those risks.
AI-Driven Attacks Are Becoming a Board-Level Concern
The issue is increasingly reaching corporate boards.
A joint letter signed by more than 100 major technology and financial companies recently warned that AI-driven cyberattacks could become significantly more widespread and called for stronger cooperation between governments and private companies.
The companies included major technology firms such as Microsoft, Alphabet, Amazon, IBM and OpenAI.
Their message was not simply that cybersecurity teams need more tools.
It was that AI-enabled attacks could create risks large enough to require a broader response from business leaders and policymakers.
The Threat Is Already Affecting AI Companies
Recent incidents involving frontier AI developers have reinforced those concerns.
Anthropic disclosed incidents in which Claude models reached real systems during cybersecurity evaluations after a testing environment was mistakenly connected to the internet.
The company responded by strengthening its security controls and temporarily pausing some higher-risk training and testing activity.
The incidents demonstrate that AI security is not merely a theoretical issue.
Even AI companies themselves are discovering new risks as models become increasingly autonomous.
Enterprise Customers Want Fewer Security Vendors
The cybersecurity market is also experiencing another important shift.
Companies increasingly want to reduce the number of disconnected security products they operate.
Managing dozens of separate security platforms can create complexity and gaps in visibility.
An industry study found that only about 35% of organizations expected to increase the number of cybersecurity vendors in their technology stacks, down from 40% the previous year.
That creates both an opportunity and a challenge for cybersecurity software companies.
Vendors need to offer products that provide clear value while integrating effectively with existing platforms.
Consolidation Could Accelerate
As enterprises demand integrated security platforms, smaller cybersecurity vendors could face increasing pressure.
Companies that provide highly specialized products may need to integrate with larger platforms or demonstrate a unique capability that customers cannot easily replace.
At the same time, large security companies could pursue acquisitions to expand their AI-security capabilities.
The result could be another wave of consolidation across the cybersecurity software market.
Investors Are Watching the AI Security Winners
For investors, the cybersecurity market offers a different AI story from traditional enterprise software.
Some software companies are being pressured because AI agents could reduce demand for certain applications.
Cybersecurity vendors have an additional tailwind because AI adoption itself creates security requirements.
That does not mean every cybersecurity company will succeed.
The market is becoming increasingly competitive, and customers are demanding measurable results.
But companies positioned around identity, cloud security, AI governance and agent protection could benefit from the next phase of enterprise AI adoption.
New Startups Are Targeting AI Agent Security
The opportunity has already attracted new investment.
Obsidian Security recently raised $85 million in a Series D financing round at a valuation of about $1.1 billion, with demand for AI-agent security cited as an important market driver.
The company focuses on monitoring and controlling AI agents operating inside enterprise applications.
Its growth illustrates how investors are identifying security gaps created by the rapid deployment of autonomous AI.
Cybersecurity Budgets Could Become More Specialized
Instead of simply increasing total security spending, companies may increasingly divide budgets into more specialized categories.
A future security budget could include separate allocations for:
- Traditional endpoint protection
- Cloud security
- Identity security
- AI application security
- AI governance
- AI agent monitoring
- Data security
- Threat intelligence
- Security operations
That would represent a significant change from the traditional cybersecurity model.
AI Security Could Become a Core Enterprise Requirement
As AI becomes embedded in everyday business operations, AI security may eventually become as standard as endpoint or cloud security.
Companies will need to answer basic questions before deploying AI systems:
Who can use the model?
What information can it access?
What actions can an agent perform?
How are those actions monitored?
What happens if the model behaves unexpectedly?
How quickly can access be revoked?
Those questions are becoming central to enterprise cybersecurity.
The Role of the CISO Is Expanding
The shift is also expanding the responsibilities of chief information security officers.
CISOs are no longer focused exclusively on protecting traditional technology infrastructure.
They are increasingly involved in AI governance, data policy, third-party AI risk and business continuity.
ISG found that U.S. organizations are increasingly integrating cybersecurity into enterprise risk management and executive decision-making.
That means cybersecurity decisions are becoming business decisions.
AI Spending Could Pull Security Budgets Along With It
The larger AI investment boom could create a continuing tailwind for cybersecurity.
Gartner forecasts worldwide AI spending of more than $2.5 trillion in 2026, including more than $51 billion in AI cybersecurity spending.
As companies invest in AI infrastructure, software and agents, they will also need to protect those systems.
That creates a potentially durable relationship between AI adoption and cybersecurity spending.
But Security Budgets Still Face Pressure
Despite strong demand, security executives are not operating with unlimited budgets.
Companies continue to scrutinize technology spending and demand measurable returns.
That means cybersecurity vendors must prove that their products reduce risk, improve efficiency or protect critical business assets.
Simply labeling a product as “AI-powered” will not necessarily be enough.
Customers increasingly want evidence that the technology solves a specific problem.
The Competitive Battle Is Shifting
The cybersecurity software market is therefore entering a new phase.
The winners may not necessarily be the companies with the most AI features.
They may be the companies that can combine AI capabilities with strong security foundations, broad integrations and measurable outcomes.
That could favor established cybersecurity platforms while creating opportunities for specialized startups.
The Bigger Picture
The AI boom is creating an unusual dynamic across the software industry.
AI is threatening to disrupt some traditional software categories.
At the same time, AI is creating new demand for cybersecurity.
Companies cannot deploy powerful AI systems without considering the risks created by those systems.
That makes security one of the areas where AI could strengthen, rather than weaken, the long-term demand for enterprise software.
The Bottom Line
U.S. companies are increasingly redirecting cybersecurity spending toward AI-specific threats as artificial intelligence becomes deeply embedded in enterprise operations.
Research from ISG found that 74% of surveyed enterprises increased investment in AI-specific security tools in 2026, while 69% increased spending on monitoring and detecting AI-related threats.
BCG’s latest research similarly shows that cybersecurity budgets continue to rise, with 83% of surveyed security leaders reporting higher spending and nearly nine in 10 organizations experiencing cyberattacks during the previous year.
Meanwhile, Gartner expects the market for securing AI to reach approximately $4.8 billion in 2027, as companies adopt specialized tools for AI application security, usage control, governance and AI gateways.
The trend is creating a favorable environment for cybersecurity software firms.
Companies such as CrowdStrike are benefiting from the perception that AI adoption can increase the need for security rather than simply threaten existing software business models.
But the market is changing quickly.
Businesses want fewer vendors, better integration and stronger evidence that security products can protect AI systems without adding unnecessary complexity.
For cybersecurity companies, that creates both an opportunity and a test.
AI may be disrupting the traditional software industry, but it is also creating an entirely new security market.
As enterprises give AI systems more access to sensitive data and business applications, protecting those systems is likely to become a permanent part of corporate technology spending.
The next generation of cybersecurity companies may therefore not simply defend computers, networks and employees.
They will defend the AI agents increasingly acting on behalf of the business.
Source angle: Latest 2026 research from Gartner, BCG and ISG on AI cybersecurity spending, enterprise security priorities, AI-agent risks and the changing cybersecurity software market, supplemented by recent developments involving major cybersecurity and AI companies.

