Landscape

The map

A taxonomy of the AI cybersecurity space: eight segments, who occupies each, and which ones are actually adjacent to each other.

evidence: high9 minupd 2026-08-29taxonomyorientation

"AI cybersecurity" names at least eight distinct markets that share a phrase and almost nothing else. They have different buyers, different technical problems, different capital intensity and different competitive dynamics. Confusing them is the most common analytical error in this space — it is what lets a founder read a headline about a $1B offensive-security valuation and conclude something about the market for code review.

This page is the orientation map. Every segment links to its deeper treatment.

#The eight segments

# Segment What it sells Buyer Occupied by State
1 Autonomous offensive security Continuous pentesting, attack simulation CISO, security ops XBOW, Horizon3, Pentera, RunSybil, Terra, Mindfort Well funded, consolidating
2 AI code security Finding and fixing vulnerabilities in the SDLC VP Eng, AppSec lead, developers ZeroPath, Corgea, Semgrep, Snyk, Socket, Endor, plus GitHub and the frontier labs Crowded on top, empty underneath
3 AI SOC and detection Alert triage, investigation, response SOC manager, CISO Dropzone, Prophet, Radiant, Exaforce, plus every platform incumbent Crowded, capital-rich
4 AI cyber labs Evaluations, research, capability measurement Frontier labs, governments Irregular, Gray Swan, METR, Dreadnode, UK AISI Small, duopoly forming
5 Securing AI systems Guardrails, prompt-injection defense, agent security CISO, platform teams Lakera, HiddenLayer, Zenity, Noma, plus acquirers Consolidating via M&A
6 Open-weight security models Models and fine-tunes Vendors, integrators Cisco Foundation AI, Trend Micro, hobbyists Thin, uneven
7 Benchmarks and evaluation Measurement Nobody pays Academia, Meta, frontier labs Non-commercial
8 Compliance and evidence Proof of security process Compliance, legal, engineering Fragmented, largely manual Underbuilt, dated demand

Segments 1 and 3 are where the money went. Segment 2 is where the founder's idea lands. Segment 4 is the category he said he wants to enter. Segments 7 and 8 are the ones nobody optimized for, and they turn out to matter — see Where the gaps actually are.

#How the segments actually relate

The useful mental model is not eight boxes but a set of dependencies.

Segments 7 and 6 are inputs, not markets. Benchmarks do not generate revenue for anyone who makes them (Cyber benchmarks and evals), and open-weight security models have not produced a standalone business (Open-weight security models). They are credibility and capability infrastructure that feeds the segments that do sell.

Segments 1 and 2 are technically closer than they look. Both reduce to: understand a system, hypothesize a weakness, prove the weakness is real. Offensive tools prove it by exploiting; defensive tools prove it by reproducing. The verification machinery is nearly the same, which is why an offensive capability inside a defensive product is an engineering asset — and, from a German entity, a legal problem (Germany: §202c and the Berlin question).

Segment 3 is further away than it looks. SOC triage is an integration and data-access business, and the benchmark evidence suggests the reasoning gains that transfer to code and offense do not transfer to alert triage (AI SOC and detection companies, Cyber benchmarks and evals).

Segment 5 is a different industry wearing similar words. Securing AI systems means prompt injection, agent permissions and model guardrails. It shares almost no technical substrate with finding vulnerabilities in code. It is also the segment with the clearest acquisition activity (Who funds this and at what price).

Segment 8 is the demand engine for segment 2 in Europe. The Cyber Resilience Act turns vulnerability handling into a legal obligation with dates attached (EU regulation as a demand engine). Nobody has built the product that makes segment 2's output satisfy segment 8's requirement as a by-product.

So what

The interesting structural fact is that segments 2, 7 and 8 form a loop that nobody has closed. The verification machinery that makes a code-security product trustworthy is the same machinery that makes a benchmark credible, and its output is the same artifact a compliance regime demands. Building one gets you most of the other two.

#The four kinds of player

Cutting across segments, participants fall into four types with very different economics.

Frontier labs. OpenAI, Anthropic, Google DeepMind, Meta. They build the most capable offensive and defensive systems in existence, gate the strongest ones, and increasingly ship competing commercial products. They are simultaneously supplier, competitor and regulator of everyone else's ceiling (What the frontier labs do themselves, Is frontier-lab gating a real wedge?).

Platform incumbents. Palo Alto, CrowdStrike, Cisco, Microsoft, Snyk, Checkmarx. They own distribution and buy capability. They are the realistic exit path — this category has produced strategic acquisitions and no IPOs (Who funds this and at what price).

Venture-backed specialists. The named startups in segments 1, 2, 3 and 5. Their common structural problem is that they mostly wrap frontier models, which makes them vulnerable to the supplier shipping the same feature.

Labs and evaluators. Segment 4, plus academic groups. They monetize through evaluation contracts, government funding, philanthropy, or eventual acquisition — not product revenue (The AI cyber lab category).

#Where the money went, and what that does and does not tell you

Offensive security raised dramatically more than defensive code security in 2024–2026. XBOW crossed $1B, Horizon3 raised at $2B+. The AI SOC segment absorbed enormous capital across a dozen companies. AI code security raised meaningfully less per company (Who funds this and at what price).

The naive read is that offense is the better market. A more careful read: offense produces demonstrable, dramatic artifacts — a leaderboard rank, a zero-day, a compromised target — that fundraise well before independent verification exists. Defense produces the absence of incidents, which is harder to demo. XBOW's fundraising record is strong evidence that investors will fund an AI security narrative on team and story well before benchmarks exist, which is a pattern to exploit rather than to resent (XBOW).

The capital asymmetry is a signal about investor attention, not about where value accrues. See Where value accrues for where it actually accrues.

#What is changing fastest

Four clocks are running, and any plan should be indexed to them.

  1. The open-weight gap. 4–7 months behind frontier on cyber and closing, down from 6–10 a year ago (Is frontier-lab gating a real wedge?). Anything premised on the gap staying wide has a shrinking window.
  2. Frontier labs entering the product market. Aardvark to Codex Security took roughly four months from invite-only to broad rollout (What the frontier labs do themselves).
  3. The EU regulatory clock. CRA Article 14 on 11 September 2026, full application 11 December 2027. These dates do not move for market reasons (EU regulation as a demand engine).
  4. Evidentiary standards. After 2026's containment incidents and the walked-back threat reports, the market's tolerance for self-reported claims is dropping (What AI is actually doing to the threat landscape). That favors whoever measures things.

#What this means for us

  • Do not reason across segments. Evidence about the offensive market says almost nothing about the defensive code-security market, and the SOC segment's dynamics are actively misleading if imported.
  • The loop between segments 2, 7 and 8 is the structural insight this map produces, and it is the basis of the recommendation in The three ideas, judged.
  • The four clocks make this a timing question as much as a strategy question. Two of them close a window and two open one; the CRA clock is the only one running in your favor.
  • Use Timeline 2023-2026 to see how these segments got here, and Where value accrues to see which layer of any of them is worth occupying.