Atlas companion available: Subscribers can explore the cyber-defense use cases, compare companies, and test the supporting research in CS Atlas.
CS View: Our conviction is high that agentic AI will become an important part of enterprise cyber defense. The opportunity is to help security teams investigate threats and carry out more of the response safely. Conviction in a separate revenue pool for restricted frontier models remains Medium because we do not yet have direct evidence of sustained paid production use.
Using agentic AI to defend the enterprise
The first leg of AI adoption in the enterprise centered on basic LLMs that employees could ask questions or use to draft content. Those early pilots did not raise anywhere near the security concerns enterprises face today as agents run wild inside their four walls. In less than a year, AI went from those early pilots to software that can interpret a goal, decide what to do next, and keep working around the clock. Enterprises have already recognized the potential, but agent use has moved ahead of governed production. They are now working through how much authority to give systems that can change files, operate software, and access company data. That means setting clear limits, requiring approval for sensitive work, and having a way to recover when something goes wrong. Our first cybersecurity report examined the controls enterprises need as AI gains access to their systems. This report looks at the next phase: using agentic AI to defend those systems. Agents can help investigate threats, find vulnerabilities, and prepare fixes. The next challenge is how much of that response the enterprise can safely let them carry out.
One example from the practitioner interviews helps illustrate the defensive use case: a security agent detects suspicious activity and disables an employee’s account. That could stop an attacker, but a mistaken decision could also interrupt legitimate work. The company needs to know why the agent acted, what it was allowed to do, and how to restore access safely. Those requirements determine how much of the response it can automate.
We measure progress in remediation through verified closure: confirming that a security problem has been resolved and the affected system still works. Disabling an account may contain an attack, but the team still needs to check whether the attacker retains another way in. The opportunity is to help security teams complete more defensive work safely. This report examines how that work divides among frontier AI developers, security platforms, and enterprise teams, and where it could create new revenue.
Exhibit 1. AI Makes Discovery Faster; Enterprise Change Control Becomes the Limiting Step
Frontier labs are becoming part of the defense stack
We believe an under appreciated aspect of frontier AI models is how frontier model labs are becoming suppliers of cyber-defense capability. OpenAI’s Daybreak program gives approved defenders access to models with fewer restrictions on authorized security work, with separate approval for its purpose-trained cybersecurity models. Anthropic’s Project Glasswing gives selected partners access to an unreleased frontier model for defensive work. Both programs make advanced cyber capabilities available through controlled access rather than unrestricted public use.
Cybersecurity creates a distribution problem because the same model can help a defender validate an exploit or help an attacker develop one. Public services therefore block some advanced requests, including legitimate defensive work. A trusted enterprise program can allow more capability because access is tied to a verified user and a defined defensive purpose, with the provider monitoring each session. OpenAI’s Daybreak program is the clearest current example, while Anthropic’s Project Glasswing uses the same basic approach with controlled access to an unreleased model.
Frontier labs are likely to keep investing, making the case for the frontier strong, because gains in coding and reasoning already apply to cyber work. A model has the capabilities to stay with a long technical investigation or work across a large code base may create more defensive value than a public assistant that has to block advanced cyber tasks. That supports a restricted tier for vetted enterprises and governments, often through security-vendor partnerships. We are ready to treat trust-gated cyber access as an emerging product pattern. Private model weights and on-premises deployment remain unproven. A sovereign model is also a reasonable scenario for customers that require tighter isolation around sensitive telemetry, although provider and customer disclosures still have to show which delivery forms become real products.
Continue this question in Atlas: What evidence would move restricted frontier-model monetization from Medium to High conviction?
Model intelligence still needs enterprise authority
A defensive agent needs both model reasoning and the customer’s operating context. The model can help investigate a threat and prepare a response; identity and security platforms enforce what it is allowed to do. The enterprise owns the approval and recovery decisions. Partnerships are the practical near-term path because model developers and control platforms each supply part of the work needed to defend a live system.
The first financial proof we are watching for should appear in higher security-platform consumption or broader paid identity and recovery coverage as customers use AI for more defensive work. The real test is whether better reasoning helps teams resolve more exposure safely. Products that stop at recommendations leave the customer with the work of carrying out the response and the risk if it fails.
Inside the Full Report
How agentic AI can help investigate threats, contain attacks, and complete fixes.
The delivery paths and value-capture scenarios beyond today’s controlled-access programs.
Why the model layer and the security control layer remain complementary.
A threat-to-control map for the authority and tool paths agentic systems create.
A safe-remediation framework built around skill-level authority and recovery.
An auditable completeness scorecard for the leading positions.
A 2030 market model that separates gross spend from incremental revenue.
The pricing units and buyer evidence that would confirm or break the thesis.
Integrated companion research in CS Atlas for subscribers to engage more with the research.



