Cybersecurity and the Enterprise AI Control Layer
Why Cybersecurity Becomes the Budget That Lets AI Scale
Security becomes the approval gate
We have been thinking about cybersecurity as a much deeper enterprise function than the word security tends to imply. The same framework can be extended to sovereign nations. Closed and open models, including models developed outside a company’s or country’s borders, are becoming capable enough that persistent threats will be a fact of operating life. Those threats will reach a company through its products and systems. They will also reach the company’s data and, increasingly, information tied to its employees. The question is how enterprises and governments defend themselves when the tools available to attackers keep improving.
Over the last few months, we have spent considerable time speaking with enterprise decision-makers about agentic deployments, including through our own CIO/CTO survey and conversations with large corporate customers. One concern kept surfacing: security, and cybersecurity in particular. As capable open models continue to advance, the cost and technical barrier for bad actors will come down with them, increasing the threat surface corporations have to defend. For that reason, we think security will be one of the earliest and most durable sources of pull-through from enterprise AI adoption. Security attaches to an AI project as it moves into production, then returns through the existing cyber budget at renewal.
While the early evidence indicates spending is unlikely to arrive as one neat new AI-security category. Instead, AI increases the burden on security controls companies already have in place. In conversations on this with stakeholders one of the first challenges we hear brought up is data access. Before an enterprise can put a model into production, it needs to know what information the model can retrieve and whether that information should be available to the person making the request. Identity becomes more important when an agent begins to act, and runtime controls enter the picture once those actions reach production systems. Some of this need will create new products, but a meaningful share may appear as deeper use of platforms customers already own. That makes the demand easier to see than the eventual revenue pool. The need for greater control can become obvious well before investors can measure where the value is accruing. We also have outlined the need for a new class of compute, to go with a new class of models, or model variants specific to security, cyber security.
Open models raise the market floor
The external threat environment pushes that same budget in a secondary direction. Our companion research on China’s AI stack argues that China does not need semiconductor parity at every layer to keep model development moving. Adequate sovereign compute, paired with competitive open-weight models, is enough to widen access to capable AI. For cybersecurity, capability diffusion does not wait for chip parity. Any open source model, regardless of where it comes from, expands the pool of models available outside controlled services. That linkage has a clear limit: model access alone does not create a successful attacker.
Strategic competition gives nation-states a reason to keep investing in that capability. Enterprises absorb much of the operating cost because their systems are common targets. Models can package parts of reconnaissance or exploit adaptation into tools that are easier to use, which may raise attempted attack volume faster than a human-led defense process can scale. Defenders gain from the same models, but they still need a control layer that can operate at machine (agent) speed.
Exhibit 1. AI Deployment Is Outrunning the Control Layer
The budget converts through existing control points
A direct survey in the source set points in the same direction: deployment is running WELL ahead of dedicated AI-security tooling. The gap is wider if the standard is the full control path around data access and agent behavior. Survey definitions differ, so we do not treat the size as a universal market estimate. The exact number is less insightful than the behavior it reveals. Enterprises are deploying AI before they can fully explain how it behaves and some of the unintended consequences of an unstructured deployment.
Vendors that already own enterprise context or an enforcement point start with an advantage. A data-security platform can attach to a copilot rollout because it controls what the model can retrieve. Identity becomes relevant once agents receive permissions to act. Broader security platforms can spread AI-assisted workflows across an installed base, although the economics remain unclear until customers pay more or use more of the platform.
For stakeholders, a product announcement only shows that a vendor is participating. Continued use through renewal shows whether customers are willing to keep paying. The evidence so far suggests AI will expand cybersecurity spending because every production workload creates more systems and activity to secure. Much of the early spending is likely to flow through vendors already embedded in how companies protect their systems.
The rise in external threats may create a separate revenue opportunity at the model layer. As attackers gain access to more capable models, large enterprises and sovereign governments will need defensive models that can operate at the same speed. We think frontier labs such as OpenAI and Anthropic could build (may already be building) or license restricted models specifically for cyber defense. Some of these capabilities may be too sensitive for broad public access, giving the labs a direct path into enterprise and government security budgets.
Inside the Full Report
A two-pool analysis separating AI for Security from Security for AI, including the different maturity curves and budget sources.
The seven-layer Enterprise AI Control Layer map, showing where identity, data, runtime, and access controls sit around production AI.
A category conversion matrix distinguishing high-probability budget pull-through from capabilities likely to be bundled.
A vendor-positioning exhibit that maps established control-path platforms, specialists, emerging options, and exposed point tools.
A capability-diffusion framework connecting sovereign AI and Chinese open-weight releases to the enterprise security-spend ratchet, without assuming chip parity or proven attack causality.
A falsification and monitoring framework centered on paid attach, dedicated budgets, machine identity, platform consolidation, and realized SOC productivity.




