ARTICLE
Every pure-play got bought
What the 2024 to 2026 consolidation of AI security means for anyone running more than one cloud
In August 2024, Cisco announced it was buying Robust Intelligence. At the time it read as a single deal. It was the start of the fastest category consolidation most people in security have seen.
By June 2026 the count stood at fifteen. Palo Alto Networks took Protect AI and later Koi Security. Check Point took Lakera and later Cyata. SentinelOne took Prompt Security. Cato Networks took Aim Security. F5 took CalypsoAI for a disclosed $180 million, the only price anyone in the whole wave actually published. CrowdStrike took Pangea. Zscaler took SPLX. Tenable took Apex. Snyk took Invariant Labs. Proofpoint took Acuvity. A10 Networks took TrojAI. OpenAI took Promptfoo.
Six of the vendors that defined AI runtime security are now inside a platform
AI-security acquisitions by established vendors, August 2024 to June 2026
| Date | Acquirer | AI-security target | Price | Status |
|---|---|---|---|---|
| Aug 2024 | Cisco | Robust Intelligence | undisclosed | Acquired |
| Apr 2025 | Palo Alto Networks | Protect AI | undisclosed | Acquired |
| May 2025 | Tenable | Apex Security | undisclosed | Acquired |
| Jun 2025 | Snyk | Invariant Labs | undisclosed | Acquired |
| Aug 2025 | SentinelOne | Prompt Security | undisclosed | Acquired |
| Sep 2025 | Cato Networks | Aim Security | undisclosed | Acquired |
| Sep 2025 | F5 | CalypsoAI | $180M disclosed | Acquired |
| Sep 2025 | CrowdStrike | Pangea | undisclosed | Acquired |
| Sep 2025 | Check Point | Lakera | undisclosed | Acquired |
| Nov 2025 | Zscaler | SPLX | undisclosed | Acquired |
| Feb 2026 | Proofpoint | Acuvity | undisclosed | Acquired |
| Feb 2026 | Check Point | Cyata | undisclosed | Acquired |
| Feb 2026 | Palo Alto Networks | Koi Security | undisclosed | Acquired |
| Mar 2026 | OpenAI | Promptfoo | undisclosed | Acquired |
| Jun 2026 | A10 Networks | TrojAI | undisclosed | Acquired |
Still independent as of August 2026
HiddenLayer · Noma Security · WitnessAI · Zenity · Lasso Security · Pillar Security · AI-Sentinel
Sources: acquirer press releases (Cisco, Palo Alto Networks, Tenable, Snyk, SentinelOne, Cato, F5, CrowdStrike, Check Point, Zscaler, A10); Infosecurity Magazine M&A round-ups, Feb and Mar 2026.
Only F5 / CalypsoAI disclosed a price. All other figures reported in the press are estimates and are omitted here. Verified 5 August 2026.
Six of those, Robust Intelligence, Protect AI, Prompt Security, Aim Security, CalypsoAI and Lakera, were the pure-play runtime guardrail vendors that defined the category in 2023 and 2024. If you built an AI security shortlist two years ago, most of the names on it now belong to somebody else.
First, the part where we correct some marketing fluff
You will find AI-security companies describing this as the moment when every independent option vanished. That is not completely true, and it is worth saying so plainly.
HiddenLayer, Noma Security, WitnessAI, Zenity, Lasso Security and Pillar Security are all still independent as of August 2026. Zenity raised a $125 million Series C on 3 August. Noma raised $100 million. WitnessAI raised $58 million in January. These are not stragglers. Several of them are very well capitalized.
The accurate version of the claim is narrower and, we think, more interesting: the specific category of inline runtime guardrail vendors has been almost entirely absorbed into platform companies, and the independents that remain are mostly positioned somewhere adjacent, in posture management, agent identity, discovery or governance.
Why this is a normal thing that still has consequences
None of this is sinister. It is what happens when a category proves itself. Large security vendors have distribution, existing enterprise relationships and a gap in their portfolio. Startups have technology and a hard road to enterprise sales. The math is obvious from both sides.
But the second-order effect on a buyer is real, and it is not what the press releases talk about.
When AI security lives inside a platform, it comes with the platform’s assumptions. It is optimized for that vendor’s cloud, that vendor’s firewall, that vendor’s telemetry pipeline and that vendor’s console. That is not a criticism. It is the entire point of a platform, and if you are a single-cloud shop standardized on one vendor, it is genuinely the right answer and you should buy it.
The problem arrives when your reality is messier. As one prospect put it to us:
“We use three different clouds and five different LLMs. I don’t want a security tool that only works when I’m using Azure or only when I’m behind a Cisco firewall.”
For that buyer, the consolidation quietly converted a point purchase into a platform decision. You came looking for a way to stop prompt injection. You are now being asked to make a strategic bet on whose ecosystem your whole security program lives in for the next five years.
The three questions worth asking your incumbent
If your existing platform vendor now has an AI security module, and most of them do, these are the questions that separate a real capability from a slide in a quarterly business review.
1. What happens to my policies when I change model provider?
This is the cheapest question and the most revealing. Models get swapped constantly now, for cost, for capability, for a compliance requirement, for an outage. If the answer involves rewriting rules, you have discovered that your security posture is coupled to a procurement decision you will make again within eighteen months.
The property you want is architectural: policy that travels with your stack rather than with your vendor. It is not a feature that can be added later, because it is a consequence of where the security layer sits.
2. What is the measured latency, on my traffic, and will you put it in writing?
Most of the platform products publish no latency figures at all. We checked. Cloudflare, AWS Bedrock Guardrails, Azure Prompt Shields, Prisma AIRS and Cisco AI Defense all document capabilities in detail and are silent on the number that determines whether your engineers will tolerate the thing.
The published figures that do exist are not encouraging. NVIDIA's own measurements put a three-rail NeMo stack at roughly 530 milliseconds of added response latency. Meta's Prompt Guard 2 classifiers measure 19.3 and 92.4 milliseconds. A vendor benchmark from TrueFoundry put prompt-injection detection at 358.7 milliseconds.
Ask for a number. Then ask to measure it yourself.
3. What makes the decision to block, and can it be jailbroken?
Covered at length elsewhere on this site, so briefly: if a language model sits in the enforcement position, published research has demonstrated evasion rates up to 100% against comparable production systems. That may be an acceptable risk for you. It should be a known one.
What consolidation does to a roadmap
Here is the effect that shows up eighteen months after a deal closes, and it is the one nobody warns you about at signing.
An acquired product's roadmap stops being driven by what its users need and starts being driven by platform integration work. Engineers who spent two years on detection research spend the next year on console unification, single sign-on, shared telemetry schemas and getting the thing to appear in the right tab. This is necessary work. It is also not detection research, in a category where the attack techniques change monthly.
MITRE ATLAS now ships monthly content releases. It holds 16 tactics and 178 techniques as of release 2026.07, more than double where it was on an earlier version many vendor pages still quote. The OWASP LLM Top 10 was reissued on 3 August 2026 with a changed order. A detection team distracted by platform plumbing for four quarters falls behind in a way that is invisible until somebody actually tests it.
Which is, incidentally, the argument for continuous adversarial validation regardless of whose product you buy. If your vendor's coverage silently decays, the only thing that will tell you is attacking yourself on a schedule.
The uncomfortable question pointed back at us
A fair reader will have noticed the obvious problem with an independent vendor writing about the value of independence. So let us answer it before you ask.
Are we going to get acquired? We are raising a pre-seed round to fund a Kubernetes roadmap, not to flip the company. But no founder can credibly guarantee you five years of independence, and any who tries is telling you something about their relationship with the truth rather than about their cap table.
The useful response is not a promise. It is contract structure. Ask any vendor in this category, including us, for continuity terms: source escrow, assignment provisions, notice periods on material change of control, and what happens to your deployment if the acquirer sunsets the product. Those are negotiable, enforceable and worth more than a paragraph of reassurance on a website.
The other honest answer is that independence is worth something specific and limited. It is worth the fact that your policies work the same across three clouds and five models. It is worth not having your AI security be an argument for consolidating everything else. It is not worth choosing a worse product, and if the platform module genuinely covers your environment, buy the platform module.
Just run both in monitor mode for a week first, side by side, against your own traffic, and let the findings decide it rather than the logo.
‹ All articles
Do not take our word for it. Run AI-Sentinel against your own traffic.
Monitor mode goes in non-blocking, in minutes, with zero risk to live workflows. Within days you get a written audit of the prompt injections, extraction attempts and data leaks your current stack is not catching. Then you decide.
The audit is free. The blind spot is not.