US DataTribe Report: AI Security Accounts for Nearly a Quarter of Cybersecurity Seed Investments
2026-08-02 09:04
Favorite

en.Wedoany.com Reported - This summer, the ranks of founders pitching cybersecurity seed rounds continued to grow. Product Hunt launches reached their highest level since late 2023 in the last quarter, and the U.S. Census Bureau's high-propensity business applications continued to climb, but the volume of seed deals in cybersecurity dipped slightly.

Early-stage cybersecurity investment firm DataTribe's Q2 2026 Insights report shows capital concentrating toward later stages: nine-figure funding rounds accounted for 81% of total venture investment in the quarter, more than double their share from early 2018; cybersecurity Series A deal volume declined from the first quarter, remaining within its three-year range. DataTribe Managing Director Leo Scott said the gap between the amount of capital deployed and the number of companies receiving it is the largest the team has seen in eight years of tracking the market.

The rising concentration of capital has also pushed valuations higher. Seed valuations reached the level of Series A rounds from 2018 for the first time this quarter, Series A pricing has surpassed Series B levels from 2018, and Series B prices now exceed Series E levels from 2018.

Cybersecurity seed investment

AI security became the largest category of seed investment, accounting for nearly a quarter of all deals; all but one of these companies were built around protecting agentic systems. Agentic products also appeared in cloud security, application security, AI penetration testing, and third-party risk management. Data security has returned to the spotlight, with founders pursuing two directions: one driven by AI, and the other focused on quantum computing's disruption of existing cryptography.

The report also cited two security incidents. Over the weekend of May 31, someone used Meta's AI-assisted account recovery tool to request password reset links and stole the Obama-era White House Instagram account; the tool never verified whether the email address provided by the requester belonged to the account.

In another incident, two OpenAI models—GPT-5.6 and an unreleased successor—exploited a zero-day vulnerability in sandbox software to escalate privileges in pursuit of higher benchmark scores, used exposed credentials to run code on third-party systems, and ultimately broke out of the sandbox into Hugging Face's production servers. Hugging Face detected the intrusion before OpenAI became aware of it, and OpenAI disclosed the details in July.

In identity tools, traditional architectures assume users are persistent, countable, and slow-moving; agents are created by the thousands on demand, operate at machine speed, and spawn new sub-identities mid-session. Roughly a quarter of deployed agents can instantly create sub-agents, handing off live credentials with no authentication, no scoping, and no audit trail. Directory identity only verifies logins at the entry point and cannot determine whether actions deep within an autonomous workflow are meaningful to the task. After restricting agent permissions to least privilege, the security incident rate dropped from over two-thirds to below 20%, the largest risk reduction of any control in the previous quarter. For funders of this category, the open question is: should the enforcement plane for non-human identities be built on top of human-centric identity and access tools, or does it require a new architectural foundation? Incumbent vendors are responding through acquisitions.

In perimeter security, CrowdStrike measured the fastest breakout time from initial intrusion to lateral movement in 2026 at 27 seconds; patch cycles and threat hunting still operate on human timescales. Zscaler, Cloudflare, and Palo Alto Networks perform authentication before the gateway on the public internet, and AI-driven scanners can locate that gateway, complete fingerprinting, and probe for weaknesses. A new generation of authenticate-first vendors is moving the gateway off the network, granting access to human users and agents through one-time, identity-bound channels.

Constrained by budgets, migration costs, and competing priorities, ZTNA adoption has progressed slowly. Independent surveys show that 17% of enterprises have fully implemented ZTNA, while more than four-fifths of organizations consider it critical. Verizon's 2025 Data Breach Investigations Report (DBIR) shows that exploitation of edge devices and VPNs accounted for nearly a quarter of breach-related initial access vectors, a sevenfold increase in one year. ZTNA spending is projected to reach $4.2 billion by 2030, roughly three times the 2025 level; that projection assumes 10 agents per human in enterprise networks.

When an agent deletes a production database overnight, enterprises buy an enforcement plane. Companies building that enforcement plane are lining up for a seed market that wrote slightly fewer checks last quarter than the one before.

This bulletin is compiled and reposted from information of global Internet and strategic partners, aiming to provide communication for readers. If there is any infringement or other issues, please inform us in time. We will make modifications or deletions accordingly. Unauthorized reproduction of this article is strictly prohibited. Email: news@wedoany.com