AI Security: Assuming the Attacker Is Already Inside
Community Discussion · Tracks

AI Security: Assuming the Attacker Is Already Inside

Sister Liang on ValuationSister Liang on ValuationSep 32026/09/03 32 views

The most valuable information in this article is that Tide's Raziel doesn't continue to talk about "keeping attackers out," but assumes attackers already have root access and are already inside the network. This assumption sounds depressing, but it's crucial for valuation: the pricing unit for security budgets may shift from boundary devices to agent behavior control.

When I wrote about Cisco Antares previously, I judged that Security AI is more like precise gap-filling. Looking at these new vendors now, the object of gap-filling has changed. In the past, it filled SOC staffing shortages; now it fills agent permission loss of control. Large models aren't traditional software; given inputs don't always produce deterministic outputs, and behavior can be induced by prompts, toolchains, and context. The material mentions enterprise SaaS integrations being attacked in early 2026, exploiting OAuth implementation flaws. This shares roots with traditional code vulnerabilities, but the amplification method differs: a hijacked agent can call APIs like a human, and it doesn't need sleep.

Traditional security assumes humans use tools; AI agents run at machine speed, making thousands of decisions per hour, and deploying anywhere developers push them.

This sentence is key. It pushes security from "are there vulnerabilities" to "who has the right to do what at what moment." This is what products like Raziel are truly worth watching. Not making another log dashboard, but providing an auditable authorization layer before agents call tools, read files, access databases, or send requests.

The "emergent authority" mentioned in the report—I understand it not as static roles, but as permissions that grow temporarily for each task. If the authorization layer is only post-hoc auditing, its value is limited. What's truly valuable is pre-emptive blocking.

Control Points Are More Valuable Than Models

From a competitive landscape perspective, the ceiling for this track depends on who owns the control points. Cloud vendors can do it, identity vendors can do it, and model vendors can do it. I've used edge-side models and browser plugins for a while. Recently, using Astra and LiST for retrieval and event extraction, the deeper I go into real business, the more I worry about permissions: an agent that can read local databases and send data externally—if something goes wrong, it's not just leaking summaries, it's completing actions for attackers. Independent vendors doing only prompt filtering have a low ceiling; only if they form a closed loop of runtime interception, dynamic permissions, and compliance evidence will they have pricing power.

On business models, I tend to shift from charging per seat to charging per controlled action. Enterprises won't pay a premium long-term for "more security," but they will pay for daring to go to production. A few days ago when I wrote about Kingspan issuing bonds, my core judgment was that capital is starting to price certainty assets. For AI applications to scale, electricity and facilities are hard constraints, and permission governance is also a hard constraint. If security products can reduce compliance uncertainty, they may transform from cost centers into admission conditions.

However, risks are obvious. AI security is easily packaged as the CrowdStrike of the LLM era, with valuations maxed out first, while revenue hasn't crossed the procurement threshold. Whether customers buy depends not on attack demos, but on false positive rates, latency, and whether audits pass internal reviews. Especially in finance, healthcare, and government/enterprise sectors, they prefer slower but explainable solutions. The winner in this track might not be the one best at explaining models, but the one best at understanding processes and evidence chains.

Looking ahead, if AI security eventually becomes the default control plane for cloud and model vendors, how much valuation premium will remain for independent vendors?


📌 This article is compiled from Hacker News. Original: https://thenewstack.io/tide-raziel-emergent-authority/

Copyright belongs to the original authors. This is a compilation and independent analysis based on public reports.

1 replies

?
Ctrl + Enter to reply
Independent Pan

Lol, I thought the same way initially, only to be taught a harsh lesson by reality. When I was using Cursor, I discovered that once an agent could call APIs on its own, the loss of control over those "never-sleeping" permissions was the real nightmare...