VCs say AI agents need 'the next Okta' for security

VCs say AI agents need 'the next Okta' for security

Matt Hartman, chief strategy officer at cybersecurity investor Merlin Group, and Todd Graham, managing partner at Microsoft's venture arm M12, told The Register that security has been an afterthought as companies rush to deploy AI agents, and that the resulting gaps are a major opening for new startups. The piece points to what it describes as a rise in agents "hacking organizations and people" and other agent-related security mishaps, though it does not name or describe any specific incident.

Graham frames the problem as a repeat pattern: "Every time we've built a new piece of infrastructure, we've conveniently forgotten the security," he said. He traces a lineage of security vendors born from that same gap: CrowdStrike from insecure laptops, Wiz from insecure cloud, and Okta and various Active Directory add-ons from insecure identity. With AI, he said, "a lot of ships are going to rise with this tide." What is different this time, he added, is speed: companies took years to adopt cloud, but organizations are now putting agents into production with access to critical data and systems "month over month", faster than they can manage, secure or even identify those agents.

Hartman, who spent years in federal cybersecurity including senior roles at the US Cybersecurity and Infrastructure Security Agency before joining Merlin, said his firm is focused on the security layer that governs agent behavior: identity for non-human actors, clear limits on what they can access and do, and an audit trail for their actions. Government agencies, he said, are not just asking how to adopt agents but how to constrain them and prove what one did at 2 AM on a Tuesday. Both investors cautioned that a good idea alone will not be enough: because AI has made software cheaper and faster to build generally, they said, the bar for differentiation keeps rising, and founders who can pair a strong product with a real route to market have the actual opportunity.

Graham said end users are already looking for agentic-identity and governance products and predicted "someone is going to build the next Okta, just as SaaS generated Okta." But he said many current founders are "thinking way too small", solving only "a sliver of the problem" when a chief information security officer at a large company wants one system covering governance, access control and authorization together, rather than buying fifteen separate tools. He noted that securing non-human identities is already hard even without agents: service accounts are a common attack target because of their high privileges and passwords that never expire.

Beyond identity, Graham pointed to "AI endpoint security", which he compared to CrowdStrike for AI, as a second opportunity he called ripe for a founder. He said he would want to build it himself if he were not, in his words, "banned from starting any more companies", a remark the article leaves unexplained. He predicted that once a breached company is hauled before Congress and asked why it lacked antivirus or endpoint detection and response tools, AI endpoint protection will quickly be added to that same list of expected controls. Existing endpoint and antivirus vendors, he said, "will absolutely" build competing products, even as the shift disrupts vendors that already have other commitments to work through.

Graham said he is "worried" about recent real-world bad behavior by AI agents and is "very concerned" about where things end up if agents are left to their own devices, though he said he is comforted by having watched security scramble to catch up with new infrastructure before. He also said he was "pleasantly surprised" by Anthropic CEO Dario Amodei's essay "We Must Pace the Frontier" and does not view it as a cynical move to dodge antitrust scrutiny. "We've kicked the security can down the road long enough," he said, "and now we need to solve it."

Key facts

  • Matt Hartman, chief strategy officer at Merlin Group, and Todd Graham, managing partner at Microsoft's M12 venture fund, told The Register that AI agents' security gaps are a major opportunity for startups.
  • Graham argues every infrastructure wave initially skipped security and later produced dedicated vendors: CrowdStrike for laptops, Wiz for cloud, Okta and Active Directory add-ons for identity.
  • Graham predicts someone will build "the next Okta" for agentic identity and governance, but says many founders are solving only a sliver of the problem when CISOs want one unified system.
  • Graham also flags "AI endpoint security", the equivalent of CrowdStrike for AI, as a second opportunity, predicting it becomes a standard control once a breached company is questioned by Congress.
  • Graham says he was "pleasantly surprised" by Anthropic CEO Dario Amodei's essay "We Must Pace the Frontier" and does not read it as an attempt to dodge antitrust scrutiny.

Why it matters

AI agents are being plugged into production systems with access to sensitive data faster than organizations can identify, govern or secure them, echoing how laptops, the cloud and digital identity were all adopted before their security markets existed. If the pattern holds, as it did for CrowdStrike, Wiz and Okta, agent security becomes the next standalone product category rather than a feature bolted onto something else.

Who it affects

Security-focused venture funds and the founders they back stand to gain from a new wave of investment in agentic-identity and AI-endpoint-security startups. Enterprise security teams and CISOs face pressure to govern non-human agent identities that already have broad system access, and incumbent endpoint and antivirus vendors will need to extend their products to cover AI agents or risk being displaced by newcomers.

How to use it

For founders, the piece is effectively a warning against building a narrow point tool: Graham says CISOs will not buy fifteen separate products to cover pieces of agent governance, so a viable product needs identity, access control, authorization and an audit trail together. For security teams, the near-term move is to treat AI agents as non-human identities requiring the same discipline already owed to service accounts, whose high privileges and never-expiring passwords already make them common attack targets.

How solid is it

This is an opinion and analysis piece built from two on-record interviews, not a report on a specific verified incident: Hartman and Graham are named with their actual titles at Merlin Group and Microsoft's M12 fund respectively, and quoted directly by The Register's Cybersecurity Editor. It cites a rise in agents "hacking organizations and people" without naming or dating a single example, and the headline's "billion-dollar" framing is not backed by any dollar figure, valuation or market-size estimate anywhere in the article. Both sources are also venture investors describing the market they invest in as the next big opportunity, which is worth weighing.

Risks and caveats

The claimed increase in agent security incidents is asserted, not documented, in the source. Todd Graham's remark that he has been "banned from starting any more companies" is left unexplained, with no reason or authority given. Read the piece as an investor thesis rather than a market forecast: it names no dollar figures, no specific startup and no timeline for when agentic-identity or AI-endpoint-security products might actually reach the market.

“If laptops were default secure, we wouldn't have CrowdStrike. If the cloud was default secure, we wouldn't have Wiz. If identity wasn't default secure, we wouldn't have a bunch of Active Directory add-ons and Okta.”

— Todd Graham, managing partner at Microsoft's M12 venture fund