Security's Hottest New Market Is Bot Management in a Mirror
In the first week of August, investors put $270 million into companies that protect AI agents. Three rounds in five days. Two weeks later, Fortinet bought a fourth company, Virtue AI, outright. The coverage calls agent security a brand-new market, born with the agents. This is not a new market. It is bot management held up to a mirror. The same five functions and the same telemetry, sold to the opposite side of the same connection, with a single acquirer already on both lists. The mirror is even consolidating the way bot management did, only faster.
I run a data collection company, so I have spent years on one side of this glass. Bot management is the industry my crawlers meet at the front door: the wall that decides whether the machine gets the page. The first long piece on this site priced that wall. What just got funded is the same inspection, facing the other way.
What the wall does, read backward
Strip any bot-management product to its functions and you get five verbs. It fingerprints the visitor. It scores the visitor's intent. It challenges what it distrusts. It throttles what it tolerates. It logs everything for the site's security team. The customer is the website. The threat walks in from outside, and on a defended site that threat is my crawler.
Now strip Zenity, the company that raised $125 million on August 3. Its platform watches an enterprise's AI agents and, in its own words, identifies what an agent is attempting to do, then allows, modifies, or blocks the action before it happens. It scans the content the agent reads and scores the page's intent. It gates the risky action, caps what the agent can spend or delete, and logs the session for the owner's security team. The same five jobs. The customer is the visitor's owner. The threat is the page.
For twenty years the dangerous party on a web connection was the automated visitor, because automation carried scale. An AI agent flips that. It carries its owner's logins, spending power and mailbox into whatever page it reads. In April, Forcepoint researchers found ten indirect prompt-injection payloads live in the wild: instructions hidden in web content, waiting for an agent to ingest them. One aimed at file destruction. One tried to exfiltrate API keys. One embedded a PayPal link with a fixed $5,000 amount, which the researchers called a weaponized payload intended for immediate execution, not a probe. At Black Hat two weeks ago, every AI browser analyzed fell to exactly this class of attack.
View data table
| Side | Step | Function |
|---|---|---|
| The wall (sold to the website) | 1 | Fingerprint the visitor at the door |
| The wall | 2 | Score the visitor's intent |
| The wall | 3 | Challenge what it distrusts |
| The wall | 4 | Throttle what it tolerates |
| The wall | 5 | Log the session for the site's security team |
| The mirror (sold to the agent's owner) | 1 | Scan the content the agent reads |
| The mirror | 2 | Score the page's intent |
| The mirror | 3 | Gate the risky action |
| The mirror | 4 | Cap what the agent can spend or delete |
| The mirror | 5 | Log the session for the owner's security team |
The money knows this shape
Zenity: $125 million, led by Norwest, on August 3. Obsidian Security: $85 million the next day, at a $1.1 billion valuation, for securing non-human identities and AI agents across third-party apps. A third company, Oligo, closed $60 million that week on an AI-attack story. Black Hat ran in the middle of that week and supplied the demand thesis on stage. Then on August 17, Fortinet, a firewall company, skipped the venture round and bought Virtue AI. Virtue's platform attacks its customers' AI systems with a catalog of more than a hundred attack algorithms, then shields them against what it finds. Fortinet's announcement leans on a Gartner figure: securing AI ecosystems and agents is a $2.8 billion market this year, headed for $16.4 billion by 2030.
View data table
| Date | Event |
|---|---|
| Aug 3 | Zenity raises a $125M Series C, led by Norwest |
| Aug 4 | Obsidian Security raises $85M at a $1.1B valuation |
| Aug 3-8 | Three agent-security rounds (Zenity, Obsidian, Oligo) close $270M in five days |
| Aug 5-6 | Black Hat: every AI browser analyzed falls to indirect prompt injection |
| Aug 17 | Fortinet buys Virtue AI; its release cites Gartner: $2.8B market in 2026, $16.4B by 2030 |
Distil Networks, founded 2011, led the bot-management market. Imperva, an application-security platform, absorbed it in June 2019. Shape Security, also founded 2011, defended the biggest banks and airlines from bots that try stolen passwords at scale. F5, the application-delivery company, paid about $1 billion for it in December 2019. PerimeterX, the last big independent, merged into HUMAN in July 2022. Each ended up a feature of a platform that already sat in the traffic path.
The mirror is running the identical arc, faster. Protect AI, founded 2022, went to Palo Alto Networks in 2025, at a reported $650 to $700 million. Prompt Security went to SentinelOne that August. CalypsoAI went to F5 in September, for $180 million. Lakera, founded in Zurich in 2021, went to Check Point days later, at a reported $300 million. Fortinet took Virtue AI this month. The wall generation took eight years from founding to absorption. The mirror generation is taking three.
View data table
| Vendor | Founded | Outcome | Date | Price |
|---|---|---|---|---|
| Distil Networks | 2011 | Acquired by Imperva | Jun 2019 | Undisclosed |
| Shape Security | 2011 | Acquired by F5 | Dec 2019 | ~$1B |
| PerimeterX | — | Merged into HUMAN | Jul 2022 | Merger |
| Protect AI | 2022 | Acquired by Palo Alto Networks | Jul 2025 | ~$650-700M reported |
| Prompt Security | — | Acquired by SentinelOne | Aug 2025 | Undisclosed |
| CalypsoAI | 2018 | Acquired by F5 | Sep 2025 | $180M |
| Lakera | 2021 | Acquired by Check Point | Sep 2025 | ~$300M reported |
| Virtue AI | — | Acquired by Fortinet | Aug 2026 | Undisclosed |
One name sits on both lists, and it is the tell. F5 bought Shape, the wall, for a billion dollars in 2019. F5 bought CalypsoAI, the mirror, for $180 million in 2025, and now sells it as AI Guardrails. One company, one traffic path, inspection billed in both directions. Cloudflare is assembling its own both-sides position around its agent browser, where prompt-injection defense is named a top design priority. Nobody disrupted the wall vendors here. They are buying the mirror because it runs on what they already own: the session, and the question of what the machine on the wire intends.
Price it like the last war
If you are valuing an agent-security startup, the flattering comp is endpoint security, a category that produced giant standalone public companies. The evidence says the comp is bot management. That was a working market with real revenue, and it never produced an independent public company among the leaders named here. Across the two waves, the disclosed exits run from $180 million to about $1 billion. A $16.4 billion Gartner forecast does not change who ends up owning the revenue; in 2019 the wall's forecasts were real too, and Imperva and F5 collected them.
So my falsifiable read: the mirror produces no standalone public company. By the end of 2028, the leading independents, today's Zenity and Obsidian among them, sell to platforms that already carry the traffic. Or the platforms bundle the mirror around them, the way they bundled the wall. I am wrong if one of them files for an IPO by then, or if the independents still set the category's terms in 2029 while the platforms' bundled versions stall.
The payloads are live in the wild, the browsers keep falling to them, and the agents keep shipping with logins in hand. What the mirror industry sells is necessary. So was the wall, and the wall still ended up inside the platforms. F5 has already paid for both sides of the glass. Watch for the second such buyer: the day a CDN or a dedicated bot-management vendor buys one of the remaining independents, the mirror stops being a market and becomes what the wall became, a feature.