AI Platform Security: The $32B Category That Doesn't Exist Yet — But Three Breaches Just Proved It Must
The Category Formation Event
Three events in a single intelligence cycle prove that enterprise AI platforms are catastrophically insecure — and no vendor owns the solution. McKinsey's internal AI platform Lilli was breached by CodeWall's autonomous AI agent via basic unauthenticated SQL injection, exposing 46.5 million chat messages, 728,000 sensitive files, and McKinsey's entire proprietary RAG knowledge base in two hours. Perplexity's Comet AI browser was weaponized for phishing in under 4 minutes, proving that machines — not humans — are the new phishing target. And n8n's workflow automation platform landed on CISA's Known Exploited Vulnerabilities catalog with 24,700 exposed instances.
If McKinsey — with unlimited resources and reputational stakes — shipped an AI platform with 2005-era SQL injection, the base rate for enterprise AI security posture is catastrophically low.
The Insurance Demand Catalyst Changes Everything
Simultaneously, cyber insurers began bifurcating premiums based on how organizations deploy AI. Companies using AI defensively get lower premiums; those whose AI deployment introduces attack surface face surcharges. This is the first time AI security has a CFO-visible, dollar-denominated ROI beyond vague risk reduction narratives. The analog is SOC 2 compliance creating Vanta and Drata — whoever builds the AI governance-to-insurance-premium workflow owns a new multi-billion-dollar GRC category.
Google's $32B Wiz acquisition closes the cloud security era at peak multiples. But the McKinsey breach proves Wiz doesn't cover AI-native vulnerabilities: prompt injection, RAG data poisoning, agentic permission escalation, and apparently basic SQLi on brand-new AI platforms. The attack surface has shifted; the defenders haven't followed.
Competitive Landscape: Zero Incumbents
| Category | Status | Investment Timing |
|---|---|---|
| AI Application Security | Greenfield — no dominant player | Series A sweet spot NOW |
| AI Governance for Insurance | Pre-category — emerging wedge | Seed to Series A |
| Autonomous Red-Teaming | CodeWall validated category | Pre-consensus window open |
| AI Agent Sandboxing | No mature product exists | Category creating in real-time |
The autonomous red-teaming angle deserves attention: CodeWall chained four low-severity bugs into admin-level access on a live platform, demonstrating AI can replace the $2B+ human-dependent pen testing market with SaaS-margin economics. And New York enacted first-in-nation OT cybersecurity regulations for water utilities — a regulatory template that will cascade to other states, expanding the OT security TAM further.
Where This Goes Wrong
AWS expanded Security Hub to multicloud operations this cycle, which threatens standalone CSPM/CNAPP vendors. If hyperscalers extend bundling into AI security, the window for startups narrows. The race is between category formation speed and platform commoditization — bet on teams that can own a vertical wedge (healthcare AI security, financial AI compliance) before the platforms generalize.
What to do
Source 3-5 Series A deals in AI application security — companies building prompt injection defense, RAG access control, and agentic permission systems
Map the AI-governance-to-insurance-premium workflow as a thesis; identify seed-stage companies with insurance industry GTM DNA
Push security advisory to all portfolio CTOs: audit any enterprise AI platform for basic web app vulnerabilities (SQLi, auth bypass) this week
Stress-test any CSPM/CNAPP portfolio positions against AWS Security Hub multicloud expansion — model 20-30% TAM compression scenario