Contact →
The Blog
The 144:1 Problem: Why AI Agent Security Is Enterprise Tech's Next Trillion-Dollar Category

The 144:1 Problem: Why AI Agent Security Is Enterprise Tech's Next Trillion-Dollar Category

Non-human identities now outnumber human identities 144-to-1 in enterprise applications. The companies deploying AI agents fastest may not be the winners.

The 144:1 Problem: Why AI Agent Security Is Enterprise Tech's Next Trillion-Dollar Category

Inside the average enterprise application, non-human identities now outnumber human identities by a ratio of 144 to 1. That statistic, revealed by Obsidian Security following its recent $85 million Series D raise at a $1.1 billion valuation, represents one of the most underappreciated shifts in enterprise technology. While executives debate AI strategy in boardrooms, autonomous agents have already infiltrated their tech stacks, modifying data in Salesforce, sending messages in Slack, and querying databases in Snowflake without a single human clicking a button.

The funding itself tells part of the story. Over just a few weeks, three major rounds totaling $323 million closed in what investors are calling "agentic security." Obsidian raised $85 million led by Crescent Cove Advisors. Zenity secured $125 million. Onyx Security brought in $113 million. Venture capital rarely moves this fast unless investors see a category forming in real time.

But Matt Britton argues the real story extends beyond the capital deployment. According to Obsidian's customer data, over 65% of large enterprises have already given AI agents direct access to data inside third-party SaaS applications. These agents are no longer experimental copilots offering suggestions. They are executing actions autonomously, creating, modifying, and yes, deleting business data without human approval for each transaction.

This creates what Britton calls the governance gap. Companies are deploying AI agents at a pace that far outstrips their ability to govern what those agents actually do. Traditional identity and access management was built for humans who log in, authenticate, and follow predictable patterns. AI agents operate differently. They spawn sub-agents, chain together actions across multiple applications, and often inherit permissions that were never explicitly granted. The security models of the last two decades simply were not designed for this reality.

The winners in AI adoption, Britton contends, will not necessarily be the companies that deploy agents fastest. They will be the organizations that figure out how to let agents act autonomously while maintaining genuine control over what those agents do with business-critical data. Speed without governance is a liability waiting to materialize.

The Emergence of Agentic Security as a Category

Enterprise cybersecurity has evolved through distinct eras. The perimeter era focused on firewalls and network boundaries. The cloud era brought identity management and zero-trust architectures. Now, as Matt Britton has explored in discussions on the Speed of Culture podcast, we are entering the agentic era, where software acts on behalf of humans without direct oversight.

The term "agentic security" barely existed eighteen months ago. Today, it describes an emerging category of tools designed to monitor, govern, and secure AI agents operating inside enterprise environments. The challenge is fundamentally different from traditional security:

Obsidian Security's customer base reflects the urgency. The company now counts over 100 customers spending more than $100,000 annually, with 14 customers exceeding $1 million in annual spend. Fortune 500 companies including T-Mobile, Workday, and S&P Global are among those investing heavily in agentic security solutions.

The speed of adoption signals something deeper than typical enterprise software cycles. When companies that historically take 18 months to evaluate new security categories are deploying solutions within quarters, it suggests genuine fear about what might happen if they wait.

Why Traditional Security Fails Against Non-Human Identities

The 144-to-1 ratio of non-human to human identities inside enterprise applications exposes a fundamental assumption embedded in most security architectures: that humans are the primary actors requiring protection and monitoring.

Consider how identity and access management (IAM) systems have historically worked. A human employee is provisioned with credentials. Those credentials are tied to roles and permissions. The employee authenticates, often through multi-factor verification, and then accesses applications according to their assigned privileges. Security teams monitor for anomalous behavior, such as logins from unusual locations, access outside normal hours, or attempts to reach restricted resources.

AI agents break this model at nearly every point:

Matt Britton has written extensively about how Generation AI will reshape consumer behavior and business models. The agentic security challenge represents the enterprise version of this shift. Just as consumers are learning to interact with AI in new ways, enterprises must learn to govern AI in ways that did not previously exist.

The risk is not hypothetical. In conversations with enterprise CISOs, Britton consistently hears about incidents where AI agents took actions that, while technically authorized, produced business outcomes no human intended. A marketing automation agent that deleted a segment of customer records. A financial analysis agent that shared confidential projections with an external tool. An HR agent that accessed performance reviews beyond its intended scope. These are not attacks by malicious actors. They are governance failures in systems operating exactly as programmed.

The Governance Gap and Its Business Implications

The governance gap, the distance between how fast companies deploy AI agents and how well they control those agents, has become one of the defining challenges of enterprise technology in 2026. Matt Britton sees this gap as the key factor that will separate successful AI adopters from cautionary tales.

Several dynamics are widening this gap:

Competitive pressure accelerates deployment. When competitors announce AI-driven productivity gains, boards and executive teams demand similar capabilities. This pressure often bypasses the governance processes that would normally accompany new technology adoption. Shadow AI, agents deployed by business units without IT approval, has become as pervasive as shadow IT was a decade ago.

Vendors embed agents without explicit consent. Many SaaS applications now include AI agent capabilities enabled by default. Enterprises that thought they were evaluating whether to adopt AI agents discover those agents are already operating inside tools they already use. The decision was made for them.

Governance frameworks lag reality. Most enterprise governance policies were written for a world where humans initiate all consequential actions. Updating these frameworks to address autonomous agents requires legal, compliance, security, and business unit coordination that moves slowly while agent deployment moves fast.

The business implications extend beyond security. As Britton has discussed in his AI keynotes, organizations face regulatory scrutiny, customer trust erosion, and operational disruption when AI agents produce unintended outcomes. The European Union's AI Act and emerging US frameworks explicitly address automated decision-making. Companies that cannot demonstrate governance over their AI agents may face compliance penalties that exceed the productivity gains those agents provide.

Investment in agentic security is, in this context, not merely defensive. It is a prerequisite for aggressive AI adoption. The companies best positioned to deploy agents at scale will be those that have solved the governance problem, allowing them to move fast precisely because they have controls in place.

What the Funding Wave Signals for Enterprise Tech

Three agentic security companies raising a combined $323 million within weeks is not a coincidence. It reflects a venture capital consensus that this category will be large, that it is forming now, and that early leaders will capture durable market position.

Several patterns in this funding wave deserve attention:

Valuations suggest category creation, not point solutions. Obsidian's $1.1 billion valuation indicates investors see potential for platform-scale outcomes, not niche security tools. The bet is that agentic security becomes as foundational as endpoint protection or cloud security, categories that support multiple billion-dollar companies.

Customer concentration favors specialists. Obsidian's 14 customers spending over $1 million annually suggests enterprises are willing to pay significant premiums for specialized agentic security. This spending level typically indicates strategic vendor relationships rather than experimental pilots.

Fortune 500 adoption signals mainstream readiness. When T-Mobile, Workday, and S&P Global invest in a category, it suggests the technology has matured beyond early-adopter risk tolerance. These companies have rigorous vendor evaluation processes and conservative security postures. Their adoption provides validation that other large enterprises will follow.

Matt Britton anticipates that agentic security will spawn adjacent categories as well. Agent observability, the ability to understand what agents are doing in real time, will become its own market. Agent orchestration, coordinating multiple agents while preventing conflicts and redundancies, presents another category opportunity. Agent insurance, covering organizations against losses from agent misbehavior, may emerge as adoption scales.

The investors backing these companies are betting that AI agents represent a permanent shift in how enterprise software operates, not a temporary trend that will fade. If they are right, the companies that define agentic security standards will hold significant leverage in the broader AI ecosystem. As Britton explores through Suzy, understanding emerging technology trends requires looking beyond the immediate application to see how new capabilities reshape entire market structures.

Building for a 144:1 World

The 144-to-1 ratio of non-human to human identities will only grow. Every AI copilot, automation workflow, and intelligent integration adds to the non-human population inside enterprise systems. Within three years, that ratio could reach 500 to 1 or higher in technology-forward organizations.

Enterprises preparing for this reality should consider several strategic shifts:

The opportunity, as Matt Britton frequently emphasizes, is that organizations who solve the governance challenge will be able to deploy AI more aggressively than competitors who remain constrained by fear. Governance is not the enemy of innovation. It is the foundation that makes aggressive innovation possible without existential risk.

Key Takeaways

Frequently Asked Questions

What is agentic security?

Agentic security refers to an emerging category of cybersecurity tools designed to monitor, govern, and secure AI agents operating inside enterprise environments. Unlike traditional security focused on human users, agentic security addresses the unique challenges of autonomous software that can act on data without direct human oversight.

Why do non-human identities outnumber human identities so dramatically?

Every AI agent, automation workflow, API integration, and service account creates a non-human identity. A single employee might interact with dozens of systems, each of which may have multiple automated processes and AI capabilities running constantly. This multiplier effect causes non-human identities to vastly exceed human headcount.

How should enterprises start addressing AI agent governance?

Enterprises should begin by inventorying what AI agents currently operate inside their environment, as many discover agents they did not know existed. From there, establishing clear ownership, permission policies, and audit requirements for each agent provides the foundation for ongoing governance.

Will traditional IAM vendors expand to cover agentic security?

Traditional identity and access management vendors will likely add agentic capabilities, but purpose-built solutions may have advantages in the near term. The architectural assumptions underlying traditional IAM differ significantly from what agent governance requires, making full platform rebuilds challenging for established vendors.

The ratio of 144 to 1 is not just a statistic. It represents a fundamental reordering of how enterprise technology operates. Matt Britton argues that executives who grasp this shift will position their organizations for competitive advantage, while those who ignore it will face compounding governance debt that eventually demands payment. The race to deploy AI agents is well underway. The race to govern them is just beginning, and that second race will determine which organizations capture lasting value from their AI investments. For leaders navigating this transition, understanding both the opportunities and risks requires continuous engagement with how these technologies evolve. Learn more about bringing these insights to your organization at Matt Britton's Speaker HQ.

Tagged

Want Matt to bring these insights to your next event?

Matt delivers high-energy keynotes on AI, consumer trends, and the future of business to Fortune 500 audiences worldwide.

Book Matt to Speak →