Three acquisitions define the 2026 shape of the AI agent security market: Cato Networks buying Aim Security, Palo Alto Networks buying Protect AI, and Cisco buying Robust Intelligence. Each folds a point-solution AI-security vendor into a larger platform. If you are shortlisting vendors right now, the practical question these deals raise is not "which platform is best" — it is "what happens to the product I am evaluating in 12-18 months, and does that change my decision."
The three deals
Cato Networks acquired Aim Security, announced in September 2025, with integration into Cato's SASE Cloud targeted for early 2026. Cato's own announcement frames the deal as extending its SASE platform to cover enterprise AI transformation and secure adoption of AI tools, and reporting at the time noted the deal pushed Cato past $300M in annual recurring revenue. Aim Security, which had been a named agent-native security vendor with capabilities spanning AI discovery, posture management, and automated red-teaming, is being absorbed as a capability inside a broader network-security platform rather than continuing to sell as an independent product.
Cisco acquired Robust Intelligence, a vendor focused on AI model validation and security testing, and Palo Alto Networks acquired Protect AI. Both deals are cited in market coverage as moves toward unified AI security platforms — established network and endpoint security vendors absorbing AI-specific capability rather than customers assembling AI security from a standalone specialist alongside their existing platform vendor.
The pattern across all three deals is the same shape even though the acquirers come from different starting platforms (SASE, network security, cloud security): a large, already-established security vendor buys a smaller AI-native specialist and folds its capability into an existing platform surface, rather than the specialist scaling to platform breadth on its own. That is a familiar consolidation pattern in security markets generally, and it has a specific implication for the evaluation checklist below: the capability you are buying (continuous testing, red-teaming, runtime protection) tends to survive the acquisition; the standalone product experience and independent roadmap around it tend not to.
What the broader activity looks like
Beyond the three named deals, reporting tied to RSAC 2026 (held March 10-26, 2026) described a broader wave of capital movement into agentic-AI-security: roughly $3.6B in cumulative Crunchbase-tracked funding into agentic-AI-security startups, about $96B in M&A activity, and roughly $392M in new funding announced around the conference window alone. Treat these as reported aggregate figures from that coverage, not as this post's own research — the exact methodology behind "agentic-AI-security" as a funding category varies by source, and the numbers are a snapshot of a fast-moving market rather than a stable baseline.
Why acquisitions change the buying calculus
An acquisition does not necessarily make a product worse, but it changes several things a buyer should weigh independently of the product's current capability:
Roadmap continuity. A newly acquired product's roadmap typically shifts to align with the acquirer's platform priorities. Features the standalone vendor had planned may be deprioritized, accelerated, or dropped depending on how they fit the parent platform's direction — and that direction is set by a company you were not originally evaluating.
SKU and pricing stability. Acquired products are frequently repackaged — bundled into a platform tier, folded into an existing SKU, or eventually retired as a standalone purchase. A price and packaging model you locked in during evaluation may not exist in the same form a year later.
Support and product-team continuity. Post-acquisition, the team that built the product's institutional knowledge may partially or fully turn over as integration proceeds. This is not universal — some acquirers deliberately retain founding teams — but it is common enough to weigh, and worth asking about directly during evaluation rather than assuming either outcome.
Integration timeline risk. The gap between "acquisition announced" and "capability fully integrated into the parent platform" is commonly 6-18 months in this category, based on the announced timelines above (Cato's stated early-2026 target against a September 2025 announcement, for example). During that window, the product may be in a state of reduced investment as engineering attention shifts to integration work rather than net-new capability.
How to evaluate a shortlist candidate for acquisition risk
| Question | What it tells you |
|---|---|
| Is the vendor independently funded, or already inside a larger platform? | Independent vendors carry acquisition risk going forward; already-acquired vendors carry integration risk now |
| If already acquired, is the integration timeline public and has it passed? | A completed integration is more predictable than one still in progress |
| Does the acquirer's own public roadmap mention this capability, or is it silent? | Silence is a signal to ask directly, not to assume continuity |
| Can you get contractual protection (price lock, feature commitments) through the transition period? | Contract terms are a more reliable safeguard than a roadmap slide |
| Would you still choose this vendor if it were absorbed into the acquirer's platform tomorrow? | Separates "I want this specific point product" from "I want this specific capability, wherever it lives" |
Point solution or platform-bundled: a related but separate question
Consolidation raises but does not answer a related question many buyers are also working through right now: whether to evaluate agent-native pure-play vendors or platform-bundled AI-security capability from an incumbent vendor you already run. That is a distinct decision from the acquisition-risk question above — a platform-bundled option can carry its own version of roadmap risk (deprioritized relative to the platform's other priorities) even without a recent acquisition event, and the self-hosted versus managed governance trade-off compounds it further for teams weighing operational control against platform reuse. See build versus buy for AI agent governance for the adjacent question of whether to buy a vendor at all versus building the capability internally, and choosing an AI agent management platform for the broader vendor-selection process this fits into.
Building the questions into your RFP process
The acquisition-risk questions above are worth adding as standing items in whatever evaluation process you already run, not treated as a one-off exercise specific to this year's headlines. If you maintain a formal RFP or vendor-questionnaire process, the RFP checklist for AI governance platforms is a reasonable place to add them — ownership structure, funding stage, and roadmap-commitment questions belong alongside the functional and security requirements you are already asking about. Tying vendor-maturity questions to your broader AI governance maturity model also helps: a team early in its governance maturity has more flexibility to absorb a vendor transition than one with agent security workflows already deeply integrated into a specific product's specifics.
What this means in practice
None of this argues against buying a recently acquired product, or against buying from a vendor likely to be acquired later. Both are common, reasonable choices when the underlying capability fits your requirements. The practical adjustment is procedural: ask acquisition-risk questions explicitly during evaluation, get roadmap and pricing commitments in writing where you can, and revisit vendor relationships on a cadence that assumes the market keeps consolidating — because on the evidence of 2026 so far, it is.
Praesidia is an AI agent security and governance control plane — agent identity and access, guardrails, audit evidence, and cost controls in one place — and is itself one candidate in a market undergoing this consolidation; the evaluation questions above apply to us as much as to any other vendor on a shortlist. For the broader case on what a control plane in this category needs to cover regardless of vendor ownership structure, see the AI agent security guide.
Common questions
Does an acquisition mean I should avoid a vendor's product? Not automatically. Acquisitions are common in fast-growing categories and many integrations go well. The point is to evaluate the acquisition's specific terms and timeline rather than ignoring it, and to get commitments in writing on pricing and roadmap continuity where the deal is recent enough that integration is still in progress.
How long does integration typically take after an AI-security acquisition is announced? Based on the announced timelines in the deals above, roughly 6-18 months from announcement to substantial platform integration is a reasonable planning assumption, though actual timelines vary by deal and are worth confirming directly with the vendor rather than assumed from precedent.
Is Aim Security still available as a standalone product? As of the Cato Networks announcement, Aim Security's capability is being integrated into Cato's SASE Cloud platform rather than continuing to sell as an independent product — verify current packaging directly with Cato before assuming either the old or new state, since integration status changes over the timeline described above.
Should I wait for the market to finish consolidating before buying anything? Waiting has its own cost — unaddressed agent security risk in the meantime — and there is no clear signal the consolidation wave is close to finished. A more practical approach is buying for your current requirements with the acquisition-risk questions above built into the evaluation, rather than trying to time a moving market.
Does consolidation affect pricing? It can, in either direction — a larger acquirer may bundle a capability into an existing platform tier at effectively no incremental cost, or may reprice it as part of a broader platform contract that costs more than the standalone product did. This is a specific question to ask each vendor rather than something to assume from the deal type alone.
Is this consolidation specific to AI agent security, or part of a broader security-market pattern? The specific deals in this post are AI-security acquisitions, but buying smaller specialists and folding them into a broader platform is a long-standing pattern in security markets generally, not something unique to AI. What is specific to this moment is the pace: the funding and M&A figures cited above suggest the AI-security segment of that pattern is moving faster right now than security-market consolidation typically does, which is the practical reason to build acquisition-risk questions into your process now rather than treating it as background noise.