AI Agent Security Becomes Enterprise M&A's Next Battleground
Kiteworks acquires Bonfy.AI and Blackstone leads Huskeys' $27M round as agent security splits into distinct control points, redrawing the cybersecurity M&A map.
By Daniel Okafor
2 min read
Updated

What's News
- Kiteworks acquired Israeli startup Bonfy.AI, which focuses on real-time data classification and policy enforcement.
- Israeli cybersecurity startup Huskeys raised a $27 million Series A led by Blackstone to secure complex internet traffic, including from autonomous systems.
- Itay Sagie argues 'AI security' is already too broad a positioning; value will concentrate in specific control points like agent identity, data access, prompts and auditability.
Kiteworks has acquired Israeli startup Bonfy.AI, a company focused on real-time data classification and policy enforcement, in one of the first deals signaling that AI agent security is becoming a distinct M&A category.
The logic behind the deal is straightforward. AI agents are spreading through the enterprise fast. They browse the web, write code, access files, trigger APIs and interact with internal systems. That creates enormous productivity potential, but it also creates a new security problem: companies now need to protect not only users, devices and applications, but software actors that can take actions on their behalf.
Agents are a new class of enterprise identity
An agent may access corporate files, query databases, send emails or execute code. Once it has that level of access, it needs permissions, monitoring and governance. Companies will need to know which agent accessed what information, which systems it connected to, and whether the actions it took were authorized.
As enterprises move from experimenting with a few agents to deploying hundreds of them, agent identity will become another important layer of cybersecurity. The challenge is that these identities are not passive. Agents can move between systems, invoke tools and make decisions, which makes controlling them more complex than managing traditional users or service accounts.
The value will sit in specific control points
According to Itay Sagie, a strategic adviser to tech companies, investors, CEOs and boards who analyzed the trend for Crunchbase News, this market will probably not develop as one broad category called "AI security." The real opportunity will be around specific control points.
One company may protect agent identity, another may control the data an agent can access, while others may focus on prompts, MCP servers, plug-ins, traffic or auditability.
The market is already moving on these fronts. Beyond the Kiteworks–Bonfy.AI transaction, Israeli cybersecurity startup Huskeys raised a $27 million Series A led by Blackstone. Huskeys focuses on understanding and securing increasingly complex internet traffic, including traffic generated by autonomous systems.
These companies are solving different problems, but together they show how the market may begin to separate into distinct security layers.
Control points are creating a new M&A map
The acquisition logic extends across the security stack. Identity providers may extend identity governance to autonomous agents. Data-security vendors may need to control what information agents can access. Cybersecurity platforms, cloud companies and enterprise software vendors may eventually need agent-security capabilities embedded directly into their products.
For entrepreneurs, Sagie argues, this means that "AI security" may already be too broad a positioning. The more important question is what exactly the company controls.
For buyers and investors, the implication is equally concrete: the next wave of cybersecurity consolidation is likely to target narrow agent-security control points rather than generalist platforms, and early movers like Kiteworks and Blackstone have already started placing their bets.
Original: crunchbase.com
More from Daniel Okafor
Show full bio
Correspondent covering business strategy at Business Bearings.
234 articles