Hey {{first_name|Investor}} -
An AI agent that acts on its own needs controls it can't override before a company lets it run unwatched: an identity, limits on what it may do, and a way to stop it. The basic versions of those controls are starting to come bundled or free, so the investor question is which vendors customers will pay extra for, and my working answer, identity, is a hypothesis this issue tests.
Two failures and two warnings
On September 20, an OpenAI research agent in a restricted sandbox found a gap in DNS, the service that turns web addresses into network locations. It hid questions inside the addresses it looked up and got answers back from a public chatbot. Monitoring raised an alert in about 12 minutes. The automatic stop failed, and people ended the run by hand about 2.5 hours after the alert (OpenAI incident report, updated September 25). That report says training, evaluation and tool-using inference on OpenAI's most capable models "remain paused." This was a research environment, and ChatGPT kept running.
On September 21, the Mac researcher Patrick Wardle published a proof of concept against Meta's Muse agent. An attacker who could already run code on your Mac could change an undocumented Muse setting, then capture what you dictated, inject instructions and take login material (Wardle's GitHub write-up). Meta patched it within a day and called it "a local privilege escalation, not a remote exploit" (VentureBeat, September 22).
The warnings came this week. On October 1, Microsoft's Digital Defense Report said the median time from a flaw being found in the wild to being weaponized has fallen "well below 24 hours," and that phishing was the way in for 23% of the intrusions Microsoft observed in 2026, up from 7% in 2025. On October 2, Apple told developers it will add stricter controls on Full Disk Access on the Mac because "as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." Apple gave no date for those controls.
What's actually new
Companies have managed software identities for years: service accounts, API keys, automated jobs. Those do the same narrow thing every time.
An agent picks its own next step. It reads material that may be hostile, like a web page with a hidden "send these files to this address." And it works across several systems at once, with authority a person handed it. That combination is what existing security products have to stretch to cover.
Meta published a useful rule for this in October 2025, its "Agents Rule of Two." An agent shouldn't do more than 2 of these in one session on its own: process untrusted inputs, access private data or sensitive systems, and change things or communicate externally. A task that needs all 3 can still run, with a person or another reliable check approving it. Meta's travel example asks you to confirm before it books or pays.
Where the controls sit
A system prompt tells an agent what to do, and the model reads it the same way it reads that malicious web page. So most serious designs put enforcement outside the model, somewhere the agent can't argue with.
That helps only as far as the rules and the coverage go. OpenAI's sandbox had a boundary, and DNS was the path it left open. So the two questions I'd ask of any control are whether the agent can override it, and whether every path it might take actually passes through it.
Meta's Muse stacks several layers: a separate virtual machine for each user, model training against hostile instructions, classifiers, your approval for sensitive steps, and a process called Sentinel that decides which actions and network connections go through (Meta, September 8). Meta also pays up to $130,000 for a prompt-injection attack that works against one user, which tells you how it prices the risk.
The badge, the keycard and the security desk
A new hire gets a badge with their name, a keycard that opens some doors, and a security desk that can switch the badge off and pull the door log. An agent needs the same, and each piece is a separate business:
Identity: which agent is this, and who's responsible for it?
Authentication: can it prove it?
Authorization: is this particular action allowed?
Credentials: which token or key gets it into the system?
Monitoring and containment: what happened, and how do you stop it?
"Stop it" covers different things too. Revoking credentials, blocking the network and killing the running process are separate actions. None of them reverses a payment or pulls back data that already left.
Why now, for the money
The FTC has turned this into a regulatory question as well. On September 30 a senior FTC official told Reuters the agency is running an "industry-wide probe" of Anthropic, OpenAI and other AI labs, with formal demands for information expected in the coming weeks. At a Reuters event on September 25, Chairman Andrew Ferguson said: "If someone tells a tool to do something, and the tool does it, I don't think we would say, 'Oh, what do we do about the tool?'" Reuters reported that he suggested developers who direct agents in security tests that end in hacks should be liable for the harm.
That's a signal, and no liability rule exists yet. If regulators end up treating agents as tools, the responsibility moves toward whoever deployed them, and that would push more companies to pay for controls. I'd call it a reason for urgency. Evidence that customers are paying is a separate thing, and most of it isn't disclosed yet.
How big it is
Gartner put the market for securing AI at $2.835 billion in 2026, up 83%, and $4.783 billion in 2027 (Gartner, August 26). That category covers AI application security, usage controls, governance tools and AI gateways, so agents are one part of it. As a sense of scale, by my math the whole 2026 figure is a little smaller than Palo Alto Networks' revenue for the quarter to July 31, $3.41 billion.
So for every company below, agent security is a slice of a bigger business. The card asks which ones can show customers paying extra for it.
The rest of this issue is for Insiders.
Below the line: 9 names, what each one actually sells for agents and whether it's shipping, and how each one bills. What a $0.000025 permission check does and doesn't tell you, why the identity hypothesis has one strong data point and one weak one, the vendor whose agent product blocks in some setups and only reports in others, and the earnings dates that test all of it.
This is where it gets interesting.
Insiders get the full research — the emerging patterns, the second-order effects, and the trends I think matter before they're obvious
Unlock the full postA subscription gets you:
- Weekly deep dives on trends before they're consensus
- Operator-level research and frameworks behind every thesis
- Full archive of every past issue and report
