toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trading
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
To be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android app
More download options

Security teams shift focus to AI agents

2026-09-20 10:41

Enterprise security teams are preparing for a change in the threat model as AI agents gain access to the same internal systems used by employees, from SharePoint and SQL databases to code repositories and ERP platforms that can initiate payment approvals. The immediate concern is less about whether a model can generate accurate answers than whether an automated system, operating with valid credentials, can take actions outside the intent of its assigned task.

That is pushing security spending toward controls over identity, data access, and runtime behavior. A company may have correctly authenticated an AI agent, yet still face risk if the agent follows a malicious instruction embedded in a document, misuses a connected tool, or continues operating under permissions that no longer fit its assignment.

The emerging market is therefore centered on governing machine identities and monitoring agent activity after access has been granted. Vendors that once sold primarily endpoint, firewall, or identity products are adapting their platforms to answer three practical questions: what can an agent reach, what information can it retrieve, and what actions can it execute?

Security shifts from the network edge to agent actions

Traditional corporate defenses were designed around people, devices, and network boundaries. Firewalls filtered traffic entering and leaving networks, endpoint detection products watched laptops and servers, identity systems determined who could log in, and security operations centers investigated alerts.

AI agents blur those boundaries. They can authenticate into several systems in rapid succession, read a file repository, query a business database, modify a software project, and send instructions to a workflow tool. Each action may be permitted individually. The risk arises when their sequence produces an unintended result, such as exposing confidential data or approving a transaction that no human intended to authorize.

GuidePoint Security said in a September 2026 report that non-human identities outnumber human workers by as much as 75 to one in many enterprise environments. That total includes service accounts, bots, automated workloads, application credentials, and other machine-operated identities. The scale makes it harder for conventional controls to distinguish a legitimate automated task from suspicious behavior carried out through an authorized account.

The shift also changes the role of runtime controls. Rather than checking access only at the beginning of a session, companies are looking for ways to inspect what an agent attempts to do while it is operating. Such controls could block an agent from sending sensitive records to an unapproved destination, restrict high-risk commands, or require human approval before an automated workflow can make a consequential change.

Palo Alto Networks and CrowdStrike extend platform strategies

Palo Alto Networks is among the companies building a broad security platform around this model. Its portfolio now spans network protection, cloud security, security operations, identity-related capabilities, and AI security. Prisma AIRS is designed to cover models, data, AI applications, agents, and runtime controls, including an AI runtime firewall and red-teaming tools intended to test systems before deployment.

Palo Alto Networks reported revenue of $3.41 billion in its latest quarter, a 34% increase from a year earlier, including growth contributed by acquisitions. Its strategy places AI security inside a larger platform sale, which could appeal to companies seeking fewer vendors across cloud, network, and AI environments.

CrowdStrike is approaching the agent problem from its established position in endpoint telemetry. The company is extending its coverage into the execution layers where agent activity ultimately takes place: employee devices, servers, containers, cloud workloads, and identity systems. That strategy emphasizes visibility into the actual process or workload performing an action, rather than only the model generating the instruction.

CrowdStrike reported 26% year-over-year revenue growth and a 25% increase in annual recurring revenue in its latest quarter. Its expansion into identity, cloud, runtime, and security operations products gives it multiple ways to attach agent controls to existing deployments, though the company will need to show that these products can protect automated workflows as effectively as they have protected endpoints.

SentinelOne is taking a related approach at a smaller scale. Its Purple AI product is focused on automating portions of the security analyst workflow, including investigations, event correlation, and response triggers. The commercial test for such products is whether they improve the speed and quality of security operations without creating new automated failure points.

Identity governance moves closer to the center

The growing use of agents places added pressure on identity vendors because every agent requires an account, permissions, authentication methods, and a process for removing access when its role changes or ends.

Okta remains focused on authentication and access management, while SailPoint specializes in identity governance: establishing why a permission exists, who approved it, and when it should be reviewed or revoked. Those functions become more consequential when a single agent can carry permissions across several sensitive applications.

SailPoint reported annual recurring revenue growth of 25% and SaaS ARR growth of 36% in its latest quarter. The company said AI-driven ARR exceeded $70 million and that AI products contributed more than 30% of net new ARR. Those figures suggest customers are already connecting identity governance spending to AI deployment plans, particularly where agents may receive access to internal data or business workflows.

Okta reported revenue growth of roughly 11% in its latest quarter, alongside stronger cash flow and margins. Its challenge is whether agent-related identity offerings can accelerate growth beyond its current pace as customers move from experimental AI deployments to systems with broader operational access.

Data permissions and zero trust become operational controls

Varonis is positioning its data discovery, classification, permission analysis, and threat detection capabilities around AI governance and runtime controls. Before companies allow an agent to search internal files or answer questions from corporate data, they need to understand which documents contain sensitive information and whether permissions are excessively broad.

Varonis reported total revenue growth of about 18% year over year in its latest quarter. SaaS ARR increased 52%, although the company said the figure was about 25% excluding migration-driven conversion effects. Its opportunity rests on a simple deployment problem: agents cannot be safely limited if companies do not first know what data they hold and who or what can access it.

Zscaler is applying zero-trust access principles to a growing mix of employees, workloads, and agents. The model moves beyond employee-to-application access toward machine-to-application controls, where an automated system may need tightly scoped authorization to reach a particular service for a limited period.

Zscaler reported growth of roughly 25% in both revenue and ARR in its latest quarter. Excluding the Red Canary acquisition, both measures grew closer to 20%. The company’s ability to enforce authentication, authorization, and isolation across connections could become more relevant as internal traffic includes more automated workloads.

Networks remain part of the AI infrastructure buildout

Fortinet and Cloudflare illustrate how agent adoption could also reshape network security demand. Fortinet is targeting private AI deployments, including GPU clusters, private cloud environments, and so-called AI factory infrastructure. Such systems require segmentation, east-west traffic controls, firewalls, secure access service edge products, and security operations tools to manage connections inside the network.

Cloudflare operates across content delivery, web application security, DDoS protection, zero-trust services, Workers, and a global edge network. Its control points may become more valuable as traffic shifts toward agent-to-API and agent-to-agent interactions, where software systems make large volumes of machine-readable requests without direct human involvement.

Market valuations already reflect differing expectations around AI-linked growth. CrowdStrike and Cloudflare trade with higher-growth profiles, while Palo Alto Networks and Fortinet are often viewed as more defensive platform providers. SailPoint, Varonis, Zscaler, and Okta face a more specific commercial question: whether agent-security features can translate into stronger net new recurring revenue rather than simply becoming expected additions to existing products.

For cryptocurrency users and businesses, the same development reinforces the need to control non-human access. API keys connected to trading or custody accounts should be scoped narrowly, reviewed regularly, and revoked when they are no longer needed. As automated systems take on more operational work, a valid credential is increasingly the starting point for security decisions rather than the final proof that an action should be trusted.


See how banks deploy secure, workflow-aware AI agents in production in this in-depth overview.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trading
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.