How AI Reshaped Enterprise Security Demand in H1 2026

August 28, 2026

Security and AI leaders ("Sages") opened more than 500 projects (“initiatives”) on Sagetap in the first half of 2026. This report analyzes those initiatives alongside the proofs of concept (POCs) and purchases that followed. The data comes from verified CISOs and security executives who documented their work and which solutions they decided to test.

Why this matters: Analyst reports often give a sense of where a market might be heading. This report examines what security leaders were doing between January and June of this year. That includes the vendors they chose to evaluate, which often brings to light emerging companies that have not yet appeared on anyone's shortlist.

This report was made possible by our community of Sages, the security leaders who documented their initiatives, shared their evaluation criteria, and contributed their expertise to build intelligence that benefits the entire community.

Statistical claims come from verified initiative and funnel data. The sub-area groupings and market reads built on top of them are Sagetap's analysis, grounded in what we observed this half rather than in forecasts.

Our focus: The deep dives cover AI Security and Governance (more than 100 initiatives), Threat Detection and Response (more than 100), and Vulnerability Management (more than 50). The first two are the largest areas of demand on the platform. The third is the area where the gap between what Sages said they were working on and what they put to the test was widest.

A final section flags three problems taking shape at the edges of our categories, where demand exists but no product category has formed around it yet.

Throughout this report, linked phrases lead to Sages' live initiatives and evaluated products.

Join the community to access them and get the full details.

How Demand Is Shifting

At Sagetap, we measure buyer attention in two ways:

  • Demand is based on the initiatives Sages opened, meaning the work they said they were taking on. It is the earlier and more speculative signal, and it captures interest even before budget is committed.
  • Evaluation covers everything Sages do to assess a product, from vendor discovery and conversation through a full technical review. For this report, we look at the latter end of that work, the POCs and purchases, where a team has committed time to finding out whether something works.

The two don't always agree. A category can lose share of new initiatives while gaining ground in evaluation, or the reverse, and each pattern says something different about where the work is truly going. The deep dives that follow are built around those divergences.

H1 Changes Based on Demand (Initiatives)

One category, AI Security and Governance, showed a dramatic surge this half. Everything else held its ground or gave back a point or two. The chart below shows the change in each category's share of new initiatives from the second half of 2025 to the first half of 2026, measured in percentage points.

What's In

AI Security and Governance jumped from 12% to 18% of all activity, making it the only category to gain share this half. Sages want to lock down the autonomous AI agents running in their environments, and they want visibility into how employees use AI day to day.

What's Out

Threat Detection and Response, Data Protection and Privacy, Risk Management and Compliance, and Application Security all lost share. None collapsed, but attention is rotating out of these more mature areas of the security landscape.

What's Stable

Everything else held roughly flat. Identity and Access Management, Vulnerability Management, Cybersecurity Training, Cloud Security, and Email Security all held a stable share of demand, though identity shifted under the surface toward cloud entitlements and just-in-time access.

H1 Changes Based on Evaluation (POCs and Purchases)

Here’s the later-stage view. The chart below shows how each category's share of POCs and purchases changed from the second half of 2025 to the first half of 2026, in percentage points.

What's In

Every category gaining ground is one where teams are hardening infrastructure or getting ahead of AI. AI Security and Governance leads, followed by vulnerability work, the AI SOC generation of threat detection, cloud security, identity, and offensive-heavy application security.

What's Out

The human and administrative end of the market gave way. Compliance and GRC fell hardest, security awareness training dropped alongside it, and email security softened as attention moved to AI-driven phishing defenses.

What's Stable

Data Protection and Privacy and Fraud Detection and Prevention held steady, accounting for the same share of POCs and purchases in H1 2026 as they did in H2 2025.

Main Takeaways: Demand vs. Evaluation

  1. AI Security and Governance rose on both sides. It's the biggest gainer in both demand and evaluation, driven by autonomous-agent security and employee AI-usage governance.
  2. Attention is moving off human-driven work and toward AI-native tooling. Even the growth in threat detection came from AI SOC tools that automate work analysts used to do by hand.
  3. Threat Detection and Response and Vulnerability Management both gained share of later-stage activity. VM held flat in demand and TDR slipped. Sages are funding work they already understand rather than chasing new ground, which makes this the clearest signal of conviction in H1.

Deep Dives

Three areas account for most of the movement above. For each, we break down demand, show what reached a POC or purchase, and note where the two diverge.

AI Security and Governance: Finding the AI That's Already Running

AI Security and Governance now sits level with Threat Detection as the largest area of demand on the platform. The sub-areas underneath it split almost evenly between two problems, and both relate to AI that is already active. Sages are asking about agents in production and tools their employees have already adopted.

What this suggests: Most of these Sages already have an AI usage policy but no way to enforce it. The current answer is blocking, which is catching too little while slowing employees down.

Where Activity Is Concentrated

Agentic AI Security (36%)

Teams are working to inventory the autonomous agents running in their environments, control agent identity and access, and protect agents, MCP servers, and LLM gateways at runtime.

AI Usage Governance (35%)

Sages want visibility and control over how employees use AI tools, which in practice means shadow-AI discovery and DLP for AI.

AI Application Security (15%)

Sages are protecting AI-powered applications from prompt injection, model abuse, and unsafe outputs.

AI Governance and Compliance (14%)

This is the program-building work, covering use-case registries, risk assessment workflows, and approval processes.

Across all four, the most-requested capabilities are policy enforcement and guardrails, AI asset inventory, and agent behavior monitoring.

What Sages Are POCing and Purchasing

Agentic AI Security (38%)

  • An enterprise environmental services company entered POC with Sonet Governed Agentic Automation to put guardrails around autonomous agent execution. MCPs and agent-based tools are entering faster than controls can keep up, and the team's view is that process-based guardrails fail at scale.
  • A mid-market computer games company entered POC with Knostic to secure AI agents and coding assistants across its environment. It sanctions three coding tools across roughly 200 developers and citizen coders but has continued to find new unsanctioned tools.
  • An enterprise computer software company entered POC with Noma Security for AI runtime security and agent governance, with an active initiative to replace its current tool. The priority is securing the inference layer as it moves toward agentic AI, plus continuous red teaming.

AI Usage Governance (38%)

  • An enterprise computer software company entered POC with Zaun for AI-native SecOps built around shadow AI discovery and SaaS control-plane signals. The team wants faster correlation across its existing stack and coverage of its own application and API traffic.
  • A nonprofit organization entered POC with Lumia Security for AI governance and observability across the org. Their goal is to keep confidential, proprietary, and personally identifiable information out of shadow AI tools.
  • A mid-market healthcare organization also entered POC with Lumia Security for guardrails on employee AI use. It permits only Copilot today and enforces that by blocking the AI category, but wants something more targeted and less disruptive.

AI Application Security (12%)

  • A mid-market computer software company purchased Acuvity to control what flows into cloud LLMs and to put guardrails around AI-assisted development. The stated concern is sensitive data and proprietary content reaching external models, along with engineers using coding assistants without controls.

AI Governance and Compliance (12%)

  • An enterprise civil engineering company entered POC with SurePath AI to govern its internally developed AI systems alongside the external services its employees reach. The organization has written AI policy and procedures but no way to monitor or enforce them across either side.

Threat Detection and Response: The SOC Analyst Is Becoming an AI Agent

The mix inside the Threat Detection and Response category has changed since January. AI SOC Analyst is now the single biggest sub-area at 32% of demand, and it accounts for 58% of everything that reached a POC or purchase. The classic pieces (SIEM, endpoint, threat intel) are still very much in play in what Sages say they are working on, but what they are putting to the test is narrower.

What this suggests: SIEM and endpoint are still being managed as renewals, while the AI SOC budget is net new.

Where Activity Is Concentrated

AI SOC Analyst (32%)

Teams want an agentic SOC that can autonomously triage, investigate, and resolve alerts, and several describe it as a near-term requirement rather than a research project.

SIEM / Security Analytics (18%)

These are mostly renewals and replacements, and cost is driving the conversation. One Sage is moving off Splunk over ingest and storage cost; others are re-evaluating their whole SIEM/SOAR/UEBA stack at renewal.

Threat Intelligence Platform (16%)

Sages are operationalizing threat intel and, in several cases, replacing their current CTI vendor with something more modern.

EDR / XDR (13%)

Sages are extending endpoint work toward insider-threat capability and deception.

SOAR / Security Automation (7%)

Teams are automating response playbooks to cut the manual work between detection and action.

What Sages Are POCing and Purchasing

AI SOC Analyst (58%)

  • A mid-market insurance company purchased Intezer for AI-driven alert triage across 5,000 endpoints. Alert tuning is manual today, and additional SOC headcount alone wouldn't close the gap.
  • An enterprise machinery company also purchased Intezer to automate triage of roughly 4,000 alerts a month while moving detection in house from a third-party SOC.
  • A mid-market fintech company purchased Daylight Security as an AI-driven alternative to traditional MDR. It runs a managed SOC today and wanted to know whether AI could replace it or integrate with it.
  • A mid-market manufacturing company purchased Fixify to automate internal IT helpdesk work and offload part of its Tier 1 and Tier 2 ticket volume, with agent time savings and user satisfaction as the measures.
  • An enterprise civil engineering company entered POC with Prophet Security for AI SOC analysts to absorb Tier 1 work. The team runs a staffed weekday SOC with XDR covering nights and weekends and wants to free analysts for advanced investigations.
  • An enterprise civil engineering company entered POC with Dropzone AI for 24/7 agentic investigation. Investigation delays and manual tasking are the constraints, and the goal is to shift the team from reactive to predictive work.
  • An enterprise environmental services company entered POC with MAVE for agentic investigation and response. Low-fidelity alert volume obscures real incidents, and ingestion and storage costs are climbing as detection pulls in more telemetry.

SIEM / Security Analytics (17%)

  • A mid-market computer and network security company purchased Gravwell to replace SentinelOne's DataSet at renewal, seeking stronger query capability and simpler correlation across indexes.
  • A mid-market marketing and advertising company entered POC with Gravwell for a SIEM use case, currently running AWS OpenSearch. The team is also evaluating whether Gravwell could displace its MDR tooling.

SOAR / Security Automation (17%)

  • An enterprise real estate company purchased Torq to replace XSOAR, seeking a lower-code path through a sizable automation backlog.
  • An enterprise environmental services company entered POC with Torq for security hyperautomation. The goal is to automate repetitive work so the team can move to higher-leverage tasks, on the view that automation is how an outmanned team closes the gap with adversaries.

EDR / XDR (8%)

  • An enterprise insurance company purchased Halcyon for ransomware prevention and recovery. The org went through a ransomware event last year and is building out a more robust security program.

Threat intelligence accounts for 16% of demand in this area, with Sages describing plans to operationalize intel and replace their current CTI vendor. Consolidation pressure is one plausible explanation, since intel is increasingly bundled into the platforms these teams are already evaluating.

Vulnerability Management: Attention Splits Evenly, Commitment Doesn't

Vulnerability Management held steady at about 9% of all activity. Demand splits almost exactly down the middle between two ways of framing the problem, but 75% of the later-stage activity went to risk-based prioritization. While exposure management is drawing interest, it is yet to draw commitment.

What this suggests: Prioritization sits inside a program that already exists, and exposure management usually requires standing up a new one.

Where Activity Is Concentrated

Risk-Based Vulnerability Management (51%)

Sages are modernizing the vulnerability lifecycle, pulling findings from multiple scanners and prioritizing by real risk rather than raw CVSS, and increasingly asking for AI and agentic oversight to help work the backlog.

Continuous Threat Exposure Management (49%)

This is the attacker's-eye view, built on continuous external attack surface discovery and attack-path analysis with business-context prioritization. Several Sages explicitly want to move away from annual penetration testing toward continuous validation.

What Sages Are POCing and Purchasing

Risk-Based Vulnerability Management (75%)

  • A mid-market healthcare organization purchased Sevco to consolidate asset and vulnerability data. It runs Qualys across a mostly on-premise estate with heavy manual correlation and wants one tool covering both vulnerability prioritization and IT asset inventory.
  • An enterprise internet company entered POC with an agentic vulnerability triage platform (currently in stealth) to automate manual triage. The bottleneck is identifying which application owner a finding belongs to before a ticket can be assigned.
  • A mid-market law firm entered POC with an agentic vulnerability management platform (currently in stealth). Findings come from CNAPP, SCA, and SAST tooling plus continuous pentesting, but turning them into tracked tickets and following them to closure is still manual.

Continuous Threat Exposure Management (25%)

  • An enterprise civil engineering company entered POC with watchTowr for external attack surface management paired with threat intelligence. The team runs Tenable and Halo alongside separate external reconnaissance tooling, with analysts correlating by hand.

Emerging Markets

Some of the most useful signal shows up in initiatives that don't fit our categories, including requests that land in the wrong bucket, get split across several areas, or describe a problem no product owns yet. Together they map where demand is heading before it is large enough to name, so timing matters in this section.

Emerging Market #1: Hiring and Candidate Fraud Protection

Security leaders are starting to ask for technology that protects the hiring process from AI-driven identity fraud. The requests are scattered across fraud detection, identity, and initiatives that fit nowhere at all, but they describe the same problem. One enterprise cited real nation-state attempts to get fake employees hired. Another wanted to secure a high-volume remote hiring pipeline against deepfake interviews. A third was evaluating products to detect AI use in job applications. Collectively, these initiatives point toward a distinct category focused on identity-proofing the hiring funnel rather than traditional fraud detection or identity management.

These requests track a threat that moved from law-enforcement story to hiring-process problem over the past year. North Korean operatives have been documented securing remote engineering roles under stolen or fabricated identities, using AI to generate convincing résumés and to get through video interviews. US prosecutors have charged the pattern repeatedly, and threat researchers now report it spreading into European companies. For security teams, the exposure sits in recruiting, a function most security programs have never had to defend.

Emerging Market #2: Deepfake and Synthetic Media Defense

The second cluster is enterprise-wide detection of AI-generated voice, video, and image impersonation. The initiatives cover voice and video scams aimed at financial assets, stronger authentication on the voice channel specifically, and in one case a deepfake incident that hit the organization during Q1 2026. Although these opportunities are currently categorized under Digital Risk Protection, EDR/XDR, and Customer Identity, the underlying requirement is the same, which is detecting AI-generated synthetic media regardless of where the attack originates.

Deloitte's Center for Financial Services projects that generative-AI-enabled fraud losses in the US could reach $40 billion by 2027, up from $12.3 billion in 2023, a 32% compound annual growth rate. The reference incident is still the January 2024 case in which an employee wired $25 million after a video call where every other participant was a deepfake of a colleague. Sages are describing the next stage, where the voice and video channels themselves get authenticated before a transaction is ever authorized.

Emerging Market #3: AI Model Forensics and Attribution

The third emerging market centers on securing the AI supply chain and investigating model compromise after deployment. One Sage wants tooling for the case where a model is discovered to be poisoned or contaminated and the organization has to work out which downstream systems and outputs were affected. Another is focused on protecting coding assistants against indirect prompt injection. Together, these requests suggest security teams are beginning to treat AI models, prompts, and agent dependencies as supply chain assets that require provenance, forensic investigation, and incident response rather than runtime protection alone.

This is the earliest market in the section, and the standards world is arriving at the same place from the opposite direction. MITRE's ATLAS knowledge base catalogs data poisoning and model tampering as adversary techniques, and the OWASP GenAI LLM Top 10 treats prompt injection and AI supply chain compromise as first-order application risks, but both are oriented toward prevention. Sages are asking a question that maps to incident response, and the tooling for it barely exists.

None of these three is a market yet. Two are small clusters, and one is a handful of leaders describing a problem out loud for the first time. That is the value of a network like this one. By the time a problem has a category and a vendor shortlist, being early has stopped counting for anything. The same holds for the vendors building into these gaps, who are hearing the requirement before it has a name.

Published August 28, 2026 by Sagetap
The Knowledge Marketplace for Enterprise AI and Security

Analysis based on more than 500 initiatives and more than 70 later-stage POC and purchase records created on the Sagetap platform from January 1 – June 30, 2026. This report tracks what moved in and out, and what held steady across both demand and evaluation. Deep dives cover the three areas where AI is most reshaping how security teams work: AI Security and Governance (more than 100 initiatives), Threat Detection and Response (more than 100), and Vulnerability Management (more than 50).

Methodology: This report analyzed documented security initiatives from verified CISOs and security executives on the Sagetap platform. Demand figures are counts of initiatives grouped by sub-area; sub-area percentages within each deep dive are calculated against the scoped total for that area, excluding a small number of initiatives logged without a defined sub-area. Evaluation figures are counts of POC and purchase records logged during the half, assigned to sub-areas by product category. Sub-area classifications and market reads are labeled as Sagetap analysis and grounded in observed H1 2026 patterns.

Vendor selection methodology: Vendor lists throughout this report reflect the platforms Sages evaluated, ran through proof-of-concept, or purchased in documented H1 2026 Sagetap activity within each area. When Sages engage a vendor on Sagetap, they identify the products they're considering, from initial evaluation through proof-of-concept and purchase decisions. Inclusion in this report indicates evaluation frequency among practitioners during H1 2026, not endorsement or comprehensive market coverage. Many excellent vendors may not appear due to category scope, evaluation timing, or the specific focus areas analyzed in this report.

Continue Reading
Access the entire report with exclusive data and actionable insights from your peers.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Get Started

Join over 4,000+ startups already growing with Sagetap.