This library's UC-074, published March 18, 2026, documented AI agent identity security's land-grab phase: $57 billion in M&A inside twelve months, anchored by Palo Alto Networks' $25 billion purchase of CyberArk and Google's $32 billion purchase of Wiz, against Gravitee's own survey data showing 80% of Fortune 500 companies running active agents, 88% reporting security incidents, and only 14.4% with full security approval.[6] Six months later, the pattern has specialized rather than repeated. Cisco is acquiring Astrix Security, a startup founded in 2021 that secures the API keys, service accounts, and OAuth tokens autonomous agents rely on, for roughly $400 million — a precise point-solution rather than a platform buy.[1] Rubrik separately shipped Agent Identity, launched at Black Hat in August, delivering just-in-time permissions per tool call rather than the broad standing access agents typically inherit.[2] But Gravitee's own second annual survey — the same publisher UC-074 cited, a genuine like-for-like comparison — shows enterprise agent estates doubled in four months, December 2025 to April 2026, with 38% of organizations now running over 100 agents.[3] Coverage did not keep pace: only 9.5% of organizations secure more than 81% of their deployed agents, 48% of production agents run completely unsecured, and just 7.2% have named individual accountability.[3] The money moved. The products shipped. The fleet grew faster than either could cover.
UC-074 called it a land grab for good reason: $25 billion for CyberArk, $32 billion for Wiz, both explicitly framed around securing AI agent identities, inside a single twelve-month window.[6] Six months on, the deals look different in kind, not just size. Cisco's move to acquire Astrix Security — a five-year-old startup that had raised roughly $85 million from Menlo Ventures, Workday Ventures, Bessemer, CRV, and F2 — for approximately $400 million isn't a platform play.[1] Astrix does one specific thing: it discovers, manages, and monitors the API keys, service accounts, and OAuth tokens that autonomous agents actually use to act, and Cisco plans to feed that telemetry directly into Identity Intelligence, Duo, Secure Access, and Splunk.[1]
Rubrik took a different route to the same problem: building the product rather than buying it. Agent Identity, launched at Black Hat in August 2026, is one of four pillars in Rubrik's Agent Cloud platform, alongside Observability, Runtime Security, and Rewind.[2] Its core mechanism addresses a specific, named failure mode: agents typically inherit the broad, standing permissions built for human employees, so a single compromised or misbehaving agent can act destructively across SaaS applications, databases, and APIs before anyone notices. Agent Identity instead grants just-in-time permissions per individual tool call.[2] Both moves are real, dated, and aimed squarely at the gap UC-074 first flagged.
Here's what the money and the engineering haven't caught up to. Gravitee — the same publisher UC-074 originally cited for its 80%/88%/14.4% figures — released its second annual State of AI Agent Security survey in June 2026, and the comparison this time isn't about approval rates. It's about scale. Enterprise agent estates doubled in just four months, December 2025 to April 2026; 38% of organizations now operate more than 100 agents.[3] Against that growth, coverage stayed thin: only 9.5% of organizations secure more than 81% of their deployed agents, 48% of production agents run completely unsecured, and just 7.2% have named individual accountability for agent behavior.[3] 54% experienced or suspected a security incident; 34.9% confirmed one outright.[3]
This isn't a story about an industry that failed to respond — Cisco's checkbook and Rubrik's engineering team both say otherwise. It's a story about a race where the thing being secured is growing faster than the security around it, even as that security genuinely accelerates. 81.7% of the same surveyed organizations plan to deploy significantly more agents in the next twelve months.[3] The gap UC-074 measured in dollars and approval percentages is now better measured in a doubling fleet against single-digit full-coverage rates.
Enterprise agent estates doubled Dec 2025-Apr 2026; only 9.5% of organizations secure more than 81% of their deployed agents.[3]
How a $57 billion land grab specialized into point solutions while the underlying problem kept growing.
$25B CyberArk deal, $32B Wiz deal — 80% of Fortune 500 running agents, only 14.4% approved.
The Baseline~$400M for a point-solution securing the API keys and tokens autonomous agents use.
The CapitalJust-in-time permissions per tool call, replacing broad standing agent access.
The ProductAgent fleets doubled in four months. Only 9.5% of organizations secure most of their fleet.
The GapThe fleet is set to keep growing faster than coverage has shown any sign of catching up.
What's NextAgents typically inherit the broad, standing permissions built for human employees — a single compromised or misbehaving agent can act destructively before anyone notices. — Rubrik, introducing Agent Identity
| Dimension | Evidence |
|---|---|
| Operational (D6) Origin · 90 | Gravitee's own second survey: agent fleets doubled in 4 months while only 9.5% of organizations secure most of their fleet.[3]The Scale Mismatch |
| Revenue (D3) L1 · 82 | Cisco's ~$400M acquisition of Astrix Security, a precise point-solution for non-human identity security.[1]The Capital Response |
| Quality (D5) L1 · 78 | Rubrik Agent Identity's just-in-time per-tool-call permissions, replacing broad standing agent access.[2]The Engineering Response |
The cascade originates in D6 — Operational — because the lever is the disclosed scale mismatch itself: Gravitee's own second-survey data showing agent fleets doubling while coverage stayed near single digits. From D6 it cascades to D3 (Revenue — Cisco's $400M Astrix acquisition, the dated capital response) and D5 (Quality — Rubrik's Agent Identity, the dated engineering response, addressing the standing-permission flaw directly). D1, D2, and D4 are deliberately left unscored — no disclosed customer, workforce, or regulatory figure ties directly to this specific comparison.
-- UC-319: The Fleet Doubled. The Coverage Didn't: 6D Diagnostic Cascade
-- Sequel to UC-074 (Mar 18 2026, $57B AI-agent-identity M&A wave: Palo Alto/CyberArk $25B, Google/Wiz $32B; Gravitee survey: 80pct Fortune 500 run agents, 88pct incidents, 14.4pct approved). Six months later: Cisco acquiring Astrix Security (~$400M, founded 2021, raised ~$85M) - secures API keys/service accounts/OAuth tokens for autonomous agents, integrating into Cisco Identity Intelligence/Duo/Secure Access/Splunk. Rubrik launched Agent Identity (Black Hat Aug 2026), part of Agent Cloud (4 pillars: Observability/Identity/Runtime Security/Rewind), delivers just-in-time permissions per tool call vs agents inheriting broad human-style standing permissions. Gravitee's OWN 2nd annual survey (published Jun 2026, same publisher as UC-074's original citation): enterprise agent estates doubled Dec 2025-Apr 2026, 38pct of orgs run 100+ agents, 54pct experienced/suspected incident, 34.9pct confirmed, only 9.5pct secure >81pct of agents, 48pct of production agents unsecured, 7.2pct have named accountability, 81.7pct plan to deploy more. Insight: real capital (Cisco) and real engineering (Rubrik) responded to UC-074's gap, but agent fleet growth outran coverage growth.
FORAGE fleet_outruns_coverage
WHERE cisco_astrix_deal_confirmed = true
AND rubrik_product_confirmed = true
AND gravitee_second_survey_confirmed = true
ACROSS D6, D3, D5
DEPTH 3
SURFACE fleet_outruns_coverage
DIVE INTO capital_and_engineering_vs_scale
WHEN fleet_doubling_confirmed = true
AND coverage_gap_confirmed = true
TRACE ai_agent_identity_sequel_cascade
EMIT fleet_outruns_coverage_signal
DRIFT fleet_outruns_coverage
METHODOLOGY 90
PERFORMANCE 42
FETCH fleet_outruns_coverage
THRESHOLD 1000
ON MONITOR CHIRP high 'Six months after this library's UC-074 documented a $57B AI-agent-identity M&A wave (Palo Alto/CyberArk $25B, Google/Wiz $32B), the response specialized: Cisco is acquiring Astrix Security for ~$400M to secure the API keys, service accounts, and OAuth tokens autonomous agents use, and Rubrik shipped Agent Identity at Black Hat, delivering just-in-time permissions per tool call instead of broad standing human-style access. But Gravitee - the same publisher UC-074 originally cited - released a second annual survey in June 2026 showing enterprise agent estates doubled in four months (Dec 2025-Apr 2026), with 38pct of organizations now running 100+ agents, while only 9.5pct secure more than 81pct of their deployed agents, 48pct of production agents run completely unsecured, and just 7.2pct have named individual accountability. Real capital and real engineering responded to the gap; the fleet grew faster than either could cover.'
SURFACE analysis AS json
Runtime: @stratiqx/cal-runtime · Spec: cal.semanticintent.dev · DOI: 10.5281/zenodo.19043012
Instead of another mega-platform deal, Cisco bought a precise $400M point-solution; Rubrik built one instead of buying it.[1][2]
Enterprise agent estates grew from December 2025 to April 2026 faster than any single security response could plausibly track.[3]
Only 9.5% of organizations secure more than 81% of their deployed agents; 48% of production agents run completely unsecured.[3]
Real capital and real engineering answered UC-074's gap directly — the underlying problem simply grew faster than either could cover.[1][2][3]
Market and product figures are drawn from company and vendor announcements; the growth-versus-coverage comparison uses only Gravitee's own survey series across both editions, avoiding cross-publisher figures that use similar-sounding but non-comparable methodology.
The response since has been real — a $400M Cisco acquisition, a new Rubrik product built specifically for this gap. But the same survey series shows enterprise agent fleets doubled in four months, while fewer than 1 in 10 organizations secure most of their fleet. The money moved. The fleet moved faster.