Nikesh Arora has a habit of counting competitors before most people have even agreed on the problem. The Palo Alto Networks CEO recently told an audience that he sees roughly 40 companies actively building products to secure AI agents — the autonomous software systems now being deployed across enterprise workflows. That number is striking enough on its own. What makes it a story about the shape of an entire emerging industry is what Arora said next: at least 20 of those 40 startups are Israeli, according to Calcalist Tech. The AI capability race has a security shadow, and a disproportionate slice of the companies chasing that shadow are building in one place.
The observation lands at a moment when agentic AI has gone from a research concept to a live deployment challenge almost overnight. Enterprises running autonomous agents — systems that browse the web, write and execute code, interact with APIs, and take actions without human sign-off on every step — are discovering that their existing security stacks were never designed for this threat surface. Traditional endpoint and network tools assume a human is somewhere in the loop. Agents aren’t humans, and attackers already know it.

Why Agentic AI Breaks the Old Security Model
The core problem is authorization. A conventional enterprise application has defined permissions, a known identity, and a predictable set of actions. An AI agent is dynamic by design — it reasons, plans, and takes sequences of actions across multiple systems. That makes it a novel attack vector: prompt injection attacks can redirect an agent’s behavior mid-task, data exfiltration can happen through legitimate-looking API calls, and a compromised agent can pivot laterally across connected services faster than any human attacker. Securing this requires rethinking identity, observability, and runtime enforcement at a layer that didn’t exist two years ago.
Arora’s count of 40 active competitors signals that the venture and founder community has internalized this urgency. It also signals that the market is not yet consolidated — which means the window for startups to define the category’s architecture is open, but closing. Palo Alto Networks itself has been vocal about wanting to own the agentic security layer as part of its broader platform strategy, so Arora’s competitive mapping is as much a strategic statement as an industry observation. When an incumbent CEO names the number of challengers, he’s also drawing investors’ attention to the size of the prize.
Israel’s Outsized Footprint in the Emerging Category
The concentration of Israeli companies in this space — at least half of Arora’s 40 — reflects structural advantages that have been building for years. The country’s military intelligence units, particularly Unit 8200, have produced a generation of cybersecurity engineers with deep experience in offensive and defensive techniques at scale. That pipeline has been reliably converting into startups for more than a decade, and the pattern is repeating now with AI-native security. The Israeli tech ecosystem has long treated cybersecurity as a national export category, and agentic AI security fits that template precisely.

What’s new is the speed. The agentic AI security category is forming in real time, with product categories, terminology, and standards still being written. Companies are not entering a defined market — they are competing to define it. That dynamic favors founders who can move fast, iterate on threat intelligence quickly, and work close to the bleeding edge of both AI capability and adversarial technique. It’s an environment that rewards exactly the kind of engineering culture the Israeli security ecosystem has spent years producing. Whether any individual startup from that cohort becomes the dominant platform is still unknowable, but Arora’s count makes one thing clear: the fight for agentic AI security is already on, and it is more competitive — and more globally concentrated in one node — than most of the enterprise tech world has registered.
For established players like Palo Alto, CrowdStrike, and Microsoft, the implication is that acquisition activity in this space is likely to accelerate. Forty startups racing toward the same problem space will not all survive as independents. The next 18 months will probably see the field narrow sharply, either through consolidation or through the emergence of a few clear technical leaders. Arora is already watching the board.
