The Race to Become the Next CrowdStrike or Wiz of AI Security Is On
At RSAC 2026 in San Francisco, the cybersecurity industry's biggest gathering, a new race is underway: which company will emerge as the defining AI-native security platform of the next decade — and whether legacy vendors can adapt fast enough to stay relevant.

AI-native cybersecurity startups and legacy vendors compete for dominance at RSAC 2026 in San Francisco
The cybersecurity industry has arrived at RSAC 2026 — the sector's largest annual gathering at the Moscone Center in San Francisco — with a single question dominating conversations in boardrooms, investor meetings and demo halls: who will be the next CrowdStrike or Wiz in AI security?
Both companies became breakout players by moving fast and owning an emerging technology shift — cloud infrastructure for Wiz, and endpoint detection and response for CrowdStrike. Now, a new generation of AI-native upstarts is applying the same playbook to the AI threat landscape, and incumbent vendors are feeling the pressure.
"These vendors are very aware now that they need to adapt because if they don't, these smaller, AI-native companies have a very unique window where they can really penetrate the market," Dimitri Zabelin, a senior investment research analyst at PitchBook, told Axios.
A Market in Rapid Transition
The competitive urgency is playing out in real time at RSAC. Hugh Thompson, executive chairman of RSAC, told Axios that customers are spending the week comparing notes on which vendors are best at defending against AI-driven threats already hitting their environments. "You're going to see a lot of these companies have to respond at a speed that they really haven't had before," he said.
The market data backs up the pressure. In 2025, AI-native startups accounted for more than half of all global cybersecurity venture capital deals, while Q4 2025 deal value hit $5 billion — the highest quarterly level since Q2 2022. Tech Prescient Deals involving security orchestration, automation and response (SOAR) tools — platforms that identify and respond to threats such as phishing and data exfiltration — grew 76.5% in Q4 2025 alone, according to PitchBook.
The Threat Landscape Vendors Face
Legacy vendors and emerging startups are both contending with a fast-shifting environment. Some organisations are building AI-powered security operations centres in-house rather than outsourcing to vendors. Others are redirecting portions of their cybersecurity spending toward smaller, AI-focused companies. At the same time, Anthropic and OpenAI are both exploring agentic cybersecurity products built on top of their existing code security platforms — a move that puts the frontier AI labs in direct competition with specialist security vendors.
"The Market As We Know It Is Dead"
Rubrik CEO Bipul Sinha told Axios the cybersecurity market "as we know it is dead," arguing that the vendors most likely to succeed are those that reimagine their products as AI-native — not merely AI-enhanced. Earlier this year, Rubrik made its Agent Cloud generally available, offering tools for enterprises to monitor, govern and control AI agents operating across their systems. At RSAC 2026, the company also unveiled SAGE — its Semantic AI Governance Engine — described as the first AI governance engine purpose-built to secure autonomous agents in real time.
"If the company has a culture of change, adaptability, innovation — that's the company that will survive," Sinha said.
A Reality Check on Legacy Vendors
Not everyone is convinced that incumbents are moving fast enough. Jeff Pollard, vice president and principal analyst at Forrester, told Axios that some legacy vendors are failing to grasp the scale of the shift — including its workforce implications. "There is still a lot of head in the sand for the reality of the situation and a lot of marketing as well," he said. The counterargument, however, is that many large enterprises remain unlikely to quickly abandon established, long-standing security vendors in favour of early-stage AI startups — giving incumbents a window to catch up.
Innovation Sandbox Points to What's Next
A key bellwether for where market demand is heading is the RSAC Innovation Sandbox — the conference's flagship startup pitch competition, which has historically served as a launchpad for companies that go on to define the next cycle of security spending. Past finalists include Wiz, SentinelOne, and Axonius. This year, Geordie AI was crowned "Most Innovative Startup 2026," recognised for its AI governance platform that gives enterprise teams deep, continuous understanding of agentic AI behaviour. SOPHOS The result is a signal in itself: in 2026, the most urgent problem in cybersecurity is not just detecting threats, but governing the AI agents now operating inside enterprise environments.
Salma Mubarak
Cloud Security & AI Security ContributorSalma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.
At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.