The cybersecurity market is entering a new phase as enterprises move from securing AI infrastructure to securing autonomous agents that can act on their behalf.
Cybersecurity technology vendors CrowdStrike and Okta indicated in their quarterly earnings results that strong enterprise demand is increasingly being linked to the security implications of AI agents.
The “Mythos Moment” Has Become an Enterprise Security Issue
CrowdStrike Chief Executive Officer (CEO) George Kurtz framed the quarter around what he called the "Mythos moment, an inflection point in cybersecurity," referring to the launch of Anthropic's Mythos frontier AI model, which has exposed the ability of advanced AI systems to carry out deceptive and potentially harmful actions.
"The world came to understand that cybersecurity is a necessity for AI adoption. New models created a new risk environment with no turning back."
Kurtz then linked that realization to the emergence of autonomous AI agents.
"Recently, this realization became even clearer with the market’s newest adversary, AI agents themselves. We told you this was the future, and this future is now a reality."
This week, the results of an investigation into OpenAI’s breach of AI platform Hugging Face found that approximately 700 autonomous agents had escaped their evaluation environment and conducted a coordinated attack. OpenAI said the agents accessed connected systems, stole credentials and altered infrastructure, while the independent researchers found evidence of coordination and attempts to conceal their activity.
The issue for enterprise security teams is now less about whether an AI model can generate malicious code and more about what happens when an autonomous system has credentials, access to enterprise tools, persistent connectivity and the ability to act without waiting for a human decision.
"We are seeing agents go rogue, swarming to attack and moving beyond their guardrails to autonomously harm," Kurtz said. "Agents are proving capable of data theft, permission alteration, and full-on command and control at scale, leading to organizational compromise."
Protecting enterprise systems from infiltration by autonomous agents is a materially different security proposition from protecting a conventional software application.
CrowdStrike's second-quarter revenue increased by 26 percent year over year to $1.47BN, while annual recurring revenue (ARR) increased 25 percent to $5.84BN. Net new ARR reached a record for the company at $333MN, climbing by 51 percent year over year and prompting the company to raise its full-year guidance for net new ARR growth to 34 percent at the midpoint.
Okta's second-quarter results point to a similar enterprise spending environment from the identity side. Revenue reached $805MN, with new products accounting for approximately 30 percent of bookings and deals incorporating those products generating an average 40 percent ACV uplift. The company also reported more than 600 customers with annual contract value above $1MN, up by more than 20 percent year over year.
Okta Sees the Same Shift Through Identity
Okta's results point to the same trend. CEO and Co-Founder Todd McKinnon said on the company’s earnings call that AI is changing the role of identity management in an enterprise.
"The emerging use of AI by organizations and threat actors alike has further elevated the role identity plays within a company’s security posture.”
More importantly, Okta is seeing AI conversations trigger broader infrastructure and identity-modernization projects.
"Organizations are accelerating their infrastructure modernization timelines to address this heightened threat environment," McKinnon said. "We are seeing conversations that begin with securing AI broaden into identity modernization initiatives."
A company may initially approach a security vendor because it wants to control AI agents, but once that discussion begins, it can expose weaknesses in identity governance, access management, privileged permissions and legacy infrastructure.
McKinnon described identity as “the primary control plane for securing AI.”
Okta's customer base indicates how quickly the problem can emerge. McKinnon described one organization where Okta initially detected 50 Claude agents, but a few weeks later the figure had reached 1,500.
"These customers are really tangible, the risk that they’re seeing and the way this is coming into their organization," McKinnon said.
Enterprise buyers are responding before the next breach




