Black Hat USA 2026's Business Hall hadn't closed before the market formed. More than fifteen vendors — Cyera, Rubrik, SailPoint, Check Point, Sweet Security, Zero Networks, Tanium, Promptfoo, Legit Security, Acalvio, plus a dozen compliance-adjacent names — shipped Agent security products aimed at one protocol within 48 hours. Not 48 days. Forty-eight hours.
The trigger was Day 1's disclosures: framework-level vulnerabilities in Anthropic's Model Context Protocol (MCP), compute-layer attacks, prompt injection moving laterally across tool sets. The security industry responded with the synchronized efficiency of a boy band.
When was the last time fifteen companies coordinated a product launch? For me, the answer is DeFi Summer 2020 — when every fork was "revolutionary," and the only metric that mattered was total value locked. I'd spent that period reverse-engineering Curve Finance and Uniswap V2 liquidity pools, documenting a recurring arbitrage pattern in stablecoin pairs. The lesson I carried forward: speed of vendor attention is never a technology signal. It's a liquidity signal.
Liquidity doesn't lie, but it does rush.
Let's establish the baseline for those who skipped the AI infrastructure newsletters. MCP is Anthropic's open protocol, released in November 2024, designed to connect AI models to external tools and data sources. It became the standard rail for Agent tool calling — the plumbing through which autonomous AI systems talk to the enterprise. Like most plumbing, it carries the architectural sins the industry stopped making elsewhere: tool schemas that can be poisoned with malicious instructions, shared context and namespaces across MCP servers that let prompt injection walk between tools, and authorization models where "the server says so" replaces "we verified the principal."
The Day 1 researcher disclosures turned those sins into front-page material. Framework-level attacks — not just bad Agent behavior, but attacks that compromise the protocol layer itself, tampering with tool call results at the execution level. That's the threat model that launched the vendor wave.
Now here's what I actually think about the products, because I spent the weekend auditing them the way I audit smart contracts — checking what the code plausibly does versus what the press release claims.
Cyera Agent Guardian discovers Shadow Agents and maps MCP activity. That's data-loss-prevention semantics extended to AI workloads. No architectural novelty, but excellent timing.
Rubrik Agent Identity and Agent Rewind deliver asset inventory, least privilege, and rollback of Agent operations. The "Rewind" concept is the most interesting incremental idea here — reversing Agent actions via backup-style snapshots. It's an elegant transfer of backup infrastructure metaphors to Agent behavior, though causal consistency across distributed Agent orchestrations remains technically unresolved.
Check Point's AI Network Firewall detects MCP communications — next-gen firewalling with JSON-RPC awareness. Engineering value exists; theoretical breakthrough does not.
Sweet Security's Agentic AI Blocking terminates unauthorized tool calls at runtime. This is the highest-value technical play in the wave — real-time enforcement instead of passive visibility. But runtime blocking demands brutally low false-positive rates, and the operational details remain unpublished.
Zero Networks' "Least Agency" renames least privilege for the Agent era, wrapping it in human approval gates for sensitive operations. Conceptually sound; engineering is straightforward.
Tanium Atlas MCP Server, Promptfoo MCP Proxy, and Acalvio ShadowPlex round out the wave with controlled data exposure, security-proxy communication, and honeypot-based deception for Agents. All credible engineering, all extending existing security categories rather than inventing new ones.
Do you see the pattern? This entire product wave operates at Level 3-4 innovation — engineering and composition, not protocol-level research. It's existing security capabilities with MCP-shaped stickers applied. I'm not dismissing the engineering value; well-executed adaptation is the foundation of most security markets. But when fifteen vendors ship in 48 hours, you're looking at a distribution of marketing timelines, not a distribution of technological breakthroughs.
The functional categories confirm the overlap. At least four vendors target visibility and discovery (Cyera, Rubrik, SailPoint, Drata). Another three target active protection (Sweet Security, Check Point, Zero Networks). Three target MCP communication security (Tanium, Promptfoo, Legit Security). The remainder are compliance and deception extensions (Acalvio, KnowBe4, 1Password, Mimecast, Abnormal AI). Visibility already has four vendors fighting for one conceptual slot. That's a commoditization signal in week one.
The uncomfortable omission: nobody is fixing MCP itself. No vendor announced an identity framework for MCP servers — nothing analogous to SPIFFE for Agent infrastructure. No fine-grained multi-tenant trust-domain governance. No serious mTLS depth in the communication layer. The entire vendor wave assumes the protocol's foundation is solid enough to police from the outside. From my experience auditing cross-border settlement layers, I can tell you that securing the perimeter while the core clearing mechanism has an unauthenticated door is a fraud department's fantasy. You inspect traffic you can't fully authenticate. That's not security; that's observability with a risk-management dependency.
This is a market formation event, not a technology maturation event.
Here's the macro-causal reading. Fifteen-plus vendors synchronizing in 48 hours is a supply-side declaration. The security industry certified its own market in a single news cycle. What's missing is demand-side evidence: no enterprise deployment counts, no procurement pipelines, no average contract values, no budget-line attribution. Does Agent security spend come from the security budget or the AI budget? Nobody has answered that. From watching capital flow in payment systems for a decade, I can tell you that when sellers move faster than buyers, the market exists on pitch decks until the next procurement cycle proves otherwise.
Another rug? No, just a liquidity trap. The vendor wave is a liquidity trap in its purest form: capital and engineering attention flooding toward a surface area before the revenue model has been validated. Conference timing compresses the news cycle; it doesn't compress the enterprise buying clock. Expect a 12-to-18-month chaos window. Nobody in procurement knows who owns the "Agent security" budget line — the CISO, the infrastructure team managing Agent platforms, or the AI governance officer whose job title doesn't exist yet. That ambiguity kills purchases faster than any technical deficiency.
Also missing from the roster: Microsoft, CrowdStrike, Palo Alto Networks, SentinelOne, Wiz. The platform giants didn't skip this cycle because the market is uninteresting. They skipped it because they're calculating how to absorb the surface area from above. Microsoft can bake MCP security into Copilot infrastructure. CrowdStrike can announce Agent Detection and Response with its existing telemetry empire. A ten-person startup offering an MCP proxy is a feature to them, not a competitor.
The third absent dimension is geographic. No Chinese vendors appeared in the launch wave — no QAX, no Sangfor, no Alibaba Cloud. That's not a technology gap; it's an international market access gap, and it tells you this segment's competitive geography is still being drawn.
Shift the lens, though, and the same evidence reads differently. Security vendors don't invest engineering resources into protocols they expect to stay niche. Fifteen-plus firms shipping MCP-specific products means enterprise Agent deployments are already in production at meaningful scale — generating real threat signals, creating real buying pressure. The security wave is a lagging indicator. It tells you Shadow Agents — the AI version of Shadow IT, deployed by business units without security oversight — have reached critical mass. The vendors are responding to a problem that already exists on customers' networks. That's the most convincing infrastructure adoption signal I've seen in this sector all year.
The deeper relationship — and this is the part most observers miss — is that security market formation catalyzes Agent adoption rather than constraining it. Every CTO I've discussed scaling Agent deployment with names "we can't control the risk" as the blocker. When security products become available in standardized categories — discovery, blocking, compliance, deception — enterprises gain the control structures they require for production deployment. The Black Hat vendor wave is the enabling event for the next phase of Agent adoption.
The strategic battleground isn't the current ten vendors. It's the MCP control plane. Anthropic wants MCP to remain an open standard, but its security evolution now determines whether the ecosystem fragments into walled gardens — Microsoft's controlled Copilot Studio corridors, OpenAI's managed Agent stacks — or matures into something like OAuth for tool calling, with baked-in identity, fine-grained authorization, and cross-server isolation. The security vendors that launched at Black Hat have implicitly bet their products on standardization. If enterprises flee the open ecosystem's security deficiencies for closed, safer platforms, those MCP-specific products lose value overnight. Watch the MCP spec's evolution from 0.x to 1.x. That version chart is the real competitive battleground.
For buyers: avoid the hype, demand baseline maturity evidence, and let the platform players tip their hands first. The technical tier of this wave runs from POC to early production; genuine runtime-blocking with verifiable low false-positive rates is still an open slot. Also watch for pricing model evolution from per-endpoint to per-Agent-activity — the unit economics of this market are still undefined.
For market observers: track the consolidation clock. If Microsoft and CrowdStrike enter within two quarters, the independent Agent security segment gets absorbed into platform modules within 24 months. If they stay out, a real ADR category forms with identifiable leaders.
For macro types like me: the Agent security rush was never primarily about vulnerabilities. It was about liquidity — vendor attention, conference mindshare, early budget capture chasing the newest infrastructure wave. Liquidity doesn't wait for permission, and it never waits for security to be solved. It flows to whatever surface is newest, organizes itself into products, then into standards, then into a market that eventually earns its revenue.
The market declared itself in 48 hours. Now it has to prove itself over the next 48 months.