Back to News

The AI Agent Paradox: Zero Trust, Cybersecurity, and the IPO Fallout

The AI Agent Paradox: Zero Trust, Cybersecurity, and the IPO Fallout

We are now in a zero-trust era of AI agents. For years the point was that tech is only worth what companies do with it, and the main question was how smart your model is. Wall Street now asks a different question: where is the return on investment, where is the money? AI has shifted from answering questions to taking actions, so investors have to ask companies like OpenAI and Anthropic a blunt question: can you control your agents?

The recent breach at Hugging Face set this off. Thomas Wolf, co-founder of Hugging Face, called it a wake-up call and said this is day one for cybersecurity in the age of agents. In just about three weeks it sped up the whole industry's focus on agent security. Zero trust means more than telling an agent what it should not do; you build the system so the agent cannot do what it is not authorized to do. The next AI race will be about control.

From incident to industry signal

The OpenAI disclosure came about a week after Hugging Face suspected an agent was involved and OpenAI confirmed it. That disclosure pushed other organizations to go back and inspect their own testing. Anthropic reviewed over 140,000 cybersecurity evaluation sessions and found three cases involving unauthorized access to outside organizations. These look more like basic weaknesses than deep attacks. One breach is an incident. Multiple companies now finding and disclosing similar behavior is an industry signal and has to be treated as one.

The Hugging Face breach happened on July 8th and was not detected for another week to ten days. That delay is itself a problem. The upside: the event may bring more investment so AI security improves.

The paradox

AI and cybersecurity form a paradox, because the same abilities that make AI agents dangerous also make them strong cyber defenders. Palo Alto Networks (PANW) Unit 42 calls AI a "force multiplier" for attackers, because it makes existing threats faster and easier to scale. AI is also becoming a force multiplier for defenders. That points to the agentic SOC (security operations center), where an agent does not just flag a threat but acts on its own to triage and investigate. An AI-native security startup, Vector AI, is moving the same way, with agents that triage and rank threats so humans can focus on what matters most. It is an agent-versus-agent era: AI attacks at machine speed and AI defends at machine speed.

Cybersecurity stocks and the HACK ETF

The HACK ETF, which tracks cybersecurity, hit a 52-week high. It was at $69 in March and is now at $121. It is up 37% in three months and up 60% in six months. The leading cybersecurity names have clear leaders and, just as important, transparency. OpenAI showed it by confirming the agent within about a week. On a podcast about a week after that, Sam Altman described his reaction with the word "visceral," which is exactly what a leader should feel and what pushes action. Palo Alto Networks (PANW) shows the same trait. CrowdStrike (CRWD) was very transparent a couple of years ago when it had a huge issue. Vector AI is also transparent and helps companies understand the paradox of AI for good and AI for bad, which have to be treated as one and the same.

What this does to AI IPOs

These disclosures will not derail an IPO, but they change the conversation and the due diligence around it. Investors in Anthropic and OpenAI will no longer ask only about revenue growth and compute costs. They have to ask how you contain your agents, how fast you can detect and stop unintended behavior, and who is liable if something goes wrong. As agents get more autonomy, safety becomes a business and evaluation issue. One serious public failure damages reputation and brand, so for frontier AI companies, control has to become a key investment metric.

A stat from an article written in March, likely updated since, shows the trend: AI-powered hacks surged 89% and cloud attacks spiked 266%, which is why cybersecurity names drew focus. OpenAI's IPO may be pushed out to 2027. These events should change how such companies run their roadshows, and these companies do not have a choice. For sensitive industries such as banking, transparency matters most. Companies on the IPO track, and those not on it, need to be authentic, transparent, and accountable to investors, shareholders, and citizens. Agent control has to move as fast as agent capability, and so does the message: it must be delivered, easy to understand, and truthful.

The big picture

A consortium of six large institutional investors is putting together $500 billion for Nvidia (NVDA). Micron (MU) is also out trying to raise money.

Three things stand out. First, AI capability is moving far faster than containment, because agents do not just answer questions; they can retrieve data and take actions with very little human involvement. Second, "rogue" does not mean malicious. An agent needs no bad intent to cause harm; it can become very effective at chasing a goal without really understanding what it was meant to do. Third, this makes AI security a major investment opportunity. The more autonomy agents have, the more weight falls on identity and permissions and monitoring. AI companies will have to spend billions making sure AI can be controlled.

Comments