Every AI security vendor briefing this year opens with the same slide, a graph showing AI adoption racing ahead of AI security spend. The graph is not wrong. Gartner's own numbers back it up. What the slide never shows is that the vendor presenting it usually sells into the smaller of the two categories on that graph, the one actually protecting the AI, and the pitch works by making the buyer feel behind before a single feature gets demonstrated. That gap is real. Closing it requires knowing which category you are actually short on, and most CISOs are shopping in the wrong aisle.

This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.

Where The Money Actually Goes

Gartner's AI spending forecast, published in the fourth quarter of 2025, put worldwide spend on AI-amplified security tools, meaning AI used to power detection and response, at 49 billion dollars for 2025. Spend on securing AI itself, meaning protecting the models, training data, and inference pipelines those tools depend on, came to 2.8 billion dollars, about 5.5 percent of the total AI cybersecurity market. Vendors selling AI-powered SOC copilots are competing in a market seventeen times larger than the one selling AI security posture, guardrail, and red-teaming tools. That imbalance is not a scandal. It reflects a real ordering problem. Boards fund what shows a return quickly, and a SOC copilot has an obvious use case on day one. A tool that reduces the odds of a prompt injection incident has a payoff that stays invisible until the incident does not happen.

The Four Categories Worth Learning

Gartner groups the buyer-relevant part of this market under AI Trust, Risk and Security Management, structured across four layers covering governance, discovery of AI use across the organization, protection of models and data, and application security specific to AI systems. In practice that maps to four categories a CISO will actually get pitched.

AI security posture management tools inventory the models, datasets, and pipelines an organization runs and flag misconfigurations, similar in spirit to cloud security posture management but aimed at machine learning assets instead of cloud resources.

Guardrail and firewall products sit in front of a model at inference time and try to catch prompt injection, jailbreak attempts, and sensitive data leaving through the response. Lasso Security was named a representative vendor in Gartner's 2025 AI TRiSM Market Guide, in the governance and runtime enforcement category, alongside Lakera and Protect AI, two other named players commonly cited in this space.

AI red-teaming platforms automate adversarial testing against a model before and after deployment, a category HiddenLayer and CalypsoAI also compete in, often alongside the guardrail vendors above.

Agentic and non-human identity security is the newest and least settled category, built around the observation that an AI agent calling tools and APIs needs the same identity governance a human account gets, and mostly does not have it yet.

The Marketing Claim Every Buyer Should Test

In January 2026, fourteen researchers from OpenAI, Anthropic, and Google DeepMind published a paper called "The Attacker Moves Second," backed by a twenty-thousand-dollar prize pool for anyone who could break the AI defenses under test. They evaluated twelve published defenses spanning prompting, training, and filtering approaches, the same three categories most commercial guardrail products are built on. Every one of the twelve failed under adaptive attack. Prompting-based defenses fell to attack success rates of 95 to 99 percent once the attacker adapted to the specific defense in front of them. Training-based defenses fell to 96 to 100 percent. Techniques that worked included breaking a malicious request into innocent-looking fragments spread across multiple conversation turns, automated jailbreak generation through gradient optimization, and hiding instructions inside ASCII art.

This matters to a buyer because nearly every vendor demo in this category reports a defense success rate against a static benchmark, and static benchmarks are exactly what this research shows collapsing once an attacker knows what they are up against. A number on a slide that was never tested adaptively is not a security claim. It is a marketing claim wearing a security claim's clothes.

A Worked Example From The Buying Process

A regional insurer's CISO sits through a vendor demo for a prompt injection firewall. The vendor shows a dashboard reporting a 99.2 percent block rate against a public jailbreak benchmark. The CISO, having read the adaptive-attack research, asks three follow-up questions instead of signing. What is the block rate against an attacker who has access to the same benchmark and adapts to it? Does the product inspect multi-turn conversations for fragmented attacks, or only single prompts in isolation? What is the average time between a new jailbreak technique appearing in public research and a rule update shipping to cover it? The vendor cannot answer the second and third questions with a number, only a roadmap commitment. That gap, roadmap versus number, is the actual signal, and it only surfaced because the CISO knew which questions the marketing slide was built to avoid.

The Fair Case For Buying Anyway

The honest counterargument here is that a defense catching even half of unsophisticated attacks is still worth the license fee, because most attackers against most organizations are not fourteen researchers with a prize pool and gradient access to your specific model. Real-world attackers are opportunistic, and a guardrail product that stops the copy-pasted jailbreak prompts circulating on public forums has genuine value even if it collapses against a resourced, adaptive adversary. HiddenLayer's 2026 AI threat report found 31 percent of organizations do not know whether they experienced an AI security breach in the past year at all, which suggests the more urgent gap for most buyers is visibility, not defense sophistication. A product that at least tells you an attack was attempted is doing something no spreadsheet does today.

That argument holds, and it changes what the purchase should optimize for. Buy detection and logging first, defense strength second, because you cannot tune a defense against attacks you cannot see. The same report found 91 percent of organizations increased their AI security budget for 2025, but more than 40 percent put less than a tenth of that increase toward AI security specifically. The money is often already approved. It is being routed to the wrong line item.

Questions For Monday

Take these to leadership and the board before renewing or signing any AI security contract this year.

Which of the four categories, posture management, guardrails, red-teaming, or agent identity, actually matches the gap our last risk assessment identified, rather than the gap the vendor's pitch deck identified?

Has any vendor on our shortlist shown us a defense success rate against an adaptive attacker, or only against a static public benchmark?

Who owns AI security budget internally, and is that person the same one who owns the AI adoption budget, because HiddenLayer's research found most organizations report internal conflict over exactly that question?

If we cannot currently tell whether an AI system in production was attacked last quarter, why is defense sophistication the first thing we are shopping for instead of visibility?

This market is real and still forming, which means it has not yet been punished for the gap between claim and capability the way it eventually will be. Buy for the gap you can verify, not the one in the pitch deck.