

The AI security market raised $8.5 billion between 2024 and 2025. Most of it went to the wrong problems.
Less than 5% funded protection for LLMs, RAG systems, and model supply chains—the actual attack surface where breaches are happening. The rest went to legacy security vendors rebranding decade-old WAF technology with "AI-powered" labels, governance platforms documenting compliance before anyone achieved actual security, and marketing spend positioning products that don't solve the problems CISOs are hiring for.
Meanwhile, production systems are getting compromised through attack vectors that didn't exist three years ago.
Microsoft Copilot was compromised via crafted email in June 2025 (EchoLeak, CVE-2025-32711). The attack worked because Copilot auto-processed Markdown reference links in messages without sufficient sandboxing. Microsoft spent over $2 million in emergency engineering time and broke three Copilot integrations during the emergency patch cycle.
Research from Anthropic, UK AISI, and the Turing Institute demonstrated that five adversarial documents can control 90% of RAG retrieval across million-document knowledge bases. That's not a theoretical proof of concept—it's reproducible methodology that works against production RAG deployments most enterprises are running today for customer support, internal knowledge bases, and document Q&A systems.
Model supply chain attacks have gone from research papers to operational reality. Over 100 malicious models were identified on Hugging Face and PyTorch Hub in 2024-2025, distributed through repositories seeing 2.1 billion monthly downloads. ReversingLabs documented a "nullifAI" technique that exploits three zero-days in Picklescan itself, the tool most teams rely on for model scanning. When your security scanner has exploitable vulnerabilities, you have a supply chain problem.
DeepSeek's DeepThink-R1 and Grok 4 both shipped with training data backdoors that persisted for months. DeepSeek learned backdoors from poisoned GitHub repositories. Grok 4 acquired a universal jailbreak trigger ("!Pliny") from contaminated Twitter training data. These weren't targeted attacks on niche models—these were flagship releases from well-funded labs with security teams.
The pattern is clear: the threats are operational, they're being exploited in production, and they map to architectural decisions most security teams haven't addressed because they're buying vendor solutions for different problems.
Gartner reported in October 2025 that 73% of enterprises cite security concerns as the primary barrier to AI deployment. That number has been climbing since mid-2024, which means the billions spent on AI security aren't translating to deployment confidence.
The problem isn't lack of available solutions. It's that most teams don't know which threats to prioritize, which vendors actually work, or what sequence to implement controls. The market gives them 40+ vendors across six overlapping categories, marketing materials that all claim comprehensive coverage, and analyst reports that rank vendors by feature matrices instead of what they prevent in the real world.
So teams default to familiar patterns. They start with guardrails because prompt injection is well-documented and the vendors are mature. They buy governance platforms because the EU AI Act deadline is August 2026 and documentation feels like progress. They evaluate Secure Email Gateways for AI-generated phishing because that maps to an existing budget line and procurement path.
What they should be doing: fixing supply chain security first, building RAG security themselves because no vendor solves it well, then layering guardrails and governance only after fundamentals are addressed. But that sequence requires making build-vs-buy decisions most security teams aren't staffed to make, prioritizing engineering work over vendor purchases, and accepting that some critical controls can't be bought off the shelf yet.
The market created this problem by overfunding vendor solutions for narrow slices of the threat landscape while underfunding the tooling, frameworks, and implementation guidance for the harder problems. Five-person startups raised $50 million Series A rounds for guardrails platforms while open source projects addressing model integrity got GitHub stars but no institutional backing.
Over the next few weeks, we're publishing a six-part analysis of the AI security market that maps what vendors actually solve to what's actively exploited in production.
Part 2: ranks the top threats by operational priority—not OWASP categorization or theoretical severity, but what's getting exploited right now and what it costs when you get hit. Supply chain poisoning, zero-click prompt injection, model extraction, and training data poisoning get detailed breakdowns with real incident data and detection guidance.
Part 3: maps the vendor landscape across six categories: LLM Security & Guardrails, Model Integrity & Supply Chain, Data Privacy & Confidential Computing, Enterprise Infrastructure & Platforms, Governance & Compliance, and the Open Source Ecosystem. For each category, we identify which vendors lead, which are feature-complete versus vaporware, and where the gaps are that you'll be building yourself.
Part 4: covers what works versus what doesn't. We document the four failure modes teams hit most often: buying guardrails before supply chain security, relying on detection without architecture, implementing governance before fundamentals, and waiting for RAG security vendors that are 12-18 months behind the threat. We also cover what works conditionally—when open source makes sense versus when you need commercial SLAs, and when governance platforms justify the cost.
Part 5: provides the implementation sequence that works: supply chain first (weeks 1-8), RAG security second (weeks 9-16), guardrails third (weeks 17-24), compliance only if required (month 6+). Includes budget ranges for commercial versus open source approaches and resource requirements.
Part 6: forecasts where this market goes: scenarios for vendor consolidation by Q4 2027, whether prompt injection stays architecturally unfixable, and why open source likely dominates by 2028.
At the end of the series, we're releasing a comprehensive market guide with vendor evaluation scorecards, RFP question templates, and implementation checklists. That will be a gated asset—we'll share details when it launches.
This series is written for security leaders making vendor decisions in the next 90 days, teams building AI security programs from scratch, and organizations that deployed AI without security and now need to retrofit defenses. If you're spending $500K or more on AI security and questioning whether you're buying the right things, this will help you prioritize.
Part 2: AI Security Threats Ranked By What's Actually Exploited.