TOGETHER WITH
TL;DR
Most AI security spending is going to the agent: identity, authentication, guardrails.
The plane that actually gets breached is the data layers the agents can reach.
Identity and data are two halves of one control system, not two separate budget lines.
The AI security budget that will matter most is the one that unifies them, not the one that only governs the agent.
The Asymmetry
Open any AI security pitch deck this year, and the through-line is the same: govern the agent. Identify it. Authenticate it. Audit what it does. Set guardrails on its behavior. The entire conversation orbits around one question:
What is this thing, and what is it allowed to do?
"Identity" is the security layer that is supposed to answer this, but that's just one control plane.
There's another one, and it sits beneath every AI deployment that has ever worked or failed: the data that the model can access.
The data plane gets the least airtime yet absorbs the most damage. Every AI mishap in the last few years, with chatbots leaking customer records, copilots showing salary spreadsheets, and agents stealing IP, all stem from the data plane. These are diagnosed as "identity failures" after the fact, but the diagnosis is wrong. The failure lies in what the model could reach before anyone asked it a question, and that's the asymmetry of agents in the current state of the market. Most of the market is racing to build better locks for the agent.
The harder problem, and the more durable one, is governing what is on the other side of the door.
The More Things Change
The more they stay the same.
I wrote about this shape last year in the AI Security Shared Responsibility Model. The "security of using AI" is an evolving stack, with obligations on both identity and data planes at every interface, but the two were never meant to compete for time and budget. Identity tells you who or what is acting, and data tells you what they can touch. Run one without the other, and you have half of a system. You will have an identity layer with no awareness of the data beneath, or a data layer with no sense of who or what is asking the questions. Without bringing them together in concert, we’re just replaying the same old movie we’ve seen before.
In 2010, the cloud security debate got stuck on the same asymmetry: everyone wanted to talk about who could log into AWS, almost no one wanted to talk about what was sitting in those S3 buckets. It took a decade and a long parade of public breaches before "configure your buckets" became more important than "rotate your keys." AI is in the AWS-2010 phase of its own shared-responsibility maturity curve, and the data plane is the part still being treated as someone else's problem.
Sensitive data sprawl was already an unsolved problem before any of this, of course.
I wrote about it in Understanding Data Access Governance back in April 2021, before ChatGPT existed and before "AI Security" was a budget line item. The concept then was simple: most enterprises do not know what data they have, who can access it, or how that access changes over time. That was true in a world where access was mostly human and mostly slow.
AI has made that problem impossible to ignore. It's the same failure pattern, just at higher speeds. One of my current favorite sayings comes to mind: "Bad decisions at machine speed."
A modern AI deployment is, at its core, a sanctioned penetration test. It's a fast query engine that looks at every folder, drive, repo, and database the organization has ever collected. The model does not pause to ask whether the SharePoint site labeled "FY19 Comp Planning" is supposed to be readable by the finance copilot. It just reads it, summarizes it, and surfaces it to whoever asked a vaguely related question. The permissions that were merely sloppy in 2022 are now exfiltration paths in 2026.
I argued in Context is King that AI is what finally makes data loss prevention work: DLP needed context, and AI (finally) provides it. The inverse of that is the hardest part. A copilot rolled out on top of an ungoverned data estate is a discovery tool for the next incident response engagement, dressed up as a productivity feature.
The lifecycle picture matters here. AI failures rarely surface at the point everyone is watching. They start at the data layer, where access is too broad or quality is too low. AI then just amplifies the problem.
They slip past whatever governance was in place at launch, but is no longer current. By the time the impact is visible to the enterprise, the root cause is several steps upstream. In the overwhelming majority of cases, the root cause is the data itself (its quality, permissions, and lineage), not the model that reads it.
Governing the model catches almost none of this. Governing the chain has to start where it starts, and that's at the data plane.
The Control Plane You Already Have
In Governing the Ungovernable, I focused on the AI governance layer and how organizations decide what AI is allowed to do. This post is about the layer underneath that one, and should enforce the governance decisions once they are made.
Policies are the rules, but the data and identity planes are what enforce them. Attempting to do AI governance with a data plane, however, is a recipe for disaster. Both are required, and they belong in the same conversation.
The reason the two layers have to move together is mechanical. Most enterprise governance was written for systems that stopped changing after launch. Annual reviews, point-in-time audits, and snapshots of controls no longer work in the AI era. AI is the first technology at enterprise scale that does not sit still.
Agents are constantly multiplying and redeploying, everyone across the business is building new software, and it all requires access to data. The more data, the better the context (unfortunately for security teams).
Varonis saw this around the corner and put their Corp Dev team to work. In September 2024, Varonis raised $460 million through a convertible notes offering and used that capital to expand the data control plane into the surfaces AI workloads actually touch. The deployment of that capital (so far) has come in three waves:
In March 2025, Varonis acquired Cyral for about $26 million. This deal helps Varonis add database activity monitoring and structured data lineage to its data plane.
In August 2025, Varonis acquired SlashNext for about $106 million. This move brought email, the biggest unstructured data channel for many companies, into the same control plane.
In February 2026, Varonis acquired AllTrue.ai for about $180 million. This deal added an enforcement layer to the data graph that Varonis has built over the past twenty years.
Three acquisitions in eleven months, and each one of them extended that data plane into a data surface it didn’t previously have access to. Varonis made the bet that every place sensitive data lives is where the AI layer must understand what it is looking at in a secure way. You need that visibility from one holistic graph, not three separate ones. The challenge and the power of a platform like Varonis is its ability to coherently weave those threads into a central point of visibility and control.
When a copilot decides what to show in response to a user query, the key factor is the data plane. It determines who can see what. This distinction keeps "useful answers" separate from "exfiltration events." If the models can reach that data, they most certainly will at some point without visibility and enforcement guardrails. It's the exact same models as with humans, but just applied to this new and very large consumer base.
An AI security program built on a mature data governance stack isn't a nice-to-have anymore. It's the load-bearing wall under every AI rollout in the enterprise, whether the enterprise knows it's leaning on it or not.
Why the Data Plane Compounds
In "The AI Security Absorption Has Begun" post, I talked about how the broader "AI Security" domain is on a faster consolidation curve than any previous wave in the industry.
Back in "Security, Funded #210" (the same issue where Varonis announced its acquisition of SlashNext), I wrote:
... Anything that has a unique or novel dataset…or anything that can control the integration, authentication, and authorization choke points for AI workflows, is a really hot commodity right now. Earlier this year and over the last two years, the roll-up point focused mainly on data discovery and posture management.
Agent capabilities are commoditizing fast. What's fragmenting is everything around them. Over the past three years, around 49 venture-funded companies in "AI Governance" have appeared, according to the Return on Security Signal dataset. Some notable names include Knostic, AIceberg, Noma, Pillar Security, Onyx Security, Capsule Security, and Trustwise AI. Each of these companies is pitching some slice of how AI agents authenticate, what they can access, and how that behavior is supervised.
Stack the adjacent categories on top, with Non-Human Identity Security, Identity Threat Detection and Response (ITDR), and a cohort of post-2022 identity and access management startups now focusing on AI agents and machine identities, and you've got a real party. That's at least 70 unique companies, each trying to tackle authentication, authorization, observability, or lifecycle for AI workloads.
The data plane underneath them is doing the opposite, however, and that's because of one constant factor:
Data outlives agents
Those customer records written back in 2018, or the contract signed in 2021, are still there. The agent that read both of them last week will be deprecated, replaced, or re-architected within a few weeks to a few months. Even the model behind the agent will be a different version by the time this post is three months old. The data underneath is the only thing that is timeless. It's that asymmetry of data that makes the data plane the durable choke point.
In a category that is consolidating from the top down, value accrues to whoever owns the layer that does not move. The vendor that owns the agent gets disrupted by the next agent. The vendor that owns the identity layer for agents gets compressed by the platform that absorbs identity. The vendor who owns the data plane gets paid each time a new agent arrives because every new agent asks the same question: "Am I allowed to read this?" and the answer has to come from somewhere.
In the data plane, integrations, scale, and coverage are the network effects. Every connector to a new data source compounds the value of the existing graph. The companies that have been at this the longest have moats that keep getting deeper, while the agent layer above them is rebuilt every few months.
The data plane is hard to unbundle because its value comes from the connections between sources, not from the sources alone. The classification of a single SharePoint folder is almost worthless. But a graph showing all classifications, permissions, and access patterns across the entire enterprise? That, my friends, is what they call a "durable asset" in the biz.
Capital has been flowing into the data layer for years, of course. Just look at the explosive and short-lived DSPM category. This space attracted about $2 billion in startup funding from 2023 to 2025, and almost every major cybersecurity platform company has paid for a data-plane component.
AI Governance, the policy and enforcement layer, has seen more than 50 startups raise rounds within the same 3-year window. Agent-identity security is fragmenting on a similar curve, but both layers will likely have many winners. This is because policy and identity controls fit the use case and grow naturally with each new AI deployment.
The data plane underneath them all hits differently, however. You cannot run an enterprise on fifty competing answers to "who/what is allowed to see this file."
What This Means Going Forward
For security leaders staring down an AI security line item in next year's budget, the practical implication is a reshuffling of budget and priorities. A mapping of the data plane and how identities access it before the agent inventory is a logical step, and I think there are four questions worth answering:
What data do we have?
Where does it live?
Who can already access it?
And, what changes when we point an AI system at it?
Those four questions define the entire risk profile of AI deployments.
Most vendors do one of those four things well. A few do two. The handful that do all four, Varonis being a major player, are the ones who have been doing this work for long enough that what looked like a data-management product five years ago is now the load-bearing wall under every AI initiative in the enterprise.
The cyber industry has been learning (the hard way) that the agent layer, and what it means to be an “agent,” keeps changing, but the identity constructs and the data underneath do not. The vendors that win a share of the AI security budget going forward will be those already building the unification of the data and identity control planes.
Thank you for reading! If you liked this analysis, please share it with your friends, colleagues, and anyone interested in the cybersecurity market.

