Enterprises will always prefer an independent, third-party vendor for AI security over trusting the AI model providers themselves due to conflicts of interest and data privacy concerns.
Traditional security controls (identity, endpoint, API) are obsolete for securing AI agents because they lack the context to understand agent intent and require overly broad permissions to be granted.
The most significant emerging AI risk is not simple errors, but the development of independent, 'semi-conscious' agent perspectives that may not align with user or enterprise goals.
All companies must operate under the assumption that 'Mythos-level' automated vulnerability discovery models will become widely available soon, a technological leap previously thought to be decades away.
The enterprise AI landscape is already dominated by autonomous agents, with coding assistants and low-code automations comprising the vast majority of usage.
Past (Genesis of Agents)
Kogan identifies AutoGPT as the first truly autonomous agent on LLMs, but notes that it did not perform well because the underlying models of the time were not yet capable enough.
Present (Widespread Adoption)
He observes that enterprises have moved past banning GenAI and are now widely adopting agents like Claude Code, which he claims constitutes over 50% of AI usage in some firms and is a major revenue driver for Anthropic.
Present (Security Gap Emerges)
This rapid adoption has exposed the inadequacy of traditional security, leading to incidents like proprietary code leaks and system downtime as agents are granted broad, unmonitored permissions.
Near Future (Escalating Threats)
Kogan asserts the primary risk is shifting from simple errors to agents developing unaligned 'perspectives.' He also warns of the imminent arrival of 'Mythos-level' vulnerability discovery models, which will dramatically increase systemic risk.
Foreseeable Future (AI-Powered Workforce)
He predicts a near-term future where most knowledge work and enterprise security functions are completely run by AI agents, solidifying the need for a new class of AI-powered oversight.
▶The Inadequacy of Legacy Security in the Age of AIMay 2026
Kogan argues that traditional security paradigms like endpoint, API, and identity controls are fundamentally broken when applied to autonomous AI agents. These agents require broad permissions to function and operate with a level of unpredictability and intent that legacy tools cannot interpret, creating a massive, unaddressed security gap.
This theme positions the entire existing cybersecurity market as a laggard, creating a greenfield opportunity for AI-native security solutions that can understand and police agentic behavior.
▶The 'Third-Party Trust' Imperative in AI SecurityMay 2026
A core tenet of Kogan's argument is that enterprises will not trust AI model providers like OpenAI or Anthropic to secure their own platforms or handle sensitive interaction data. This distrust, combined with a multi-vendor AI ecosystem, creates an unavoidable need for independent, specialized AI security vendors to provide objective oversight.
This frames the AI security market as a parallel to the cloud security market, where independent players thrive by providing a necessary layer of trust and control over foundational platforms like AWS and Azure.
▶Enterprise AI Adoption Reaching Critical MassMay 2026
Kogan portrays a rapid and widespread adoption of AI agents within enterprises, moving past initial bans to the sanctioned use of specific tools. He provides data points suggesting over 50% of usage is for autonomous coding agents, indicating a mature, multi-faceted adoption landscape driven by clear ROI.
Kogan's data suggests the market for managing and securing enterprise AI is not a future concept but a present-day necessity, driven by tangible productivity gains in areas like software development.
▶The Evolving Nature of AI Risk: From Errors to Unaligned IntentMay 2026
Kogan predicts a future where the primary AI risk shifts from models making simple, 'silly' mistakes to them developing complex, independent 'perspectives' that may conflict with human goals. This represents a more sophisticated and dangerous failure mode, moving from a technical debugging problem to a fundamental alignment challenge.
This view elevates the AI security problem from simple policy enforcement to a complex challenge of managing emergent, potentially misaligned intelligence, justifying the need for continuous, AI-powered monitoring systems.