The Funding Arrived After The Exploit
This week two startups raised money to secure "agentic AI" systems, Reco taking $55 million and Rig Security emerging from stealth with $12 million, both pitched as defences against autonomous AI agents run amok. In the same news cycle, SecurityWeek reported hackers already using ChatGPT's custom GPTs inside ClickFix attacks, and OpenAI itself pulled the launch of GPT-6.1 Astra to publish safety cases rather than ship it. The argument here is simple: the capital raised this week is chasing a threat model that attackers, not analysts, defined first, and the rest of the week's breach reports, from a Pentagon personnel agency losing data on 3 million people to a 1,500-location pizza chain confirming a cyberattack, shows the funding is arriving into an environment where far more basic failures are still going unpatched.
Listen to this piece 7 min
Two funding rounds landed this week for companies that secure "agentic AI", the term of art for AI systems that act on their own rather than simply answering prompts. Reco raised $55 million. Rig Security came out of stealth with $12 million aimed specifically at agentic AI identity risks. Both are serious sums for a category that barely had a name eighteen months ago. Both arrived in the same week SecurityWeek reported that hackers are already using ChatGPT's custom GPTs inside ClickFix attacks, a technique that tricks victims into running malicious commands themselves. The defence industry is still building the product. The attackers are already in production.
The Money Landed the Same Week as the Exploit
There's a pattern in security funding where capital chases headlines rather than incidents, and it's easy to be cynical about any round that uses the word "agentic" in its pitch deck right now. But the timing here is worth sitting with rather than waving away. Reco and Rig Security aren't responding to a hypothetical. The ClickFix reporting describes attackers using OpenAI's own custom GPT infrastructure as a delivery mechanism, which means the attack surface these two companies are pricing already has live traffic on it. Hackers were not waiting for a security company to name the category first. They had already built the attack, and the funding round showed up afterwards to price the damage.
This matters because "agentic AI security" as a pitch usually leans on a future tense: agents will act with more autonomy, agents will hold more credentials, agents will make decisions without a human in the loop, and organisations need to prepare now. That framing sells well to investors because it implies a market that's about to exist. What actually happened this week is that the market already exists, and the first documented misuse case beat the funding announcement to market by days, not years.
What the Breach Ledger Actually Shows
Set the agentic AI story next to the rest of the week's breach reporting and a different picture appears, one that the funding narrative mostly ignores. A Russian pizza chain with 1,500 locations confirmed a cyberattack after hackers claimed the breach first. The Arizona Supreme Court said hackers stole residents' personal data. The Pentagon's personnel agency disclosed a breach affecting 3 million people. Dutch police arrested a convicted hacker in the ShinyHunters investigation. Microsoft dissected a new strain, NeedyMantis, tied to the Daemon Tools hacking group. Kiteworks had to patch a critical flaw before it could bring customer systems back online.
None of that is agentic AI. It's credential theft, unpatched infrastructure, and organisations that got breached the ordinary way, the way organisations have been getting breached for a decade. A separate SecurityWeek piece this week, on four cyber threats with "big plans for the future", makes the same point from the analyst side: the threats worth worrying about aren't exclusively next-generation. Some of them are just competently run versions of attacks that already work. The Vietnamese man charged this week in a $16 million pig-butchering crypto scam didn't need an AI agent. He needed patience and a phone.
The Wordfence scan data tracked by the SANS ISC diary tells the same quiet story every week: the internet's baseline attack traffic, the automated scanning and probing that never stops, doesn't care whether your security budget went to an agentic AI startup or a patch management contract. It's still knocking on the same doors it always has.
The Frontier Lab Blinked First
The most telling data point of the week didn't come from a security vendor at all. OpenAI called off the launch of GPT-6.1 Astra and instead published safety cases for frontier training. Read plainly, that's the company building the underlying models declining to ship the next one on schedule because it wasn't confident enough in the safety work to defend it publicly. That's a company with more visibility into its own agent behaviour than any downstream security vendor pulling the handbrake.
Compare that to the confidence embedded in a funding pitch. A startup raising $55 million or $12 million has to describe a threat it can defend against, with a product roadmap and a defensible category. OpenAI, holding the actual model weights, chose to publish a safety case instead of a product. Those are two very different postures toward the same underlying uncertainty, and only one of them is honest about how unsettled the ground still is.
The Gap Nobody's Pricing
None of this means Reco or Rig Security are wrong to exist, or that their funding is wasted. Identity risk in autonomous AI systems is real, and someone has to build tooling for it before it becomes the next Pentagon-scale breach rather than after. But the sequence this week runs backwards from how security spending is supposed to work. Ideally, capital arrives ahead of the threat, buys time, and the exploit never gets written because the defence was already in place. That is not what happened here. The ClickFix reporting came out the same week as the funding, not months before it, which means the two startups are effectively racing a threat that has already shipped rather than getting ahead of one that hasn't.
There's also a quieter risk buried in a different story this week, one that has nothing to do with agentic AI at all: the report on using device linking to eavesdrop on WhatsApp and Signal. That's a reminder that plenty of the most exploitable weaknesses in modern communication and identity systems are boring, structural, and have nothing to do with autonomous agents. Money follows the interesting threat model, not necessarily the one doing the most damage. This week, both things happened to be true at once, and only one of them got a funding round.
The lesson isn't that agentic AI security is a bad bet. It's that the industry keeps discovering, round after round, that its funding cycle runs a step behind its adversaries' shipping cycle. Attackers don't wait for a market category to be named before they use it. They used ChatGPT's custom GPTs before anyone had priced the risk. The money arrived on time for the news cycle. It arrived late for the exploit.
Wyre's opinion bylines are editorial personas of Floof Digital LLC, not separate members of staff. Essays are produced with AI assistance under human editorial direction. How Wyre works.