The Category That Got Acquired Before It Got Built.
AI Security is the steepest demand curve in cyber right now. Three of the four canonically cited vendors have already been absorbed into Cisco, Palo Alto, and Check Point. The citation graph is months behind the deal flow — and the engines are still telling buyers to look at dead startup names.
The steepest curve in cyber.
| Term | 12-mo searches | YoY |
|---|---|---|
ai security | 84,800 | +129% |
prompt injection | 53,200 | +145% |
ai security tools | 31,000 | +331% |
agentic ai security | 18,150 | +1,752% |
ai security solutions | 17,130 | +287% |
ai security platforms | 6,940 | +1,442% |
The named pure-plays, all flat or contracting.
| Vendor | 12-mo | YoY | Status |
|---|---|---|---|
| HiddenLayer | 38,200 | +27% | Independent — but collision-tainted (neural-network "hidden layer") |
| Protect AI | 20,780 | −26% | Acquired by Palo Alto Aug 2025 — ships as Prisma AIRS |
| Robust Intelligence | 7,660 | −74% | Acquired by Cisco Aug 2024 — sunset into Cisco AI Defense |
| Lakera AI | 6,960 | −4% | Acquired by Check Point 2025 |
The engines still cite the acquired names.
| Vendor | Engines citing | Acquisition status |
|---|---|---|
| Lakera | 4 / 4 | Check Point · 2025 |
| HiddenLayer | 4 / 4 | Independent |
| Protect AI / Prisma AIRS | 4 / 4 | Palo Alto · 2025 |
| Robust Intelligence / Cisco AI Defense | 3 / 4 | Cisco · 2024 |
| Mindgard · WitnessAI · Prompt Security · Lasso · Wiz AI-SPM | 2 / 4 | Independent (Wiz now Google) |
What this category did differently.
AI Security is the steepest demand curve in cyber right now. The umbrella term ai security is up 129% year-over-year. Prompt injection is up 145%. AI security tools is up 331%. Agentic ai security is up 1,752% — it barely existed two years ago.
Now ask the four AI engines who the best AI-security vendors are. Perplexity, ChatGPT, Grok, and Gemini all cite the same canonical four: Lakera, HiddenLayer, Protect AI, and Robust Intelligence.
Three of those four have already been acquired. Robust Intelligence went to Cisco in August 2024. Protect AI went to Palo Alto Networks in August 2025 — it ships now as Prisma AIRS. Lakera went to Check Point in 2025. The pure-play AI-security category got built and consolidated inside an eighteen-month window.
The citation graph hasn't caught up. The engines still recommend the acquired names because the open-web evidence still references them — blog posts, comparison sites, the vendors' own pre-acquisition pages. Buyers click through to absorbed brand pages and bounce.
AI citation is the slowest-decaying inventory of who used to matter. Right now it's pointing buyers at suite SKUs wearing dead startup names.
The new sub-quadrant: absorbed but still cited.
The frame from the first two pieces — brand search × AI citation, four quadrants — needs a third axis for this category: acquisition state. A vendor cited by all four AI engines but already inside a larger acquirer occupies a unique position. Pricing power and category narrative live with the acquirer. Brand equity and citation share live with the dead name.
That's the cleanest argument for why citation has to be tracked separately from acquisition-status feeds: they decay on different clocks.
Pattern reproduced.
Across three categories — MDR, CNAPP, AI Security — the same instrument produced three sharper versions of the same lesson:
- MDR — citation universal across the top four; brand search contracting across the top three; Expel is the cleanest "citation without search" case.
- CNAPP — category-term inversion (acronym down 45%, full term up 269%); every vendor's brand search contracting 30 to 53%; Aqua Security holds 13,820 brand searches with zero AI citations — the most-exposed quadrant.
- AI Security — category demand up 129 to 1,752%; three of the four cited pure-plays already absorbed into larger acquirers; the citation graph still recommends them.
The frame holds. The lesson for any category forming under AI-mediated discovery: the buyer's mental model is being trained by engines whose training data is months behind the deal flow. The vendor who wins the next eighteen months in AI security won't be the one with the cleanest product. It'll be the one whose name the engines learn next.