Series 01 · The Search–Citation Gap № 03 of 03 ● AI Security division

The Category That Got Acquired Before It Got Built.

AI Security is the steepest demand curve in cyber right now. Three of the four canonically cited vendors have already been absorbed into Cisco, Palo Alto, and Check Point. The citation graph is months behind the deal flow — and the engines are still telling buyers to look at dead startup names.

The pair · Demand side · Category demand

The steepest curve in cyber.

Term12-mo searchesYoY
ai security84,800+129%
prompt injection53,200+145%
ai security tools31,000+331%
agentic ai security18,150+1,752%
ai security solutions17,130+287%
ai security platforms6,940+1,442%
Google US, last 12 months vs. prior 12 months. Source: MyTelescope.
The pair · Demand side · Vendor brand search

The named pure-plays, all flat or contracting.

Vendor12-moYoYStatus
HiddenLayer38,200+27%Independent — but collision-tainted (neural-network "hidden layer")
Protect AI20,780−26%Acquired by Palo Alto Aug 2025 — ships as Prisma AIRS
Robust Intelligence7,660−74%Acquired by Cisco Aug 2024 — sunset into Cisco AI Defense
Lakera AI6,960−4%Acquired by Check Point 2025
Brand-collision tax is at its maximum in this category — "Lakera" against the LA Lakers, "HiddenLayer" against neural-network architecture, "Protect AI" against UniFi cameras, "Robust Intelligence" against research papers on robust AI.
The pair · Citation side

The engines still cite the acquired names.

VendorEngines citingAcquisition status
Lakera4 / 4Check Point · 2025
HiddenLayer4 / 4Independent
Protect AI / Prisma AIRS4 / 4Palo Alto · 2025
Robust Intelligence / Cisco AI Defense3 / 4Cisco · 2024
Mindgard · WitnessAI · Prompt Security · Lasso · Wiz AI-SPM2 / 4Independent (Wiz now Google)
Query: "best AI security vendor for protecting LLM applications and GenAI workloads in 2026." Fanned across Perplexity, OpenAI, Grok, Gemini.

What this category did differently.

AI Security is the steepest demand curve in cyber right now. The umbrella term ai security is up 129% year-over-year. Prompt injection is up 145%. AI security tools is up 331%. Agentic ai security is up 1,752% — it barely existed two years ago.

Now ask the four AI engines who the best AI-security vendors are. Perplexity, ChatGPT, Grok, and Gemini all cite the same canonical four: Lakera, HiddenLayer, Protect AI, and Robust Intelligence.

Three of those four have already been acquired. Robust Intelligence went to Cisco in August 2024. Protect AI went to Palo Alto Networks in August 2025 — it ships now as Prisma AIRS. Lakera went to Check Point in 2025. The pure-play AI-security category got built and consolidated inside an eighteen-month window.

The citation graph hasn't caught up. The engines still recommend the acquired names because the open-web evidence still references them — blog posts, comparison sites, the vendors' own pre-acquisition pages. Buyers click through to absorbed brand pages and bounce.

The argument

AI citation is the slowest-decaying inventory of who used to matter. Right now it's pointing buyers at suite SKUs wearing dead startup names.

The new sub-quadrant: absorbed but still cited.

The frame from the first two pieces — brand search × AI citation, four quadrants — needs a third axis for this category: acquisition state. A vendor cited by all four AI engines but already inside a larger acquirer occupies a unique position. Pricing power and category narrative live with the acquirer. Brand equity and citation share live with the dead name.

That's the cleanest argument for why citation has to be tracked separately from acquisition-status feeds: they decay on different clocks.

Pattern reproduced.

Across three categories — MDR, CNAPP, AI Security — the same instrument produced three sharper versions of the same lesson:

  • MDR — citation universal across the top four; brand search contracting across the top three; Expel is the cleanest "citation without search" case.
  • CNAPP — category-term inversion (acronym down 45%, full term up 269%); every vendor's brand search contracting 30 to 53%; Aqua Security holds 13,820 brand searches with zero AI citations — the most-exposed quadrant.
  • AI Security — category demand up 129 to 1,752%; three of the four cited pure-plays already absorbed into larger acquirers; the citation graph still recommends them.

The frame holds. The lesson for any category forming under AI-mediated discovery: the buyer's mental model is being trained by engines whose training data is months behind the deal flow. The vendor who wins the next eighteen months in AI security won't be the one with the cleanest product. It'll be the one whose name the engines learn next.

Read Dispatches →