The AI Revolution: Trends that are Shaping the Future of Cybersecurity
Introduction
Similar to the birth of the World Wide Web and cloud computing, AI is a technology that is revolutionizing the software market. The key players in this revolution are digital infrastructure providers, LLM companies, incumbent software platform vendors, AI-native start-ups (point solutions & platforms), in-house development teams, and AI orchestration layer providers that sit between the LLMs and all the other software players.
Mapping this market when it is evolving hourly and there is significant geopolitical and economic turmoil makes the endeavor more suited to streaming commentary than a conventional market analysis. But with a broad enough brush and a narrow enough canvas (cybersecurity product development), we can identify some trends that are informative for near- to mid-term cybersecurity product roadmaps.
The following excerpt is from Enea’s white paper “Understanding & Managing AI in Network Security“. It looks at the key AI market trends that are shaping the future of cybersecurity.
Infrastructure Trends
Data centers remain at the epicenter of a digital infrastructure investment supercycle, with global data center capacity expected to double by 2030. This growth will be increasingly decentralized as workloads shift from centralized clusters to regional hubs and edge locations.
In 2027, inference workloads could overtake training as the dominant AI infrastructure requirement. However, beyond the shift to inference workloads (which often need to be close to the sources producing and consuming data), decentralization is also being driven by sovereignty demands, and energy concerns. Energy challenges include scarcity, cost, long grid connection delays, Bring-Your-Own Energy mandates (BYOE).
Impact on Cybersecurity Roadmaps:
Energy efficiency, cost and distributed workloads won’t just shape infrastructure they will shape all AI software development, including cybersecurity. Expect:
- Increased attention to hardware‑aware development (optimization for GPUs, TPUs, NPUs, DPUs in addition to CPUs)
- Inference optimizations for cost and energy efficiency (model compression, batching, routing)
- Increased attention to system- and architecture-level security to help address an expanded attack surface due to distributed and composable AI.
LLM Trends
LLM Verticalization
To deliver ROI on astronomical investments, frontier models need to be the go-to base model for as many constituents as possible, such as developers of derivative models (e.g., fine-tuned models), commercial enterprise software suites, and in-house development teams. In addition, while frontier models may be converging on general capabilities, they are also producing use case-aligned capabilities to expand market share and increase stickiness in verticals (e.g., Claude for coding, Gemini for large corpus & real-time search, ChatGPT in customer service, etc.). And they are releasing capabilities that make it easier to develop, deploy and secure AI agents.
The result of this is LLMs are expanding their footprints up the vertical AI stack by integrating what have to-date been downstream functions, like model-agnostic agent development frameworks, agent harnesses and multi-agent orchestration, and even genAI applications (like Claude Code Security).
LLM Trends Impact on Software Vendors
Impact on General Software Market

Let’s look at that dynamic for the segments outlined above, including AI orchestration layer providers, incumbent software platform vendors, AI-native start-ups, and in-house development teams, with a special focus on the cybersecurity software market.
Impact on Downstream Orchestration Providers
If an AI orchestration layer provider specializes in genAI app and/or agent development and orchestration, they will feel competitive pressure from LLMs unless their offer is buffered by a compelling value prop, broad integration capabilities, and model-agnosticism. This is because, at present, much verticalization is still model dependent at root. For example, Claude Code Security can analyze any codebase, but it can’t function without Claude (input agnosticism is OK, even desirable, model agnosticism is not). The same applies to Anthropic’s recently released Claude Agent Teams agent harnesses and orchestration capability.

Impact on Incumbent Enterprise Software Platform Vendors
Some of the makers of enterprise productivity platforms are also frontier model companies and hence the primary LLM for platform AI capabilities is pre-determined (e.g., Google Gemini and Google Enterprise). Other general enterprise productivity platforms like Microsoft Enterprise, and domain-specific enterprise platforms like Salesforce, use multiple models (see for example Salesforce’s list of supported models). Overall, all such platforms could potentially benefit from model enhancements in security and orchestration, even if the choice of LLMs may be constrained by platform design or corporate policy.
Cybersecurity Platform Focus: Impact of LLM + AI Native Platform Trends
Like Salesforce, enterprise cybersecurity platforms are a domain-specific type of platform, and as with other types of platforms, LLM verticalization will likely add value to, rather than competing with, their offers. In fact, this enhancement effect is probably especially true for cybersecurity platforms – and for in-house developers of bespoke security apps too, because if LLM verticalized capabilities improve safety and security (like Claude Code Security and ChatGPT’s Lockdown Mode and Elevated Risk labels), they contribute to defense-in-depth security, which is a pillar of cybersecurity, and more needed than ever in the era of AI-powered attacks.
Other market buffers for cybersecurity platforms versus LLMs are that the cybersecurity market is relatively small compared to other enterprise software categories (so not the most attractive target), and CISOs have to meet reliability and budgetary demands and navigate insurance and regulatory compliance requirements. So the pragmatic choice is to remain with conventional security platforms.
Will today’s AI-native security platforms become simply “security platforms” tomorrow?
But conventional cybersecurity platforms do need to use acquisitions, integrations and in-house initiatives to fill AI gaps that LLMs and AI start-ups might address. They may also need to navigate price pressure from CISOs who could at least theoretically address specific functional AI gaps with in-house development projects.
And, at a more important level of market transformation, an important question arises: as AI penetrates conventional business systems, will today’s AI-native security platforms expand and evolve until they are the equivalent of today’s ‘conventional’ security platform?
It is the case today that if you look at AI-native security platform architectures, you will find network diagrams showing internal and external users, devices and data sources that resemble conventional network security paradigms, differing primarily in the exclusive focus on AI models, applications and users (i.e., agents).

Time will tell how this evolves (and everything is evolving fast!), but it is clear today that traditional cybersecurity platforms are integrating AI capabilities and reinforcing their market strengths, including:
Developing value-added services or functions that exploit their depth of domain experience and the value of the comprehensive data they can provide to customers.
- Enabling their customers to interact with that data and the tools they provide in the AI-native way they like – with natural language!
- Making ‘frictionless friction’ security options available, like a ‘any-browser’ runtime security option for safer interactions online.
- Thinking of AI agents as customers too!
- Leverage AI to enable customers to tailor their solution to their needs, demotivating them from developing an alternative in-house with AI coding.
Integrating Hybrid & Conventional IT Systems into AI-Native Security Platforms

Chief among these key technologies is deep packet inspection, which is the data and traffic intelligence backbone of enterprise security platforms including those mentioned above—SSE, SWG, CASB, NGFW/FWaaS, WAF, and DLP—as well as wide-area networking (SD-WAN) and integrated SD-WAN and SSE which brings all these components together under the familiar Secure Access Service Edge (SASE) label coined by Gartner, Inc.
For more information on deep packet inspection and AI, click here.
###
To discover more about AI and the challenges it brings to network security, download the full white paper on “Understanding and Managing AI in Network Security” below.

Developing value-added services or functions that exploit their depth of domain experience and the value of the comprehensive data they can provide to customers.