Our Takeaways from Latio's 2026 AI Security Market Report

If you are anywhere near AI security (which is almost everyone these days), this report is a must-read. (You can read the full report here.) Latio founder and the author of this report, James Berthoty, deeply understands this space and fully vets the products he writes about. The depth and expertise really do show.
The 2026 edition covers a market that Latio counts at roughly 400 AI security startups, backed by survey data from practitioners and security leaders. It traces how the space has evolved since its 2025 edition from "a disjointed landscape of solutions to unclear problems" and has arrived at the second wave of AI security that is converging around securing AI wherever it runs (i.e., the endpoint), not controlling how employees reach it.
James did an outstanding job vetting and distinguishing between the different categories and entry points for each vendor.

And where Latio's reports really shine, it closes with a buyer's guide that gives end users real recommendations for navigating it all.
Here are our takeaways and perspectives on that shift from the data + AI security lens.
The endpoint is now the control point for AI security
If you take one thing away from this report, it's that the endpoint is now the most important layer for AI security. Latio frames the evolution of the past year: the AI security challenge has narrowed to AI running on employee devices, and where you control the data moving through them.

We've seen the same, and we're glad the industry is narrowing in on where AI risk actually lives. A year ago, security teams were asking about which AI websites their employees were visiting. Now their primary concern is around the AI tools and agents running on machines they can’t see.
But even on the endpoint, there is breadth and nuance. The report maps the endpoint market from broader endpoint controls to OSS supply chain security, then places the emerging AI-focused vendors along their own spectrum, from intent-based EDR on one end to runtime monitoring of AI activity on the other.

That distinction matters and it’s clear that the market (nor end users) totally understand. We’ve shoved a ton of use cases and outcomes into "endpoint AI security." Some protect the machine, some protect the code, and some protect the data. They share a where, not a what.
Data security on the endpoint is a gap
Our other takeaway is that the what matters as much as the where. And the what is data. The report singles out DLP and Insider Threat as a distinct use case within AI security, naming endpoint DLP as one of the market gaps emerging vendors (including Bold) are moving into.

Latio points out that the endpoint security market has been stagnant for years. Device management on one side, attack prevention on the other, and not much built in between. Endpoint DLP sat in that gap, and it shows: too many false positives, constant tuning, and teams who eventually turned blocking off because it was stopping real work.
Latio's view is that AI changes this by reading the intent behind how data gets moved. Instead of matching a pattern and guessing at risk, a tool that understands what the data is and who is moving it can tell a real problem from someone doing their job.
Where Bold fits
At Bold, we've been building for that exact gap, and Latio recognized us for our "granular context and intent-based controls for protecting the data on end-user devices." AI governance, data loss prevention, and insider risk are three doors into one layer. The same core concern sits at the intersection of all three: data. What is the data? Who or what is moving it? Where is it going? AI is now the fastest-growing place those questions come up, but they are not new questions.
"AI security" may go down as one of the most disjointed and ill-defined spaces in infosec history. Hundreds of vendors describe overlapping capabilities in near-identical language, and the control points are still shifting. We deeply appreciate James and the Latio team's effort to demystify it and give end users practical guidance for picking the right solutions and vendors for their specific needs.
Read the full 2026 AI Security Market Report here.



