What happens to endpoint security in the AI age?
Lots of opportunity to capture the market, but it's risky
Disclaimer: Opinions expressed are solely my own and do not express the views or opinions of my employer or any other entities with which I am affiliated.
I’ve intentionally made all of my posts free and without a paywall so that my content is more accessible. If you enjoy my content and would like to support me, please consider buying a paid subscription:
I’m back to writing about markets that are poised to expand as AI adoption deepens inside the enterprise. Last week, we looked at AI proxies and the critical need for a low-latency, high-throughput network layer to govern streaming tokens. That post triggered a flurry of conversations about endpoint security, and it made me realize we need to look closer at the machine itself.
Right now, the vast majority of local AI agents run directly on developer laptops. While companies like Cursor are pushing hard toward cloud-hosted development environments, which I believe is the inevitable future due to the operational logistics of laptops going offline, we are not there yet. It will take time to fully migrate the engineering runtime to the cloud. Until then, the endpoint remains the primary execution layer for autonomous code.
This newsletter is going to look a bit different from my usual market deep dives. I don’t have a single, definitive conclusion yet. Instead, I want to map out the structural changes happening on the machine and look at the real opportunities for both incumbent giants and emerging vendors.
The changing of the guard
Endpoint security is a story as old as time. In the 2010s, we witnessed a massive architectural battle as enterprises migrated away from static offices to the cloud and distributed laptops. That era marked a clear changing of the guard. We saw a shift from old-school, signature-based prevention platforms like Symantec and early next-gen attempts like Cylance, moving toward the reactive, response-driven EDR model pioneered by Crowdstrike.
It is clear who won that war, but the outcome was far from obvious at the time. I wrote a detailed breakdown on the fragility of that specific market in an earlier piece.
Building endpoint agents is notoriously brutal. It requires deep operating system introspection, hooking into system calls without triggering kernel panics or destroying battery life. Very few companies do this well.
However, my view is that you can actually get away with a subpar agent if you back it with an elite global infrastructure. Look at Cloudflare’s Warp agent for their Gateway product. The local software itself is incredibly lightweight and doesn’t do heavy lifting on the machine; it simply intercepts and routes local traffic to their global edge network, where the actual policy enforcement and inspection happens. Legacy secure web gateways like Zscaler used this exact blueprint to scale.
AI endpoint security will likely follow this same infrastructure pattern. Because almost all heavy LLM computation happens on a remote server rather than the local silicon, the endpoint agent doesn’t need to be massive. It just needs to be a performant traffic cop routing to a specialized proxy.
Management vs. security: The blurring line
If we set aside the raw proxy network layer, the remaining endpoint opportunities fall into two traditional buckets: management and security. Historically, IT handled management and InfoSec handled security, but the rise of autonomous agents is completely blurring that line.
To establish the baseline, traditional endpoint management is about visibility, patching, and software deployment. The dominant players here are Microsoft, Jamf for Apple ecosystems, and Tanium for massive enterprise fleets. This software exists to ensure laptops are compliant and up to date, and it is the mechanism used to deploy EDR tools like Crowdstrike and SentinelOne. The EDR tools then sit on the machine to hunt for active runtime threats and malware.
The endpoint matters more today than it ever has because AI agents are no longer just suggesting code; they are autonomously executing privileged actions, interacting with local shells, and modifying system configurations. When an agent has the privilege to run commands locally, a simple logic or hallucination error can lead to a severe incident. Consider a local agent trying to optimize a dependency loop, accidentally downloading an unvetted, malicious open-source package, and running it locally because it determined the package looked legitimate.
The IT operational trap
This is a highly complex market to sell into because enterprise IT teams are currently stuck in a structural trap. They are either heavily overstaffed or completely understaffed, with very little middle ground.
In bloated enterprises, IT teams are overstaffed with individuals performing hyper-specialized, repetitive operational tasks. AI is on track to completely eliminate these commodity roles. The catch is that when AI automates those tasks away, it is incredibly difficult for a bureaucratic organization to reallocate those specialized workers to higher-value engineering problems. Consequently, selling AI-enabled endpoint tools into these overstaffed legacy environments is a massive uphill battle.
The real growth market belongs to lean, modern startups that don’t have a dedicated IT department at all. In these companies, software engineers or operations generalists are forced to moonlight as IT administrators. Because these teams are small and focused on velocity, they represent the true AI theme: using autonomous software because a single human couldn’t possibly manage the workload without it. They need an agent that regularly handles endpoint patching, monitors fleet health, and auto-enforces compliance in the background without filing a manual ticket. There are other massive IT responsibilities like access provisioning and identity, but fixing the machine baseline autonomously is the core endpoint hurdle.
Mapping the contenders and the checkbooks
Right now, there is no obvious frontrunner for the agentic endpoint.
There is a non-zero chance that frontier AI labs like OpenAI or Anthropic could capture this layer. They already own the developer interface and are building their own security primitives. However, securing an endpoint requires continuous, passive system monitoring, which is a fundamentally different product architecture than on-demand, prompt-driven chatbot interactions.
Instead, Microsoft and Google have the most realistic shot at integrating AI natively into endpoint management. Microsoft has a natural monopoly on Windows endpoints, though they rarely build elegant management experiences outside their own ecosystem. Google, on the other hand, is uniquely positioned to build a cross-platform play. Following their massive acquisition of Wiz, Google Cloud commands an ecosystem that can link threat intelligence directly with cloud-to-runtime visibility. If Google leverages this combined footprint to push out from ChromeOS into macOS and Windows endpoint compliance, they pose a serious threat to traditional IT setups.
The legacy EDR giants like Crowdstrike and SentinelOne obviously have the kernel-level real estate to win this space. But their primary buyer persona is the traditional security operations analyst, a cohort that is historically slow to adopt AI due to organizational inertia. While Crowdstrike is actively pushing marketing around their AI capabilities, their actual core product development inside local agent runtimes moves at a legacy enterprise pace.
The most fascinating dark horse here is Tanium, particularly with their push into the Atlas platform. Tanium already possesses the rare platform architecture that merges IT operations with security visibility. Their new platform layer uses an ensemble of models to ditch traditional fixed modules in favor of dynamically generated pages tailored to what the user is working on, alongside features targeting local LLMs and Model Context Protocol (MCP) servers running on developer endpoints.
It is still too early to say if Atlas will deliver on this promise, and the platform undoubtedly has a long way to go, but it is highly promising. I am cautiously optimistic. I’ve argued in the past that complex, feature-rich legacy platforms that are historically difficult to use actually stand to benefit the most from AI. If you have spent nearly two decades building a massive matrix of deep features, you can use an AI natural-language interface to abstract that complexity away entirely. It is entirely acceptable to have a massive product if you can completely hide the plumbing behind an intelligent assistant.
Ultimately, who wins this market depends entirely on who holds the checkbook, and that is going to split down organizational fault lines. In AI-forward companies, the budget is essentially one big blob. They don’t care about internal territory wars; they care about macro efficiency, so any tool that saves aggregate headcount and automates the fleet will win.
In older, traditional companies, this market is going to be incredibly political. The rise of these unified AI endpoint platforms represents an opportunity for serious consolidation of certain IT and IT security responsibilities. How that plays out depends entirely on how executive leadership wants to steer the political ship.
The ultimate winner in the endpoint market will be the vendor that can thread a very narrow needle: maintaining the deep, performant system telemetry required by legacy enterprises while delivering a frictionless, highly automated product experience that allows lean companies to automate their entire IT footprint out of the box.




