OpsControl.
Market Pulse · Cybersecurity

Security vendors race to own the AI control plane

AI moved from message to operating model, while balance sheets, trials and customer proof points were quietly reset.
Week of 21 September 2026 · built from 80 observed events over 14 days · 11 companies watched · 423 signals in 30 days · 30+ sources each

AI stopped being a theme and became the category frame

The clearest shift of the fortnight was not that cybersecurity vendors talked about AI. It was how completely AI displaced older positioning. On 15 Sep, SentinelOne changed its hero line from “The Autonomous Security Platform Built for Advantage” to “The World Runs on AI. We Secure It.” The same day, Palo Alto Networks moved its hero from identity chaos to “Let AI coding do more. With you in control.” On 16 Sep, Fortinet replaced event-led messaging with Gartner Magic Quadrant leadership for Hybrid Mesh Firewall.

CrowdStrike pushed the same line from the top. On 21 Sep, George Kurtz used CNBC to emphasise “agent states” and warn that AI-related cyber threats are already present. On 14 Sep, CrowdStrike launched a new autonomous product and released foundry-skills 1.5.0 with support for AI coding assistants including Claude Code, Codex, Copilot CLI, Cursor and Antigravity CLI. On 15 Sep, CrowdStrike and Wipro launched a CISO Command Centre.

The identity and exposure vendors followed. On 20 Sep, Okta’s CEO discussed AI agents in identity management as Helen Riley joined the board. On 17 Sep, Tenable was reported to be integrating OpenAI GPT Cyber Models to inspect community-created AI components. On 16 Sep, Proofpoint expanded insider-risk tools and AI-powered investigations into Microsoft 365. This is no longer feature dressing. The market is converging on a single claim: secure the agents, the code they produce, the identities they use and the data they touch.

The platform race is being financed and widened

Palo Alto Networks made the most direct inorganic move. On 14 Sep, it acquired Console, an IT help desk start-up, for $500mn, alongside reported 63 percent NGS ARR growth and a $282mn GAAP net loss. The signal is consistent with the homepage shift a day later: service workflows, developer control and security policy are being pulled into one operating layer.

Proofpoint’s reported pursuit of Varonis is the other large strategic marker. On 13 Sep and again on 19 Sep, multiple sources said Proofpoint was in advanced talks to acquire the data security company, with the potential deal described as worth billions. Proofpoint also appointed Brian Levey as chief legal officer and Puja Jaspal as chief people officer on 13 Sep, then expanded Microsoft 365 insider-risk coverage on 16 Sep. Leadership, product and M&A all pointed at the same surface: data movement inside the enterprise.

Tenable strengthened financial flexibility. On 17 Sep and 18 Sep, it raised $800mn in 0.25 percent convertible notes, added capped calls, ended its 2021 credit facility, announced plans for a $170.5mn share repurchase and payoff of a term loan. It also added Continental to its public customer wall on 17 Sep. That is not a sleepy exposure management vendor. It is a company preparing its balance sheet while the market reprices cyber risk around AI and infrastructure.

The real fight showed up in pages, ads and trials

The week’s most telling competitive movement was below the press-release line. CrowdStrike added 21 Falcon Shield product pages on 14 Sep, then on 20 Sep added 9 blog pages and 77 product pages while removing 85 product pages and one documentation page. In the same interval, it changed the site to feature “CrowdStrike is the only vendor named a Customers’ Choice for ITDR” and removed Fal.Con Las Vegas news framing. That is a fast handover from event momentum to proof and packaging.

On 14 Sep, CrowdStrike also added Firewall Management, Endpoint Detection and Response, Threat Intelligence & Hunting, Identity Protection and IT Hygiene to the Falcon Free Trial tier. A trial expansion of that breadth matters because it moves evaluation from a single wedge to a platform sample. It also landed while the company was adding AI security content, partnership material and developer assets, which makes the offer look less like a promotion and more like a funnel redesign.

Paid acquisition was synchronised across the category. CrowdStrike had 40 new Google ad creatives first shown from 26 Aug and running by 17 Sep. Palo Alto Networks had 40 new creatives by 20 Sep, Tenable 34 new creatives first shown 18 Sep, Qualys 24 first shown 18 Sep, SentinelOne 31 first shown 9 Sep, Okta 39 first shown 8 Sep, Proofpoint 28 first shown 2 Sep, Rapid7 14 first shown 17 Sep and Fortinet 20 first shown 11 Sep. The simultaneity is the point. When almost every major vendor refreshes message, pages and ads within the same fortnight, the market is not merely reacting to demand. It is trying to define the buying vocabulary before budget owners do.

Customer proof was edited with the same urgency. Darktrace introduced 30 new customer pages and removed 30 blog pages on 18 Sep, while adding a marine services resilience case study and logos for a US public interest law firm and a UK infrastructure services company. Fortinet added Pinery Water & Wastewater and published an OT security case study on 16 Sep, then refreshed customer logos again on 17 Sep. Rapid7 added two case studies on 14 Sep. These are small moves individually. Read together, they show vendors swapping generic education for vertical proof.

Operational trust remained the constraint

The fortnight also showed why the AI control-plane story cannot run on marketing alone. Palo Alto Networks had six CVEs published on 10 Sep across Prisma Access Agent and PAN-OS, covering information disclosure, privilege escalation, cross-site scripting, command injection and buffer overflow issues. Fortinet had CVE-2026-84390 published on 11 Sep with a CVSS score of 9.8 for FortiMonitorOnSight versions 7.2.0 through 7.2.7. CrowdStrike had CVE-2026-40058 published on 15 Sep with a CVSS score of 8.8 affecting the Falcon sensor for Windows.

Service reliability had its own drag. On 16 Sep, Qualys reported four minor incidents, including a delay in data processing on US Platform 3, intermittent login issues on IN Platform 1 lasting about 978 minutes, and patch deployment failures across shared platforms. On 17 Sep, Tenable reported a major connector normalisation failure for the Vulcan Platform in the EU region. On 20 Sep, Rapid7 reported four service incidents, including dashboard and reporting degradation in Vulnerability Management and a customer portal degradation incident with no impact lasting about 424 minutes.

None of these events changes the direction of travel. They do set the ceiling for trust. The vendors are asking customers to let AI agents, identity systems, code assistants and exposure engines sit closer to operational decision-making. In that context, vulnerabilities and status incidents are not background noise. They are part of the buyer’s assessment of whether a vendor can be the system of control rather than another system to control.

Pricing moves observed
CompanyChangeDate
CrowdStrikeFirewall Management, Endpoint Detection and Response, Threat Intelligence & Hunting, Identity Protection and IT Hygiene were added to the Falcon Free Trial tier.2026-09-14
The takeaway

Cybersecurity’s centre of gravity moved towards AI control this fortnight. SentinelOne, Palo Alto Networks, CrowdStrike, Okta, Tenable and Proofpoint all made dated moves around AI agents, AI coding, AI investigation or AI-secured identity and data. The sharper signal was operational: CrowdStrike widened its free trial on 14 Sep, major vendors refreshed ads almost simultaneously, Darktrace and others swapped broad content for customer proof, and Palo Alto and Proofpoint used M&A to extend the platform perimeter. Buyers are being taught a new category map. The constraint is trust, because CVEs and service incidents at CrowdStrike, Fortinet, Palo Alto Networks, Tenable, Qualys and Rapid7 show that the vendors racing to secure the expanded surface must also prove they can operate reliably on it.

Calls on the record

Each week this page takes a position and grades it in public once the horizon passes. Misses stay up. The full record.

open called 21 September 2026 · judged by 5 November 2026
CrowdStrike will expand its Falcon Free Trial tier to include additional AI security features within the next 45 days.
CrowdStrike's recent trial expansion and addition of AI security content suggest a strategic move to broaden its trial offerings to attract more users and showcase its AI capabilities.
open called 21 September 2026 · judged by 20 November 2026
Proofpoint will announce the acquisition of Varonis within the next 60 days.
Multiple sources have reported that Proofpoint is in advanced talks to acquire Varonis, and the strategic alignment in leadership and product expansion supports this move.
open called 14 September 2026 · judged by 29 October 2026
Proofpoint will announce a strategic partnership or acquisition related to data security within 45 days.
Proofpoint's reported talks with Varonis and its recent focus on expanding AI-powered investigations and SOC capabilities suggest an active interest in consolidating its position in data security, likely leading to a strategic move to enhance its offerings.
open called 14 September 2026 · judged by 13 November 2026
CrowdStrike's price cut on Falcon Go and Falcon Pro will lead to a reported increase in SMB customer acquisition within 60 days.
The significant reduction in pricing for Falcon Go and Falcon Pro, combined with added features like IT Hygiene, positions CrowdStrike to attract smaller businesses that previously found the products too expensive, making it a strategic move to capture a broader market segment.
open called 7 September 2026 · judged by 6 November 2026
Palo Alto Networks will introduce a new AI-driven feature or product specifically targeting incident response automation within the next 60 days.
Palo Alto Networks' acquisition of Console and its focus on AI security suggest an emphasis on automating security operations, including incident response, which aligns with their recent strategic moves and market positioning.
open called 7 September 2026 · judged by 6 November 2026
CrowdStrike will announce a new partnership or integration specifically focused on enhancing AI-driven cybersecurity for operational technology (OT) environments within the next 60 days.
CrowdStrike has been expanding its capabilities in AI-driven cybersecurity, particularly with its recent focus on agentic security and partnerships like the one with Cognizant for OT cybersecurity. This indicates a strategic move towards strengthening its position in the OT security market.

This is the public read. OpsControl customers see this market live: every signal, graded and evidenced, the day it happens.

Track your own market