$1 in Security for Every $735 in AI. That's the Real $234 Billion Question.

$1 in Security for Every $735 in AI. That's the Real $234 Billion Question.

Amir Ofek, aizomeAmir Ofek· CEO & Co-founder of aizome6 min read

Gartner's prediction that agentic AI will disrupt $234 billion in SaaS spending by 2030 has been getting a lot of attention. It should. The scale of the reallocation is significant enough to reshape enterprise software markets, alter vendor relationships that took decades to build, and create a new generation of winners and losers in enterprise technology.

But there is a number that tells a more urgent story than $234 billion.

$1 in AI security for every $735 in AI capability.

That ratio - documented in Speakeasy's 2026 AI Governance report - describes where most enterprises actually are today. Three orders of magnitude of imbalance between what organizations are spending to deploy AI and what they are spending to govern it.

That imbalance is the real question. Not whether the $234 billion gets reallocated; it will. But which side of the governance gap your enterprise is on when it does.

The Reallocation Is Already Happening

The Gartner SaaS disruption number describes a structural shift that is already in motion.

AI agents are replacing the human activity that justified per-seat SaaS pricing. When a Finance agent processes vendor invoices autonomously, the seats in the ERP that justified the license count don't get renewed. When a customer service agent handles tier-one resolutions end to end, the per-agent contact center licenses shrink. When a code review agent replaces a workflow that required three engineers, the developer tooling subscriptions consolidate.

This is not a future scenario. GitHub, Zendesk, and Workday have already moved to outcome-based pricing because their largest customers are making exactly these calculations right now.

The enterprises capturing value from this reallocation are deploying AI agents into their core business processes - Finance, HR, Sales, Operations, IT - with the confidence to expand scope as agents demonstrate value. They are compounding the productivity gains while their peers are still running pilots at the edges.

What separates the compounders from the pilots? It is not the quality of the AI. It is the governance infrastructure that makes enterprise leaders confident enough to deploy agents into consequential workflows.

Why Security Should Not Be the Barrier

Here is the finding that should be on every enterprise AI leader's agenda.

Stanford's 2026 AI Index found that security and risk are now the primary barrier to scaling agentic AI, cited by 62% of organizations. It outranked technical limitations and regulatory uncertainty by 24 percentage points.

The constraint is not the model. The models are good enough. The constraint is not the use case. The business case is proven. The constraint is that most enterprise leaders do not trust their governance infrastructure enough to deploy agents into the workflows where the real value lives.

That distrust is rational. The 2026 CISO AI Risk Report surveyed 235 large-enterprise security leaders and found that 92% lack full visibility into their AI identities, 86% do not enforce access policies for AI identities, and 71% report that AI systems create compliance gaps that existing tools cannot close.

These are not organizations that haven't thought about AI governance. These are organizations that have thought about it and found that their existing infrastructure is insufficient. They are right to be cautious. The question is whether caution translates into building the infrastructure that resolves it, or staying in the pilot stage while competitors compound.

The $1 to $735 Problem

The ratio itself deserves more attention than it gets.

$1 in AI security for every $735 in AI capability is not an accident. It reflects how enterprise technology investment decisions actually work. Capability investment has a clear ROI story: productivity gains, cost reduction, competitive positioning. Security investment has a harder ROI story: incident avoidance, compliance readiness, risk reduction. The capability story wins budget conversations. The security story wins incident postmortems.

The consequence of that imbalance, at the scale of enterprise AI deployment, is a growing population of AI agents operating in consequential workflows with governance infrastructure that is three orders of magnitude underpowered relative to the capability being deployed.

Every agent operating without a verified identity is a potential accountability gap. Every agent operating without organizational intent capture is a potential scope violation. Every agent operating without runtime behavioral governance is a potential incident waiting for the right trigger — a workflow change, a prompt manipulation, a model update to surface.

At $1:$735, the trigger arrives before the infrastructure does. Every time.

What the Enterprises Capturing the $234 Billion Have in Common

The reallocation is not inevitable for every enterprise. It is inevitable for the market. But which specific organizations capture the value of that reallocation, and which ones absorb the costs, depends on a specific set of decisions being made right now.

The enterprises on the winning side of the $234 billion shift share four characteristics, based on what we see in the organizations deploying AI agents at scale with confidence.

They treat governance as infrastructure, not compliance. The distinction matters. Compliance-oriented governance is built to satisfy an auditor. Infrastructure-oriented governance is built to enable deployment. The organizations deploying agents confidently built governance infrastructure first, not because a regulation required it, but because they understood that governance is what makes deployment at scale possible.

They know what is running in their environment. Not the approved list. The actual list. The number of AI agents operating without formal registration in most enterprise environments is significantly higher than any security team's inventory. Organizations that invest in AI know what they have, which means they can govern it, which means they can trust it with more consequential work.

They have answered the accountability question before the incident. Every agent has a verified identity. Every agent action is traceable to a human authorization - making AI agents accountable. When something goes wrong - and something will go wrong - the investigation has a starting point. The organizations that have not answered the accountability question before the incident are the ones that spend months in remediation instead of deployment.

They have runtime governance, not just provisioning controls. Knowing what an agent is permitted to do at provisioning time is necessary but not sufficient. Knowing what it is actually doing right now - whether its behavior is consistent with its organizational intent, whether it has drifted, whether the chain it is operating in is producing outcomes consistent with what was originally authorized - is what makes deployment into sensitive workflows defensible.

The Business Case for Getting the Ratio Right

The $1:$735 imbalance is not sustainable as AI deployment scales. The question is what forces it to correct.

For some enterprises, the correction will be forced by an incident. An AI agent causing a material breach, a compliance violation, a surge of token consumption, or an unauthorized transaction at a recognizable company will make the governance investment undeniable. Those enterprises will spend the next 12 months in remediation mode rather than deployment mode. The cost of the incident will dwarf the security/identity investment they avoided.

For others, it will be forced by regulation. Enforcement of the EU AI Act is underway. FINRA's 2026 oversight requirements are in effect. The regulatory clock that has been building is running. The enterprises that made the governance investment before the deadline will meet it without disruption. Those that didn't will meet them under pressure.

For the enterprises on the winning side of the $234 billion reallocation, the correction will be self-imposed because they understood that $1 in security for every $735 in capability is not a cost center ratio. It is a deployment ceiling.

The governance infrastructure that closes the gap is not what slows AI adoption down. It is what makes meaningful AI adoption possible. Every dollar invested in governing enterprise AI agents correctly is a dollar that expands the scope of what agents can be trusted with, which is how the compounding begins.

The $234 billion is moving. The enterprises that built governance infrastructure before they needed it will be in position to capture it. The ones that maintained the $1:$735 ratio will be trying to close the gap while the market moves without them.

Amir Ofek is CEO and Co-Founder of aizome, an Enterprise AI Agent Identity Fabric Platform and a founding player in the ARISE - Agentic Runtime Identity Security Enforcement - category.


Amir Ofek, aizome

Amir Ofek

CEO & Co-founder of aizome

Related content

The latest news, technologies, and resources from our team.

  • Why Token Spend Is the New Shadow IT Problem

    A decade ago, the shadow IT problem looked like this: employees signing up for SaaS tools with a credit card, bypassing procurement, running business workflows on software IT didn't know existed. The same problem is back. It looks different this time. And almost no organization has solved it. Token spend is the new shadow IT.

  • ServiceNow's CEO Just Confirmed It. 2.2 Billion Agents. 2.2 Billion New Identities.

    On ServiceNow's latest earnings call, Bill McDermott said something that stopped me. "There are 2.2 billion agents entering the enterprise globally. That's 2.2 billion new identities." That is the most important statement made about enterprise AI security on an earnings call this year. When a Fortune 500 CEO names agent identity as the central enterprise security challenge, in front of investors, on a quarterly earnings call, the category has officially arrived.

    Amir Ofek, aizome

    Amir Ofek

  • NIST Just Proved Rules Aren't Enough. Intent-Based Identity Is What Comes Next.

    Darktrace's conclusion from the NIST analysis is that AI security must shift from rules to behavior. This is right. But behavioral detection alone has a limitation that matters for enterprise AI agent governance: it tells you when something looks different. It does not tell you whether what is different is wrong. The answer is not behavior alone. It is identity and intent as the reference layer against which behavior is evaluated.

    Amir Ofek

    Amir Ofek

  • 7 Types of AI Agents Every Security Team Needs to Know (And How to Govern Each One)

    Most "types of AI agents" guides are written for the people building them. This one is written for the people who have to answer for what those agents do once they're running. Same seven architectures - rule-based, conversational, predictive, collaborative, adaptive, RPA, and cognitive — but classified by what actually determines risk: autonomy, system reach, and permission inheritance. Because a rule-based agent and a fully autonomous one don't belong under the same policy, and most enterprise AI risk programs stall exactly because they're treated like they do.

  • The Enterprise Guide to AI Agent Identity, Governance, and the ARISE Category

    Enterprise AI agents are operating in Finance, HR, Sales, Operations, and IT at organizations across every industry - accessing sensitive data, executing multi-step workflows, and making consequential decisions, often with no human in the loop. The identity and governance infrastructure designed to secure human employees and traditional machine identities was not built for this.

    aizome - Making AI Agents Accountable

  • Why an LLM Is Not the Core Component of Intent Analysis

    Most vendors policing AI agents are using an LLM as the core component of their intent analysis. We think that's the wrong architectural choice - and here's the more nuanced picture of what actually works at production scale.

    Chen Pipek, CPO & Co-Founder, aizome

    Chen Pipek

Subscribe to the Aizome newsletter

Occasional, substance-first notes on making enterprise AI agents accountable. No spam; unsubscribe anytime.

We use your email only to send you our newsletter. See our privacy policy for how we handle your data. You can unsubscribe at any time.