$1 in Security for Every $735 in AI. That's the Real $234 Billion Question.

$1 in Security for Every $735 in AI. That's the Real $234 Billion Question.

Amir OfekAmir Ofek· CEO - Co-founder of aizome6 min read

Gartner's prediction that agentic AI will disrupt $234 billion in SaaS spending by 2030 has been getting a lot of attention. It should. The scale of the reallocation is significant enough to reshape enterprise software markets, alter vendor relationships that took decades to build, and create a new generation of winners and losers in enterprise technology.

But there is a number that tells a more urgent story than $234 billion.

$1 in AI security for every $735 in AI capability.

That ratio - documented in Speakeasy's 2026 AI Governance report - describes where most enterprises actually are today. Three orders of magnitude of imbalance between what organizations are spending to deploy AI and what they are spending to govern it.

That imbalance is the real question. Not whether the $234 billion gets reallocated; it will. But which side of the governance gap your enterprise is on when it does.

The Reallocation Is Already Happening

The Gartner SaaS disruption number describes a structural shift that is already in motion.

AI agents are replacing the human activity that justified per-seat SaaS pricing. When a Finance agent processes vendor invoices autonomously, the seats in the ERP that justified the license count don't get renewed. When a customer service agent handles tier-one resolutions end to end, the per-agent contact center licenses shrink. When a code review agent replaces a workflow that required three engineers, the developer tooling subscriptions consolidate.

This is not a future scenario. GitHub, Zendesk, and Workday have already moved to outcome-based pricing because their largest customers are making exactly these calculations right now.

The enterprises capturing value from this reallocation are deploying AI agents into their core business processes - Finance, HR, Sales, Operations, IT - with the confidence to expand scope as agents demonstrate value. They are compounding the productivity gains while their peers are still running pilots at the edges.

What separates the compounders from the pilots? It is not the quality of the AI. It is the governance infrastructure that makes enterprise leaders confident enough to deploy agents into consequential workflows.

Why Security Should Not Be the Barrier

Here is the finding that should be on every enterprise AI leader's agenda.

Stanford's 2026 AI Index found that security and risk are now the primary barrier to scaling agentic AI, cited by 62% of organizations. It outranked technical limitations and regulatory uncertainty by 24 percentage points.

The constraint is not the model. The models are good enough. The constraint is not the use case. The business case is proven. The constraint is that most enterprise leaders do not trust their governance infrastructure enough to deploy agents into the workflows where the real value lives.

That distrust is rational. The 2026 CISO AI Risk Report surveyed 235 large-enterprise security leaders and found that 92% lack full visibility into their AI identities, 86% do not enforce access policies for AI identities, and 71% report that AI systems create compliance gaps that existing tools cannot close.

These are not organizations that haven't thought about AI governance. These are organizations that have thought about it and found that their existing infrastructure is insufficient. They are right to be cautious. The question is whether caution translates into building the infrastructure that resolves it, or staying in the pilot stage while competitors compound.

The $1 to $735 Problem

The ratio itself deserves more attention than it gets.

$1 in AI security for every $735 in AI capability is not an accident. It reflects how enterprise technology investment decisions actually work. Capability investment has a clear ROI story: productivity gains, cost reduction, competitive positioning. Security investment has a harder ROI story: incident avoidance, compliance readiness, risk reduction. The capability story wins budget conversations. The security story wins incident postmortems.

The consequence of that imbalance, at the scale of enterprise AI deployment, is a growing population of AI agents operating in consequential workflows with governance infrastructure that is three orders of magnitude underpowered relative to the capability being deployed.

Every agent operating without a verified identity is a potential accountability gap. Every agent operating without organizational intent capture is a potential scope violation. Every agent operating without runtime behavioral governance is a potential incident waiting for the right trigger — a workflow change, a prompt manipulation, a model update to surface.

At $1:$735, the trigger arrives before the infrastructure does. Every time.

What the Enterprises Capturing the $234 Billion Have in Common

The reallocation is not inevitable for every enterprise. It is inevitable for the market. But which specific organizations capture the value of that reallocation, and which ones absorb the costs, depends on a specific set of decisions being made right now.

The enterprises on the winning side of the $234 billion shift share four characteristics, based on what we see in the organizations deploying AI agents at scale with confidence.

They treat governance as infrastructure, not compliance. The distinction matters. Compliance-oriented governance is built to satisfy an auditor. Infrastructure-oriented governance is built to enable deployment. The organizations deploying agents confidently built governance infrastructure first, not because a regulation required it, but because they understood that governance is what makes deployment at scale possible.

They know what is running in their environment. Not the approved list. The actual list. The number of AI agents operating without formal registration in most enterprise environments is significantly higher than any security team's inventory. Organizations that invest in AI know what they have, which means they can govern it, which means they can trust it with more consequential work.

They have answered the accountability question before the incident. Every agent has a verified identity. Every agent action is traceable to a human authorization - making AI agents accountable. When something goes wrong - and something will go wrong - the investigation has a starting point. The organizations that have not answered the accountability question before the incident are the ones that spend months in remediation instead of deployment.

They have runtime governance, not just provisioning controls. Knowing what an agent is permitted to do at provisioning time is necessary but not sufficient. Knowing what it is actually doing right now - whether its behavior is consistent with its organizational intent, whether it has drifted, whether the chain it is operating in is producing outcomes consistent with what was originally authorized - is what makes deployment into sensitive workflows defensible.

The Business Case for Getting the Ratio Right

The $1:$735 imbalance is not sustainable as AI deployment scales. The question is what forces it to correct.

For some enterprises, the correction will be forced by an incident. An AI agent causing a material breach, a compliance violation, a surge of token consumption, or an unauthorized transaction at a recognizable company will make the governance investment undeniable. Those enterprises will spend the next 12 months in remediation mode rather than deployment mode. The cost of the incident will dwarf the security/identity investment they avoided.

For others, it will be forced by regulation. Enforcement of the EU AI Act is underway. FINRA's 2026 oversight requirements are in effect. The regulatory clock that has been building is running. The enterprises that made the governance investment before the deadline will meet it without disruption. Those that didn't will meet them under pressure.

For the enterprises on the winning side of the $234 billion reallocation, the correction will be self-imposed because they understood that $1 in security for every $735 in capability is not a cost center ratio. It is a deployment ceiling.

The governance infrastructure that closes the gap is not what slows AI adoption down. It is what makes meaningful AI adoption possible. Every dollar invested in governing enterprise AI agents correctly is a dollar that expands the scope of what agents can be trusted with, which is how the compounding begins.

The $234 billion is moving. The enterprises that built governance infrastructure before they needed it will be in position to capture it. The ones that maintained the $1:$735 ratio will be trying to close the gap while the market moves without them.

Amir Ofek is CEO and Co-Founder of aizome, an Enterprise AI Agent Identity Fabric Platform and a founding player in the ARISE - Agentic Runtime Identity Security Enforcement - category.


Amir Ofek

Amir Ofek

CEO - Co-founder of aizome

Related content

The latest news, technologies, and resources from our team.

  • AI Agent Security Isn't Too Complex to Start. You're Just Missing the Map.

    AI agent security doesn't have to be overwhelming. Instead of chasing every new acronym or vendor category, start with three simple questions that cut through the noise. This practical framework helps CISOs prioritize discovery, identity, and runtime governance in the right order, so you can build an AI agent security strategy that actually works.

    Chen Pipek, CPO & Co-founder aizome

    Chen Pipek

  • AI Agents Don't Create Security Debt. They Collect It.

    Permissions copied from one employee to the next when someone changed roles. Temporary access granted three years ago and never revoked. Files shared "just for now" that are still accessible today. These are not new problems. They have been accumulating in enterprise environments for years, sitting underneath security programs that were doing their best but were never designed to surface them systematically. AI agents surface them all at once. At machine speed.

    Chen Pipek, CPO & Co-founder aizome

    Chen Pipek

  • 35% of Organizations Can't Shut Down a Rogue AI Agent. Are You One of Them?

    There is a question that boards are now asking CISOs that did not exist eighteen months ago. "If one of our AI agents went rogue right now - if it started doing something it was never supposed to do - could you stop it? How long would it take?" According to Writer's 2026 enterprise AI survey, 35% of organizations admit they could not shut down a rogue AI agent if one emerged. Three surveys. Three methodologies. One consistent finding: a significant fraction of enterprises have deployed AI agents they cannot stop.

    Amir Ofek

    Amir Ofek

  • NIST Just Named Five AI Agent Identity Problems.

    When the National Institute of Standards and Technology publishes a warning about enterprise AI agent security, CISOs pay attention. NIST's NCCoE named five specific identity and authorization practices that present substantial security challenges for agentic AI systems. I am not going to claim that NIST endorses aizome. What I am going to do is walk through each of the five problems NIST names and show you the architecture we built to address them. Because the architecture NIST says enterprises need is the architecture aizome already built.

    Amir Ofek

    Amir Ofek

  • How Sales, Marketing, and Operations Teams Are Using Local AI Tools to Get Work Done And What Makes It Safe to Scale

    Between purpose-built agents and shadow AI tools is a third category that most enterprises have not yet built governance infrastructure to support. Local AI tools. Claude Cowork. Claude Desktop. Tools that connect to the systems an employee already uses, respond to natural language instructions, and produce work that previously required hours of manual effort. The tool is legitimate, the user is known, but the data access pattern is new, the workflows are ungoverned, and the boundary between "this employee's work" and "this AI tool's access" is not clearly defined in any existing identity framework.

Subscribe to the Aizome newsletter

Occasional, substance-first notes on making enterprise AI agents accountable. No spam; unsubscribe anytime.

We use your email only to send you our newsletter. See our privacy policy for how we handle your data. You can unsubscribe at any time.