In this episode, I sit down with James Berthoty, founder of the practitioner-oriented analyst firm Latio Tech, to discuss Latio's second annual AI security market report. James was on the show last summer when the first report framed the market around browsers and cloud infrastructure.
This year the report calls the endpoint the second era of AI security, and we spend most of the conversation on why.
James's read is that the first era amounted to "security tools in search of a use case," mostly built around aliasing sensitive data before it reached a model provider.
Agents changed that.
Once Claude Code and its peers started taking actions with every credential sitting on a developer's laptop, the developer endpoint went from a long-standing blind spot to the center of the category.
He borrows a line from GitHub's CTO that we are in the pre-HTTPS era of AI security, doing risky things we will later find hard to believe.
The numbers back the shift.
Per the report, dedicated AI security budget went from 8% of organizations last year to 37% this year, with another 24% undecided. James says most of that money is coming from AI governance budgets, which explains why nearly every vendor is pivoting toward the category and why roughly 400 AI security startups are competing for the same buyers.
Where James and I diverge is runtime. I argued the category sprinted to AIDR and runtime enforcement faster than AppSec ever did because autonomy and tool calls make runtime where the risk shows up.
James calls runtime "the patchwork thing" and pushes posture and blast radius instead. His framing is that his agent should not be able to take down the prod database because he should not be able to take down the prod database. He also thinks the category's runtime orientation owes a lot to which company CrowdStrike happened to acquire.
We close on buying advice. James's core recommendation is to rank the specific AI tools you are worried about, whether that is Claude Code, Copilot, Agentforce, or desktop apps, and let that shape the vendor shortlist. A demo will not tell you what you should care about.
We discuss:
Why the first era of AI security was model-centric and what agents changed
The "pre-HTTPS era" framing and why developer endpoints carry the highest risk
Platform versus endpoint specialist, and why the answer depends on your existing stack and which team owns the problem
AI security budgets jumping from 8% to 37% and where that money is coming from
How to cut through 400 vendors and test runtime detection claims during a POC
Runtime versus posture, blast radius, and why the Hugging Face incident was a misconfiguration story
What 2025's proxy and browser acquisitions bought the incumbents, and why the endpoint is the next M&A wave
Intent-based detection and the worker privacy problem it creates
Whether frontier labs absorb the vendor market, and what Anthropic's inference hooks signal
MCPs and skills as a software supply chain problem, with ADR as the natural answer
James's buying advice for CISOs and IT teams
Prefer to listen?
Please be sure to leave the show a rating/review, as it truly helps!
Links
Timestamps
0:00 Intro
0:31 How Latio Tech started
2:05 The endpoint as the second era of AI security
2:51 "Security tools in search of a use case" and the pre-HTTPS era
5:37 Platform versus endpoint specialist
8:16 Do you need a purpose-built AI security platform?
11:16 AI security budget from 8% to 37%
14:24 400 startups and real differentiation
15:41 The commoditized feature list and testing intent-based detection
17:32 Posture, blast radius, and the Hugging Face example
20:14 Runtime versus posture debate
23:35 What acquirers got for their money
26:27 The fight over laptop protection
29:02 Intent-based detection and worker privacy
30:26 The next M&A wave and the hosted agent prediction
33:55 Frontier labs, inference hooks, and the vendor market
36:32 MCPs and skills as supply chain
39:30 Buying advice for security leaders
44:08 Wrap









