In this episode, I sit down with founder and managing partner of Boldstart Ventures, Ed Sim, to discuss where AI security and agentic infrastructure are actually heading, including on-prem models, private evals, agentic identity, and vulnerability chaining. Ed has been an inception-stage investor for nearly 30 years and has run Boldstart since 2010, and about a third of the firm’s investments are in cyber.
He was the first investor in Protect AI, which sold to Palo Alto Networks in a reported ~$700M exit roughly a year before ChatGPT launched, and he is early in companies like Keycard, Surf AI, and June.
I read a lot of Ed’s content because he sits outside the security echo chamber and looks at this market through a CTO, CIO, and investor lens. That perspective made for one of my favorite conversations in a while.
We chatted about:
Why a day-one partnership looks different now that anyone can vibe code an MVP
The Protect AI acquisition and what the first exit in AI security signaled to the market
Competing as an inception fund against mega-funds writing giant seed rounds
What founders should actually look for in a venture partner beyond the check
The shift from building intelligence to controlling it, with routing, post-training, and on-prem deployment
Why enterprise data, workflows, and private evals are becoming the crown jewels
Vulnerability chaining, attack path reasoning, and how tools like Mythos are reshaping the security budget conversation
Agentic identity and why Keycard treats agents as short-lived problem solvers rather than digital twins
The Surf AI thesis on automated security hygiene and tying every asset back to an owner
The real bottleneck slowing agent adoption in the enterprise
Prefer to listen?
Please be sure to subscribe and leave a review, it makes a big difference for the show!
The bar for a cybersecurity startup just went way up
Ed was blunt about the state of the market. “The world needs more cybersecurity, but we don’t need all the cybersecurity companies that we have right now.” Anyone can build now, and a moat that used to last twelve or eighteen months can get copied in a fraction of that time. So a good cyber idea is table stakes, not a differentiator.
What he looks for underneath the idea is depth on the AI side. He wants to know whether a founder is going to build or post-train their own model, how deep the moat and the flywheel go, and how deep the product gets into customer environments. That is a real shift in what earns a day-one check, and it is worth internalizing if you are a practitioner trying to read which startups will still be here in a few years.
From building intelligence to controlling it
The through line of the whole conversation was Ed’s argument that the first era of AI was about building intelligence and the next one is about controlling it. Once the frontier labs filed to go public, the tokenomics stopped being a rounding error, and enterprises started routing queries so they are not paying for state-of-the-art on every request. From there it is a short hop to post-training open models and asking why you would hand your data to a third party at all.
He put the incentive problem in memorable terms. “I think the biggest heist ever happening right now is that OpenAI and Anthropic created their own forward deployed engineering companies.” His point is that the data leaving your company is not just data, it is a map of how your company works, and your private evals are the thing you least want a competitor’s model to learn from. This is where I think a brand new set of security problems opens up around model hosting, lineage, and the security of running these things in your own environment.
Vulnerability chaining makes reasoning the whole game
We spent real time on what reasoning models do to vulnerability management, which is squarely in my wheelhouse. For years we prioritized the top criticals and highs by severity score and largely ignored the mediums and lows. Ed’s framing is that these models change that math. “Take 10 vulnerabilities that might have been on the backlog and you staple them together and create an attack path. When you create an attack path and these things can reason, that’s crazy.”
That is the industrialization of vulnerability discovery and exploitation, and it cuts both ways. The same capability that lets a defender do continuous attack path reasoning is available to the attacker, and the tooling we built to manage all of this, from CVE databases on down, is already straining under the volume. Ed also tied it to the budget conversation, noting that the worry is not whether continuous reasoning works, it is what it costs when you run it against all of your code, cloud configs, identities, and network state.
Agentic identity is becoming its own category
Ed funded Keycard two years ago and made a strong case that agent identity is not a feature that gets absorbed, it is a category. His description of the primitive is the clearest I have heard. “If you believe that every agent should have its own identity, that it shouldn’t go through Chris or Ed, if you believe they should be ephemeral and dynamic, and you believe that there should be an audit trail, and then if you can cryptographically prove that the agent is not hacked in the whole process, that’s what we’re building.”
What I appreciated is that he does not think one vendor wins the whole thing. Large incumbents will take share, and a few companies that treat this holistically rather than as a single point product will win alongside them. He also credited the community-building work here, specifically Keycard bringing in Ali Howe and the Insecure Agents podcast, which is on my own go-to list for learning about agentic IAM.
The bottleneck is not tooling, it is knowing where to start
I closed by asking Ed what actually holds back agent adoption when only a small percentage of organizations have agents in production. His answer was refreshingly human. “Most people don’t even know where to get started.” Coding works and gets most of the token spend, but the business workflows are largely untouched, and the whole landscape is confusing about which model, which platform, and which first workflow to automate.
That is why the easy-button players like Palantir have pull, and why Ed thinks there is room for many easy buttons rather than one lab dominating everything. It also lands on a theme he and I share. There will be people who look at this moment and feel overwhelmed, and people who look at it and feel invigorated, and it is the second group that ends up thriving. As Ed put it, security now needs hardcore AI people, the ones who build models, to come into the field, and we are already seeing it happen.
Thanks to Ed for coming back on the show. Follow his newsletter, What’s Hot in Enterprise IT/VC, and connect with him on LinkedIn for some of the sharpest content on enterprise infrastructure, AI, and security investing.









