Black Hat USA 2026, Day 1. A researcher stands on stage and drops a detail that will ripple through every security vendor's roadmap for the next two years: the Model Context Protocol — the pipes connecting LLMs to the tools they call — contains framework-level vulnerabilities. Not prompt injection tricks, not social engineering. Compute-layer attacks that can alter tool-call results at the execution level. The room goes quiet. Then, within 48 hours, more than fifteen vendors simultaneously announce products to protect this same protocol.
Let that sink in. Fifteen-plus vendors, forty-eight hours. Cyera, Rubrik, SailPoint, Check Point, Sweet Security, Zero Networks, Tanium, Promptfoo, Legit Security, Acalvio, KnowBe4, Drata, 1Password, Mimecast, Abnormal AI — names spanning data security, identity governance, firewalls, deception tech, and compliance. They weren't coordinating. They were reacting to the same signal. If you've spent enough time tracing market formation from its genesis block, you've seen this pattern before: a standard stabilizes, a vulnerability gets disclosed, and suddenly every vendor with adjacent infrastructure capability realizes they can slap a new label on existing tech and ride the wave.
Tracing the code back to its genesis block, MCP is Anthropic's November 2024 open protocol for connecting AI models to external data sources and tools. It became the default plumbing for agent tool-calling faster than anyone expected. By mid-2026, enterprises had agents running in production — not pilots, not demo environments. Agents with planning capabilities, tool-calling authority, and direct access to internal data lakes. Agents that no security team fully understood. The market formation we witnessed at Black Hat is not primarily a technology story. It's an architectural confession: enterprises lost control of their agent estate, and the security industry noticed.
The vendors' product categories read like a taxonomy of institutional anxiety. First, visibility and discovery: Cyera's Agent Guardian, Rubrik's Agent Identity, SailPoint's Agentic Fabric, Drata's compliance angle. These products discover Shadow Agents — agents deployed by business units without IT approval — and create asset inventories. Sound familiar? It's the Shadow IT problem of the 2010s, reincarnated with autonomous tool-calling abilities. The second category is active defense: Sweet Security's Agentic AI Blocking terminates unauthorized calls at runtime; Check Point's AI Network Firewall claims L7-level MCP traffic inspection; Zero Networks' Least Agency embeds the least-privilege principle into agent authorization, with mandatory human approval for sensitive operations. Third category: MCP-specific communication security — Tanium's Atlas MCP Server controls data exposure to Claude and other models, Promptfoo's MCP Proxy intermediates agent traffic, Legit Security's VibeGuard 2.0 protects AI coding agents. The final category is deception and compliance theater: Acalvio's ShadowPlex plants decoy tools to lure attackers, KnowBe4 extends to Claude risk management, Abnormal AI moves to agent-layer threat detection.
Reading this list, my cryptographic skepticism kicks in hard. Based on my audits, from the 2017 ICO whitepapers to DeFi's composability disasters, when fifteen vendors ship the same product category within 48 hours, the overwhelming majority are adapting existing capabilities, not building new technology. Cyera's Agent Guardian is DLP technology extended to MCP traffic. Check Point's AI Network Firewall is NGFW with a JSON-RPC protocol parser. KnowBe4 is doing what KnowBe4 always does — compliance frameworks stapled to the agent narrative. The architecture is captured in the names: Agent Guardian, Agent Identity, Agentic Fabric. These are all nouns describing the same thing: old security infrastructure with an AI-smelling perfume sprayed on top.
But something more consequential is embedded in this wave. Where liquidity flows, truth eventually pools. The security vendors are all betting that MCP becomes the permanent standard for agent tool-calling. This isn't incremental — it's a strategic bet with real financial downside. What does that tell us about MCP's actual adoption inside enterprises? Security vendors don't spend engineering resources on niche protocols. MCP penetration must be far deeper than public discussions suggest; agents are already running business processes that matter. The Shadow Agents problem is worse than anyone will admit publicly, and the security teams are being outmaneuvered by their own business units, whose employees are spinning up AI agents the way 2017 retail investors spun up ICO collectibles. The amplification of MCP as a target is also the clearest proof that autonomous agent operations have crossed the pilot-phase threshold.
Decoding the signal hidden in the noise, the most important technical gap is the absence of an identity standard for MCP servers. Every vendor is implementing its own agent identity discovery mechanism, creating the same fragmentation problem that SPIFFE solved for microservices — if it ever gets solved here at all. Without a verifiable identity layer, authorization decisions rest on shaky ground. The second glaring gap is agent behavioral baseline modeling. Runtime blocking and deception traps require distinguishing normal agent behavior from malicious activity. But agent workflows are inherently dynamic, context-dependent, and multilayered across tool chains. Building a reliable baseline — a "normal" for software whose behavior is generated probabilistically based on intent prompts — is an unsolved problem. Sweet Security's runtime termination and Acalvio's honeypots depend entirely on this unsolved problem. Their market presence is a statement of intent, not a proof of effect. The third gap: cross-agent causal tracking, critical for Ruby's Agent Rewind concept, which promises temporal rollback of agent actions. In single-agent systems, a rollback is tractable. In multi-agent orchestration, the causal chain complexity explodes. Determining which agent's action caused the resulting side effects, and rolling it back without breaking dependent operations, is the same hard problem as reverse transaction ordering in a distributed network.
Now let's talk about the elephant in the conference hall: the absence of Microsoft, CrowdStrike, and Palo Alto Networks from this initial surge. Also missing: Chinese security vendors like Alibaba Cloud, Tencent Cloud, Qi Anxin. The market isn't shaped yet. But the real competition is not between these fifteen vendors — it's between the security layer and the platform layer. Anthropic invented MCP. OpenAI has its own protocol, recently adopting partial MCP support. Microsoft's Copilot Studio runs connectors and MCP simultaneously. These platform providers can implement native agent security directly into the model runtime, eliminating the need for standalone security layers entirely. Security vendors are building castles on a protocol owned by their future competitors, who are also their allies today. This is the same structural tension I observed in DeFi: composability is a double-edged sword. Security vendors are composing on MCP's openness, but the protocol's evolution is controlled by the very labs racing to embed guardrails into their platforms. The independent vendor window is eighteen to twenty-four months before platform-native security eats their market.
And here's the contrarian narrative that nobody in that conference hall will tell you. This entire vendor wave is a supply-side self-confirmation, not a demand-side validation. Walk through the math from my 2021 NFT research, where I found 80% of secondary market volume was wash-trading. The same pattern applies here: narratives confirm themselves through coordinated announcement energy before verifiable data exists. Not a single vendor presented customer adoption numbers, contract values, or third-party red-team validation of their agent-blocking capability. The market is being created by FUD and vendor momentum, not by proven security effectiveness. And that's fine — that's normal — but it means the next twelve months will be a brutal sorting process. The vendors with actual agent behavior detection will survive. The compliance-tag vendors will be revealed as effectively tokenless cryptocurrencies. Where real production risk is hidden, truth eventually forces itself out, with a drawdown. For buyers, the immediately actionable principle aligns with how I've always approached unverifiable markets: follow the smart contract, ignore the whitepaper. Don't buy the agent security platform based on press release language; demand a proof of capability against actual attack tooling.
The deeper question we should be asking isn't which vendor wins. The deeper question is whether an open, security-by-design agent infrastructure is achievable at all when the platform owners control both the protocol and the competing security layer. MCP's open standard may collapse into closed, managed enclaves with native security built in — a safer architecture, but one that returns enterprise AI to the walled-garden model that the crypto industry has spent a decade working against. Bubbles burst, the architecture remains. What forms after this wave will determine who controls the identity, audit, and trust layer of the entire agent economy. The vendors who survive are those whose security has teeth. The market might blow off in a credit squeeze of unmet expectations, but the architectural demand for agent security — that is permanent infrastructure. Whether it's built by independent vendors or embedded in the platform parent's proprietary ecosystem matters far more than any product on the Black Hat floor.
Between the quick-fix announcements and the platform wars, one question lingers, unanswered because nobody on that stage has an incentive to answer it: when the first major enterprise loses $100 million because an agent executed a maliciously crafted MCP tool call, will you know which of these fifteen products was in the path? That's the signal to watch. The rest is noise.


