
This development highlights the increasing importance of the cybersecurity ecosystem. As AI models become more capable at coding and automation, they are lowering the barriers for both defenders and cyber attackers to discover and exploit software vulnerabilities.
Five key implications for cybersecurity:
- Accelerating vulnerability exploitation
AI is materially reducing the time required to identify and exploit software vulnerabilities. This compression of attack timelines raises the stakes for organisations, which must
respond faster and with greater precision. As a result, cybersecurity is likely to become a larger and more urgent component of IT budgets, with increased emphasis on automated threat detection and rapid remediation. - Rising demand for multi-LLM protection
Enterprises are increasingly deploying multiple large language models (LLMs), combining proprietary systems with external Application Programming Interfaces (APIs) that route queries to the most suitable model. While this architecture improves efficiency, it also introduces new risks: expanded attack surfaces, greater data exposure, and increased complexity in monitoring.
This shift has several implications:
- Network security: Cisco estimates enterprise network traffic with agentic AI adoption could rise closer to 9x. The surge in machine-generated traffic reinforces the need for scalable, AI-aware network security as a foundational layer.
- Zero Trust and endpoint security: Zero Trust Architectures based on continuous verification of users, devices, and access are increasingly important in mitigating AI-enabled threats. Endpoint security also plays a critical role in controlling “shadow AI” (unauthorised generative AI usage) and preventing data leakage.
- Identity security: As AI agents increasingly operate alongside humans, robust identity governance, privileged access controls and multi-factor authentication are essential to limit system access and reduce the potential impact of credential theft or breaches.
- Convergence of security and observability
Historically, observability (monitoring and diagnosing) focused on system performance, and security solutions focused on threat detection and prevention. Adoption of AI results in the creation of a shared data layer where threat detection is increasingly dependent on the telemetry
streams (records of a security event) that were the core focus for observability, resulting in changing competitive dynamics between players in each sector. - Greater emphasis on application security
Mythos enables faster and more efficient detection of software bugs, increasing the importance of identifying and resolving vulnerabilities earlier in the development lifecycle. This approach enhances overall software resilience and reduces downstream risk once applications are deployed. Improved efficiency in vulnerability discovery could alter competitive dynamics, potentially favouring vendors that can integrate AI deeply into development workflows.
- Regulation reinforcing cybersecurity priorities
The US Securities and Exchange Commission (SEC) has introduced enhanced disclosure requirements for public companies, mandating reporting of material cyber incidents and broader risk management practices. As the threat landscape evolves with AI, it potentially redefines what constitutes “material risk” and “reasonable care”, which could further drive cybersecurity investment and governance standards.
Investing in cybersecurity through an active lens
Project Glasswing also highlights the emerging role of AI companies such as Anthropic as strategic partners within the cybersecurity ecosystem. While their advanced capabilities present opportunities, they also reinforce the need for secure and responsible deployment of AI technologies.
We are closely monitoring both the evolution of these models and the competitive responses from other AI developers. At the same time, we are assessing how cybersecurity vendors are embedding AI into their platforms to enhance protection, automation, and threat intelligence.
Industry commentary supports the view that AI represents a structural growth driver. Research from McKinsey & Co. suggests strong expectations for sustained AI integration across security solutions, pointing to a multi-year growth runway.
While there is ongoing debate about the potential for AI model providers to disrupt traditional software businesses, we believe Mythos may shift the narrative for cybersecurity towards partnership rather than displacement. As organisations adopt agentic AI at scale, demand for protection, governance, and risk management should increase in tandem. Given the pace of technological change and evolving competitive dynamics, we expect cybersecurity to remain a fertile area for active stock selection.
Agentic AI: An AI system that uses sophisticated reasoning and iterative planning to autonomously solve complex, multi-step problems. Vast amounts of data from multiple data sources and third-party applications are used to independently analyse challenges, develop strategies and execute tasks.
Generative AI: Refers to deep-learning models that train on large volumes of raw data to generate ‘new content’ including text, images, audio and video.
Large Language Model (LLM): A specialised type of artificial intelligence that has been trained on vast amounts of text to understand existing content and generate original content.
Zero Trust Architecture: A cybersecurity framework built on the principle of “never trust, always verify”.
These are the views of the author at the time of publication and may differ from the views of other individuals/teams at Janus Henderson Investors. References made to individual securities do not constitute a recommendation to buy, sell or hold any security, investment strategy or market sector, and should not be assumed to be profitable. Janus Henderson Investors, its affiliated advisor, or its employees, may have a position in the securities mentioned.
Past performance does not predict future returns. The value of an investment and the income from it can fall as well as rise and you may not get back the amount originally invested.
The information in this article does not qualify as an investment recommendation.
There is no guarantee that past trends will continue, or forecasts will be realised.
Marketing Communication.