While the market fixates on the $435 million that flooded into AI agent security startups across a single six-month stretch, a quieter pair of numbers deserves the spotlight: 79% of enterprises have deployed autonomous AI agents, and roughly 2% secure them with purpose-built identity controls. That is a 40x gap. Follow the liquidity, ignore the hype — and you will notice this gap has a shape that crypto investors have watched open and close many times before.
I have spent my career measuring the distance between a project's promises and its code. In 2017 I audited more than fifty whitepapers during the ICO mania and flagged ten fraudulent token models before the bubble burst. The arithmetic never really changes: deployment outruns defense, capital chases the narrative, and the invoice arrives later, addressed to whoever skipped the fine print.
The enterprise framing for this gap comes from SailPoint, the incumbent identity-security vendor that went private in a roughly $6.9 billion buyout and returned to public markets in 2025. Its executives have been unusually vocal — a CEO, a CTO, a CMO, all pushing the same thesis: agent adoption has outrun the machinery meant to govern it, and the fix is to fold identity directly into the agent's execution loop. The supporting cast is real. Zenity, Horizon3.ai, and Corma are genuine companies with genuine funding records, and $435 million moving into a nascent security category over six months is not fiction. What is fiction is the idea that this is a new problem.
For anyone who has run an on-chain agent, the enterprise vocabulary is a translation exercise. When SailPoint's CTO describes agents firing 10,000 tool calls per second, he is describing a throughput regime crypto has inhabited for years. MEV searchers, liquidation bots, arbitrage engines, and yield-farming scripts are autonomous agents in everything but name — they hold credentials, they move value, and they execute thousands of calls with no human in the loop. The difference is that in crypto, the identity primitive was never a login. It was a private key. A wallet is simultaneously an identifier, an authorization token, and an audit anchor, and it has been non-human-native from day one.
That is the part the enterprise framing misses. Traditional IAM was built human-first: session-level, hour-scale, person-in-the-loop. Agents need machine-in-the-loop, call-level, millisecond-scale authorization. Crypto stumbled into the right architecture by accident, because its founding constraint — no central authority to vouch for you — forced identity to be cryptographic, portable, and permissionless. When a DeFi protocol grants a smart contract an allowance, it is performing exactly the intent-based governance the enterprise world now sells as a breakthrough. The allowance is bounded, revocable, and enforced by code rather than by policy.

But here is where the crypto blueprint stops being a triumph and becomes a warning. The algorithm has no conscience, and neither does a signed transaction. Crypto's identity model solved authentication and left authorization half-built. Approvals are routinely set to unlimited; private keys are pasted into browser extensions; protocol admins hold upgrade rights that no multisig quorum can meaningfully constrain once a single signer is compromised. The same lateral-movement risk the enterprise report attributes to AI agents — credentials spreading, permissions sprawling, one breach cascading across a network — is the story of every major DeFi exploit of the last four years. Crypto did not avoid the 40x gap. It just moved it on-chain, where it is denominated in real money and settles in seconds.
The recursive-trust problem sharpens the point. If an agent's intent is parsed by a large language model, and that same model governs the agent's permissions, then you have built a system in which a probabilistic engine supervises itself. Who audits the auditor? Crypto has an answer the enterprise world has not yet adopted: verifiable execution. Zero-knowledge proofs, on-chain policy engines, and transparent audit trails let a third party confirm what an agent did without trusting the agent's own account of itself. The MCP protocol's emerging security layer gestures at this, but the enterprise stack still assumes a trusted middle.
This is where the money gets interesting. The insurance signal buried in the source material is the most consequential data point of all: 76% of organizations expect agent governance to shape their insurance terms, and underwriters may soon require specific identity-security protocols as a condition of coverage. Cyber-insurance has always been the quiet enforcer of security practice — the way auto insurers made airbags non-optional. Crypto has no such backstop. There is no underwriter for a re-entrancy attack, no premium discount for a well-audited vault. Volatility is the price of admission, and for on-chain agents, so is the absence of a safety net.
The contrarian read is that these are two separate markets, one regulated and one not, and that enterprise agent security has nothing to do with crypto. I think the opposite. The convergence is already underway: tokenized treasuries, institutional custody, and regulated stablecoins are dragging the enterprise identity stack into the same room as the crypto one. When the two finally share infrastructure, the winner will not be the vendor with the loudest 40x headline — it will be whoever built identity that is cryptographic by default, granular by design, and auditable without asking permission.
The platform giants are waiting in that room. Microsoft, Okta, and Palo Alto can bundle agent governance into products enterprises already pay for, and single-point security startups have historically ended up acquired or abandoned. Crypto learned this lesson when independent infrastructure firms were absorbed by the exchanges. Chaos is data in disguise — and the data says the 40x gap will not be closed by a new product category. It will be closed by architecture that treats every actor, human or machine, as a key that must be verified and a permission that must expire.
So watch the insurance clauses, watch the platform bundling, and watch whether the on-chain agents now running quietly across every major chain become the template or the cautionary tale. The enterprise world is discovering in 2026 what crypto has been pricing since 2020: identity is not a feature you add after deployment. It is the foundation you either build on — or fall through.