The first hint came somewhere between the third and fourth pitch on March 24. By the mid-morning break at Y Combinator's Winter 2026 Demo Day, the pattern was unmistakable: nearly a tenth of the startups presenting to roughly 1,500 investors had built security tools for a world where AI agents operate autonomously—and not all of them safely.
It wasn't subtle. Attendee Sameer Nanda, who publishes an independent analysis after each YC batch, later tallied 190 companies in the cohort and found that 74% touched artificial intelligence in some capacity. But the real investor attention? That clustered around a smaller set of founders who'd apparently decided the industry's breakneck sprint toward autonomous systems had created gaps wide enough to drive a truck through.
Or, as it turned out, wide enough to let a malicious actor impersonate your bank's website while an AI agent dutifully hands over login credentials.
The Unsexy Plumbing Problem
Crosslayer Labs made the case for why web infrastructure—the kind of behind-the-scenes technology most people never think about—suddenly matters when machines start browsing the internet without supervision.
The founding team isn't exactly unknown. Henry Birge-Lee, Grace Cimaszewski, and Prateek Mittal (a Princeton professor who won the ACM Grace Hopper Award) previously invented MPIC, a protocol now deployed at major certificate authorities. Their new company monitors DNS, BGP routing, TLS certificates, and JavaScript from the outside, watching for the telltale signs someone's spoofing a domain or hijacking a certificate.
The pitch resonated, perhaps more than the founders expected. TechCrunch flagged them in a March 26 roundup of standout companies, describing their focus on "detecting website spoofs amid an agent-driven threat landscape." YC partner Tyler Bosmeny backed them.
Why does this matter now? Because when a human gets phished, they might hand over their password. When an AI agent gets phished, it might autonomously transfer funds, file fraudulent tax returns, or—depending on what it's been trained to do—make purchasing decisions that redirect hundreds of thousands of dollars before anyone notices. The threat model isn't theoretical anymore.
The Runtime Problem Nobody Wanted to Talk About
At least three startups in the cohort asked the same uncomfortable question, just from different angles: what do you do when your AI agent is about to do something catastrophically stupid?
Salus, founded in 2026 by Kevin Pan and Vedant Singh, built an API wrapper that intercepts agent actions at runtime and blocks the incorrect ones before they execute. The two-person team published benchmarks on τ²-bench and ODCV-Bench—the kind of engineering rigor that signals seriousness to investors who've seen too many vaporware demos.
Agentic Fabriq went broader. Founders Paulina Xu and Matthew Xu, both with MIT pedigrees, built a single control plane for data permissions across AI agents and human employees. The premise: enterprises can't scale agent deployment if they don't have a clean answer to "which agents can access which customer databases." Legacy identity and access management systems, it turns out, weren't designed for non-human actors making autonomous decisions.
Baseframe took the preventive route—self-fixing automations that scan network traffic for PII leaks, prompt injection attempts, and malicious code before the agent executes anything. Founders Anshul Paul and Vaibhav Agrawal positioned it as catching vulnerabilities upstream rather than cleaning up disasters after the fact.
Then there's Hex Security, which runs continuous penetration tests using AI agents to probe for weaknesses. The team—Ahmad Khan, Huzaifa Ahmad, and Prama Yudhistira—self-reported having prevented "$3B+ in potential damages," a figure that comes with all the caveats that entails. They cited a September 2025 intelligence report from Anthropic on state-sponsored AI-driven attacks, suggesting this isn't a speculative threat model. TechCrunch noted them again in a March 28 follow-up on investor favorites.
Turning the Tables

BeeSafe AI pitched something genuinely unusual: undercover AI agents that engage attackers to extract mule accounts, domain infrastructure, and operational details. In other words, they're using automation to bait organized fraud networks into revealing themselves.
The founding team includes Daniel Spokoyny, who holds a CMU PhD in machine learning and NLP, and Ariana Mirian, a security researcher with stints at Google Chrome and Censys. They're starting with financial crime use cases—essentially turning the attacker's own automation against itself.
How this scales legally is unclear. So is the operational playbook when a honeypot agent successfully infiltrates a fraud network. But the pitch apparently resonated with investors who've watched organized crime adopt agent-based tooling over the past year.
Not Everything Is Digital

A handful of startups reminded the room that physical security still exists, even if it's getting an AI upgrade.
Lexius applies computer vision to legacy CCTV systems, adding intelligence without requiring hardware replacement. Founders David Elskamp and Liam Webster highlighted retail loss prevention, and their website cites deployments at Erewhon and Nisa for real-time shoplifting detection and video traceback. TechCrunch summarized them as embedding "advanced AI into security systems."
Protent went further into predictive territory, analyzing surveillance feeds for police departments to detect early escalation patterns—behavioral cues that traditional motion detection misses. Cofounders Srihan Balaji (ex-Lockheed Martin Research, ex-AWS) and Abhisheik Sharma report working with departments in the Atlanta, Chicago, and St. Louis metro areas, though the company hasn't disclosed specifics on deployment scale.
MouseCat, founded by Nicholas Aldridge (who worked on AWS Bedrock) and Joseph McAllister (ex-Coinbase risk team), investigates fraud across cloud data sources like Databricks and Snowflake. And Milliray built radar systems to track small drones—a harder problem than it sounds, given how poorly traditional airspace monitoring handles cheap consumer drones flying at low altitudes.
Reading the Tea Leaves

The concentration of security startups in this batch reflects something more substantive than opportunistic trend-chasing.
Academic research throughout late 2025 and early 2026 documented specific vulnerabilities in agent systems. A January 2026 arXiv paper proposed a SUPERVISOR module that reduced social engineering attack success rates against web automation agents by up to 78.1%. Another paper, published March 13, introduced AEGIS, a pre-execution firewall for tool calls. The founders who went through YC's winter program absorbed those findings and built products around them.
Nanda's April 1 analysis—again, unofficial but informed—estimated that 14 companies in the batch had already crossed $1 million in annual recurring revenue by Demo Day. That suggests genuine customer demand rather than speculative tooling built for a market that doesn't exist yet. The security cohort includes teams with backgrounds at AWS, Coinbase, Lockheed Martin, and Google. Not exactly fresh graduates chasing headlines.
YC invested $500,000 into each company under its standard deal: $125,000 for 7% equity on a post-money SAFE, plus $375,000 on an uncapped MFN SAFE with pro rata rights. That structure gives the accelerator exposure across the full portfolio, including the less obvious bets that might not generate immediate buzz.
Some of these security tools will fail to find product-market fit. Others may consolidate as the market matures. A few will likely get acquired before they ever raise a Series A.
But the batch composition itself tells a story—one that suggests the industry has moved past the initial euphoria of deploying AI agents everywhere and started grappling with the uncomfortable logistics of trust, perimeter defense, and governance when the actors making decisions aren't human.
Whether enterprises are ready to pay for those answers is a different question entirely.
