Select your country

Not finding what you are looking for, select your country from our regional selector:

Search

| Blog

Who are the key players in the AI ecosystem when it comes to cybersecurity?

TLTR

  • A look at the evolution of the Cyber AI ecosystem: initially composed of three groups (hyperscalers, cyber pillars, analytical challengers), the ecosystem has become more complex with the addition of two new entities (frontier AI model providers and AISec players), increasing from three to five profiles, which makes reading the cyber map increasingly challenging ; 
  • Roles and characteristics of the different groups:
    Hyperscalers provide computing capabilities and integrate large language models (LLMs) into their cloud services.
    Frontier AI model providers (e.g., OpenAI, Anthropic) offer generative models accessible via APIs, while also serving as sources of intelligence.
    Cyber pillars enhance their detection platforms with AI, often through acquisitions.
    Native AI actors design solutions that incorporate AI from the outset ; 
  • Implications for cybersecurity and risk management: data is central to the success of these models. The balance between behavioral AI and generative AI is evolving, and managing AI-related risks (especially concerning model security) is becoming crucial. Multi-vendor coordination and support from integrators or MSSPs (Managed Security Service Providers) are key to developing a coherent and effective strategy.

The evolution of an AI cybersecurity ecosystem: an expanding family

The cybersecurity ecosystem is undergoing a major transformation with the emergence of artificial intelligence models. With the number of key players increasing from three to five - making it more complex to assess and manage risks - this shift, fuelled by the arrival of large language models, is profoundly altering defence and orchestration strategies. Understanding this evolution is essential for anticipating the challenges ahead and strengthening organisations’ security. Let's deep dive into this brave AI world with by Gwenwal Riou, Global Director of Strategy and Alliances at Orange Cyberdefense. 

From a Three-Body Problem to a Five-Body Problem

In physics, the three-body problem is not just complicated. Past a certain number of objects in interaction, no stable, predictable solution exists anymore, and the system becomes chaotic. The cybersecurity ecosystem before generative AI could already be read through three main families with distinct logics: hyperscalers, who sold compute and storage with security as an adjacent capability, cyber pillars, the established vendors built through acquisitions and detection platforms based on rules, and analytical challengers such as SentinelOne, Darktrace or Vectra AI, who already stood apart through behavioral machine learning rather than signatures. Three bodies, three sources of value, a system that was still readable.

The arrival of large language models did not simply add new players. It brought two new bodies, frontier model providers and AISec, and it transformed the first three from within: hyperscalers now inject LLMs where they used to sell compute, cyber pillars embed generative copilots on top of their rule-based platforms, and analytical challengers add a generative layer on top of their behavioral core. The system moved from three bodies to five, and it is this reshuffling, more than the number of players alone, that makes the ecosystem harder to read today.

Hyperscalers

Hyperscalers act as providers of compute and storage, and they now inject LLMs directly into workstations and cloud-native solutions to support and increase user productivity. This family includes large technology groups such as Microsoft, Google Cloud and AWS (Amazon Web Services), through digital assistants like Microsoft Copilot, which turn a plain-language request into a sequence of automated actions. Some also offer model libraries that can be built directly into applications running on their infrastructure.

Their strength comes from the sheer scale of data they process, their financial weight, and a presence already embedded in most IT environments, which makes adoption almost automatic. Their customers, in exchange, need to watch two things: dependency on a single vendor, and costs that rise quickly with query volume.

Frontier AI model providers

A separate family stands apart from hyperscalers even though it is sometimes tied to them through infrastructure: the labs that design and train the models themselves, such as Anthropic or OpenAI. Their business is not selling compute or storage, it is selling access to a model, usually through an API, which makes them fairly agnostic to the infrastructure underneath. Anthropic runs on AWS and Google Cloud, OpenAI runs on Azure, and this layered dependency adds a further risk for the customer relying on both.

Their relevance to cybersecurity comes from two things. First, they supply the generative foundation that other families build on top of, from SentinelOne's Purple AI to the copilots embedded by cyber pillars. Second, they have become a source of threat intelligence in their own right: both Anthropic and OpenAI now publish their own findings on cyberattacks orchestrated or assisted with their models, which makes them a direct part of the threat landscape as much as a defense provider.

Cyber pillars

The established vendors of the cybersecurity industry, such as Cisco (through Splunk) or Palo Alto Networks, form a third family. These pillars extend their detection and response platforms (XDR, SIEM) by adding AI and machine learning modules. Their edge is the proprietary data they have already accumulated: they combine network and endpoint telemetry to strengthen alert correlation, and they now extend this logic to more and more data sources through a platform approach.

This evolution has largely been built through acquiring third-party technologies, which then sit on top of older proprietary layers, and the cost is an integration complexity these vendors have to manage on an ongoing basis.

AI native players

Some players in this ecosystem are not cyber vendors who added AI. They are AI pioneers for whom cybersecurity was, from the start or close to it, the field of application. SentinelOne, Darktrace, Vectra AI and Abnormal Security share this trait: an architecture built around AI from day one, not added later.

SentinelOne is a good example. The company starts from the idea that response time to a ransomware attack has to be measured in milliseconds, and that no architecture depending on a round trip to the cloud can meet that bar. This is why its behavioral models run directly on the agent, able to link the processes of a single device together (this is the logic behind its Storyline technology) to reconstruct the chain of an incident, then neutralize the threat and restore the system without waiting for a central decision. Generative AI, through Purple AI, has since been added on top, but at a different level: it queries and reasons after the fact on the data this behavioral layer produces, without replacing the blocking decision made locally in milliseconds.

AISec

The last family covers players positioned on the fast-growing segment of AI security, also called AISec or security for AI. They protect the supply chain of the models themselves, against prompt injection, data poisoning and model theft, and they build their offering directly around the ten risks listed in the OWASP ("Open Worldwide Application Security Program") Top 10 for large language models. This is a young market, and consolidation is already underway rather than still to come: among the four most cited players in the space, HiddenLayer and Lakera remain independent, but Robust Intelligence was bought by Cisco in October 2024 and Protect AI by Palo Alto Networks in April 2025, two deals that directly benefit vendors already present in the families above.

Key findings in reading the evolving AI cybersecurity landscape: what should your roadmap look like?

The established vendors of the cybersecurity industry, such as Cisco (through Splunk) or Palo Alto Networks, form a third family. These pillars extend their detection and response platforms (XDR, SIEM) by adding AI and machine learning modules. Their edge is the proprietary data they have already accumulated: they combine network and endpoint telemetry to strengthen alert correlation, and they now extend this logic to more and more data sources through a platform approach.

This evolution has largely been built through acquiring third-party technologies, which then sit on top of older proprietary layers, and the cost is an integration complexity these vendors have to manage on an ongoing basis.

Keep "Ctrl" with the fast evolving frontiers of AI and cybersecurity with our latest brochure below. 

Other articles of interest

24/7 incident hotline