
15 September 2026 | Rapport
The cybersecurity ecosystem is undergoing a major transformation with the emergence of artificial intelligence models. With the number of key players increasing from three to five - making it more complex to assess and manage risks - this shift, fuelled by the arrival of large language models, is profoundly altering defence and orchestration strategies. Understanding this evolution is essential for anticipating the challenges ahead and strengthening organisations’ security. Let's deep dive into this brave AI world with by Gwenwal Riou, Global Director of Strategy and Alliances at Orange Cyberdefense.
In physics, the three-body problem is not just complicated. Past a certain number of objects in interaction, no stable, predictable solution exists anymore, and the system becomes chaotic. The cybersecurity ecosystem before generative AI could already be read through three main families with distinct logics: hyperscalers, who sold compute and storage with security as an adjacent capability, cyber pillars, the established vendors built through acquisitions and detection platforms based on rules, and analytical challengers such as SentinelOne, Darktrace or Vectra AI, who already stood apart through behavioral machine learning rather than signatures. Three bodies, three sources of value, a system that was still readable.
The arrival of large language models did not simply add new players. It brought two new bodies, frontier model providers and AISec, and it transformed the first three from within: hyperscalers now inject LLMs where they used to sell compute, cyber pillars embed generative copilots on top of their rule-based platforms, and analytical challengers add a generative layer on top of their behavioral core. The system moved from three bodies to five, and it is this reshuffling, more than the number of players alone, that makes the ecosystem harder to read today.
Hyperscalers act as providers of compute and storage, and they now inject LLMs directly into workstations and cloud-native solutions to support and increase user productivity. This family includes large technology groups such as Microsoft, Google Cloud and AWS (Amazon Web Services), through digital assistants like Microsoft Copilot, which turn a plain-language request into a sequence of automated actions. Some also offer model libraries that can be built directly into applications running on their infrastructure.
Their strength comes from the sheer scale of data they process, their financial weight, and a presence already embedded in most IT environments, which makes adoption almost automatic. Their customers, in exchange, need to watch two things: dependency on a single vendor, and costs that rise quickly with query volume.
A separate family stands apart from hyperscalers even though it is sometimes tied to them through infrastructure: the labs that design and train the models themselves, such as Anthropic or OpenAI. Their business is not selling compute or storage, it is selling access to a model, usually through an API, which makes them fairly agnostic to the infrastructure underneath. Anthropic runs on AWS and Google Cloud, OpenAI runs on Azure, and this layered dependency adds a further risk for the customer relying on both.
Their relevance to cybersecurity comes from two things. First, they supply the generative foundation that other families build on top of, from SentinelOne's Purple AI to the copilots embedded by cyber pillars. Second, they have become a source of threat intelligence in their own right: both Anthropic and OpenAI now publish their own findings on cyberattacks orchestrated or assisted with their models, which makes them a direct part of the threat landscape as much as a defense provider.
The established vendors of the cybersecurity industry, such as Cisco (through Splunk) or Palo Alto Networks, form a third family. These pillars extend their detection and response platforms (XDR, SIEM) by adding AI and machine learning modules. Their edge is the proprietary data they have already accumulated: they combine network and endpoint telemetry to strengthen alert correlation, and they now extend this logic to more and more data sources through a platform approach.
This evolution has largely been built through acquiring third-party technologies, which then sit on top of older proprietary layers, and the cost is an integration complexity these vendors have to manage on an ongoing basis.
Some players in this ecosystem are not cyber vendors who added AI. They are AI pioneers for whom cybersecurity was, from the start or close to it, the field of application. SentinelOne, Darktrace, Vectra AI and Abnormal Security share this trait: an architecture built around AI from day one, not added later.
SentinelOne is a good example. The company starts from the idea that response time to a ransomware attack has to be measured in milliseconds, and that no architecture depending on a round trip to the cloud can meet that bar. This is why its behavioral models run directly on the agent, able to link the processes of a single device together (this is the logic behind its Storyline technology) to reconstruct the chain of an incident, then neutralize the threat and restore the system without waiting for a central decision. Generative AI, through Purple AI, has since been added on top, but at a different level: it queries and reasons after the fact on the data this behavioral layer produces, without replacing the blocking decision made locally in milliseconds.
The last family covers players positioned on the fast-growing segment of AI security, also called AISec or security for AI. They protect the supply chain of the models themselves, against prompt injection, data poisoning and model theft, and they build their offering directly around the ten risks listed in the OWASP ("Open Worldwide Application Security Program") Top 10 for large language models. This is a young market, and consolidation is already underway rather than still to come: among the four most cited players in the space, HiddenLayer and Lakera remain independent, but Robust Intelligence was bought by Cisco in October 2024 and Protect AI by Palo Alto Networks in April 2025, two deals that directly benefit vendors already present in the families above.
The established vendors of the cybersecurity industry, such as Cisco (through Splunk) or Palo Alto Networks, form a third family. These pillars extend their detection and response platforms (XDR, SIEM) by adding AI and machine learning modules. Their edge is the proprietary data they have already accumulated: they combine network and endpoint telemetry to strengthen alert correlation, and they now extend this logic to more and more data sources through a platform approach.
This evolution has largely been built through acquiring third-party technologies, which then sit on top of older proprietary layers, and the cost is an integration complexity these vendors have to manage on an ongoing basis.
Keep "Ctrl" with the fast evolving frontiers of AI and cybersecurity with our latest brochure below.

15 September 2026 | Rapport

19 August 2026 | Blogg

20 April 2026 | Blogg
The “dual use” nature of AI is pushing cybersecurity forward at a rapid pace. The big issues are sovereignty, access to defensive tools and containing the spread of technologies that could be weaponized.

31 August 2026 | Blogg