
Every enterprise just absorbed a workforce nobody interviewed, onboarded, or supervises. Attackers hired theirs first. Here's where the next decade of security value gets built.
Key Findings
- The clock-speed gap is widening. AI-enabled adversary attacks grew 89% in 2025 and average breakout time fell to 29 minutes, while most defense still runs on human schedules.
- Code now ships faster than humans can review it. With AI writing most new code at some of the largest software companies, design-time threat modeling becomes the only security gate that scales.
- Machine identities are the least governed privileged population. Non-human identities outnumber employees more than 80 to 1, yet their credentials rarely rotate and their access is almost never rightsized.
- Autonomous defense is only as good as its ground truth. AI-run investigation needs years of real, adjudicated incidents behind it, which synthetic data and vendor demos cannot replace.
- Three control points will define the next decade. Security value accrues to companies that vet the unhired workforce at design time, govern it at the identity layer, and supervise it at machine speed.
Inside virtually every enterprise we meet, an employee nobody hired is hard at work.
It's writing production code that will ship in today's sprint. It's holding credentials to the company's most sensitive systems. It never sat for an interview, never passed a background check, doesn't appear in any HR system, and will never show up to a review. And it isn't one employee. It's thousands of them, added faster than any hiring spree in corporate history.
That's the defining security fact of the AI era: enterprises are absorbing an unhired workforce of AI agents, machine identities, and autonomous processes, and managing it with none of the discipline they'd apply to a human workforce one-tenth the size.
At the same time, the bad guys were also onboarding their workforce. But faster.
Few people have watched this unfold from the attacker's side longer than Dave Kennedy, a career red-teamer, founder of TrustedSec, and co-founder and CEO of our portfolio company Binary Defense. His read is blunt:
"Attackers don't hold change-management meetings. They operationalized AI the week it got good. Tradecraft that took my red teams three weeks now runs overnight, unattended. Defense isn't losing on skill. It's losing on clock speed.”
The clock-speed gap
The numbers from the front lines back him up. According to CrowdStrike's 2026 Global Threat Report, attacks by AI-enabled adversaries grew 89% in 2025, and the average cybercrime breakout time (initial access to lateral movement) collapsed to just 29 minutes. A campaign that used to take a skilled crew weeks of reconnaissance, tooling, and social engineering now runs overnight, staffed by agents that don't sleep, don't get sloppy, and cost almost nothing to scale.
Most security programs, meanwhile, still run on human clock speed: quarterly pen tests, annual access reviews, ticket queues, tier-1 analysts triaging alerts one at a time. That mismatch (machine-speed offense against human-speed defense) is the clock-speed gap, and it's widening.
As investors, we believe this imbalance is one of the most important structural forces in security today. And you can't address it with another point product, because the unhired workforce doesn't show up in one place. It shows up in three places, and each becomes an important control point. This is where enduring security companies must be built.
1. It's writing the code
AI now writes most of the new code at some of the world's largest software companies. At Google, CEO Sundar Pichai said in April that 75% of the company's new code is AI-generated and approved by engineers, up from 50% just six months earlier. Software volume is exploding while the number of humans reviewing it stays flat.
Every security gate that depends on a human reading code after it's written is now broken logic. Quality can't be inspected at the end of a line that moves this fast. The only control point that can truly scale proportionately sits upstream of the code itself: the design.
So threat modeling (figuring out how an attacker would abuse a system and designing it so they can't) stops being a whiteboard exercise done once a year for the crown-jewel app and becomes an automated, continuous discipline, with security requirements engineered into the architecture before an agent writes the first line against it. When machines build from blueprints, the blueprint is the perimeter. “Secure by design” stops being a regulator's slogan and becomes the only gate an enterprise can actually hold.
That's why we believe design-time security moves from nice-to-have to the top of the security funnel. It is also the thesis behind our investment in ThreatModeler.ai, which has spent years building exactly this discipline and, through its Nexus platform, enables enterprises to secure designs at a scale we have never seen before.
2. It's holding the keys
Every AI agent, service account, workload, API key, and pipeline is an identity, with credentials, entitlements, and access to real systems. These non-human identities already outnumber human employees by more than 80 to 1 (CyberArk's Identity Security Landscape report), and every agent deployment pushes the ratio even higher.
Apply the workforce test. Human employees get onboarded, badged, reviewed, and offboarded. The unhired workforce? Its credentials rarely rotate. Its access is almost never rightsized. Nobody offboards a service account when the project ends. No manager reviews an agent's entitlements. In most enterprises, the largest population of privileged identities has the least governance.
Attackers have done this math too. Compromising an over-permissioned machine identity is quieter, cheaper, and more durable than phishing a human: no MFA prompt, no suspicious login from a strange city, no one to notice something is off. As agentic AI takes hold, identity, not the network, becomes the control plane of enterprise security. And most of that plane is increasingly machines.
The discipline emerging around this is identity risk management: continuously discovering the non-human population, mapping what each identity can actually do, and cutting the blast radius before an adversary finds it. It's the thesis behind our investment in Axiad, which is focused squarely on lighting up non-human identities and risk across the entire identity landscape, in real time.
3. It's powering the SOC
The third place the unhired workforce shows up is the one place it belongs: on defense. A 29-minute breakout time doesn't wait for a tier-1 analyst to work a queue. If detection and response runs at human speed, the adversary wins on tempo alone. Every time.
So the security operations center is becoming a place where AI conducts the investigation (correlating signals, pulling context, building the timeline, containing the endpoint) while humans supervise the work: on the loop, not in the line. The analyst's job shifts from grinding through alerts to commanding a machine-speed operation, and the metric that matters becomes leverage: how much verified investigation each human can supervise.
Here's where much of the AI-security hype falls apart, and for anyone walking the halls of the RSA Security Conference this year, you know it's been extra noisy. Autonomous defense is only as good as its ground truth. If you remember the once-hot UBA (user behavior analytics) category, we've seen this movie before. If your baseline normal is compromised, so too is your detection capability. The same concept applies here, and no amount of marketing spend can stop a fly-by-night platform trained on synthetic data and vendor demos from doing the wrong thing when it matters.
The operators best positioned to build trustworthy autonomous defenses are the ones sitting on years of real, adjudicated incidents. That's the messy reality of what real-world attacks actually look like and what response truly works, and it cannot be shortcut, scraped, or vibed into existence.
That's the logic behind NightBeacon CMD, the AI product suite from Binary Defense, built by elite practitioners and assembled on more than a decade of managed detection and response outcomes. NightBeacon Command brings AI-run investigation to the SOC in a way that makes operational sense for practitioners and gives defenders the much-needed ability to close the clock-speed gap.
The Opportunity
The unhired workforce is not a forecast. It is already on the job at nearly every company we meet: writing the code, holding the keys, and, at the enterprises getting this right, running the defense. Managed like a workforce (vetted at design time, governed at the identity layer, supervised at machine speed), it becomes the biggest force multiplier security has ever had. Left unmanaged, it can create the biggest attack surface we have ever seen.
That's why we've concentrated our conviction across these areas and will continue to invest in durable control points. The winners of the next decade in security will be companies that put the unhired workforce to work safely, and the investors who back them.
Jeremy Lai is a Partner at Invictus Growth Partners. Invictus Growth Partners is an investor in Axiad, Binary Defense, and ThreatModeler.ai.
