Agentic Anarchy
Agentic product capability is advancing faster than explicit security ownership for identity, tool access, authorization, and external consequence.
Start with the pressure: sales, launch, abuse, agents, data, or guardrails
Intelligence
Validated empirical, diagnostic, interpretive, operating-model, and workforce findings.
Agentic product capability is advancing faster than explicit security ownership for identity, tool access, authorization, and external consequence.
Executive AI risk narratives often fail to translate into named controls, owners, and evidence artifacts at the engineering level.
AI security hiring is weighted toward experienced practitioners while the discipline lacks mature entry pathways and workforce infrastructure.
Organizations often treat the model as the AI product while under-modeling the data, context, prompts, tools, orchestration, infrastructure, and generated artifacts around it.
AI language can appear in security hiring without materially changing the underlying responsibilities, controls, or operating model.
The market asks for AI security engineering skills before it has standardized, practical evaluation pathways to validate them.
Adjacent engineers — platform, DevOps, and ML engineers without a security background — report low self-rated confidence on AI security tasks (1.25-1.55 of 5, 16-25% confident), but the barriers they report are training and role-definition gaps, not vocabulary or credential gaps.
Prompt-injection, function-calling, and tool-calling security signals remain a small share of the research and tooling surface today, but are rising quickly.
Across 53,865 analyzed media items, capability coverage outpaces security coverage by roughly 5.0:1 (8,447 capability items vs. 1,682 across every security-labeled bucket combined).
94.3% of observed repositories in GHArchive's bounded rolling-window sample (412 of 437) remain unclassified as AI-security-specific — the AI-native tooling ecosystem employers ask for barely exists yet.
Established compliance language substantially outweighs AI-native governance and control vocabulary in hiring language.
Organizations frequently move from policy or tooling claims directly to assurance without demonstrating the control, test, telemetry, and evidence chain.
53 AI-relevant CVEs have reached CISA Known Exploited Vulnerability status — actively exploited in the wild today, not a theoretical future risk.
Of 8 tracked AI-native security frameworks, 5 are document-only and only 3 are machine-readable — none are natively integrated into CI/CD pipelines, security tooling, or automated evidence collection.
AI security hiring often compresses responsibilities historically distributed across several security disciplines into one requisition.
3,411 of 10,152 unique arXiv papers in the current pull are strict AI-security papers, already naming concrete work in prompt/generation security, agentic action security, model and ML attack security, governance assurance, privacy protection, MCP/tool-use security, and red teaming.
Only 8 Wikimedia pages are narrowly tagged AI-security-specific against a field with 3,411 strict AI-security arXiv papers and 437 classified GitHub repos — there is no canonical public reference for AI security engineering as a practice.
Differential privacy and privacy-preserving ML remain active arXiv research terms (112 and 32 papers in the current pull), but privacy still appears in hiring language mainly as a GDPR/compliance checkbox rather than a named engineering capability.
AI security hiring language increasingly reflects probabilistic systems reasoning and ambiguity tolerance rather than deterministic pass/fail control thinking.
AI red teaming is frequently described as a standalone activity even though durable value depends on control engineering, telemetry, replay, remediation, and regression.
arXiv puts only 1.99% of papers (202 of 10,152) in detection and runtime monitoring, and media coverage of AI cyber defense is just 0.9% of volume (486 of 53,865 items) — among the least-researched and least-covered AI security topics.
Compliance automation incumbents appear in hiring language more visibly than AI-native security testing and evaluation tooling.
The market prices one role while frequently describing team-level capability breadth, compressing five or more specialties into a single requisition.
Some organizations are too small to hire the unicorn role the market has priced, but too exposed to defer AI security entirely.