Europe Wrote the Rules. America Bought the Market.
By Yuri Bobbert, PhD
Palo Alto Networks, Check Point, Cisco and F5 have collectively spent more than $1.4 billion acquiring AI governance startups, according to industry funding trackers. In the same window, standalone governance and decisioning players such as LeapXpert (reportedly around $180 million) and Taktile (around $110 million, led by Goldman Sachs) closed large rounds on their own. None of these companies train foundation models. They are security, networking and workflow vendors, and investors, spending real money to get into a category they did not build. That is worth sitting with for a moment.
Buying instead of building
When an established security vendor acquires rather than builds, it is usually a sign the underlying capability has become table stakes faster than internal engineering roadmaps can move. Palo Alto Networks, Check Point, Cisco and F5 already sell network and endpoint security to the same enterprises now racing to deploy AI agents and copilots. Buying an AI governance startup is the fastest way to bolt a compliance and risk layer onto an existing platform before a competitor gets there first, and before the customer's procurement team asks why it is not already included.
The parallel investors keep drawing is SOC 2 for cloud. A decade ago, cloud security certification went from a nice-to-have to a deal-blocking requirement almost overnight, and an entire audit and tooling industry grew up around it. The bet behind this wave of M&A and funding is that AI agent governance, meaning audit trails, authority tiers, model documentation and continuous monitoring, is about to follow the same curve, except compressed into months rather than years because regulators (the EU AI Act's enforcement powers being the clearest example this month) are moving in parallel with the market.
The capital behind this wave is not European
Look closely at who is actually behind these numbers and a pattern emerges that has little to do with technology and everything to do with geography. Palo Alto Networks, Cisco and F5 are American companies, headquartered in California and Washington, running on American technology stacks. Check Point likes to describe itself as global, but it is dual headquartered in Tel Aviv and California, not Europe. LeapXpert's $180 million round was led by Riverwood Capital, a US growth equity firm. Taktile is, in fact, a Berlin based company, but its $110 million Series C was led by Goldman Sachs Asset Management, an American institution, with European funds such as Balderton Capital and Index Ventures riding along rather than sitting in the driver's seat.
Not one of the leading checks in this wave of AI governance dealmaking came from a European investor, and not one of the platforms doing the buying runs on an EU technology stack. For a category that exists largely because of European regulation, with the EU AI Act's new enforcement powers being the clearest driver this month, that is a notable gap. The rules are being written in Brussels. The capital deciding who builds the tooling that responds to those rules is, almost without exception, being deployed from San Francisco, Seattle, Tel Aviv and New York.
Europe is regulating a market it is not funding at the same scale, and organizations that care about where their AI governance vendor's technology actually sits, and who ultimately controls it, may want to weigh that imbalance alongside the usual feature comparison.
That imbalance sits on top of an already uneven playing field. I have pointed out elsewhere that the sheer volume of EU technology regulation, GDPR, NIS2, DORA and now the AI Act among them, already pushes a meaningful share of European scale ups to relocate outside the bloc rather than absorb the compliance burden. A governance market whose capital comes almost entirely from outside Europe, layered on top of that existing asymmetry, does not make the compliance burden lighter for the European companies still trying to carry it. Three smaller deals in the fuller breakdown below complicate that picture slightly: DTCP, a Deutsche Telekom backed fund, led a round for compliance automation player anecdotes, and Switzerland's Join Capital backed AI risk startup Calvin Risk at seed stage. All three are real. All three are also two to three orders of magnitude smaller than the acquisitions and mega rounds actually driving this wave. NL-based Deeploy raised a 2.5 million euro seed round plus up to 7.5 million euros from the EIC Accelerator, of which 2.5 million euros is grant funding and 5 million euros is reserved as equity for its next round. The pattern holds where the money is largest, it is just not absolute everywhere.
Where the AI trust money actually went, in full
The $1.4 billion figure above covers four acquirers. It is not the whole picture. Widening the lens to every acquisition and funding round across the AI trust and governance stack, from August 2024 through August 2026, disclosed and estimated deal values add up to something closer to $5.5 billion, and that is a floor, since several of the largest lines below are ranges rather than confirmed numbers. Figures are compiled from public deal announcements, company disclosures and industry funding trackers, and estimates are marked as such.
Add it up across every layer and the wave that produced the $1.4 billion headline is, if anything, understating the case. Most of the biggest numbers still sit with acquirers and lead investors based in the United States, with Israel showing up through Check Point's dual headquarters, and Europe showing up only in a handful of smaller rounds inside the compliance and pure play categories.
What the money is actually pricing in
Two things stand out in how the capital is splitting. First, incumbents are paying for distribution and integration, not just technology. An acquired AI governance startup is worth more once it can be sold through an existing security sales motion to an existing customer base than it was as a standalone product. Second, the size of the standalone rounds, LeapXpert and Taktile among them, suggests investors do not think the category consolidates into two or three winners quickly. There is still room being priced in for independent, best-of-breed governance platforms that sit above any single vendor's stack and cover the AI systems a company did not build itself, which is most of them.
That second point matters more than the headline acquisition numbers.
Governance that lives inside one security vendor's product only sees what that vendor's tools touch. A vendor-tunnel-vision.
An organization's actual AI footprint, procured software with embedded AI features, vendor models, internally built agents, rarely stays inside one vendor's perimeter. The market appears to be pricing in both a consolidation trade and a case for independent, continuous coverage across all of it.
Buying tools does not close the knowing-doing gap
Acquiring new technology is an easy story for a listed company to tell. It shows up in an earnings call as evidence of innovation, it extends the portfolio, and it lets a security vendor claim it now covers AI governance without waiting on a product roadmap. What that story leaves out is a pattern that keeps showing up in how organizations actually run IT and security programs: the knowing-doing gap I have written about before, meaning the distance between what a company knows it should do and what it actually does day to day, and its close relative, tool sprawl, where point solutions get purchased faster than any of them get properly implemented, integrated or used.
Neither gap closes by buying another tool, and that matters more for AI, not less. The AI wild west most organizations are currently operating in will not be tamed by adding one more governance product to a stack that already has too many of them. It gets tamed by looking closely at how AI is actually implemented and used inside real business processes, and by designing those processes to be secure from the outset instead of patching them after something goes wrong. AI has a far-reaching effect on how a business process runs, and if that process was not designed with AI's impact in mind from the beginning, no amount of tooling stacked on top of it afterward will fully make up for that. Everything that used to work as a manual, periodic IT governance check becomes insufficient once AI sits inside the process. It needs new, deliberate design from day one, not a retrofit once the audit finds the gap, a dynamic I describe at length in a piece on digital security more broadly, and one that applies just as directly once AI sits inside the process.
What most of the acquired tooling in this wave is built to watch for also stops short of the actual attack surface. It covers access control, data handling and model documentation, but rarely the moment-to-moment risk of how a model itself gets talked into doing something it should not. I have made the board-level case elsewhere that prompting and the social manipulation of large language models deserve their own governance lens, separate from traditional application security: an LLM is not just software with a vulnerability list to patch, it is a conversational surface that can be persuaded, coaxed or slowly steered off course by the people and systems interacting with it, and no dashboard bought off the shelf catches that unless the underlying process was designed to watch for it.
That points to a different kind of tool than most of what is being acquired or funded in this wave. Not another dashboard bolted onto an existing platform, but something built to map the entire workflow of a business process, including how people and other systems actually prompt and interact with the AI inside it, and determine where the real protect surface sits, before anyone decides what needs governing and how. Vincent van Dijk and I proposed exactly this kind of structured, collaborative approach to AI risk assessment, built on NIST's risk categories and gathering the views of every AI actor involved rather than relying on one reviewer's judgment call, precisely because a single-person or single-tool view of AI risk tends to carry the same blind spots it is supposed to catch.
Avoiding FOMO is not the same as investing thoughtfully
A fair share of the AI investment driving this wave, on both the vendor and the enterprise side, is happening because leaders do not want to be seen missing the AI race, not because they have worked out how AI should be integrated safely into their own processes. Analysts and investors tend to reinforce that pattern, treating any company that is not visibly spending on AI as a laggard by default. But some of the organizations sitting out this particular rush may not be behind at all. They may simply be taking the time to understand how AI actually changes their business processes before buying tools to manage a problem they have not yet fully mapped. Being early is not the same as being right, and being careful is not automatically the same as being behind.
What this means for GRC teams, founders and investors
For GRC and AI risk professionals, the practical read is that governance tooling is no longer optional line-item spend waiting for budget approval. It is becoming a bundled feature inside security platforms your organization may already own, which raises the bar on what a good AI governance program needs to do beyond what comes free with the firewall. For tech founders and entrepreneurs building in this space, incumbent acquisitions at this scale are validation that enterprise buyers see AI governance as core infrastructure, not a nice-to-have add-on, and that the door for independent platforms is still open. For investors, the combination of strategic M&A and large standalone rounds in the same category, at the same time, is a reasonably strong signal that this is not a hype cycle running on enthusiasm alone; procurement budgets are actually moving. That said, the same investors would do well to separate genuine process redesign from acquisitions made mainly to keep pace with the news cycle, and European buyers in particular may want to ask where their governance vendor's technology and capital actually sit.
What incumbent-bundled governance tends not to solve is continuous, audit-ready evidence across an organization's full AI supply chain, not just the pieces one vendor's tools can see, and not just the tools themselves without the process work underneath them. insAIght is built for that broader inventory: mapping AI systems, vendors, processes and dependencies continuously rather than waiting for the next procurement cycle or acquisition to draw the boundary. Anove has written before about how proximity to the AI buildout can inflate a vendor's perceived importance without a matching increase in visibility into what that vendor actually does to your risk posture, and about how LLMs themselves function as a new kind of attack surface; the same caution applies to governance tooling bought as a feature rather than adopted as a discipline.
The open question
The money has already voted. Whether the total is $1.4 billion in acquisitions or $5.5 billion across the full AI trust stack, the message is the same: AI governance is becoming permanent infrastructure. This may be its SOC 2 moment. Or it may be a capital rush ahead of regulation that Europe could still soften. But markets move faster than policy. Companies are buying, investors are betting, and governance is becoming a recurring budget line, not a temporary compliance project.
The real risk is assuming that buying the tool solves the problem. It does not. Governance only works when technology is matched by process redesign and when buyers understand who ultimately owns, funds, and controls the technology they rely on. Europe wrote the rules. Capital is deciding who gets paid to enforce them.
Learn more
- insAIght: continuous, audit-ready visibility into the AI systems, processes and vendors an organization actually depends on, independent of any single security vendor's product boundary.
- ExplAIn: check whether the AI tools already in use across your organization would hold up to scrutiny.
- The Picks-and-Shovels Rally: What $100 Billion Valuations for Vertiv, Seagate and SanDisk Actually Signal
- LLMs as a New Attack Surface: what does it mean for AI governance?
References
- Bobbert, Y. (2024). How Companies Can Deal With the Increase of EU Tech Regulations. ISACA Netherlands Chapter. https://isaca.nl/how-companies-can-deal-with-the-increase-of-eu-tech-regulations/
- Bobbert, Y. (2025). The Knowing-Doing Gap in Digital Security. ISACA Netherlands Chapter. https://isaca.nl/the-knowing-doing-gap-in-digital-security/
- Bobbert, Y. (2025b). LLMs as a New Attack Surface: Board-Level AI Risk Governance. ISACA Netherlands Chapter. https://isaca.nl/llms-as-a-new-attack-surface-board-level-ai-risk-governance/
- Bobbert, Y., & van Dijk, V. (2023). An Exploration of AI Risk & Collaborative Assessment Methodology. ISACA Netherlands Chapter. https://isaca.nl/an-exploration-of-ai-risk-collaborative-assessment-methodology/
- AI Governance Market Funding Trends, New Market Pitch (industry funding tracker), reported acquisition and funding figures for Palo Alto Networks, Check Point, Cisco, F5, LeapXpert and Taktile.
- Deal and funding figures for the full stack breakdown compiled from public disclosures, company announcements and industry funding trackers, August 2024 to August 2026.
Appendix: the VC firms behind these vendors, and where they are based
The table below compiles the most notable venture capital and institutional investors found across the 26 companies named in this piece, whether acquired or independently funded, going back through each company's investor history where relevant, not just the single round already cited above. Names and round attributions are cross checked against public deal announcements, company and investor press releases, and Crunchbase, and country of origin is checked against each firm's own headquarters information alongside Wikipedia's List of venture capital firms. Entries marked single source should be treated as indicative rather than fully confirmed.
| VC firm | Country of origin | Companies backed, from this article | Note |
|---|---|---|---|
| Sequoia Capital | United States | Robust Intelligence, Apex Security, Vanta | Confirmed, multiple sources |
| Index Ventures | Switzerland, founded; dual US/UK today | Taktile, Arthur AI | Confirmed |
| Y Combinator | United States | Vanta, Taktile | Confirmed |
| Insight Partners | United States | Fiddler AI, Reco | Confirmed |
| Tiger Global Management | United States | Robust Intelligence, Taktile | Confirmed |
| Ballistic Ventures | United States | Pangea, Noma Security, WitnessAI | Confirmed |
| Evolution Equity Partners | Switzerland and United States | Protect AI, Noma Security | Confirmed |
| Mozilla Ventures | United States | Fiddler AI, Credo AI, Holistic AI | Confirmed |
| Glilot Capital Partners | Israel | Noma Security, anecdotes | Confirmed |
| DTCP (Deutsche Telekom Capital Partners) | Germany | Zenity, anecdotes | Confirmed |
| Lightspeed Venture Partners | United States | CalypsoAI, Fiddler AI | Confirmed |
| GGV Capital | United States | Drata | Confirmed |
| ICONIQ Growth | United States | Drata | Confirmed |
| Greylock Partners | United States | TruEra | Confirmed |
| Accel | United States, with a major UK arm | Sprinto | Confirmed |
| Acrew Capital | United States | Protect AI, Arthur AI | Confirmed |
| Workday Ventures | United States | Reco, Vanta | Confirmed |
| Riverwood Capital | United States | LeapXpert | Confirmed, already cited above |
| Goldman Sachs Asset Management | United States | Taktile, Vanta | Confirmed |
| Balderton Capital | United Kingdom | Taktile | Confirmed, already cited above |
| Norwest Venture Partners | United States | Zenity | Confirmed, already cited above |
| SoftBank Vision Fund 2 | Japan | Zenity | Confirmed, already cited above |
| Hitachi Ventures | Japan, parent; VC arm based in Germany | Zenity | Confirmed, already cited above |
| LG Technology Ventures | South Korea | Zenity | Confirmed, already cited above |
| Intel Capital | United States | Zenity | Confirmed, already cited above |
| Sound Ventures | United States | WitnessAI | Confirmed, already cited above |
| Qualcomm Ventures | United States | WitnessAI | Confirmed, already cited above |
| Samsung Ventures | South Korea | WitnessAI | Confirmed, already cited above |
| Forgepoint Capital | United States | WitnessAI | Confirmed, already cited above |
| Zeev Ventures | Israel | Reco | Confirmed, already cited above |
| TIAA Ventures | United States | Reco | Confirmed, already cited above |
| RPS Ventures | United States | Fiddler AI | Confirmed, already cited above |
| Baird Capital | United States | ModelOp | Confirmed, already cited above |
| Join Capital | Switzerland | Calvin Risk | Confirmed, already cited above |
| Abstract Ventures | United States | Holistic AI | Confirmed |
| BoxGroup | United States | Holistic AI | Confirmed |
| GV (Google Ventures) | United States | WitnessAI | Single source, unverified |