
Buying AI's Honeypot Problem
Posted August 18, 2026
Chris Campbell
Yesterday I wrote about Grok Bots—AI agents rummaging through your digital life like raccoons in a dumpster.
This morning, I received the question a smarter version of me would've landed yesterday:
"What's the solution? How does someone use these AI agents while maintaining security online? Are there companies specifically working on solving the uncertainty about who holds the keys? Grok Bot is one example, but ChatGPT also recently launched the ability to connect bank accounts and medical records."
There is. And it’s also investable.
Consider what just happened.
Frontier AI companies are asking hundreds of millions of weekly users to hand over their medical records. Then their bank logins. Chase. Fidelity. Schwab.
If you’re not creeped out by this—and even if you are—there's a way to play this. Several, actually.
But first, you need to understand the biggest risk hiding underneath the whole thing.
AI’s Honeypot Problem
Your bank knows your money. Your doctor knows your health. Your therapist knows your demons. Your search bar knows your questions.
Until now, no single entity has asked you to willingly give up all of them at once. Now they do—plus every 2am fear you've ever typed into a chat box.
None of it is privileged. No doctor-patient protection, no attorney-client shield. Chat logs are discoverable, and courts have already ordered AI companies to preserve them.
And the part nobody talks about: the machine can also infer things you never typed. The pregnancy from the purchases. The depression from the existential questions. The divorce from the transactions.
All of it sitting in one place, inside companies burning billions a year that will eventually need to make it back.
These are already the biggest honeypots on Earth.
A hospital breach leaks your health. A bank breach leaks your money. A breach here leaks your entire life.
And there’s one thing you can count on…
Every hacker on the planet is working the locks right now.
Bigger problem: the technologies that would truly fix this remain niche. On-device AI lags frontier scale by a mile. Confidential computing—where even the provider can't read your data—is an Apple feature and a stack of research papers.
Despite all of this…
People are going to use these things regardless. They always do. The seatbelt got invented after the car did—and the companies positioned to build the seatbelts are the trade.
Who Holds the Keys?
So back to the question… who holds the keys?
The answer the industry landed on: nobody should. Least of all the agents.
The agent never gets your password, per se. You grant it a scoped, revocable token—a keycard that opens specific doors, for a limited time, and dies the moment you kill it.
If the agent goes rogue, you revoke the token. Here, the blast radius shrinks to whatever that one key could reach.
The industry calls this "non-human identity."
Machine identities already outnumber humans inside the enterprise by 80 to 1—and AI agents are pouring gasoline on that ratio. Every single one needs credentials issued, scoped, rotated, revoked.
The infrastructure to govern that population barely exists. Which is why the giants went shopping.
Palo Alto Networks closed its $25 billion acquisition of CyberArk in February—the largest identity deal ever. Cisco bought Astrix. Okta bought Axiom. IBM owns HashiCorp's Vault.
Three of the biggest buyers in security spent the last year acquiring locksmiths.
That’s the first layer. Now let’s look at the second.
The Hole in the Armor
Here's what identity doesn't fix: prompt injection.
I mentioned it yesterday.
A poisoned email can whisper instructions to your agent, which then misuses the legitimate keys you handed it. Every action looks authorized. Because technically, it is.
Identity limits the blast radius, but it doesn't stop the blast.
Enter the second layer: runtime security. Software that watches the agent every second, catches it mid-action, yanks its credentials before the damage spreads.
The catch? It's expensive. Inference stacked on inference stacked on inference (inferenception?). A per-action toll on the entire agentic economy. But, as you know, expensive problems make excellent businesses.
And again, the buyers beat you to the startups. SentinelOne bought Prompt Security. Check Point bought Lakera. Palo Alto—again—bought Protect AI.
Notice who showed up twice.
Palo Alto now owns the identity layer and the runtime layer. One ticker, both barrels. The keys and the cameras. Those two layers are part of the solution. And the trade.
In the meantime, prompt injection still has no cure—every fix on the market limits the damage rather than prevents it.
What does this mean for you? The best security layer is still the one between your ears.
Fast Times at Honeypot High
Until the seatbelts get built, caution is the seatbelt. So understand what you're handing over.
Connect only what you must. Revoke what you don't use. And never tell a chatbot anything you wouldn't want read aloud in a courtroom.
And last but most important, remember this: The fast get rich in the AI era. But the careful get to keep it.
