Europe Wrote the Rules. America Bought the Market.
By Yuri Bobbert
Palo Alto Networks, Check Point, Cisco and F5 have collectively spent more than $1.4 billion acquiring AI governance startups, according to industry funding trackers. In the same window, standalone governance and decisioning players such as LeapXpert (reportedly around $180 million) and Taktile (around $110 million, led by Goldman Sachs) closed large rounds on their own. None of these companies train foundation models. They are security, networking and workflow vendors, and investors, spending real money to get into a category they did not build. That is worth sitting with for a moment.
Buying instead of building
When an established security vendor acquires rather than builds, it is usually a sign the underlying capability has become table stakes faster than internal engineering roadmaps can move. Palo Alto Networks, Check Point, Cisco and F5 already sell network and endpoint security to the same enterprises now racing to deploy AI agents and copilots. Buying an AI governance startup is the fastest way to bolt a compliance and risk layer onto an existing platform before a competitor gets there first, and before the customer's procurement team asks why it is not already included.
The parallel investors keep drawing is SOC 2 for cloud. A decade ago, cloud security certification went from a nice-to-have to a deal-blocking requirement almost overnight, and an entire audit and tooling industry grew up around it. The bet behind this wave of M&A and funding is that AI agent governance, meaning audit trails, authority tiers, model documentation and continuous monitoring, is about to follow the same curve, except compressed into months rather than years because regulators (the EU AI Act's enforcement powers being the clearest example this month) are moving in parallel with the market.
The capital behind this wave is not European
Look closely at who is actually behind these numbers and a pattern emerges that has little to do with technology and everything to do with geography. Palo Alto Networks, Cisco and F5 are American companies, headquartered in California and Washington, running on American technology stacks. Check Point likes to describe itself as global, but it is dual headquartered in Tel Aviv and California, not Europe. LeapXpert's $180 million round was led by Riverwood Capital, a US growth equity firm. Taktile is, in fact, a Berlin based company, but its $110 million Series C was led by Goldman Sachs Asset Management, an American institution, with European funds such as Balderton Capital and Index Ventures riding along rather than sitting in the driver's seat.
Not one of the leading checks in this wave of AI governance dealmaking came from a European investor, and not one of the platforms doing the buying runs on an EU technology stack. For a category that exists largely because of European regulation, with the EU AI Act's new enforcement powers being the clearest driver this month, that is a notable gap. The rules are being written in Brussels. The capital deciding who builds the tooling that responds to those rules is, almost without exception, being deployed from San Francisco, Seattle, Tel Aviv and New York. Europe is regulating a market it is not funding at the same scale, and organizations that care about where their AI governance vendor's technology actually sits, and who ultimately controls it, may want to weigh that imbalance alongside the usual feature comparison.
That imbalance sits on top of an already uneven playing field. Bobbert (2024) has pointed out that the sheer volume of EU technology regulation, GDPR, NIS2, DORA and now the AI Act among them, already pushes a meaningful share of European scale ups to relocate outside the bloc rather than absorb the compliance burden. A governance market whose capital comes almost entirely from outside Europe, layered on top of that existing asymmetry, does not make the compliance burden lighter for the European companies still trying to carry it.
What the money is actually pricing in
Two things stand out in how the capital is splitting. First, incumbents are paying for distribution and integration, not just technology. An acquired AI governance startup is worth more once it can be sold through an existing security sales motion to an existing customer base than it was as a standalone product. Second, the size of the standalone rounds, LeapXpert and Taktile among them, suggests investors do not think the category consolidates into two or three winners quickly. There is still room being priced in for independent, best-of-breed governance platforms that sit above any single vendor's stack and cover the AI systems a company did not build itself, which is most of them.
That second point matters more than the headline acquisition numbers. Governance that lives inside one security vendor's product only sees what that vendor's tools touch. An organization's actual AI footprint, procured software with embedded AI features, vendor models, internally built agents, rarely stays inside one vendor's perimeter. The market appears to be pricing in both a consolidation trade and a case for independent, continuous coverage across all of it.
Buying tools does not close the knowing-doing gap
Acquiring new technology is an easy story for a listed company to tell. It shows up in an earnings call as evidence of innovation, it extends the portfolio, and it lets a security vendor claim it now covers AI governance without waiting on a product roadmap. What that story leaves out is a pattern that keeps showing up in how organizations actually run IT and security programs: the knowing-doing gap (Bobbert, 2025a), meaning the distance between what a company knows it should do and what it actually does day to day, and its close relative, tool sprawl, where point solutions get purchased faster than any of them get properly implemented, integrated or used.
Neither gap closes by buying another tool, and that matters more for AI, not less. The AI wild west most organizations are currently operating in will not be tamed by adding one more governance product to a stack that already has too many of them. It gets tamed by looking closely at how AI is actually implemented and used inside real business processes, and by designing those processes to be secure from the outset instead of patching them after something goes wrong. AI has a far-reaching effect on how a business process runs, and if that process was not designed with AI's impact in mind from the beginning, no amount of tooling stacked on top of it afterward will fully make up for that. Everything that used to work as a manual, periodic IT governance check becomes insufficient once AI sits inside the process. It needs new, deliberate design from day one, not a retrofit once the audit finds the gap, a dynamic Bobbert (2025a) describes at length in the context of digital security more broadly, and one that applies just as directly once AI sits inside the process.
What most of the acquired tooling in this wave is built to watch for also stops short of the actual attack surface. It covers access control, data handling and model documentation, but rarely the moment-to-moment risk of how a model itself gets talked into doing something it should not. Bobbert (2025b) makes the board-level case that prompting and the social manipulation of large language models deserve their own governance lens, separate from traditional application security: an LLM is not just software with a vulnerability list to patch, it is a conversational surface that can be persuaded, coaxed or slowly steered off course by the people and systems interacting with it, and no dashboard bought off the shelf catches that unless the underlying process was designed to watch for it.
That points to a different kind of tool than most of what is being acquired or funded in this wave. Not another dashboard bolted onto an existing platform, but something built to map the entire workflow of a business process, including how people and other systems actually prompt and interact with the AI inside it, and determine where the real protect surface sits, before anyone decides what needs governing and how. Bobbert and van Dijk (2023) proposed exactly this kind of structured, collaborative approach to AI risk assessment, built on NIST's risk categories and gathering the views of every AI actor involved rather than relying on one reviewer's judgment call, precisely because a single-person or single-tool view of AI risk tends to carry the same blind spots it is supposed to catch.
Avoiding FOMO is not the same as investing thoughtfully
A fair share of the AI investment driving this wave, on both the vendor and the enterprise side, is happening because leaders do not want to be seen missing the AI race, not because they have worked out how AI should be integrated safely into their own processes. Analysts and investors tend to reinforce that pattern, treating any company that is not visibly spending on AI as a laggard by default. But some of the organizations sitting out this particular rush may not be behind at all. They may simply be taking the time to understand how AI actually changes their business processes before buying tools to manage a problem they have not yet fully mapped. Being early is not the same as being right, and being careful is not automatically the same as being behind.
What this means for GRC teams, founders and investors
For GRC and AI risk professionals, the practical read is that governance tooling is no longer optional line-item spend waiting for budget approval. It is becoming a bundled feature inside security platforms your organization may already own, which raises the bar on what a good AI governance program needs to do beyond what comes free with the firewall. For tech founders and entrepreneurs building in this space, incumbent acquisitions at this scale are validation that enterprise buyers see AI governance as core infrastructure, not a nice-to-have add-on, and that the door for independent platforms is still open. For investors, the combination of strategic M&A and large standalone rounds in the same category, at the same time, is a reasonably strong signal that this is not a hype cycle running on enthusiasm alone; procurement budgets are actually moving. That said, the same investors would do well to separate genuine process redesign from acquisitions made mainly to keep pace with the news cycle, and European buyers in particular may want to ask where their governance vendor's technology and capital actually sit.
What incumbent-bundled governance tends not to solve is continuous, audit-ready evidence across an organization's full AI supply chain, not just the pieces one vendor's tools can see, and not just the tools themselves without the process work underneath them. insAIght is built for that broader inventory: mapping AI systems, vendors, processes and dependencies continuously rather than waiting for the next procurement cycle or acquisition to draw the boundary. Anove has written before about how proximity to the AI buildout can inflate a vendor's perceived importance without a matching increase in visibility into what that vendor actually does to your risk posture, and about how LLMs themselves function as a new kind of attack surface; the same caution applies to governance tooling bought as a feature rather than adopted as a discipline.
The open question
$1.4 billion in acquisitions plus large standalone rounds either means AI governance has found its SOC 2 moment, with incumbents and independents both building out a durable market, or it means capital is chasing a compliance deadline that regulators could still soften, as the EU's own Digital Omnibus already has once this year. Either way, the money is a clearer signal than any regulator's press release that the market expects AI governance to be a permanent line item, not a temporary compliance scramble, provided the tools being bought are matched with the process redesign they actually require, and provided buyers pay attention to whose capital and technology sit behind the tooling.
Learn more
- insAIght: continuous, audit-ready visibility into the AI systems, processes and vendors an organization actually depends on, independent of any single security vendor's product boundary.
- ExplAIn: check whether the AI tools already in use across your organization would hold up to scrutiny.
- The Picks-and-Shovels Rally: What $100 Billion Valuations for Vertiv, Seagate and SanDisk Actually Signal
- LLMs as a New Attack Surface: what does it mean for AI governance?
Book a demo to see how insAIght gives you continuous AI governance coverage that does not stop at the edge of any one vendor's platform.
References
- Bobbert, Y. (2024). How Companies Can Deal With the Increase of EU Tech Regulations. ISACA Netherlands Chapter. https://isaca.nl/how-companies-can-deal-with-the-increase-of-eu-tech-regulations/
- Bobbert, Y. (2025a). The Knowing-Doing Gap in Digital Security. ISACA Netherlands Chapter. https://isaca.nl/the-knowing-doing-gap-in-digital-security/
- Bobbert, Y. (2025b). LLMs as a New Attack Surface: Board-Level AI Risk Governance. ISACA Netherlands Chapter. https://isaca.nl/llms-as-a-new-attack-surface-board-level-ai-risk-governance/
- Bobbert, Y., & van Dijk, V. (2023). An Exploration of AI Risk & Collaborative Assessment Methodology. ISACA Netherlands Chapter. https://isaca.nl/an-exploration-of-ai-risk-collaborative-assessment-methodology/
- AI Governance Market Funding Trends, New Market Pitch (industry funding tracker), reported acquisition and funding figures for Palo Alto Networks, Check Point, Cisco, F5, LeapXpert and Taktile.