
Hyperscalers lead model security because they control the research, training pipelines, and AI development environments.
Cybersecurity platforms lead enterprise defense because they control detection, runtime surfaces, and post-deployment correlation.
But neither group has addressed the upstream attack surface that now determines software security: the coder—human or AI—who creates it.
Over the last decade, two sectors accumulated significant influence in global security:
Each group is positioned to lead in a different direction.
Each has a structural strength.
But both inherited a security model from a world that no longer exists.
The industry still treats security as something that begins after code is written:
But AI has shifted software development upstream.
Code is no longer produced solely by a developer sitting at a keyboard.
It is authored, modified, and propagated by:
This creates two distinct perimeters:
The first perimeter is heavily defended.
The second is largely unobserved.
This is the structural gap.
1. Formal Research Infrastructure — they employ teams who study:
These are the failure modes that will define the next decade.
2. Visibility Across AI Workflows — Hyperscalers control the surfaces where AI generates code:
They see the shift from human-only authorship to hybrid authorship.
3. Ability to Instrument Models and Toolchains — only hyperscalers can embed safeguards inside:
These structural advantages position them to lead model-layer and workflow-layer AI security.
Cybersecurity hyperscalers excel at:
But these systems operate after code exists.
Their architectures do not reach into:
Because innovation often arrives via acquisition rather than foundational research, deep AI-native primitives are difficult to build.
This is a structural limitation.
Security platforms that were designed to protect infrastructure cannot easily pivot to protect AI software creation.
And this is where the new risk lives.
The last 20 years of cybersecurity were built on four pillars:
These defend the runtime world.
But AI development has changed the shape of risk.
Instead of asking:
“Is this code secure?”
We must now ask:
“Who authored this code, under what conditions, using what tools, and does their behavior align with their identity?”
When an AI agent generates, merges, or deploys code, runtime systems have no context for:
These questions cannot be answered without observing the coder.
The upstream attack surface is visible but unclaimed.
No hyperscaler owns it.
No cybersecurity platform owns it.
No AppSec, SIEM, XDR, CNAPP, or ASPM platform reaches this deep.
And no model-level AI safety method captures developer behavior.
The least defended point is the coder—human or AI—whose actions create all downstream artifacts.
This is the structural inversion.
AI has created a new reality:
This creates a new mismatch:
behavior vs. identity drift
Traditional tools cannot see this mismatch because they observe infrastructure, not authorship.
Whoever solves this upstream perimeter becomes the control plane for AI-native software security.
It will not replace existing tools.
It will sit above them.
It will provide upstream context every other system depends on.
For hyperscalers, this aligns with their AI research depth and toolchain control.
For cybersecurity platforms, it challenges their architectural assumptions.
The next major category in security will be the system that governs:
This is where breaches originate.
And it remains the largest unsolved surface in the enterprise.
AI security cannot begin at the model.
And it cannot begin at the cloud.
It must begin at the coder.
Hyperscalers will recognize this.
Cybersecurity platforms will adapt to it.
Boards will ask a new question:
“How do we secure the people and AI systems who create our software?”
There is only one direction the industry can move:
Upstream.
To the source.
To the coder.
→ Book a live demo and see how Archipelo helps teams align velocity, accountability, and security at the source.
Archipelo helps organizations ensure developer security, resulting in increased software security and trust for your business.
Try Archipelo Now