Why AI Security Is Getting Rebuilt From Scratch
In this episode I sit down with Ed Sim, founder and managing partner of Boldstart Ventures, to dig into where AI security, agentic infrastructure, and the venture market are actually heading.Ed has been an inception-stage investor for nearly 30 years and has run Boldstart since 2010, backing hardcore technology companies across AI infrastructure, cybersecurity, and physical AI. He was the first investor in Protect AI, which sold to Palo Alto Networks in a reported ~$700M exit roughly a year before ChatGPT launched. He is also early in companies like Keycard, Surf AI, and June. About a third of Boldstart's investments are in cyber, so Ed sees this market from the founder and investor side in a way most security conversations do not.We get into why the era of building raw intelligence is giving way to an era of controlling it, what that means for on-prem models and private evals, and why Ed thinks nearly everything in security is going to get rebuilt from scratch.In this episode:- Why a day-one partnership looks different now that anyone can vibe code an MVP- The Protect AI acquisition and what the first exit in AI security signaled to the market- Competing as an inception fund against mega-funds writing giant seed rounds- What founders should actually look for in a venture partner beyond the check- The shift from building intelligence to controlling it, including routing, post-training, and on-prem deployment- Why enterprise data, workflows, and private evals are becoming the crown jewels- Vulnerability chaining, attack path reasoning, and how tools like Mythos are reshaping the security budget conversation- Agentic identity and why Keycard treats agents as short-lived problem solvers rather than digital twins- The Surf AI thesis on automated security hygiene and tying every asset back to an owner- The real bottleneck slowing agent adoption in the enterpriseChapters:0:00 Intro0:35 Ed's background and inception investing1:57 Day-one partnerships in the vibe-coding era3:53 The Protect AI exit to Palo Alto6:14 Competing as an inception fund against mega-funds9:17 What founders should look for in a VC partner11:48 From building intelligence to controlling it15:52 Boldstart's domain-specific model portfolio16:16 Private evals, context, and memory as crown jewels17:18 Mythos, vulnerability chaining, and attack path reasoning20:59 How much access should you give the model22:07 On-prem context and the autonomous workforce24:49 Agentic identity and Keycard28:11 Building brand and community with Insecure Agents31:30 The Surf AI thesis and automated security hygiene34:13 The real bottleneck to agent adoption37:09 The easy button, Palantir, and a multi-model world38:24 Two types of people in this new eraConnect with Ed:LinkedIn: https://www.linkedin.com/in/edsim/Boldstart Ventures: https://boldstart.vcEd's newsletter, What's Hot in Enterprise IT/VC: https://www.whatshotit.vcMore from Resilient Cyber:Substack: https://www.resilientcyber.ioSubscribe for more conversations with security practitioners and leaders.#aisecurity #agenticai #cybersecurity #venturecapital #appsec



