The AI narrative is shifting rapidly. We are moving past basic chat interfaces and entering the era of Agentic AI—autonomous AI agents designed to plan, use tools, access systems, and execute complex tasks with limited human input.
Top Software Stocks for Security and Cost Control
While this promises massive productivity gains, it introduces two massive headaches for enterprise IT: runaway token costs from multi-step reasoning, and a vastly expanded attack surface as these agents hold credentials and operate at machine speed.
Based on a recent scan of top software stocks, the clearest winners in the Agentic AI boom aren’t necessarily the application builders, but the companies providing the “picks and shovels” to secure and monitor these agents. Here is a breakdown of the top beneficiaries.
1. AI Observability & Token Cost Control (AI FinOps)
As companies deploy fleets of AI agents, tracking how much these agents spend on LLM API calls becomes critical. Multi-step reasoning and tool invocations drive high, variable token costs.
- DDOG (Datadog): Datadog is a premier play for controlling AI spend. Their LLM & Agent Observability tools track token usage, costs, latency, and full agent traces (including prompts and tool decisions). By integrating AI Costs directly into Cloud Cost Management, Datadog provides budget alerts and helps engineering teams optimize agentic token spend in production, solving the “runaway AI budget” problem.
- DT (Dynatrace): Similar to Datadog, Dynatrace’s AI Observability app is essential for complex, interconnected microservices. They offer deep agentic framework support (including LangChain, Bedrock AgentCore, and Google ADK), tracking end-to-end agent flows, tool interactions, and cost anomalies to keep autonomous systems running efficiently.
2. AI Agent Security & Non-Human Identities (NHI)
When an AI agent is given permission to read emails, access Salesforce, or write code, it requires an identity. Securing these Non-Human Identities (NHIs) and monitoring their runtime behavior is the next massive cybersecurity frontier.
- CRWD (CrowdStrike): Widely viewed as foundational infrastructure for the agentic era. CrowdStrike is building out an Agentic Security Platform featuring Charlotte AI (agentic triage and SOC workflows) and AgentWorks (to build and orchestrate security agents). They are actively developing capabilities like “Falcon Shield” to monitor shadow AI, secure agent identities, and detect anomalous behavior across SaaS environments.
- OKTA (Okta): Okta is arguably the most direct play on identity governance for agents, pioneering “Okta for AI Agents.” It handles discovery, lifecycle management, and authorization for autonomous agents. Okta treats agents as “first-class identities,” allowing IT to enforce least-privilege access and hit a “kill switch” to revoke tokens if an agent goes rogue.
- S (SentinelOne): As CrowdStrike’s primary rival, SentinelOne is expanding with Prompt AI Agent Security and Purple AI / Athena. They provide essential runtime and policy controls, bringing agentic capabilities for threat triage and investigation to the endpoint and cloud workloads where these agents execute.
- FTNT (Fortinet): Expanding its Security Fabric with AI-driven operations. Fortinet is actively securing networks, cloud environments, and AI workloads, positioning itself to capture the rising cybersecurity spend driven by agentic adoption.
3. The Agentic Data, Infrastructure & DevSecOps Layer
Agents need an environment to operate in, memory to draw from, and platforms to govern their development.
- MSFT (Microsoft): The heavyweight champion across the entire stack. Beyond just Azure OpenAI, Microsoft is building the control plane for governing agents via Agent 365, managing agent identities through Entra, and securing the ecosystem with Project Perception and Defender extensions. They benefit across building, running, and securing agents.
- SNOW (Snowflake): Snowflake is focusing heavily on the “trusted agentic enterprise.” With the Cortex AI Gateway, they provide AI observability, cost management, and secure third-party agent access, ensuring agents can safely interact with enterprise data while controlling consumption costs.
- GTLB (GitLab): A strong beneficiary in the development lifecycle. GitLab’s Duo Agent Platform allows enterprises to build, orchestrate, and govern AI agents across DevSecOps (coding, review, security remediation). It features built-in governance, auditing, and context features designed to reduce token usage and hallucinations.
- MDB (MongoDB): While slightly more indirect, MongoDB’s vector search capabilities act as the essential “brains” or memory storage (via RAG) for agents to query before they act.
Agentic AI is still in its early innings, but it is already driving measurable budget shifts toward FinOps (token cost management) and NHI security. Investors looking to capitalize on this shift should prioritize infrastructure security (CRWD, OKTA, S, FTNT, MSFT) and observability leaders (DDOG, DT, SNOW).
Discover more from CANSLIM Research
Subscribe to get the latest posts sent to your email.