Omkar Khadamkar Work with me
Where security software is heading

Evidence log

Each forecast on the home page, and the dated signals that support it or cut against it. Items are added as they happen and never removed, so the forecasts can be scored in public.

Last entry 23 Sep 2026 · 7 entries · summaries, not legal advice; every entry links its source

Hypothesis

By 2029, AI agents do most of the work inside security products

The scarce skill becomes designing where a person reviews, overrides and audits them.

being testedresolves 20292 for · 0 against · 0 mixed

  1. The same integrated SOC puts AI inside the case view, next to the evidence an analyst weighs.

    The AI works inside the case; the analyst's job moves to reviewing and overriding it.

    supportsMicrosoft Learn

  2. Wiz extends its partner network with MCP-powered agent integrations.

    Another company's agent is now a user of the product, so its answers become a design surface.

    supportsFuturum

Force 1

The areas are merging

Access, Data, Identity and detection stop being separate products; the hardest calls sit between them.

being testedresolves ongoing2 for · 0 against · 0 mixed

  1. Microsoft previews an integrated SOC in Defender: XDR, SIEM and AI in one portal, so one case can mix native and ingested evidence.

    Detection tools that used to be separate products now share one case and one screen.

    supportsMicrosoft Learn

  2. The same integrations let agents act across products through one layer.

    Decisions that start in one product finish in another.

    supportsFuturum

Force 2

Laws now set the clock

Reporting deadlines measured in hours turn compliance into screens people use under pressure.

being testedresolves ongoing3 for · 0 against · 0 mixed

  1. Sophos: 46% of MSPs say customers rely on them to act as their CISO, and 55% still do part of their security reporting by hand.

    The reporting that deadlines demand is still partly manual: a design gap under a legal clock.

    supportsHelp Net Security

  2. The EU Cyber Resilience Act's reporting duty starts: an early warning on an actively exploited weakness within 24 hours.

    A 24-hour clock is now law for product makers.

    supportsEuropean Commission

  3. NIS2 applies in the EU: early warning within 24 hours, notification within 72 hours, final report within a month.

    The first broad hours-not-weeks reporting clock for essential and important entities.

    supportsEuropean Commission