Every enterprise deploying AI agents right now is dealing with a question nobody planned for: what, exactly, is this thing allowed to access?
Tailscale, the Toronto-based VPN startup, just made its first acquisition. Border0, a seven-person privileged access management company out of Vancouver, joined Tailscale on March 17. The deal puts Border0 founder Andree Toonk, a former Cisco senior engineering manager with a decade of network infrastructure experience, into the role of Director of Engineering at Tailscale. His team is building what amounts to air traffic control for autonomous software.
The problem is practical, not theoretical. Companies are deploying AI agents that write code, query databases, modify production servers, manage Kubernetes clusters, and interact with sensitive customer data. These agents request permissions, move across systems, and take actions that traditional identity tools were never designed to handle. A human employee gets onboarded, assigned a role, given credentials. An AI agent gets spun up, runs for 45 seconds, touches six different systems, and disappears. The security model for the first scenario does not work for the second.
Border0’s technology manages and monitors what people and software are allowed to access across production systems, databases, and infrastructure. Tailscale’s mesh VPN already acts as the connective layer for corporate networks. Together they can answer the question that every CISO is now asking: which agents can touch which systems, under what conditions, with what audit trail?
A New Category of Commerce
According to Bloomberg, Tailscale’s customer base grew rapidly since 2024, with a significant portion of that growth tied directly to the explosion of agentic AI. Companies discovered that Tailscale’s platform could function as an access control layer for agents accessing corporate data. That was not the product’s original purpose. The customers found the use case before the company did.
This is how new industries form. Not from a grand vision but from a collision between a new technology and an existing problem. AI agents created a security gap. Tailscale happened to be positioned in the gap. Border0 had the specialized tooling to fill it. The acquisition is the formalization of something that was already happening in production environments.
The pattern extends beyond Tailscale. When PromptSpy became the first documented AI malware, it demonstrated that the attack surface for AI systems is fundamentally different from traditional software. When Microsoft’s Copilot bypassed data loss prevention controls to read confidential emails, it proved that enterprise AI tools can ignore the security boundaries they are supposed to respect. Each incident creates demand for a product category that did not exist two years ago.
The story of AI in 2026 is not just about what the models can do. It is about the entire ecosystem of businesses that form around managing what they are allowed to do. Privileged access management for AI agents is one category. Compliance monitoring for autonomous decisions will be another. Audit logging for agent-to-agent communication will be a third. Each of these will be a company. Some of them will be billion-dollar companies. And most of them do not exist yet.
What This Means for Everyday People
If your company uses AI tools that access internal systems (Copilot, Salesforce Einstein, coding assistants, customer service bots), the question of what those tools can see and do is probably not well defined. Tailscale’s acquisition of Border0 is one company’s answer to that problem, but the problem itself affects every organization deploying AI agents. The tools your employer gives access to your data are increasingly autonomous. Whether anyone is controlling what they touch is a question worth asking your IT department.
For inquiries and analysis contact laterstack@proton.me