※ Kernwerk

Edge AI split in two, compression and security, and chipmakers bought one half

Doing edge AI takes two things that have nothing to do with each other:

  • Compression, so the model fits the chip you can afford and runs fast enough on it to be worth shipping.
  • Security, so the model stays your IP once the device is in someone else’s hands, on someone else’s bench, being read.

Five years ago you bought both from independent vendors. Compression is no longer much of a decision: almost every company that did it well now belongs to a chipmaker, so choosing a compression tool now means choosing whose chip you buy. Security is still a decision, because nobody has bought that half.

What follows is a map of who owns what in edge AI today, how it got that way, and what it leaves you to do yourself when you ship.

The short version:

  • Eighteen independent edge AI companies were bought, or agreed to be bought, between 2021 and 2026, and almost all of them were on the compression side.
  • Compression is now something you buy from the company that sells you the chip. Security is not, and the two have never had the same vendors.
  • From September 2026 the CE marking stops letting you treat them as two purchases, which is the part most stacks are not ready for.

A taxonomy of the edge AI market

The market sorts into six layers, ordered here from what a chip is built out of to what finally ships on it. Each one is a different business, with different customers and different margins:

  • IP, short for intellectual property, is licensable circuit design.
    Processor cores, neural accelerators, memory controllers: pieces a chipmaker buys and integrates rather than designing from scratch. Arm, Cadence, Synopsys and CEVA sell blueprints and not parts, so you never buy from this layer, and every part you buy contains it.
  • Silicon vendors design and sell the chip itself.
    The physical part, with a datasheet, a price and a promised lifetime. The margin in this market sits here, which is why every other layer eventually gets bent toward making one vendor’s part the easy choice.
  • Accelerator startups sell a neural processing unit, or NPU.
    A separate chip that runs a model faster, or at lower power, than a general purpose processor can, sitting on the board beside the microcontroller. The tier exists to give you more compute without changing chip vendor, which is exactly why chip vendors have been buying it.
  • Modules and SoMs, system on modules, are ready made boards carrying somebody else’s chip.
    The power supply, the memory and the radio are already designed and certified. You buy one to design a product around a working board instead of designing a circuit board around a bare chip.
  • Model tooling turns a trained neural network into something that fits and runs on a chosen part.
    Quantisation, pruning, graph compilers, AutoML platforms and the runtime that executes the result. Skip this layer and a model trained on a workstation simply does not fit in the memory of a microcontroller, let alone finish in time.
  • Device security keeps a shipped device from being read or altered.
    Secure boot, secure elements, trusted execution environments or TEEs, key provisioning and attestation. It protects the firmware and the keys by default, and whether it protects your model is a separate question with a different answer.

The first four are the hardware you buy. The last two are software, and they are the two this post measures.

A five band stack of the edge AI industry, read top to bottom: IP, silicon vendors, accelerator startups, modules and SoMs, and a fifth band split into two side by side columns of the same length, model tooling and device security. Each band is glossed with what that layer sells. Acquired companies are struck through with the buyer named beside them: twelve of the seventeen names in the model tooling column, and one of the thirteen in device security.
A sample of the stack, not a complete census. A struck name has been acquired and the buyer is named beside it; a dashed box means agreed but not closed. Nineteen names are struck here against eighteen deals in the next figure: the extra one is Synopsys taking Intrinsic ID, a security deal rather than part of the wave this post traces.

The bottom band carries the finding. Twelve of the seventeen model tooling companies have been acquired, against one of the thirteen in device security, and that buyer sells design IP rather than parts. Buying the tooling is a clear pattern. Buying the security is not one, or not yet.

A list of eighteen acquisitions from 2021 to 2026, grouped into two phases named for what was bought: 2021 to 2024, buying the toolchains, and 2025 to 2026, buying the chip companies. A coloured swatch on each row says whether the company bought was a toolchain, a chip company or a board. Each row reads year, company, arrow, buyer, with the buyers in one column so the arrows stack. The Hailo row is drawn with a dashed box to mark a deal agreed but not closed, and two rows carry a dagger for a buyer that does not sell chips.
Eighteen deals, five years. Dates and terms verified from company announcements in September 2026, with one exception noted below.

The first wave bought the toolchains

Between 2021 and 2025, most of the independent companies whose job was getting a model onto small hardware were acquired by companies that make hardware. The pattern is older than the table: Apple was reported to have bought Xnor.ai, an on-device AI company, in 2020, on terms neither side confirmed.

  • STMicroelectronics took Cartesiam in 2021 and turned it into NanoEdge AI.
  • Syntiant, itself a chip startup, took Pilot AI and its eighteen people in October 2022. Renesas took Reality AI the same year.
  • TDK announced Qeexo at CES in January 2023, which put an AutoML platform inside the company that sells the sensor it runs on. Infineon took Imagimob later that year.
  • NVIDIA bought twice: Deci in April 2024, reported at around $300 million, and OctoAI that September.
  • Nordic took the IP, the assets and thirteen engineers out of Neuton.AI in June 2025.
  • STMicroelectronics came back for Deeplite in April 2025, which makes it the second two-time buyer in the list after NVIDIA. The row is the only one not sourced to the buyer: ST published nothing, and it rests on Deeplite’s own announcement and on its founding studio.
  • Red Hat took Neural Magic in November 2024, one of only two deals in the list where the buyer will never sell you a chip.

Qualcomm did it three times. Foundries.io in March 2024, Edge Impulse in March 2025, and then Arduino in October 2025, arriving with a board built on its own Dragonwing silicon. Buying Arduino is not really a hardware purchase. It is a purchase of the place where a few million people learn what an embedded device is.

The logic is sound from where the buyers sit. A chip is worth more when it is easy to deploy on, the tooling is cheaper to buy than to build, and every acquisition removes a company that was helping customers evaluate competing parts. What it does to the rest of us is narrow the field of tools that will honestly tell you another vendor’s chip is the better fit.

The second wave buys the chip companies

The buyers do not change between the two waves. They are silicon vendors in both. What changes is what they buy: until 2024 it was software companies, and from 2025 it is chip companies. There is a prologue a year earlier: Amazon paid $80 million for Perceive, the edge inference chip business Xperi had spun up, and closed it on 2 October 2024. Amazon is the second buyer in the table that does not sell silicon, and the qualifier matters, because Amazon designs its own and ships it inside its own devices. A chip company was bought by a company that wanted the chips for itself.

  • NXP bought Kinara for $307 million in an all-cash deal that closed on 27 October 2025.
  • AMD took Untether AI’s engineering team in 2025, and Untether filed for bankruptcy that October.
  • AMD signed a definitive agreement for Taalas on 6 August 2026. That one has not closed either.

And in July 2026 Microchip signed a definitive agreement for Hailo, the best funded independent NPU company in the field, which had been valued at $1.2 billion in early 2024 and whose SPAC had collapsed at under half that. Terms were not disclosed. At the time of writing that deal has not closed; it is expected to at the end of September.

So the independent accelerator tier is going the same way the independent tooling tier went, on a four year delay and with worse outcomes for the founders. Same buyers, one layer down. Being the horizontal player in this market, the one who works across everybody’s chips, turns out to be a position you occupy on your way to somewhere else.

What this costs you, concretely

The pattern requires no bad faith to explain. In a market where the margin lives in silicon and the software is a feature that sells it, consolidation is the expected outcome rather than a departure from one. But if you are choosing a stack this year, it changes the calculation in three ways.

  • The tool you standardise on today may belong to a competitor’s silicon vendor next year. It keeps working. What changes is the roadmap, which stops being neutral, the support for the parts you actually use, which gets thinner, and the benchmark comparing your chip favourably against the new owner’s, which quietly disappears.
  • Portability is no longer a free default, it is a thing you pay for. Every acquisition adds gravity toward one vendor’s runtime. If you want to keep the option of moving from an NXP part to a Renesas one, that option now has an owner and a price.
  • The survivors are priced by the same logic. When a company with Hailo’s funding ends up selling on undisclosed terms, everyone still independent is negotiating in that shadow.

The overlap nobody is in

The same companies sorted a second way give a second result. The stack above places each company in the layer it occupies. The diagram below places it by which of three questions it can answer: does it make the chip, does it shrink the model onto the chip, does it keep the model from being read back off the board.

Three overlapping circles labelled silicon, model tooling and device security. The centre, where all three overlap, holds seven chipmakers set in bold and nothing else: ST, NXP, Infineon, Renesas, Microchip, Qualcomm and TI, annotated the only full stack. The overlap of model tooling and device security without silicon is drawn as a dashed box holding two names, Latent AI and Kernwerk, annotated two companies, and one of them is writing this. Outside every circle, module makers Toradex, Variscite and Seeed are listed under the heading answers none of the three.
The same companies, sorted by what they can sell you rather than which layer they sit in.

The sort gives three results.

  • Only seven companies answer all three questions, and all seven arrived from the same direction. STMicroelectronics, NXP, Infineon, Renesas, Microchip, Qualcomm and Texas Instruments were making chips first. They have been selling secure elements for twenty years and bought the toolchain in the last five. Nobody has come the other way, adding silicon to a toolchain or to a security business.
  • Almost everyone else answers exactly one. Module makers answer none of the three: Toradex, Variscite and Seeed sell somebody else’s chip on a finished board, which is a real business and not one of these.
  • Two names sit where model tooling meets device security with no fab underneath. Latent AI, and us.

The consequence is a pricing one. There are two ways to buy both halves today. A chip vendor will sell them to you together, and the price is that you buy their silicon and keep buying it. One of the two companies in the gap will sell them to you together without the silicon, on whichever part you already chose. Nothing else on the diagram sells both.

Everything counted here is as of September 2026, and two of the eighteen deals have not closed yet. The pattern is not finished, which is why every figure carries its date.

Make the model fit. Keep the model yours. We compress a trained model onto the part you can afford to ship, and seal it so it cannot be lifted back off the board. Both halves, from one supplier, on whichever silicon you chose. Talk to us.