Two AI security startups just raised $143M in three days, and the message is clear: enterprises are finally freaked out about who controls their agents.
The Summary
- Onyx Security raised $113M and Hush Security raised $30M within 48 hours, both focused on governing AI agents in enterprise environments.
- The convergence signals a new category emerging: non-human identity security, treating AI agents like employees who need credentials, permissions, and audit trails.
- Smart money is betting that enterprises won't deploy agents at scale without security infrastructure that makes compliance officers sleep at night.
The Signal
Onyx Security's $113M round and Hush Security's $30M raise aren't just funding announcements. They're proof that the enterprise AI agent deployment curve just hit the "oh shit, we need to control these things" inflection point. When two companies solving the same problem raise nine figures in the same week, it means buyers are already calling.
The timing tracks. Enterprises spent 2024-2025 experimenting with AI agents for customer service, data analysis, and internal operations. Now those pilots are graduating to production, and CIOs are asking questions that sound a lot like the early cloud security days: Who has access? What can they do? How do we audit them? What happens when an agent goes rogue or gets compromised?
"Non-human identity security is the new perimeter. Agents aren't users. They're autonomous actors that need their own governance framework."
Both Onyx and Hush are building infrastructure to answer those questions. The focus is on creating identity and access management systems purpose-built for AI agents, treating them as distinct entities with credentials, permissions, and behavior monitoring. It's IAM for non-humans, and it's becoming a mandatory piece of the stack as agents touch more sensitive systems.
The $143M combined investment tells you where the market is going. Investors are betting that every enterprise deploying agents at scale will need this layer. It's not optional infrastructure. It's the difference between agents that improve productivity and agents that accidentally leak customer data, trigger unauthorized transactions, or violate compliance rules. The companies that solve AI agent governance own a tax on the entire agent economy.
The Implication
If you're building AI agents or selling them into enterprise, add "governance-ready" to your feature list yesterday. Buyers are already asking how your agents integrate with identity systems, what audit logs they generate, and how permissions get scoped. The enterprise sales cycle for agents without clear governance stories is about to get longer.
For security teams, this is your window. The AI agent governance category is forming right now, and the winners will be whoever ships the most enterprise-friendly solution fastest. Think about how Okta owned SSO or how CrowdStrike owned endpoint security. Same pattern, different substrate.