Two Israeli startups just raised $220 million combined to solve a problem most companies don't realize they have yet: their endpoints can't keep up with their AI agents.

The Summary

The Signal

Endpoint security has been the same fight for twenty years: detect malware, block suspicious processes, keep the laptop from becoming a liability. That playbook assumes humans are still driving. It assumes decisions happen at human speed, that access patterns stay predictable, that you can audit what happened after the fact.

AI agents break all of that. An agent making API calls at 3am isn't suspicious, it's Tuesday. An agent pulling data from six different systems in parallel isn't exfiltration, it's how it works. Traditional security tools flag agent behavior as anomalous because it looks nothing like a human clicking through Salesforce.

"The endpoint itself becomes the bottleneck when your workforce includes autonomous processes operating 24/7 across cloud and local systems."

Glow and Bold are both building security layers designed for this. The details are thin, but the thesis is clear: you need security that operates at agent speed, that understands when an autonomous process is doing its job versus when it's been compromised. The $1.2 billion valuation on Glow suggests investors believe this is infrastructure, not a feature.

What makes this notable is the timing and the geography. Israel has built its tech economy on security expertise, born from necessity. Now that expertise is turning toward a new attack surface: the boundary between human-controlled systems and agent-controlled ones. When an agent has credentials, when it can write code, when it operates unsupervised, traditional perimeter security doesn't cut it.

The real question is what "AI-powered endpoint security" actually means in practice. Is it anomaly detection tuned for agent behavior? Is it sandboxing for autonomous processes? Is it a new permissions model that lets you give an agent narrow access without handing it the keys to everything? The press coverage doesn't say, and the companies are still in launch mode.

Key unknowns:

  • Whether these platforms secure the endpoint device or the agent software itself
  • How they handle the credential problem when agents need persistent access
  • What happens when the security layer needs to make split-second decisions about blocking an agent mid-task

The Implication

If you're running AI agents in production, your current endpoint security isn't ready. It was built for a world where devices had one user, where sessions had start and stop times, where you could reasonably audit every login. That world is over.

Watch how these platforms handle the permission problem. The hard part isn't detecting threats. The hard part is designing a security model that lets agents do their jobs without turning every device into a liability. That's the real innovation here, assuming they've cracked it.

Sources

GritDaily