Okta to Acquire Identity Threat Detection Firm Permiso

Okta on Thursday said it has signed a definitive agreement to acquire Permiso Security, a cloud-native identity security platform that specializes in detecting and mitigating threats across human, non-human, and agentic identities in multi-cloud environments. The deal extends Okta’s reach beyond identity management and into the realm of security operations, positioning the company to compete more directly on identity threat detection and response (ITDR).

Once folded into Okta’s identity security fabric, Permiso’s technology is expected to help organizations close operational blind spots and extend runtime detection and response across every type of identity in their environment.

“We’re thrilled to welcome Permiso to Okta as we help companies secure their agentic enterprises where humans, applications, service accounts, and AI agents work together,” said Ely Kahn, Chief Product Officer at Okta. He added that Permiso brings “proven identity threat detection and response capabilities, and an incredible threat research and security team that will advance Okta’s threat detection and prevention capabilities.”

Following the close of the transaction, Okta plans to unify identity threat detection and identity posture management into a single security offering, built around several capabilities inherited from Permiso.

Expanding Into the Security Operations Center

Beyond product features, the acquisition is expected to expand Okta’s footprint into the core Security Operations Center (SOC), giving the company a stronger foothold to partner with enterprise CISOs on evolving SecOps challenges. Permiso’s threat research arm, P0 Labs, will be folded into Okta’s research capabilities, adding post-authentication insight into suspicious behavior across cloud and AI environments. Combined with Okta’s existing threat intelligence operation, the company says this will strengthen detections, threat hunting, and its product roadmap across the identity lifecycle.

Deal Terms

The transaction is expected to close in the third quarter of Okta’s fiscal year 2027, subject to customary closing conditions. Okta said the deal is not expected to affect the financial guidance it issued on May 27, 2026. Financial terms of the acquisition were not disclosed

Advertisement. Scroll to continue reading.

Related: Palo Alto Networks to Acquire CyberArk for $25 Billion

https://www.securityweek.com/okta-to-acquire-identity-threat-detection-firm-permiso/




AI Governance Is the New Security Baseline

Artificial intelligence is no longer experimental inside the enterprise, and neither should be the governance surrounding it.

AI adoption is now embedded into workflows and influencing decisions. Agentic AI is also on the rise, and according to Cyber Security Tribe’s 2026 Annual State of the Industry Report, nearly three-quarters of cybersecurity practitioners report using or actively developing agentic AI within their cybersecurity programs. 

However, governance is still catching up. AI governance is the framework of policies, processes, and oversight mechanisms organizations put into place to ensure AI systems are developed and used ethically, legally, safely, and transparently. And while 70% of organizations now have AI policies in place, the report shows that AI policy strictness averages 6.7 out of 10, reflecting a tension: controls must be strong enough to prevent data exposure and misuse, yet flexible enough to allow for innovation and avoid driving users toward unsanctioned tools.

This balancing act is defining the next phase of enterprise AI.

From Visibility Gaps to AI Sprawl

Fragmentation is a consistent concern among cybersecurity leaders. Employees access AI tools through web applications, browser extensions, desktop software, APIs, and increasingly through autonomous agents capable of interacting with other systems. Business units experiment independently, employees adopt preferred tools, and organizations rapidly introduce new models.

The result is AI sprawl: a distributed, fast-moving surface area that stretches across web and endpoint environments at a pace few governance processes were designed to accommodate.

Traditional security architectures were not designed for this reality, either. Point solutions often introduce complexity and sacrifice unified control. Network-based inspection lacks full visibility into encrypted browser sessions. API integrations provide partial visibility, but they miss user-level interactions at the presentation layer. 

What remains largely unaddressed is governance at the point where humans and AI actually interact: the session itself. Without visibility and control at that interaction layer, organizations are left reconstructing intent after the fact rather than shaping behavior in real time.

And the proliferation of agentic AI is only expanding the risk model. Autonomous systems rely on data quality, model reliability, and defined permission boundaries. If inputs are flawed or guardrails are insufficient, automation can amplify errors at machine speed. Other risks include over-automation, compliance gaps, and a lack of auditability around AI-driven actions.

Governance As Enablement, Not Friction

The challenge for leaders is how to embrace AI without eroding control. While early AI governance concerns chiefly surrounded preventing data leakage into public models, today’s enterprise AI governance must address agent permissions, accountability, autonomous tool execution, the boundary between enterprise data and foundation models, and more. 

This requires embedding operational guardrails into daily workflows. That might include:

  • Clear scoping of approved use cases by risk tier.
  • Defined data handling rules aligned to data classification standards.
  • Role-based access to AI tools and agents.
  • Comprehensive logging of prompts, outputs, and tool actions.
  • Continuous monitoring rather than periodic reviews. 

Just as cybersecurity frameworks have evolved from “paper compliance” to measurable control effectiveness, AI governance must move from theoretical acceptable-use statements to dynamic, enforceable controls. 

Further, these frameworks deliver the most value when they serve as a shared language between security, IT, and the board. AI governance must translate technical behavior into business risk terms: revenue impact, regulatory exposure, operational continuity, and customer trust.

The False Choice of AI Risk

The 2026 data suggests we are at a turning point. Most organizations have AI policies, many are deploying agents, and boards increasingly recognize cyber risk. But while AI is embedded, governance maturity varies widely.

That’s partially because, too often, enterprises frame AI risk as a binary: block risky tools or tolerate uncertainty. But it’s a false choice. Enterprises don’t have to sacrifice innovation for control.

AI governance models must prioritize visibility, consistent policy enforcement, and controls that move with the user across environments. As AI becomes embedded across browsers, SaaS platforms, and autonomous agents, governance can no longer be fragmented or point-in-time. It needs to operate wherever AI interactions occur. If AI is becoming the primary interface to enterprise systems and data, governance must be designed to operate just as seamlessly at that same layer.

No longer is adoption the yardstick by which we measure enterprise AI maturity. In 2026, responsible control of AI is the new baseline.

https://www.securitymagazine.com/articles/102416-ai-governance-is-the-new-security-baseline




Doing More with Less: Practical Security Solutions for Resource Strapped Schools

With school buildings averaging nearly 50 years old nationwide, many districts may struggle with deteriorating facilities, outdated infrastructure, or insufficient technology. Budgets are stretched with varying priorities, yet safety threats continue to grow, challenging schools to strengthen their security posture using the resources they have on hand. By focusing on foundational, code-compliant practices and operational discipline, schools can significantly enhance safety in practical, cost-effective ways. 

Facility Maintenance

A critical first step is ensuring all facilities are well maintained. Offering clean, orderly and visibly cared-for environments helps reduce the opportunity for vandalism and discourages unsafe and unauthorized activity on school grounds. Enhancements, such as additional windows or improved lighting in darker places inside the building and exterior areas, can increase visibility by eliminating blind spots and supporting natural surveillance, which are key components to a safer campus.

Clear Procedures 

Operational consistency is especially important when keeping a school safe. Aging physical infrastructure and manual processes can introduce vulnerabilities if daily procedures are not followed rigorously. Schools manage a wide range of individuals throughout the year who each require different areas of access – including contractors, substitutes and volunteers. Without clear protocols for granting and monitoring access, the risk of unauthorized entry increases. Simple habits, such as ensuring classroom and office doors are secured at all times, are low-cost practices that help strengthen internal security of the school.

Having strong key control and access management practices in place provides another layer of protection for the school without requiring advanced technology. Establishing a well-defined key procedure for issuing, tracking and retrieving keys helps ensure only authorized individuals can access specific areas. By having strong key tracking practices in place, schools can hold an accountability system, allowing them to proactively identify gaps before they potentially become security incidents.

Visitor management is another essential area schools must pay close attention to, and often a very overlooked layer of security. Offering a single, secured point of entry for visitors helps control who is entering and leaving the building. Visitor identity verification and a clear pre-approved entry protocol help prevent unauthorized pickups or entry attempts. While having strong internal hardware limits access internally, strong visitor management helps control the external perimeter, a critical component of the overall safety of the campus.

Building a Culture of Safety

In addition to physical and operational improvements, a strong culture of safety can be equally impactful. Encouraging participation in regular training can help everyone understand their role in maintaining a secure environment. Regular training can range from recognizing unusual behavior and knowing how to respond during various emergency situations. Simple daily procedures like verifying doors are closed and locked, confirming visitor protocols are being followed, and identifying areas where student behavior may indicate risk reinforce strong safety habits. When consistent, these simple habits can become very effective. When students and staff understand safety protocols and expectations, districts can create a proactive environment where issues are spotted early and addressed quickly, helping strengthen overall safety.

As the most widely recognized national framework K-12 physical security, the Partner Alliance for Safer Schools (PASS) provides clear, tiered guidelines that help districts implement effective, code-compliant measures based on their current resources and facility needs. PASS guidelines emphasize the importance of classroom door locking from the inside only, so no individual must step into the hallway. 

Beyond door security, PASS also highlights the importance of accessible communication tools. Staff should be able to easily reach a telephone, panic button, intercom call button or two-way radio to alert administrators or first responders when help is needed. 

Lastly, a comprehensive Emergency Operations Plan (EOP) is an essential component and conducting safety drills throughout the year will strengthen preparedness. Schools that gather feedback from students and staff after drills take place can uncover pain points, make adjustments and strengthen procedures.

By implementing low-cost initiatives, districts can take important steps toward creating a safer, more resilient learning environment. This includes prioritizing facility upkeep, improving operational discipline, strengthening access control and enhancing classroom readiness. With thoughtful planning and consistent execution, schools can make meaningful progress toward strengthening their security posture, while building a strong foundation for future safety investments. 

https://www.securitymagazine.com/articles/102412-doing-more-with-less-practical-security-solutions-for-resource-strapped-schools




Timeless Compliance: Why Better Questions Beat Bigger Frameworks

In 2009, a surgeon named Atul Gawande and a team backed by the World Health Organization showed that a 19-item surgical checklist could cut complications and deaths by dramatic margins across eight hospitals worldwide. Not a thousand-page protocol. Not a comprehensive framework. Nineteen items, printed on a single card. Aviation learned the same lesson decades earlier: the pre-flight checklist fits in a pilot’s hand, not in a binder. Nearly two decades later, I watch security teams send AI vendors questionnaires with 300 questions, half of which begin with “describe your approach to…” and almost none of which would catch a real failure. We have the frameworks. What we don’t have is the checklist.

The timing matters. The EU AI Act’s enforcement teeth for general-purpose AI arrive this August, high-risk obligations are phasing in behind them, and ISO/IEC 42001 is now showing up by name in third-party risk questionnaires. NIST’s AI Risk Management Framework has become the default answer for “show me you have an AI risk program” in North America. Add the OECD Principles, HITRUST’s AI assurance work, sector regulators like the FDA, and a growing patchwork of US state laws, and most enterprises are now operating under two or more frameworks simultaneously.

Here’s the part that surprises people: the frameworks themselves largely agree. Published crosswalks show substantial overlap between ISO 42001, NIST AI RMF, and the EU AI Act. An organization that builds its program thoughtfully can satisfy all three with a single set of processes and documentation. The problem isn’t the frameworks. The problem is what happens downstream, when those frameworks get translated into the questionnaires, audits, and attestations that land on real desks.

The Questionnaire Problem

If you’ve been on the receiving end of an AI security questionnaire lately, you know the artifact I’m describing. Hundreds of questions. Free-text answers. Prompts like “Describe how your AI system ensures fairness” or “Explain your approach to responsible AI.” These questions have three fatal flaws.

First, they can’t be answered with evidence, only with prose. And prose isn’t compliance; it’s creative writing. A vendor with a mature program and a vendor with a good technical writer produce indistinguishable answers. The exercise rewards confident fiction and punishes honest uncertainty. When I see a question that any vendor can answer without producing a single artifact, I know that question isn’t reducing anyone’s risk.

Second, they ignore the nature of the systems they’re assessing. As I wrote in the last column, LLMs are stochastic systems that are extremely difficult to replay and troubleshoot. A point-in-time attestation about model behavior is stale the moment a model version changes, a system prompt is updated, or a temperature setting moves. Asking “does your model produce biased outputs?” as a yes/no compliance question fundamentally misunderstands what these systems are. The right question is whether you can measure it, log it, and show me the trend.

Advertisement. Scroll to continue reading.

Third, they don’t scale with risk. I’ve seen the same 300-question addendum sent to a vendor running a marketing chatbot and a vendor deploying clinical decision support. When everything is high-risk, nothing is. The EU AI Act got at least this much right: its four-tier risk classification exists precisely so that obligations scale with consequences. Most homegrown questionnaires have no tiers at all.

What Usable Actually Looks Like

I want to propose a different bar for AI compliance, and it borrows directly from the checklist lesson: a framework is only as good as its worst question. Before any question makes it into your AI assessment, whether that’s a vendor questionnaire, an internal review gate, or an audit program, it should pass five tests:

1. Answerable with an artifact. Every question should map to evidence: a log, a config, an eval report, a data flow diagram, an architecture document. If the only possible answer is an essay, cut it or rewrite it. “Describe your approach to model security” becomes “Provide your logged inference parameters (model version, temperature, top P, token limits) for your production deployment.”

2. Scoped to risk tier. Classify the system first, then ask the questions that tier deserves. A limited-risk internal tool gets ten questions. A system touching patient data or financial decisions gets the full treatment. Don’t send Annex IV-depth documentation requests to a chatbot vendor.

3. Measurable or binary where possible. “Do you run evals? At what cadence? What was your last pass rate on your safety benchmark?” beats “describe your testing philosophy” every time. Reviewers can score it, trend it, and compare it across vendors.

4. Decision-relevant. For each question, ask: if the answer came back bad, would it change our decision? If removing the question wouldn’t change any outcome, remove the question. This single test eliminates half of most questionnaires I’ve seen.

5. Mapped once, reused everywhere. Build your control set once, then use the published crosswalks to answer NIST, ISO, and EU AI Act asks from the same evidence base. One process, multiple regulatory readings. If your teams are producing separate documentation for each framework, you’re paying a triple tax on the same work.

The Questions That Actually Matter

If I had to compress AI vendor assessment down to a single card, it would look something like this: Where is the model deployed, and who is the upstream provider? What data flows in, and what flows out, and where is that logged? Where are copies of that data stored, for how long, and who can access them? What inference parameters are logged per request, and can you replay an incident? What is your eval suite, what does it cover, and how often does it run against production? Where are the human oversight points, and what can the system do without one? What is your incident process when the model does something it shouldn’t? How do you swap or change models, what testing gates a switch, and do downstream customers get notified?

Notice these are largely the same questions I argued for in the red teaming column: before deploying, know where the model runs, what inputs it processes, what the outputs look like, and how business risk gets revisited over time. That’s not a coincidence. Good security questions and good compliance questions converge, because both are ultimately about whether you understand the system you’re operating.

Standardize the Model Card

There’s one industry fix that would eliminate half of these questions before they’re ever asked: a standardized model card. I raised this in the last column, noting that model cards tend to offer some insights but measurements aren’t standardized across the industry, and it matters even more for compliance than it does for red teaming. Today, every model provider publishes something different: different eval benchmarks, different safety disclosures, different levels of detail on training data, different definitions of the same terms. That inconsistency is exactly what forces every downstream customer to run their own bespoke questionnaire, and forces every vendor to answer the same questions a hundred different ways.

Imagine instead a model card with a fixed schema: model version and lineage, training data provenance categories, where and how long data is retained, a common core of eval benchmarks with published scores, documented safety mitigations, default inference parameters, and a change log tied to every model swap or version update. SOC 2 didn’t succeed because it was clever. It succeeded because everyone agreed on what the report looks like, so one artifact could answer a thousand customers. The model card should be AI’s equivalent: produce it once, keep it current, and let it stand in for the first fifty questions of every assessment. Standards bodies are circling this idea, and both ISO 42001’s documentation requirements and the EU AI Act’s transparency obligations gesture at it. But until the schema is common, buyers can force the issue by asking for the same fields, in the same format, every time. Procurement pressure standardized SOC 2. It can standardize the model card too.

The key insight I want to share is this: compliance is an evidence problem, and for AI, evidence is an observability problem. The organizations that will sail through the enforcement wave now arriving aren’t the ones with the thickest binders. They’re the ones whose logging, evals, and documentation were designed so that any reasonable question can be answered in minutes with an artifact rather than in weeks with an essay. This is what I mean by timeless compliance. Frameworks will keep multiplying, regulators will keep diverging, and the models themselves will be unrecognizable in three years. But the principles underneath don’t move: know your system, log what matters, measure continuously, scale scrutiny to risk, and never ask a question you can’t act on. Those held true for surgical checklists and pre-flight cards, they held true for SOC 2 and ISO 27001, and they will hold true for whatever comes after the current generation of AI standards. Comprehensive coverage is a moving target. Simplicity, done honestly, is permanent.

This column is Part 3 of multi-part series on securing generative AI:

Part 1: Back to the Future, Securing Generative AI
Part 2: Trolley problem, Safety Versus Security of Generative AI
Part 3: Build vs Buy, Red Teaming AI
Part 4: Timeless Compliance (This Column)

Learn More at the AI Risk Summit | Ritz-Carlton, Half Moon Bay

https://www.securityweek.com/timeless-compliance-why-better-questions-beat-bigger-frameworks/




AI Applications Contain Security Vulnerabilities, According to Report

A penetration testing report by BreachLock found that 100% of AI applications tested contained vulnerabilities aligned with the OWASP Top 10 for LLMs. Prompt injection (LLM01) was the most prevalent and impactful finding in the dataset, present in 28% of tested applications.

The report also identifies a sharp shift in how attackers are targeting web applications. Insecure Design and business logic flaws (OWASP A04) rose from 8% to 16% of findings year over year, a trend-defining increase in the 2026 web application dataset. Testers observed attackers exploiting race conditions in checkout flows, escalating privileges through parameter manipulation, and bypassing approval workflows outright. These issues do not appear on automated scanner reports. Finding them requires testers who understand how an application is supposed to behave and can reason through how that logic can be subverted.

Cloud environments produced the highest concentration of severe risk in the dataset. Cloud security audits carried a Critical finding rate of 1.34%, thirteen times higher than the rate found in web application testing, driven largely by exposed S3 buckets, leaking Lambda functions, and disabled GuardDuty monitoring.

Mobile applications showed a similarly narrow but severe risk profile. Hardcoded credentials in iOS applications accounted for 97% of all Critical mobile findings this year. These credentials can be extracted with free, publicly available tools in minutes, and credential-related vulnerabilities continue to be a top attack vector in headlines this year.

Download the report.

https://www.securitymagazine.com/articles/102476-ai-applications-contain-security-vulnerabilities-according-to-report




Majority of Organizations Unsure if They Could Detect AI Attack

A report by Onapsis analyzed the results from a study on artificial intelligence (AI) security and enterprise resource planning (ERP). The report found that nearly one in four organizations (22%) report experiencing a security incident in the last twelve months where bad actors used AI to exploit their critical business platforms. 

The report also found that 70% of senior cybersecurity leaders have only some trust or no trust at all in AI to secure their organizations’ business critical data. However, more than half (58%) report that their organizations started using AI-based apps or agents that touch their ERP system within just the last six months, and 86% say they have already integrated, or will shortly integrate, AI directly into their ERP code.

Nearly 57% of respondents report that at least one business unit has objected to implementing AI within the ERP environment, with the security team topping the list of resistant groups (41.4%), followed by IT (20.7%) — the very function responsible for the ERP. The top reasons cited for resistance were lack of confidence in AI security (75%) and compliance risk (71.6%).

According to the report, 68.6% of respondents say they are only “somewhat” or “not very” confident that their current security defenses could even detect an AI-based attack. A similar share — 70.6% — report having only some, or no trust at all in AI applications and agents to secure their organization’s most business-critical data. When asked what it would take to build that trust, respondents pointed to robust access management controls (61.8%), strong personal data protections (45.8%) and sandboxing or digital twin environments (36.8%) as the top requirements over the next 12 months.

Download the report.

https://www.securitymagazine.com/articles/102475-majority-of-organizations-unsure-if-they-could-detect-ai-attack




DataBahn Raises $40 Million for Agentic Data Pipeline Management

DataBahn today announced closing a $40 million Series B funding round that brings the total raised by the company to $59 million.

Founded in 2023, Texas-based DataBahn helps organizations automate data integration, management, and optimization, and reduce costs.

According to the company, its solution provides seamless data collection and integration, SIEM and data storage optimization, data ownership and governance, and real-time visibility and insights.

DataBahn’s agentic data control plane activates, governs, and orchestrates enterprise data across sources, destinations, and AI models, enriching and routing only the data required for real-time operations.

Its data fabric covers various types of data, including security, application, OT, IoT, and observability data.

DataBahn’s fresh investment round was led by Insight Partners, with additional support from previous investors Forgepoint, GTM Capital, and S3 Ventures.

Advertisement. Scroll to continue reading.

The company plans to use the funding to accelerate investments in R&D and product innovation, and to expand its agentic data control plane.

“The next generation of enterprise infrastructure won’t be built around moving more data—it will be built around intelligently orchestrating the right data at the right time. We believe every enterprise will need an agentic data control plane that continuously reduces, enriches, governs and activates enterprise data for both applications and AI,” said DataBahn co-founder and CEO Nanda Santhana.

Related: Discern Security Raises $13 Million in Series A Funding

Related: Mate Security Raises $35 Million for Agentic SOC

Related: Cantina Emerges From Stealth With $8 Million in Funding

Related: ThreatLocker Raises $190 Million in Series F Funding

https://www.securityweek.com/databahn-raises-40-million-for-agentic-data-pipeline-management/




Cantina Emerges From Stealth With $8 Million in Funding

Cybersecurity startup Cantina today emerged from stealth mode with $8 million in fresh funding for autonomous vulnerability management.

Bringing the total raised by the company to $16.5 million, the new investment round was led by Framework Ventures.

Based in New York, Cantina has built a community-powered agentic security platform that relies on autonomous security workers to identify, prioritize, and remediate vulnerabilities.

The platform allows organizations to use out-of-the-box, custom-built, and proven community-built agents shared by other customers to automate vulnerability management.

Cantina’s platform maps identities, servers, repositories, databases, and other assets across an organization’s environment, applies business context, and provides security teams with an overview of risks, flagging issues that require prioritization.

According to the startup, the platform learns with each investigation, becoming more precise with each alert and focusing on risks that matter.

Advertisement. Scroll to continue reading.

The solution maintains a dynamic digital twin of the organization’s environment, surfaces and ranks security issues, automates investigations and remediation, and verifies that fixes have been successfully implemented.

“Attackers can identify vulnerabilities, understand systems, and build exploits faster than ever before. Security teams cannot keep responding with workflows built for a pre-AI world. Defenders need AI that doesn’t just identify problems, but helps investigate them, coordinate remediation, validate fixes, and continuously gets smarter with every issue it resolves,” said Cantina co-founder and CEO Hari Mulackal.

Related: Mate Security Raises $35 Million for Agentic SOC

Related: ThreatLocker Raises $190 Million in Series F Funding

Related: Spur Raises $200 Million for IP Intelligence Platform

Related: OT Security Startup Frenos Raises $1.52 Million

https://www.securityweek.com/cantina-emerges-from-stealth-with-8-million-in-funding/




Discern Security Raises $13 Million in Series A Funding

Discern Security today announced raising $13 million in a Series A funding round that brings the total raised by the company to $16 million.

The investment round was led by Forgepoint Capital, with additional support from First Rays Ventures, Growth Enjin Partners, Vela Ventures, and angel investors.

Founded in 2023, California-based Discern Security provides an agentic, proactive security platform for continuous security posture evaluation and security control improvement.

The Discern Security Loop platform unifies data from an organization’s environment and combines AI agents and human-approved workflows with business context to identify control gaps and prioritize remediation.

It allows security teams to assess controls, automate workflows, and prioritize remediation through proactive, agent-driven security operations that unify security data and vendor best practices.

Discern connects all findings to assets, controls, and compliance requirements to automate analysis and help organizations strengthen security posture while gaining measurable evidence of progress.

Advertisement. Scroll to continue reading.

The company will use the fresh funding to expand its engineering and product teams, accelerate platform development and adoption, and grow its AI Skills and autonomous capabilities library.

“AI can significantly improve security posture by closing control gaps with existing tools, but doing so requires a deep understanding of the organization’s environment, business context, and security stack,” said Forgepoint Capital partner Rey Kirton.

“Discern brings that understanding into an AI-powered workspace that helps users investigate, act, and continuously improve security,” Kirton added.

Related: Cantina Emerges From Stealth With $8 Million in Funding

Related: Cyera Acquiring Oasis Security in $1 Billion Deal

Related: Act Security Emerges from Stealth to Fight the Patch Problem

Related: Hush Security Raises $30 Million for AI Agent Governance

https://www.securityweek.com/discern-security-raises-13-million-in-series-a-funding/




Onyx Security Raises $113 Million to Control AI Agents in the Enterprise

Onyx Security on Wednesday announced raising $113 million to secure AI adoption in the enterprise.

The Series B funding round was led by Bessemer Venture Partners, with participation from Cyberstarts, TCV, Conviction, FirstMark, Vintage, QuantumLight, and G Squared.

Onyx has raised a total of $153 million since its founding two years ago, and the latest funding will be used to train its proprietary models and scale its go-to-market efforts.

While the Israeli company did not officially disclose its valuation, the new capital injection reportedly values the startup at an estimated $640 million.

Onyx Security offers a centralized platform that helps organizations identify and regulate the use of advanced AI tools across their networks. The solution is designed to address the risks introduced by highly capable AI agents that are granted access to critical corporate systems without built-in accountability or oversight.

According to the company, the technology relies on its own proprietary models to track an AI agent’s decision-making process at every step, enabling it to intervene and rectify any unintended or malicious behavior as it happens across SaaS, cloud, and endpoint environments.

Advertisement. Scroll to continue reading.

The solution enables enterprises to find shadow AI implementations, enforce real-time safeguards against threats like prompt injections, and meet regulatory compliance standards.

“As AI agents become embedded in critical business workflows, enterprises need a way to ensure they operate safely, predictably, and within policy,” said Hila Zigman, general partner at Cyberstarts. “Onyx is building the control layer that makes enterprise AI adoption possible at scale. We believe this will become one of the defining security categories of the coming decade.”

Related: Mate Security Raises $35 Million for Agentic SOC

Related: ThreatLocker Raises $190 Million in Series F Funding

Related: Spur Raises $200 Million for IP Intelligence Platform

https://www.securityweek.com/onyx-security-raises-113-million-to-control-ai-agents-in-the-enterprise/