Obsidian Security closed an $85 million Series D in early August 2026, led by Crescent Cove Advisors with existing investors Greylock Partners and Menlo Ventures returning, pushing the company's valuation to roughly $1.1 billion. The pitch isn't a new firewall or a new SaaS scanner — it's visibility and control over what AI agents are doing once they're granted access to enterprise systems, built on models like Claude, ChatGPT, and Microsoft Copilot Studio.
The problem the money is chasing
AI agents don't log in like employees. They operate as non-human identities with API keys, service accounts, and standing permissions — often broader than any single human would be granted, because nobody wants to be the one re-approving an agent's access every time it needs to touch a new system. That convenience is exactly what's creating the exposure: more than 100 of Obsidian's customers now spend over $100,000 a year just to see what their agents are doing with the access they've already been given.
This isn't a hypothetical risk category. It's the direct consequence of the adoption curve covered in Gartner's 40%-by-2026 prediction — the same agents driving productivity gains are the ones nobody has fully instrumented for monitoring, and most existing security tooling was built to watch human behavior, not autonomous agent behavior operating at machine speed.
Why "we trust our vendor" isn't a security posture
The instinct for a lot of companies is to assume that if the underlying model is from a reputable lab, the agent built on top of it inherits that trust. It doesn't. An agent's risk profile is defined by what it's allowed to do — which systems it can read, which it can write to, whether its actions are logged and reversible — not by which foundation model is generating its decisions. Two agents built on the identical model can have wildly different blast radii depending entirely on how their access was scoped.
The question isn't whether your AI agents are smart enough to be trusted. It's whether you'd notice if one of them wasn't.
What actually needs to happen before agent number three
Three things, in order: scope every agent's access to the narrowest set of systems it needs, not the broadest set that's convenient; log every agent action the same way you'd log a privileged human session, with an audit trail that survives the agent's own reasoning being wrong; and review those logs on a cadence, not just after an incident. None of this is exotic — it's the same governance discipline security teams already apply to service accounts and API keys. Agents just make the volume and speed of that activity much higher.
This is why Acclivity Labs treats security as a first-class agent in the stack rather than a bolt-on: our Cybersecurity Agent and SOC 2 & Compliance agent are built to monitor the rest of the agent suite's activity, not just the perimeter around it.