Obsidian Security did not raise $85 million because enterprises are excited about AI agents. It raised because they have already deployed them and cannot see what those agents are doing. The Palo Alto company closed a Series D in early August at a $1.1 billion post-money valuation, led by Crescent Cove Advisors, with existing backers Greylock Partners and Menlo Ventures following on. Total capital raised now sits above $200 million.
The figure in that announcement that actually matters is not the valuation. More than 65 percent of the enterprises Obsidian protects have already given AI agents access to data inside third-party applications. Not pilots in a sandbox. Live access to the systems those companies run on.
A permissions problem, not a model problem
Obsidian’s product monitors non-human identities: the service accounts, tokens and agent credentials that increasingly move through corporate software with no person attached. Its customers are running agents built on Microsoft Copilot Studio, Salesforce Agentforce, n8n and Anthropic’s Claude Code and Cowork, pointed at data warehouses, CRMs, developer tools and collaboration platforms. The pitch is that the company can see what each agent is permitted to reach and what it actually does once it gets there, including modifying and deleting records.
That framing sits some distance from how AI risk usually gets discussed. Public argument centres on model behaviour: hallucination, bias, jailbreaks. Operational risk inside a large company looks more mundane and considerably more expensive. An agent holding a valid token and overly generous scopes does not need to be tricked into causing damage. It only needs to be wrong once while carrying write access to a production system.
Retrofitting oversight is harder than it sounds. A single agent workflow may authenticate to half a dozen systems using credentials issued at different times by different teams, and the permission that matters is rarely the one someone reviewed at setup. Human identity tooling assumes a person who logs in, works, and logs out. Agents run continuously, act on schedules nobody watches, and inherit whatever scope was convenient on the day they were connected.
Why security budgets are moving first
Enterprise AI spending this year has followed a consistent sequence. Companies sign the platform deal, roll agents out to staff, then discover a governance gap nobody owned. Ryanair’s five-year Google Cloud agreement, announced last week, puts Gemini Enterprise in front of 35,000 employees across crew scheduling, fleet operations and maintenance planning. Deployments at that scale generate precisely the question Obsidian is selling an answer to: which agent touched which system, under whose authority, and can anyone prove it afterwards.
Regulation is pushing in the same direction. The EU AI Act’s high-risk obligations became enforceable on 2 August, bringing documentation, logging and human oversight requirements into scope for systems used in areas such as credit scoring and insurance underwriting, with penalties reaching €15 million or 3 percent of global annual turnover. Logging has stopped being a nice engineering practice. In several jurisdictions it is now evidence.
What the round signals for the category
A $1.1 billion valuation for a company securing agent identities suggests investors believe this is a durable budget line rather than a feature the large platform vendors will absorb. That is a genuine bet. Microsoft, Salesforce and the major cloud providers all have obvious incentives to build native controls for agents running on their own stacks. The counterargument, and the one Obsidian is making, is that no single platform vendor is well placed to police what happens across all of them simultaneously, and cross-platform sprawl is exactly where agent risk accumulates.
Adoption data from adjacent sectors supports the thesis. Cambridge’s Centre for Alternative Finance, surveying 628 organisations across 151 jurisdictions for its 2026 report on AI in financial services, found 52 percent of industry respondents piloting or scaling agentic AI and 21 percent already running it in production, with fintechs ahead of established institutions at 57 percent against 45 percent. Those are not companies known for reckless technology rollouts.
For businesses outside the security industry, the sequencing is the point. If more than 65 percent of one vendor’s enterprise base has already wired agents into third-party systems, then in most large organisations the deployment decision was made somewhere well below the executive floor. Governance is arriving after the fact, which is the normal pattern for any technology that spreads through individual teams before it reaches a procurement committee.
The next twelve months should settle whether agent security becomes its own budget line or gets folded back into identity management, where non-human credentials have historically lived. Either way, the firms writing cheques for it are not doing so speculatively. They are doing it because the agents are already inside.
For more coverage of enterprise AI, visit Mylistingo.







