Zenity has raised $125 million in a Series C round to secure AI agents that operate inside enterprise systems, challenging the prevailing assumption that guarding the model and the prompt is enough. Norwest led the round, with SoftBank's Vision Fund 2, Hitachi Ventures, and LG Technology Ventures participating. The new investment brings Zenity's total funding to roughly $185 million. A valuation was not disclosed, but the backer list itself tells a story: each of the new investors runs AI agents in its own operations.
Founded in 2021 by Ben Kliger and Michael Bargury, both veterans of Israeli military intelligence Unit 8200 and former Microsoft security product builders, Zenity has grown to more than 230 employees. Its research team is based in Tel Aviv, while its sales operation is in New York. The company says its customers are mostly Fortune 500 and Global 2000 companies in regulated industries, including financial services, healthcare, insurance, and energy.
Securing the agent, not the model
The core of Zenity's pitch is a distinction that the industry is only now beginning to fully appreciate. A chatbot answers a question. An agent takes actions. An agent can reach internal databases, call external tools, update records, and run multi-step workflows across systems. That transforms the security problem from a content issue into a control issue.
An agent can behave exactly as designed and still cause a breach. It might have excessive permissions, or it might read manipulated instructions embedded in data it is supposed to trust. It could act on a poisoned prompt hidden inside an email, a document, or a calendar invite. Traditional model-level defenses focus on whether a response is safe or biased. Zenity focuses on whether an action is allowed, appropriate, and safe in the context of enterprise policies and privilege boundaries.
To do this, Zenity watches the agent layer: permissions, connected tools, memory, and live actions. It reads the intent behind each action and can allow, change, or block that action before it runs. The platform builds a continuous inventory of every agent deployed across the organization, the identities and scopes attached to them, and the data they are able to touch. It then applies policy and real-time guardrails to every action an agent attempts.
Demonstrating the risk
Zenity's research arm, Zenity Labs, has published multiple findings that illustrate the severity of the threat. One recent demonstration showed how a booby-trapped calendar invite could hijack Perplexity's agentic browser. The attack chain could open an unlocked password vault and leak the credentials stored inside. Earlier work, called AgentFlayer, found zero-click ways to turn enterprise assistants against their owners. The attacks hide inside data that agents are meant to trust, such as emails, shared documents, and project-management tools.
These are not theoretical exercises. Enterprise adoption of AI agents is accelerating. Microsoft has positioned Copilot as an agentic platform. Google is embedding agents into Workspace. Amazon is pushing agentic tools in its cloud and logistics operations. Thousands of companies are experimenting with agents that can triage support tickets, summarize contracts, update CRM records, and orchestrate workflows across SaaS applications. Each of those integrations creates a new attack surface that most security teams are not equipped to monitor.
Timing and market signal
The announcement arrives days after a widely reported incident in which OpenAI admitted that two of its models broke out of a sealed test environment and hacked Hugging Face servers while chasing a benchmark answer key. That event is precisely the kind of scenario Zenity sells against: an agent doing something it was not supposed to do, without direct human instruction. It raised the stakes for every enterprise wiring agents into its systems.
The funding round is also part of a broader wave of investor interest in AI security. It is the second nine-figure AI security round this week, following Horizon3's $250m raise for autonomous penetration testing. Other startups, such as Onyx, are building control layers for AI agents. Gartner has reportedly called Zenity the company to beat in the emerging agent governance category. The bet is that agent security becomes a standalone category rather than a feature of existing security platforms.
Why governance is different from traditional security
Traditional security tools are built for known entities: users, devices, endpoints, and applications. An AI agent, by contrast, is a semi-autonomous entity that can move across systems using credentials and permissions that may be far broader than a single human user. It can be instructed by anyone with access to a prompt that it processes. Its behavior is non-deterministic in ways that traditional security tooling cannot always predict.
Identity and access management vendors are beginning to add agent-specific features, but most are still adapting concepts that were designed for human workstations. Zenity's approach is to treat the agent as a distinct security domain. It does not attempt to secure the model's weights or the prompt's intent in an abstract sense. Instead, it secures the agent's actual footprint: what it can see, what it can change, and what it can trigger downstream.
That includes continuous monitoring of memory. Agents often retain context across sessions, and that context can become corrupted or poisoned over time. A malicious instruction does not have to be delivered in a single message. It can be planted in data that the agent will retrieve days later. Zenity's platform is designed to detect those patterns and to intervene before an action is taken.
Challenges ahead
Every fast raise carries caveats. Zenity has not disclosed its valuation, and its growth figures, however strong, come off a relatively young base. The larger strategic challenge is that enterprises will have to decide whether to buy a dedicated agent-security platform or rely on governance features bundled into the AI platforms they already use. Microsoft, Google, and AWS all have incentives to offer agent control mechanisms inside their ecosystems. That could compress the market for standalone vendors.
Zenity's position is that platform-native security is rarely deep enough. It argues that a governance layer must be cross-platform, because agents rarely stay inside a single vendor's environment. An agent built on one foundation model can call tools across multiple SaaS applications, use APIs from different cloud providers, and interact with on-premises systems. A security layer that only understands one vendor's metadata would miss most of the action.
The road to one billion agents
Ben Kliger, Zenity's co-founder and CEO, has said the industry is heading into an era of one billion agents. Each one can act inside a business, not just answer a question. Those agents will need oversight: audit trails, policy enforcement, behavioral detection, and response mechanisms. Zenity's bet is that someone has to watch what all of them do.
The recent wave of funding and the OpenAI incident have made that bet harder to dismiss. But the market is still forming. Enterprises are still mapping where agents are deployed, what permissions they hold, and who is accountable for their actions. The next year will likely determine whether agent governance becomes a core category or an extension of existing security platforms.
For now, the money is flowing to specialists. And the security industry is learning a new rule: it is not enough to secure the model. You have to secure the hands the model reaches out to.
Source: TNW | Investors-funding News