Back to front page
Agents/Security August 18, 2026

AI Agents Move in Milliseconds. Security Teams Still Move in Days. One Startup Just Raised $85 Million to Close the Gap.

Obsidian Security raised $85 million at a $1.1 billion valuation to extend SaaS governance into runtime controls for autonomous AI agents, as enterprise non-human identities multiply and traditional detection-and-response workflows fall behind.

For most of the last two decades, enterprise security has run on a simple assumption: a human is sitting behind the keyboard, and if something looks wrong, someone has a few minutes — or at least a few seconds — to notice and respond. That assumption is now colliding with a workforce that never sleeps, never asks for permission twice, and can burn through a thousand actions before a human even opens the alert.

That collision is exactly what Palo Alto-based Obsidian Security is betting its next chapter on. The company announced on August 4, 2026 that it raised an $85 million Series D led by Crescent Cove Advisors, with participation from Greylock Partners, Menlo Ventures, Norwest Venture Partners, IVP, Google Ventures, and Wing Ventures. The round values Obsidian at $1.1 billion, pushing it past unicorn status and bringing its total funding to more than $200 million across five rounds since it was founded in 2017 by a team of former Carbon Black and Cylance security engineers.

The Numbers Behind the Urgency

Obsidian didn't raise this round to defend against a hypothetical. According to CEO Hasan Imam, more than 70% of the company's customers already let AI agents operate inside third-party SaaS applications — and that share is climbing. Inside those applications, Obsidian says non-human identities (API keys, OAuth tokens, service accounts, and now autonomous agents) now outnumber human ones by roughly 144 to 1.

That ratio is the crux of the problem. Traditional identity and access management was built to govern people: predictable login patterns, business-hours activity, a finite number of accounts to audit. Agentic AI breaks all three assumptions at once. As Imam put it bluntly: "The concept of detection and response doesn't work in the agentic world. Agents move in seconds, maybe milliseconds." By the time a security analyst reviews a flagged event, an autonomous agent may have already read a file, called an API, or pushed a change — and moved on to the next task.

From SaaS Visibility to Agent Runtime Control

Obsidian built its original business on giving security teams visibility into what was happening inside SaaS platforms like Salesforce, Workday, and Microsoft 365 — the blind spot left behind once companies moved critical data out of on-premise systems they controlled directly. The company's pitch now is that AI agents are repeating that same migration, just faster: as Imam described it, "AI agents gravitate toward third-party applications. That's where the data lives, that's where the work happens, and that's exactly where the risk lives too."

With this raise, Obsidian is extending that governance layer to cover autonomous agents directly, including newly announced native controls for Anthropic's Claude Code and Cowork. The capabilities let security teams restrict what an agent can touch in production data, manage which files it can open, right-size access that's broader than a task actually requires, block unsanctioned use of MCP servers and other tools, and — critically — intervene on destructive actions at runtime, before they complete, rather than after the fact in a log review.

That runtime-intervention piece is the real departure from how most security tooling has worked. Historically, "governance" for SaaS and cloud systems has largely meant retrospective auditing: something happens, it's logged, and a human decides later whether it was a problem. Obsidian's bet is that agentic AI makes retrospective auditing close to useless, because the damage — a deleted production table, a leaked customer record, a malformed change pushed to a live system — is already done by the time anyone looks.

Who's Actually Paying For This

The commercial traction backs up the urgency narrative. Obsidian says it now has more than 100 customers spending over $100,000 annually, with 14 of those spending north of $1 million a year, and counts 60 of the Fortune 500 among its customer base — spanning financial institutions, social media platforms, and telecom providers, sectors where both regulatory exposure and the blast radius of a bad agent action are highest.

That customer profile matters for reading this story correctly. This isn't a startup selling a hypothetical to security theater budgets; it's landing seven-figure contracts with some of the most heavily regulated and highest-stakes environments in the enterprise. The $1.1 billion valuation reflects investors betting that the same category of buyer — banks, telecoms, large platforms — is about to need this kind of control for every business unit that adopts agentic tools, not just the early ones.

Part of a Bigger Pattern

Obsidian's raise doesn't exist in isolation. It lands on top of a story AI News has tracked building since early summer: our July 3 piece on the industry's belated scramble toward "Agent Zero Trust" after protocol wars left agent-to-agent authentication as an afterthought, and June coverage of enterprise agent infrastructure evolving into its own identity, observability, and cost-management layer. What's different now is that the conversation has moved from "we should probably think about this" to venture capital writing nine-figure checks and Fortune 500 companies signing seven-figure contracts to solve it today.

It's also a useful counterpoint to stories like the tldv incident we covered on August 14, where a six-month-long silent data exposure from an AI notetaker showed exactly what happens when a tool with broad access to sensitive data operates without the kind of runtime governance Obsidian is selling. The pattern across both stories is the same: enterprises are handing AI systems — whether copilots, notetakers, or fully autonomous coding agents — deeper access to real data and real systems faster than most organizations' security posture has caught up.

The open question is whether governance tooling like Obsidian's can actually keep pace with how fast agent capabilities are expanding, or whether — like detection-and-response before it — it will always be playing catch-up to whatever agents can do next. For now, the market is voting with real money that it's worth trying.

Sources

Obsidian Security: Unlocking AI Potential Securely — https://www.obsidiansecurity.com/news/unlocking-ai-potential-securely

SiliconANGLE: Obsidian Security raises $85M as AI agents create cybersecurity's next major attack surface — https://siliconangle.com/2026/08/04/obsidian-security-raises-85m-ai-agents-create-cybersecuritys-next-major-attack-surface/

Unite.AI: Obsidian Security Raises $85 Million Series D at Unicorn Valuation — https://www.unite.ai/obsidian-security-raises-85-million-series-d-at-unicorn-valuation/

Axios Pro: Obsidian Security raises at $1.1B valuation — https://www.axios.com/pro/enterprise-software-deals/2026/08/04/obsidian-security-agents-crescent-cove