Share with your CISO
Onyx Security is betting that AI agents, software that acts autonomously inside enterprise systems, will become the dominant threat surface faster than most security teams expect. The Israeli-American startup raised $113 million in Series B funding led by Bessemer Venture Partners, bringing total funding to $153 million in two years. Its Secure AI Control Plane already monitors more than 1.1 million agents across Fortune 500 customers in financial services, healthcare, energy, and technology, analyzing 66 million AI sessions in real time. Revenue has quadrupled since emerging from stealth four months ago.
What this means for your business
The speed of this funding round matters more than the size. Onyx went from founding to $153 million raised in two years, with a partnership from Anthropic already in place, which means the vendor consolidation race in AI agent security is already underway. CISOs who haven’t yet mapped which agents are operating inside their environment are not early in the evaluation cycle, they’re behind it. The organizations best positioned here are those that already run mature identity and access management programs, because agent governance is essentially that problem at machine speed and scale.
The underlying claim Onyx is making, that traditional security tools weren’t designed for software that makes decisions on behalf of users, is correct and underappreciated. Existing security architecture assumes a human initiates an action and a tool executes it. Agents invert that model: the agent decides, then acts, often across multiple connected systems in a single session. Perimeter security, endpoint detection, even most SIEM platforms (security information and event management systems that aggregate and analyze security logs) were built to catch human-initiated anomalies. An agent moving laterally through a CRM, an ERP, and a data warehouse in thirty seconds doesn’t trigger the same signatures.
Onyx’s 66 million sessions figure deserves scrutiny, and not because it’s implausible. A vendor reporting its own telemetry four months out of stealth, with revenue still in early-growth territory, has every incentive to frame scale as validation rather than as a baseline that still requires independent stress-testing. The Anthropic partnership is real signal, but it’s also Anthropic protecting its enterprise sales motion, not a neutral security audit. The question a CISO should be asking isn’t whether agent governance is a real category, it clearly is, but whether a point solution built two years ago can hold its architecture advantage once CrowdStrike, Palo Alto, and Microsoft finish mapping agents into their existing platforms. I’d revisit that competitive insulation assumption the moment any of the incumbent security platforms announces native agent session monitoring at comparable scale.
Concept deep-dive: AI Control Plane
A control plane is the layer of infrastructure that manages and directs how other systems behave, distinct from the data those systems process. In networking, the control plane tells traffic where to go; the data plane carries it. Onyx applies this architecture to AI agents, sitting above the agents themselves to observe, analyze, and interrupt their actions in real time. The business case is straightforward: enterprises need a single governance layer before agents proliferate faster than any team can audit them individually.
Based on reporting from Onyx Security Raises $113 Million to Keep Humans in Control of AI Agents, originally published 2026-08-01 23:14:00.

