Hush Security Raises $30 Million to Secure the Next Wave of AI Workers

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

Hush Security has raised a $30 million Series A, bringing total funding to $41 million, to build what amounts to a passport system for AI agents inside the enterprise. The company assigns each AI agent a managed digital identity, replaces standing API keys with just-in-time access (credentials that exist only for the duration of a specific task), and continuously monitors every action those agents take. Akamai joined as a strategic investor alongside Battery Ventures and YL Ventures. Kyndryl, the world’s largest IT infrastructure services provider, is already deploying the platform internally and reselling it to enterprise customers.

What this means for your business

The Gartner projection sitting inside this story deserves a hard look: the average Fortune 500 company running more than 150,000 AI agents by 2028, up from fewer than 15 last year. Whether that number proves precise or hyperbolic, the directional point holds, and CISOs who are already stretched managing human identity sprawl now face a non-human identity problem that compounds faster than any hiring wave. If your organization has already deployed AI agents on any enterprise platform, the 96% figure from Omdia, that nearly every organization is running agents on governance models not designed for them, almost certainly includes you.

The core vulnerability here is what you might call credential inheritance: AI agents typically get provisioned with broad, permanent API keys borrowed from service accounts built for a different era, and nobody’s watching what they do with them. Hush’s just-in-time model is the right architectural answer. A credential that expires when the task ends can’t be exfiltrated for later use, can’t be quietly reused by a compromised agent, and leaves an auditable trail. The question isn’t whether this approach is sound; it’s whether Hush is the vendor to deliver it, or whether your existing identity provider, a CyberArk or a SailPoint, gets there first.

Kyndryl’s role as both customer and reseller is the tell worth watching. Large IT services firms don’t white-label technology they expect to replace in 18 months. That partnership gives Hush a distribution path into enterprise accounts that most two-year-old security startups can’t touch, and it insulates the company somewhat from the “acqui-hire it and absorb it” fate that ends many Israeli security startups early. The decision this reframes isn’t whether to buy a dedicated AI agent identity tool; it’s whether your next identity platform renewal should carry an explicit requirement that non-human identity management is a first-class capability, not a promised roadmap item.

Concept deep-dive: Just-in-time access

Just-in-time access means a credential, a password, API key, or permission, is created at the moment it’s needed and automatically revoked when the task is done, rather than sitting permanently in a system waiting to be stolen. Think of it as a valet key instead of a master key. For AI agents that might execute thousands of tasks across dozens of systems, permanent credentials are an enormous attack surface. Just-in-time access shrinks that surface to near zero between actions.

Based on reporting from Hush Security Raises $30 Million to Secure the Next Wave of AI Workers, originally published 2026-07-29 02:21:00.

TAGGED:
Share This Article