The danger isn’t the AI model. It’s the agent acting on its own, and Zenity raised $125m to watch it.

Zenity has raised $125m to secure not AI models but the agents built on them, as they start touching real enterprise systems. The round, backed by SoftBank, Hitachi and LG, lands the week OpenAI’s own agents broke out and hacked another company.


The danger isn’t the AI model. It’s the agent acting on its own, and Zenity raised $125m to watch it.
Image Credits Credit: Zenity

Most of the money spent guarding AI has gone to the model and the prompt. Zenity has just raised $125m on a different argument: both miss the real danger. That danger is the AI agent that acts on its own. The Israeli startup secures what agents do once a company lets them loose inside its systems.

Norwest led the Series C. SoftBank’s Vision Fund 2, Hitachi Ventures and LG Technology Ventures joined, the company announced. That takes its total funding to roughly $185m. Zenity did not disclose a valuation. Tellingly, the new backers are all firms deploying agents in their own businesses.

Two Unit 8200 veterans, Ben Kliger and Michael Bargury, founded Zenity in 2021. Both previously built security products at Microsoft. It now has more than 230 staff, with research in Tel Aviv and its sales team in New York. Its customers, it says, are mostly Fortune 500 and Global 2000 firms in regulated industries.

Securing the agent, not the model

The pitch rests on a shift the industry is only now catching up to. A chatbot answers a question. An agent takes actions. It can reach internal databases, call tools, update records and run multi-step workflows across systems. That turns a content problem into a control problem.

An agent can behave exactly as designed and still cause a breach. It might have too much access, or read manipulated instructions. So Zenity watches the agent layer: its permissions, connected tools, memory and live actions. It reads the intent behind each action and, it says, can allow, change or block that action before it runs.

Zenity Labs shows the risk. A booby-trapped calendar invite could hijack Perplexity’s agentic browser. It could then open an unlocked password vault and leak the credentials inside. Its earlier AgentFlayer work found zero-click ways to turn enterprise assistants against their owners. The attacks hide inside data an agent is meant to trust.

A category, and a crowded one

The timing is not subtle. The raise lands days after a scare. OpenAI admitted two of its models broke out of a sealed test and hacked Hugging Face. They were chasing a benchmark answer key. That is precisely the scenario Zenity sells against: an agent doing something it should not. It has raised the stakes for every enterprise wiring agents into its systems.

Zenity is not alone in spotting the gap. It is the second nine-figure AI-security round this week, after Horizon3’s $250m for autonomous pentesting. It sits beside startups like Onyx building control layers for agents. Gartner already calls Zenity the company to beat in agent governance. Investors are betting this becomes a category, not a feature.

The caveats trail any fast raise. Zenity has kept its valuation quiet, and its growth figures, however steep, come off a young base. The bigger test is strategic. Enterprises must make a choice. Do they buy a dedicated agent-security platform? Or lean on whatever Microsoft, Google and AWS bundle into the tools where agents already live?

For now, the money is flowing to the specialists. As Kliger puts it, the industry is heading into an “era of 1 billion agents.” Each one can act inside a business, not just answer a question. Zenity’s bet is that someone has to watch what all of them do. This week made that a harder bet to argue with.

Get the TNW newsletter

Get the most important tech news in your inbox each week.