Obsidian Security raises $85M as AI agents create cybersecurity’s next major attack surface
SiliconANGLE John Furrier ● Covered by 3 sources
Obsidian Security just raised $85M at a $1.1B valuation to police AI agents running loose in company software. Turns out giving bots access to your data creates a whole new security headache nobody's fully solved.
Obsidian Security closed an $85 million Series D this week, pushing its valuation to $1.1 billion, and the timing tells you everything about where enterprise security money is flowing right now. Crescent Cove Advisors led the round, with Greylock Partners and Menlo Ventures returning as backers. CEO Hasan Imam told theCUBE the raise came down to two things: explosive growth among big customers—more than 14 now paying north of $1 million a year, over 100 paying six figures—and a scarier trend underneath it all. AI agents are now touching corporate data inside third-party apps, and most companies aren't ready for what that means.
According to Imam, over 65% of Obsidian's enterprise customers have already handed AI agents access to data within SaaS platforms. These aren't human employees logging in with passwords. They're bots authenticating via APIs, OAuth tokens and machine credentials, moving through cloud applications at speeds no security analyst can match. Traditional identity and access management tools were built for people, not for software that reasons, touches storage, and takes action across systems in milliseconds. Imam calls this the arrival of non-human identity as its own security category, and he's betting a lot of enterprise budget is about to follow that logic.
The real shift Imam describes is about timing, not just access. Governance can't stop at the moment an agent gets permission to enter a system—it has to follow the agent into what he calls runtime, watching and constraining what it actually does once inside. That's a different problem than classic detection-and-response security, where a human team investigates an alert hours or days later. Imam is blunt about why that model breaks down here: agents act in seconds, sometimes less, and by the time a human notices, the damage is done. Detection has to become prevention, instantly, or it's useless.
What's interesting is Imam doesn't expect companies to centralize AI agent identities the way they do employee logins. Agents will sprawl across departments, cloud providers and outside platforms, resisting any single control point. Instead, Obsidian is betting that governance will get bolted onto the infrastructure agents actually run through—things like Model Context Protocol servers and API gateways—giving companies runtime brakes on what an agent is allowed to do inside any given app. It's a messier, more distributed vision of security than the neat perimeter model IT teams grew up with, but it matches how agentic AI is actually spreading through real companies right now.
My take
Every hot enterprise trend spawns its own security vendor gold rush, and agentic AI is no exception—Obsidian just got there early with real customer traction to back the valuation. The bigger story is what it says about how fast AI agents outran the tools meant to govern them: companies handed bots the keys before anyone built proper locks, and now they're paying a premium to retrofit control. Expect a wave of copycat funding rounds chasing the same gap, most of which will quietly fold once the market consolidates around two or three winners.
Read more about this at: SiliconANGLE
Related stories
Oak launches identity-control plane for managing humans, apps, and AI agents
TechCrunch · 2 weeks ago ·
43
Cyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agents
TechCrunch · 1 week ago ·
49
Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era
TechCrunch · 2 weeks ago ·
18