Obsidian Security lands $85m to police rogue AI agents #AI


Obsidian

Obsidian Security, a platform securing non-human identities and AI agents across third-party applications, has closed an $85m Series D funding round.

The round was led by Crescent Cove Advisors, with participation from existing backers Greylock Partners and Menlo Ventures. It follows a period of accelerating customer growth for Obsidian, with more than 100 customers now spending over $100K a year on the platform and upwards of 14 customers spending more than $1m annually.

The raise comes as businesses roll out AI agents built on leading models, including Anthropic’s Claude, OpenAI’s ChatGPT and Microsoft Copilot Studio, and look for ways to govern how those agents behave once embedded in the third-party applications that underpin daily operations.

Obsidian points to non-human identities now outnumbering human identities by 144 to 1 within these applications, a gap it says is widening further as agents built on frontier models proliferate, often in settings where closing a single exposure can take months. With enterprises running agents across several AI ecosystems simultaneously, the company argues that agent misbehaviour is becoming more frequent and that security teams require a single control point spanning every ecosystem in use.

Obsidian will direct the new capital toward extending its reach across the Fortune 500 and Global 2000, positioning its platform as the standard for governing what AI agents can reach and do inside enterprise systems. The company says its traction with the world’s largest organisations has itself become a growth driver, as a larger customer base feeds network intelligence that turns risks identified at one company into faster safeguards for every other customer on the platform.

Obsidian’s technology centres on runtime governance that identifies and halts privilege escalation, excessive data access and policy breaches for agents operating on platforms such as Microsoft Copilot, n8n, Google Vertex, Amazon Bedrock and OpenAI, among others. This sits alongside a full inventory of every agent, MCP server and large language model active inside third-party systems, giving security teams visibility over what is connected before problems emerge.

The company also detailed a set of new capabilities building on that foundation. The first extends Obsidian’s agent access governance to Anthropic’s Claude Code and Cowork, adding to existing coverage of platforms including Copilot Studio, OpenAI, Salesforce Agentforce and n8n, and allowing security teams to discover, control and enforce what these agents can access within critical applications, from restricting dangerous permissions on production data to blocking unsanctioned MCP and tool use.

The second introduces real-time runtime protection for agents built on Microsoft Copilot and Anthropic Claude, designed to catch privilege escalation, excessive data access and policy violations at the point of execution rather than after the fact, drawing on risk factors aligned with OWASP standards.

The third delivers a complete inventory of MCP servers across the enterprise mapped to the agents invoking them, intended to expose unsanctioned usage and the potential downstream impact of agentic connections to backend systems. The fourth tracks every large language model powering agents in an environment, alerting security and compliance teams when models are switched or substituted so that only sanctioned models remain in operation.

Obsidian frames the investment against a backdrop of mounting concern among security teams, who it says most commonly flag agents taking destructive or irreversible actions, unsanctioned agents connecting to critical systems without approval, and agents accessing data they were never intended to reach. The company cites recent incidents including an AI agent that triggered a 13-hour cloud outage after being granted overly broad permissions, an agent that deleted decades of irreplaceable personal files, and an agent that bypassed an application’s native guardrails to delete a company’s production database and backups.

Obsidian Security CEO Hasan Imam said, “AI agents gravitate toward third-party applications. That’s where the data lives, that’s where the work happens, and that’s exactly where the risk lives too. Frontier and open-source models alike are pushing agents deeper into these environments faster than most security teams can track.

“More than 70% of our customers already let agents into third-party apps, and that number is only going up. We intend to be the platform that protects enterprises from agents going rogue in third-party applications, so enterprises get the full return on every agent they deploy. That’s the future we’re building toward.”

Read the daily FinTech news

Copyright © 2026 FinTech Global



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW