AI agents are moving from answering questions to taking actions inside companies, and investors are betting that securing those agents could become a major new cybersecurity market.

Zenity, an AI security startup focused on autonomous agents, has raised $125 million in Series C funding led by Norwest, as businesses put AI agents deeper into workflows that touch corporate data, software, cloud infrastructure and internal systems.

New investors Qumra Capital, SoftBank Vision Fund 2, Hitachi Ventures and LG Technology Ventures joined the round. Existing backers Vertex Ventures, Third Point Ventures, DTCP and Intel Capital participated too.

The new financing comes as companies race to deploy AI agents that can do far more than generate text. These systems can invoke tools, access databases, execute code, interact with SaaS applications and make decisions with varying degrees of human oversight.

That shift creates a security problem that traditional cybersecurity tools weren’t built to solve.

Zenity is betting that enterprises will need a dedicated security layer sitting between AI agents and the systems those agents can touch. The company says its technology can identify what an agent is attempting to do and allow, modify, or block an action before it happens.

The stakes get higher as agents gain more autonomy.

A chatbot producing a bad answer is one problem. An AI agent with access to corporate email, cloud storage, source code, credentials and business applications creates a very different risk.

Zenity co-founder and CEO Ben Kliger sees that transition accelerating toward what he calls an era of 1 billion agents.

“Enterprise AI is skyrocketing,” Kliger said. “AI experimentation is long over, and any organization on the planet is promoting AI agents at velocity and adoption rates never seen before in any tech wave. AI agents change everything in the way that we all work and operate as enterprises are promoting agentic AI in SaaS, on local devices with coding agents and agentic browsers, and in their public cloud infrastructure. They are rebuilding their infrastructure with agentic infrastructure and employees that access enterprise data, tools, and own business processes and decisions.”

Kliger said the financing will help Zenity take its AI agent security platform to more organizations worldwide.

“As we enter the era of 1 billion agents, our newly announced funding is helping make that vision a reality. This investment allows us to bring AI agent security to many more organizations around the world.”

AI agents create a new security problem

For much of the generative AI boom, enterprise security discussions centered on models, prompts and the information employees might paste into AI applications.

Agents change the equation.

An AI agent can potentially read an email, retrieve a document, query a database, call an API, modify a file or trigger another application. Coding agents can interact with development environments and software repositories. Browser agents can operate across websites and connected services.

That means a compromised agent may become an entry point into the applications and data surrounding it.

Zenity has spent years building around that problem. The company says its platform looks at an agent’s intent rather than relying solely on prompt inspection or analyzing an incident after it has occurred.

The goal is to determine whether an action represents legitimate work or behavior that has been manipulated, compromised or pushed outside the agent’s intended purpose.

Zenity says it can then allow, modify or block the action before execution.

The platform works across agents built using major enterprise AI platforms and frameworks, including Microsoft Copilot, ChatGPT Enterprise and Gemini. It covers coding agents such as Claude, Codex and Cursor, along with custom agentic systems running on AWS Bedrock and AgentCore, Microsoft Foundry and Google Vertex AI.

That breadth matters for large companies. Enterprises are unlikely to standardize every AI workload around a single model provider or agent framework, leaving security teams responsible for agents scattered across cloud platforms, SaaS applications, employee devices and internal systems.

With $125M in Funding, Zenity Aims to Secure Enterprise AI Agents as Agentic AI Adoption Accelerates

The emerging distinction between securing AI prompts and securing AI actions could become one of the defining cybersecurity issues of the agentic AI era.

An attacker no longer needs to compromise an AI model itself if the attacker can manipulate the information an agent consumes or influence what the agent does next.

Zenity’s own security research has demonstrated how that can play out.

Researchers at Zenity Labs disclosed AgentFlayer, a class of zero-click attacks that the company said could hijack enterprise AI agents, manipulate workflows, steal sensitive information, and abuse connected systems without requiring direct interaction from a user.

The research team has examined similar risks across several widely used AI products.

In one case, Zenity researchers showed how a malicious calendar invitation could hijack Perplexity’s Comet browser and gain access to an unlocked 1Password vault.

The team found a critical vulnerability affecting Microsoft Copilot Studio. Separate research demonstrated how a poisoned document uploaded to ChatGPT could exploit connected services such as Google Drive and SharePoint to extract enterprise information.

Those findings point to a broader problem emerging around agentic systems: an AI agent can inherit the permissions and access available to the user or environment where it operates.

Security teams may soon need to treat agents more like privileged software identities than chatbots.

Fortune 500 companies are already deploying Zenity

Zenity says most of its customers are Fortune 500, Global 2000, and other large organizations operating across financial services, healthcare, pharmaceuticals, technology, energy, and manufacturing.

SoftBank Corp. is among its customers, and Zenity says some of its longest-standing customers are Fortune 50 companies.

“As our use of AI agents continues to grow, maintaining security, governance and operational control is essential,” said Tadashi Iida, Senior Vice President & CISO & CRO, SoftBank Corp. “Zenity enables us to confidently deploy AI agents across the enterprise, giving us the visibility and governance required to support innovation at scale.”

Zenity says revenue has tripled in each of the past two years and is on pace to triple again this year.

The company now employs more than 230 people globally. Research and development is centered in Tel Aviv, with go-to-market operations led from New York.

Zenity plans to use the Series C financing to develop its platform, grow Zenity Labs and increase its presence in Europe and Asia Pacific.

Investors bet on AI agent security

Norwest partner Assaf Harel said the investment firm had followed Zenity for years before leading the Series C.

“We have followed Zenity’s journey for years and have been impressed by the team’s vision and execution. As enterprises rapidly adopt AI agents across critical workflows, organizations need a new approach to security built for this new and continuously evolving reality,” Harel said.

“Zenity has an early mover advantage in building an end-to-end AI agent security and the largest and rapidly growing footprint of successful implementation across Fortune 1000 customers. The company is in pole position to emerge as a category leader, and we’re excited to partner with Ben, Michael and the entire team as they continue to shape the future of AI agent security.”

The funding follows growing recognition of AI agent governance as a separate enterprise technology category.

In an April 2026 report titled “AI Vendor Race: Zenity Is the Company to Beat in AI Agent Governance,” Gartner wrote that “Zenity’s purpose-built agentic-centric architecture, intent-aware detection and continued end-user interest put it at the forefront of the AI agent governance race.”

Gartner added that “enterprise adoption of autonomous AI systems is rapidly amplifying risks and invigorating activity in the AI agent governance market.”

Zenity has contributed research to OWASP Top 10 projects and open-source frameworks such as MITRE ATLAS, efforts aimed at documenting and categorizing security threats involving AI systems.

The race to secure AI’s next phase

The cybersecurity industry has spent decades building defenses around people, devices, applications, networks and cloud infrastructure. AI agents are introducing another identity into that equation: software capable of acting on behalf of users and organizations.

The question is no longer limited to what an AI system can say.

It is increasingly about what an AI system is allowed to do.

That distinction could become far more significant as companies connect agents to email, databases, code repositories, browsers, payment systems and internal business applications.

For Zenity, the bet is straightforward. If enterprises end up operating thousands or millions of agents, those agents will need permissions, policies, monitoring and controls much like human employees and software applications do today.

The $125 million Series C gives the company more capital to pursue that thesis at a time when the underlying technology is moving from demos into real corporate workflows.

And if Kliger’s prediction of an era of 1 billion AI agents comes anywhere close to reality, securing those agents could become one of cybersecurity’s biggest new markets.

Zenity team