# The $113 Million Bet That Your AI Agents Are Already Out of Control


Enterprise security has always chased the threat. Firewalls came after the network. EDR came after the endpoint. Cloud security came after the workload. Now $113 million says the next unchecked frontier is the AI agent — and the window to get ahead of it is closing fast.


Onyx Security announced the raise this week, positioning itself squarely in a category that barely had a name eighteen months ago: AI agent governance. The pitch is straightforward and the problem is real. Enterprises are deploying AI agents — autonomous systems that can browse the web, write and execute code, query databases, send emails, and trigger workflows — without the security controls they'd apply to any human or service account doing the same things.


That gap is not theoretical anymore.


## What "Controlling AI Agents" Actually Means


The term sounds abstract until you map it to what agents actually do in production environments. A customer service agent might have read access to CRM records, ticketing systems, and billing history. A coding agent might be able to push to repositories or invoke cloud APIs. An HR workflow agent could query personnel files, draft termination letters, and schedule calendar events.


None of those actions are inherently dangerous. But string them together under a model that's been manipulated through prompt injection, misconfigured with excessive permissions, or simply given an ambiguous instruction — and you have a system that can exfiltrate data, corrupt records, or pivot deeper into your infrastructure with no human in the loop and no audit trail traditional security tools can read.


The Onyx bet is that enterprises need a dedicated control plane for this: something that enforces least-privilege for agent identities, monitors behavioral drift, detects injection attacks at runtime, and provides the kind of visibility that a SIEM or EDR vendor never anticipated needing to handle.


## Why Now, and Why $113 Million


The capital markets don't fund categories this aggressively unless adoption is already happening. And it is. According to Gartner projections that have since proven conservative, the majority of enterprise software vendors now ship at least one AI agent feature. Salesforce Agentforce, Microsoft Copilot, ServiceNow's AI workflows — these aren't pilot programs anymore. They're default-on configurations in tools that live at the center of corporate operations.


Security teams are behind. Most organizations have no inventory of what agents are deployed, what permissions they hold, or what external systems they connect to. Shadow AI — the consumer AI use that security teams couldn't see — was the warning shot. Agentic AI is the live round.


The $113 million figure is also telling in context. This is not seed-stage optimism. This is growth capital for a company that has presumably demonstrated product-market fit with paying enterprise customers. Sequoia, Lightspeed, and the other institutional names that write checks this size in 2026 want to see retention metrics and expansion revenue before they commit. Onyx has apparently shown them something.


## The Attack Surface Nobody's Mapped Yet


Three vectors deserve more attention than they're getting in coverage of this raise.


Prompt injection at scale. Indirect prompt injection — where a malicious payload embedded in content the agent reads causes it to deviate from its instructions — is trivially executable against most production agents today. An agent scraping supplier invoices for an accounts payable workflow reads a PDF containing hidden instructions. The agent complies. No alarm fires. The category of tools Onyx is building toward is one of the few realistic defenses.


Credential sprawl through agent identities. When a human employee is offboarded, their accounts get deprovisioned. When an AI agent is retired or replaced, its OAuth tokens, API keys, and service account permissions frequently stay active. Organizations are already accumulating ghost credentials from deprecated agents — valid, scoped, unmonitored access that an attacker with any one of those tokens can use indefinitely.


Supply chain risk in agent frameworks. Most enterprise agents aren't built from scratch. They're assembled from LangChain components, AutoGen patterns, or vendor-provided agent toolkits. Those frameworks pull dependencies. Those dependencies have vulnerabilities. The SolarWinds model — compromise the build toolchain, reach every downstream customer — applies to AI agent infrastructure and almost nobody is treating it that way yet.


## HackWire Analysis


The $113 million raise is a landmark, but the more interesting signal is what it says about where we are in the adoption curve. Security investment follows exploitation, and this level of institutional conviction means someone has seen enough real incidents to believe the market is about to materialize fast.


Contrast this with the cloud security buildout of 2018–2021. The pattern is nearly identical: enterprises adopted cloud faster than security teams could instrument it, a cluster of startups emerged to fill the gap, and the category consolidated through acquisitions. Palo Alto, CrowdStrike, and Wiz all benefited from that dynamic. AI agent security is on a compressed version of the same trajectory — the adoption gap is narrower because the enterprises involved learned from cloud, but the tooling deficit is, if anything, deeper because the behavior of agents is far less deterministic than a virtual machine or a Lambda function.


What the current coverage of this raise is mostly missing is the identity angle. The loudest conversations around AI security focus on data — training data poisoning, model inversion, output filtering. Those matter. But the immediate operational risk in enterprise environments is about *what agents are allowed to do*, not just what they know. A misconfigured agent with admin-scoped credentials is a security incident waiting for a trigger. Onyx is selling into that gap, and the enterprises that haven't audited their agent permission sets by Q1 2027 will be explaining themselves to their boards after the fact.


For defenders right now: treat every AI agent like a privileged service account. Audit existing permissions. Require explicit scope declaration for any new agent deployment. Start logging agent actions the same way you'd log privileged user activity. You don't need Onyx's product to do any of that today — you need the discipline to apply existing frameworks to a new class of system.


— HackWire Editorial


---


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)