Hush Security Raises $30 Million to Put AI Agents Under Proper Control

A Tel Aviv startup wants every autonomous AI program inside a company to carry a verifiable identity and leave a full paper trail. Investors just backed that idea to the tune of $30 million.

ThreatVectr Newsdesk· 3 min read
Full-frame photoreal editorial image of a dark modern security operations centre at night, rows of monitors glowing with abstract identity graphs and network no
Share

Key points

  • Hush Security closed a $30 million Series A round on 9 July 2025, bringing its total funding to $41 million.
  • Akamai Technologies led the round alongside existing backers Battery Ventures and YL Ventures.
  • Founded in 2024, the company came out of stealth in September 2025 with a platform designed to track and control AI agents inside corporate networks.
  • The platform issues short-lived, task-specific permissions to AI agents rather than permanent passwords, and logs every action they take.
  • Hush plans to use the money to hire engineers and salespeople and deepen support for identity and access management ecosystems.

Software that acts on its own is no longer science fiction. Companies today run AI agents, meaning programs that can book meetings, query databases, write code, or move files without a human clicking anything. The problem is that most businesses have no clear picture of what those agents are doing or what sensitive systems they can reach.

Hush Security, a startup founded in 2024 and based in Tel Aviv, is trying to fix that. The company announced a $30 million Series A funding round, with backing from internet infrastructure giant Akamai Technologies and returning investors Battery Ventures and YL Ventures. Total funding now stands at $41 million.

What does Hush Security's platform actually do?

In plain terms: it gives every AI agent an identity card, watches what the agent does, and can cut its access instantly if something goes wrong.

Instead of handing an AI agent a permanent password, or API key, that lets it roam freely, Hush issues what it calls just-in-time permissions. Think of these as single-use visitor passes: the agent gets access to exactly one resource, for exactly as long as the task takes, and nothing more. When the task is done, the pass expires.

Every action the agent takes is written to an audit trail, a running log that compliance teams or investigators can review later. A central kill switch lets administrators shut down any agent across the whole organisation at once.

The company also maps which tools and external services each agent can reach, including MCPs, which stands for Model Context Protocol connectors, meaning the plug-in style links that let AI agents talk to outside software and data sources.

Why does this matter to ordinary employees?

If your company uses AI tools that can read emails, access customer records, or approve transactions, those tools carry real risk if they are not tracked. A misbehaving or hijacked agent could quietly leak sensitive data or make changes nobody authorised.

Hush argues that businesses know how to manage access for human staff but have not applied the same discipline to software that acts on its own. CEO Micha Rave put it directly: "AI agents need strict identity, not just API keys."

The funding will go toward hiring, building out integrations with identity and access management (IAM) systems, which are the software platforms companies use to control who, or what, can log in to which systems, and expanding partnerships.

Common questions

Does this affect regular employees or just IT teams?

Mostly IT and security teams will configure the platform, but employees who rely on AI tools at work benefit indirectly because properly governed agents are less likely to expose the personal or business data those tools handle.

Is AI agent security a new regulatory concern?

Regulators have not yet issued final rules specific to AI agents, though guidance from bodies such as the U.S. Securities and Exchange Commission on material cyber risk disclosure, under its 2023 final rule, already covers incidents involving automated systems that cause significant harm.

© 2026 Threat Vectr