Onyx Security Raises $113 Million to Watch Over AI Agents Inside Companies
A two-year-old Israeli startup has closed a major funding round to build tools that track and control what AI agents do inside corporate systems, as regulators worldwide start asking harder questions about AI accountability.

Key points
- Onyx Security raised $113 million in a Series B round announced Wednesday, bringing its total funding to $153 million since it was founded two years ago.
- Bessemer Venture Partners led the round, with seven other firms participating, including Cyberstarts and TCV.
- The company's estimated valuation reached $640 million, though Onyx did not officially confirm that figure.
- The funding will go toward training Onyx's own AI models and expanding its sales operation.
- Onyx targets a specific risk: AI agents, meaning software programs that act on a company's behalf and make decisions automatically, operating without adequate oversight.
What does Onyx Security actually do?
Onyx sells a platform that watches AI agents at work inside a company and steps in if something goes wrong. Think of an AI agent as a piece of software that can book meetings, process invoices, or pull customer records on its own, without a human clicking each step. That autonomy is useful. It is also a security problem if no one is watching.
The company's software tracks each decision an AI agent makes, in real time, across cloud services, software-as-a-service (SaaS) tools like Salesforce or Slack, and individual computers. If the agent does something outside its intended boundaries, Onyx can intervene before damage spreads.
One specific threat the platform guards against is prompt injection, where a criminal hides malicious instructions inside text or data that an AI agent reads, tricking it into taking harmful actions the operator never intended.
Why does the regulatory angle matter here?
Onyx's compliance pitch is timely. Across multiple jurisdictions, regulators are moving to hold companies accountable for how AI systems behave.
The European Union's AI Act, which began phasing in during 2024, requires organisations using high-risk AI systems to maintain logs, human oversight, and transparency about automated decisions. In the United States, the Securities and Exchange Commission (SEC), under its cybersecurity disclosure rules that took effect in December 2023, expects public companies to disclose material risks, and an AI agent that breaks into the wrong data or leaks sensitive records could easily clear that materiality bar.
Shadow AI, meaning AI tools that employees install and use without telling the IT or security team, complicates every one of those obligations. Onyx says its platform can find those hidden deployments and bring them under policy control.
| Funding round | Amount | Lead investor | Date |
|---|---|---|---|
| Seed / Series A | $40 million | Not disclosed | Prior to 2025 |
| Series B | $113 million | Bessemer Venture Partners | June 2025 |
| Total raised | $153 million | ||
| Estimated valuation | $640 million | June 2025 |
Should ordinary employees care about any of this?
Directly, yes. AI agents increasingly have access to the same systems employees use: HR records, customer data, financial tools. A misconfigured or manipulated agent could expose personal data without any human ever noticing a breach occurred.
If your employer uses AI tools to handle internal processes, it is reasonable to ask whether those tools are monitored and what data they can access. That is not paranoia; it is the same question a good compliance officer should already be raising.
Cyberstarts general partner Hila Zigman said in the announcement that AI agents embedded in business workflows need to "operate safely, predictably, and within policy," describing Onyx's approach as "the control layer that makes enterprise AI adoption possible at scale."
SecurityWeek first reported the funding details.
Common questions
Is an AI agent the same as a chatbot?
No. A chatbot answers questions when you ask them. An AI agent acts on its own, carrying out multi-step tasks like searching files, sending emails, or updating records, without waiting for a human to direct each move.
Do regulations already require companies to control AI agents?
Partially. The EU AI Act and existing SEC disclosure rules create obligations that touch this space, but specific rules for agentic AI are still developing. Regulators in both the US and EU have flagged the oversight gap publicly.



