Obsidian's Bet on the Agent Leash
How a $1.1 billion valuation for AI agent security reveals the control problem enterprises created the moment they let software act on its own.
The rush to deploy AI agents inside real business systems has quietly created a new category of risk — and a new market to police it.
The pitch used to be simple: give an AI assistant your calendar, your CRM, your code repository, and watch it save you time. Then the assistants stopped waiting to be asked. Microsoft's Copilot Studio, Salesforce's Agentforce, and Anthropic's Claude Code began doing things — pulling records, writing to databases, moving files, triggering workflows — inside the same enterprise systems that hold a company's most sensitive data. Somewhere in that shift, "AI adoption" became "AI with the keys," and a lot of security teams realized they had no idea which doors were open.
Obsidian Security just raised $85 million to sell them the locks. The Series D values the company at $1.1 billion, according to SecurityWeek, and pushes its total capital raised past $200 million. The round was led by Crescent Cove Advisors, with Greylock Partners and Menlo Ventures taking part. The money is earmarked for one thing: expanding into what the company calls agentic AI security — the discipline of watching what autonomous agents are allowed to touch, and stopping them when they reach too far.
What Obsidian actually does
Strip away the category jargon and Obsidian is building a supervisor for software that supervises itself. Its platform monitors AI agents operating across third-party applications — BankInfoSecurity reports it governs what tools like Microsoft Copilot Studio, Salesforce Agentforce, the automation platform n8n, and Anthropic's Claude Code and Cowork are permitted to access and execute inside enterprise systems such as data warehouses, developer tools, CRMs, and collaboration apps.
The problem it targets is structural. A traditional software integration is predictable: it does the one thing it was wired to do. An AI agent is not. It reasons its way toward a goal, and along the way it may decide to read a customer database, call an external API, or edit a document — actions no one explicitly scripted. Multiply that by dozens of agents running across a company's SaaS stack, each with its own permissions, and the attack surface stops being a wall and becomes a weather system.
That is why the company frames its work as runtime governance rather than a one-time permissions review. Knowing what an agent could do at setup is not the same as knowing what it is doing at 3 a.m. on a Tuesday. Obsidian's argument is that the second question is the one that keeps CISOs awake, and that no one was answering it.
Why the money is chasing the leash, not the agent
For two years, capital poured into the agents themselves — the models, the orchestration layers, the platforms that let a business spin up a digital worker in an afternoon. Obsidian's raise is a marker that the smart money now also wants to fund the brakes.
The demand signal is concrete. Obsidian says it has more than 100 customers each spending over $100,000 a year, and more than 14 spending over $1 million. Those are not pilot-project numbers; they are the spending patterns of enterprises that have already deployed agents at scale and discovered they need adult supervision. The company has also pointed to a striking adoption statistic behind the urgency — that roughly 70% of its clients now allow AI agents to interact with business data directly. Once agents are inside the perimeter and touching real records, governance stops being optional.
This is the "picks and shovels" logic of every technology boom, with a twist. In the last cycle, the shovels were compute and data infrastructure. In this one, a parallel market is forming around containment — the tools that make autonomy safe enough for a regulated bank or hospital to sign off on. You can think of it as the difference between selling someone a very fast car and selling them the seatbelt, the airbag, and the insurance policy. The second market only exists because the first one got real.
The stakeholders
For enterprises, the calculus is uncomfortable. They adopted agents to move faster, and now they are being asked to spend again to slow those agents down safely. But the alternative — an agent with broad permissions quietly exfiltrating data or executing a destructive action because a prompt was poisoned — is the kind of incident that ends careers and invites regulators. Governance is becoming the price of admission for agentic AI in any serious industry.
For the agent platforms — Microsoft, Salesforce, Anthropic — Obsidian is both a friend and a subtle indictment. A thriving third-party security layer makes their agents more deployable, which helps sales. But it also concedes that the platforms' own native controls are not enough for customers who take security seriously. Every dollar Obsidian earns is a dollar those platforms did not capture, and a signal that "trust us" was not a sufficient answer.
For investors, the appeal is that security spending is durable in a way that experimental AI budgets are not. When agents fail, someone has to be accountable, and accountability requires visibility and control. That makes agent governance one of the rare AI categories with a clear, non-speculative buyer: the security team that has to sign the audit.
The lesson for builders
The through-line here is older than AI. Every time software gains a new power, a shadow industry rises to constrain it. The internet gave us firewalls. Cloud gave us posture management. Mobile gave us device management. Autonomous agents are now getting their own control plane, and the companies building it are being valued as if this is the beginning of a large, permanent category rather than a temporary patch.
If you are building agents, the takeaway is that autonomy is a liability until it is governed. The features that make an agent useful — its ability to act broadly, reason independently, and reach across systems — are precisely the features that make it dangerous, and enterprises now know it. The more capable your agent, the more your customer will pay to watch it.
Obsidian's valuation is a wager that the agent era will be defined not only by what these systems can do, but by how confidently a company can prove what they didn't do. In a world of software that acts on its own, the leash may turn out to be worth as much as the dog.
Frequently Asked Questions
What is AI agent security?
AI agent security is the practice of monitoring and controlling what autonomous AI agents are permitted to access and execute inside enterprise systems. Unlike traditional software integrations, agents can reason and take unscripted actions, so security tools focus on runtime governance — watching agent behavior as it happens and limiting its reach across applications like CRMs, data warehouses, and developer tools.
How much did Obsidian Security raise and at what valuation?
Obsidian Security raised $85 million in a Series D round at a $1.1 billion valuation, led by Crescent Cove Advisors with participation from Greylock Partners and Menlo Ventures, according to SecurityWeek. The round brings its total funding to more than $200 million.
Which AI agents does Obsidian monitor?
According to BankInfoSecurity, Obsidian's platform governs agents including Microsoft Copilot Studio, Salesforce Agentforce, the automation tool n8n, and Anthropic's Claude Code and Cowork, tracking what they can access and do across third-party enterprise applications.
Why are investors funding AI agent security now?
As enterprises deploy AI agents that act autonomously inside sensitive systems, the risk of an agent taking a harmful or unauthorized action rises sharply. Security spending tied to compliance and accountability tends to be more durable than experimental AI budgets, which makes agent governance an attractive, non-speculative market.
Editor's note — sources: SecurityWeek (funding, valuation, investors); BankInfoSecurity (platform scope, governed agents); Obsidian Security (company announcement, customer metrics). All figures attributed to these sources; no quotes exceed 15 words.
Subscribe to join the discussion.
Please create a free account to become a member and join the discussion.