Why the Shift to Agentic Security Led to Obsidian’s $85 Million Series D
Enterprise adoption of artificial intelligence is rapidly shifting from passive chatbots to autonomous agents, and the security industry is raising massive capital to police them. Obsidian Security, the Palo Alto-based SaaS security leader, has raised an $85 million Series D funding round at a $1.1 billion valuation, crossing into unicorn status to solve the looming crisis of non-human identity governance. Led by Crescent Cove Advisors with participation from Greylock Partners and Menlo Ventures, the round pushes Obsidian's total funding over $200 million and highlights a critical industry inflection point: securing autonomous AI agents is now a multi-billion-dollar enterprise priority.
The Agentic Pivot: Moving Beyond Human IAM
The deal arrives during a highly active week for what is quickly being termed "agentic security." Just days prior, security startup Zenity secured a $125 million round, signaling a coordinated institutional bet on runtime governance for AI. For the last two decades, enterprise security was built around Identity and Access Management (IAM)—securing human credentials, enforcing multi-factor authentication, and managing human single sign-on (SSO). Today, that paradigm is structurally broken.
Obsidian points to a stark structural imbalance in modern enterprise software: non-human identities now outnumber human ones by an estimated 144 to 1. These non-human identities are no longer passive API keys or static service accounts; they are autonomous developer agents, sales copilots, and background workflows that read, write, and execute code without human oversight. When an LLM-driven agent operates on behalf of an employee, traditional perimeter-based security cannot tell the difference between a legitimate automated task and a malicious privilege escalation exploit.
Securing Autonomous AI Agents at Runtime
The core of Obsidian's approach is real-time runtime governance. Rather than simply auditing SaaS configurations after the fact, the platform blocks privilege escalation and data access violations before an autonomous agent's actions can execute. This is particularly crucial as enterprises build custom pipelines using frameworks like Microsoft Copilot Studio, Salesforce Agentforce, and workflow automation tool n8n.
Furthermore, Obsidian is extending native security governance to cutting-edge developer tools like Claude Code (developed by Anthropic) and Cowork. As software engineers increasingly delegate repository management, testing, and deployment to autonomous AI entities, the risk of supply chain attacks and accidental data exposure scales exponentially. If a developer agent is given access to a code repository, what prevents it from pulling sensitive production environment variables or writing vulnerable code?
"AI agents gravitate toward third-party applications. That’s where the data lives, that’s where the work happens, and that’s exactly where the risk lives too. More than 70% of our customers already let agents into third-party apps, and that number is only going up."
Hasan Imam, CEO of Obsidian Security
The Rise of Model Context Protocol (MCP) Governance
A key focus of Obsidian's expanded R&D is the security and inventory of Model Context Protocol (MCP) servers. Originally introduced to standardize how LLMs securely connect to external data sources and tools, MCP has quickly become the preferred pipe for agentic integration. However, because MCP servers bridge the gap between open-ended foundation models and highly sensitive internal databases, they present an incredibly attractive attack vector for prompt injection and unauthorized data exfiltration.
Without an active runtime inventory, security teams are completely blind to which MCP servers are active in their environments, what data they can access, and which LLMs are querying them. Obsidian’s runtime governance aims to provide a centralized dashboard for these integrations, allowing security operations centers (SOCs) to monitor agent behavior with the same granularity they apply to human employees.
Real Revenue Meets the Hype
While many AI safety and alignment investments remain speculative, agentic security is driven by immediate, existential enterprise demand. The financial metrics of Obsidian's Series D demonstrate that Fortune 500 CISOs are actively writing large checks to solve this problem:
- Enterprise Penetration: 60 of the Fortune 500 are already on Obsidian's customer roster.
- High-Value Contracts: Over 100 paying customers spend more than $100,000 annually.
- Seven-Figure Scale: More than 14 customers spend above $1 million annually with the company.
These figures show that the market for AI governance is not a future-looking projection; it is a live, rapidly expanding line item in enterprise security budgets. For global financial institutions, healthcare providers, and telecommunications giants, the risk of data leakage via autonomous systems is the single largest blocker to scaling their AI investments.
The Takeaway: Security is the Real Bottleneck to AI Adoption
The sudden influx of capital into Obsidian Security and Zenity reveals a fundamental truth about the current state of the industry: the primary bottleneck to the autonomous agent era is not model capability, context window limits, or latency. The bottleneck is trust. Until enterprise security teams have the tools to audit, restrict, and block autonomous systems in real-time, the most transformative agentic technologies will remain trapped in sandboxed pilot programs. Obsidian's $1.1 billion valuation is a bet that the company providing the safety harness will ultimately control the keys to the entire autonomous enterprise.
This article was ultrathought.
Get breaking news, funding rounds, and analysis delivered to your inbox. Free forever.