Skip to content
Software Supply Chain Security

AI-agent governance: Obsidian Security haalt $85 miljoen

AI-agent governance

Obsidian Security raised $85 million in a Series D round, valuing the company at $1.1 billion. According to the company, this investment brings the total raised to more than $200 million. The funding will be used to accelerate the platform’s expansion toward agentic AI security.

The core of its approach is AI-agent governance: defining, controlling, and enforcing what AI agents are allowed to open, access, and execute within an organization’s systems. The focus isn’t only on detecting problems after the fact, but—most importantly—on clearly mapping risks in advance and blocking actions the moment policy is violated.

Why AI agents need extra security

AI agents are increasingly operating outside an isolated environment. They get access to third-party systems where business data and workflows converge, such as databases/warehouses, developer tools, CRMs, and collaboration apps.

That’s where the security risk lies: where data exists, the potential impact of misuse also exists. Obsidian describes it as a shift in risk areas—agents gravitate toward third-party applications, where the biggest dangers emerge when access is overly broad or privileges can be escalated.

What the platform means by AI-agent governance

Obsidian offers a platform to govern AI agents and SaaS applications. It focuses on monitoring what agents—using tools available on the market (the company cites Microsoft Copilot Studio, Salesforce Agentforce, n8n, and Claude Code/Cowork, among others)—may access and run in enterprise environments.

At the center is a runtime governance layer. This layer is designed to recognize risks while agent actions are executing, such as:

  • Privilege escalation (escalating permissions)
  • Overly broad data access (retrieving too much or overly sensitive data)
  • Policy violations (actions that don’t match what the organization allows)

These checks are tied to enforcement rules based on OWASP-aligned risk criteria, so high-risk actions can’t simply proceed.

Enforcing policy during execution: runtime is the priority

A key difference between traditional approaches and what Obsidian describes is the timing of intervention. The platform is built to evaluate actions before they have an effect, rather than reporting only after the fact.

The company also says only a limited portion of security teams has the capacity to inspect and enforce agent traffic in real time. With AI-agent governance, Obsidian aims to close that gap by governing the interactions within third-party apps themselves.

Inventory of MCP servers and the risk of unsanctioned connections

In addition to policy rules, the platform also works with an overview of the connections active within an organization. Obsidian calls it an inventory of MCP servers that are connected, with the inventory linked to the specific agents that call those servers.

That enables teams to:

  • see which MCP connections are allowed and which are not
  • detect unauthorized or unsanctioned MCP connections
  • estimate the potential impact of agent-to-backend relationships

For organizations working with multiple agents and toolchains, this helps make the “landscape” of agent integrations easier to understand faster—and investigate deviations more targetedly.

New expansion: native controls for Claude Code and Cowork

With its latest step, Obsidian adds native governance controls for Claude Code and Cowork. This allows security teams to tighten agent permissions around production contexts.

Concretely, the expansion focuses on being able to:

  • limit agent permissions around production data
  • control access to sensitive files
  • adjust overly broad permissions
  • block unauthorized MCP or tool usage

With these controls, the platform aligns with a practical reality: security teams often need to quickly identify where permissions are too broad, and then scale back that access without shutting down all agent usage.

Relationship with existing security practices: from misuse to control

While AI agents are different from traditional software security, the underlying questions are strikingly familiar: who can do what, under which conditions, and what happens when an action isn’t allowed? In that sense, AI-agent governance fits into the same line as broader efforts around runtime protection and limiting unwanted access.

If you’re looking for similar logic around control and incident impact, you can also check earlier analyses on this site, such as what you do now after hacks and patches, or reporting about chained attacks where multiple systems are affected, such as TP-Link Omada ZTP: chained attack across entire networks. Both pieces emphasize that limiting damage often comes down to restricting access and directing what systems are allowed to do for each other.

What does this funding mean for organizations?

This funding round shows that AI-agent governance is gaining importance quickly. For organizations, it means the question shifts from “can we let AI agents do their work?” to “how do we make their actions manageable within our enterprise environment?”

Obsidian’s roadmap appears to focus on making policy concrete where it matters most: during runtime, in the connections between agents and backend systems.

Practical points for security teams

Even without knowing the exact platform, there are a few takeaways that fit the approach Obsidian describes. Start by looking at which systems agents are allowed to access (data stores, tools, collaboration apps), then determine which actions you want to allow—and which you want to block.

It also helps to set up your inventory of agent integrations: what connections exist, which agents use them, and where do you draw the line between “authorized” and “undesired”? Once that’s clear, you can make governance more practical and enforce it faster.

Conclusion

With $85 million in a Series D round, Obsidian Security positions itself further at the intersection of agentic AI and cybersecurity. The platform centers on AI-agent governance: runtime control over actions, limiting privileges and data access, and recognizing unauthorized connections via MCP servers.

The expansion with native governance controls for Claude Code and Cowork makes that promise more concrete for teams deploying AI agents in environments with production data. For organizations that want to realize value from agents without increasing risk, this is exactly the kind of control that’s increasingly becoming necessary.

Source: https://www.securityweek.com/obsidian-security-raises-85-million-at-1-1-billion-valuation/