Key Takeaways

  • Norwest Venture Partners led the Series C round, bringing total funding to approximately $185 million.
  • The platform monitors how autonomous AI agents interact with enterprise systems and can block or modify actions before execution.
  • The investment reflects growing corporate demand for controls that extend beyond model security and prompt inspection.

Zenity has raised $125 million in a Series C round as enterprises confront a new security problem: AI systems that do more than generate text. Increasingly, autonomous agents can access data, invoke tools, update records, and execute multistep business processes.

Norwest Venture Partners led the round. New investors Qumra Capital, SoftBank Vision Fund 2, Hitachi Ventures, and LG Technology Ventures participated alongside existing backers DTCP, Vertex Ventures, Third Point Ventures, and Intel Capital. The transaction brings Zenity's total funding to approximately $185 million.

Almost all the new financing is primary capital intended for the company's global expansion. A secondary component of around $10 million gives some founders and employees an opportunity to sell shares.

Founded in 2021 by two Unit 8200 veterans, the startup combines security research with controls designed for active AI agents. The founders now serve as the CEO and the CTO. Before launching the company, they worked together at Microsoft, leading the development of cloud and operational technology security products.

Protecting an autonomous agent requires fundamentally different controls than filtering a chatbot's response. When an employee-facing assistant can retrieve a customer file, initiate a payment, or alter a production workflow, a malicious prompt is only one part of the risk. Excessive permissions, compromised integrations, unintended behavior, and poorly defined business boundaries can also produce damaging outcomes.

The platform maps where agents operate, which enterprise systems they can reach, and what business functions they are intended to perform. It then monitors their activity in real time against corporate policies and permissions. Before an action is executed, the system evaluates its apparent intent and can allow, modify, or block it.

By bridging application security and AI governance, the platform secures Microsoft Copilot, ChatGPT Enterprise, Gemini, Claude, Codex, Cursor, and internally developed agents, giving customers a way to supervise activity across a mixed environment rather than treating each AI service as a separate island.

Regulatory and advisory frameworks are increasingly addressing these specific attack surfaces. The NIST AI Risk Management Framework calls attention to emergent behavior and unintended actions in AI systems. ENISA has highlighted AI supply-chain and model-misuse risks, including scenarios involving systems that can modify data or trigger transactions without direct human oversight. Meanwhile, ISO information security guidance provides a management foundation that enterprises can adapt as AI agents gain access to sensitive systems.

Those references do not amount to a complete technical blueprint for agent security. Still, they point toward a shared requirement: organizations need visibility, access controls, documented accountability, and a way to intervene when automated behavior moves outside approved boundaries.

Competition is forming quickly. The firm operates in an emerging category that also includes protect-ai, Lakera, and HiddenLayer, although those vendors have differing areas of emphasis across machine-learning pipelines, models, and AI applications. The startup maintains that its advantage lies in monitoring agents while they are running, rather than concentrating only on models, prompts, or post-incident investigation.

The Series C gives the organization substantial capital to expand while the category is still taking shape. The tougher task comes next: proving that runtime controls can scale across thousands of agents without slowing legitimate work or burying security teams in alerts. For enterprise buyers, that balance may determine whether autonomous agents remain limited experiments or become trusted participants in everyday operations.