SignalFeed

Cloudflare Built a Browser for AI Agents. Kitesurf Uses 1/7th the Memory of Chromium and Doesn't Fork a Line of It.

Obsidian's Series D closed at a $1.1B valuation after nearly 70% of its enterprise clients admitted to already letting AI agents interact with business data — often without adequate controls. The funding validates a new security category, and the risk it addresses is already in your SaaS stack.


On August 5, 2026, Obsidian Security closed an $85 million Series D led by Crescent Cove Advisors, with participation from Greylock Partners and Menlo Ventures, at a $1.1 billion valuation. The press release announced the unicorn milestone. The more important number was buried lower: nearly 70% of Obsidian's enterprise clients were already allowing AI agents to interact with their business data at the time of the raise.

That 70% figure is the market reality that validates both the raise and the category Obsidian has spent three years building. Enterprise AI agent adoption has moved faster than the security infrastructure around it. The same organizations that required 18–24-month approval cycles for new AI tools in 2024 are now running AI agents inside their core SaaS applications — Salesforce, Workday, ServiceNow, Microsoft 365, Slack — with security visibility into what those agents are doing that is substantially less comprehensive than their controls on human employee access.

The gap between agent deployment speed and agent security depth is the market that Obsidian's $85M will address. And it is a market that already exists inside most enterprise SaaS stacks, whether security teams know it or not.

Why AI Agents Break Traditional Enterprise Security

Traditional enterprise security architecture was designed around a human-centric model: a person authenticates with a username and password, is granted access to resources based on their role, and security tools monitor that person's behavior patterns for anomalies. The model works because humans are slow, contextual, and auditable — they access data at human speed, their behavior reflects their job function, and their actions can be reviewed in relation to their identity and role.

AI agents break every one of those assumptions.

Speed. A human analyst who manually reviews customer contracts is limited by reading speed — perhaps 50–100 documents per hour. An AI agent with the same task can read, process, and act on thousands of documents per hour. When an agent's behavior becomes anomalous — accessing records it shouldn't, transmitting data outside the enterprise boundary, or executing actions beyond its defined scope — the damage compounds at machine speed before traditional anomaly detection can fire.

Permissiveness. AI agents require broad access to do their jobs. An agent configured to manage customer relationships needs read/write access to CRM records, email correspondence, calendar data, and potentially financial records. The least-privilege principle — grant only the minimum access required for a task — is difficult to apply to AI agents without breaking their functionality, because their value comes precisely from their ability to access and synthesize information across systems.

Behavioral unpredictability. Unlike a service account that executes a fixed set of operations on a known schedule, an AI agent's behavior depends on the prompts it receives, the tools it has access to, and the outputs of prior steps in its reasoning chain. An agent configured to "help customers resolve billing disputes" might — given the right sequence of inputs — read financial records it wasn't intended to access, send data outside the enterprise via email or webhook, or execute transactions that require human authorization. The range of possible agent behaviors is not fully enumerable at deployment time.

Non-human identity proliferation. Enterprise SaaS applications now support AI agent integrations through native frameworks — Salesforce Agentforce, Microsoft Copilot Studio, Slack AI, ServiceNow AI Agents — each of which creates new service accounts, API keys, or OAuth tokens when deployed. An enterprise with 50 deployed AI agent integrations has 50 non-human identities with production-level access to its SaaS data. Most of those identities are not enrolled in the same access review, audit logging, and anomaly detection processes that govern human accounts.

Security ControlHuman UsersAI AgentsGap
Access authenticationMFA, SSO, conditional accessAPI key or OAuth tokenNo MFA, often no rotation
Least-privilege enforcementRole-based access controlBroad OAuth scope at deploymentScope rarely reviewed
Anomaly detectionUEBA (user behavior analytics)Not covered by UEBABlind spot
Access reviewQuarterly human access reviewOften never reviewedGrowing exposure
Audit loggingComprehensive in most enterprisesPartial — depends on SaaS platformIncomplete trail
Data exfiltration controlsDLP on human endpointsNot applied to agent outputsMajor gap

What Obsidian's Platform Actually Does

Obsidian Security monitors what AI agents do inside enterprise SaaS applications in real time — not at the network perimeter, and not at the model API layer, but at the application action layer where the agent's behavior has tangible consequences.

The platform integrates with SaaS applications including Microsoft 365, Salesforce, Workday, ServiceNow, Slack, and Google Workspace, and monitors the specific actions that AI agents take inside those applications: what records were read, what data was written or modified, what was sent to external systems, and what permissions were invoked. This is runtime security in the literal sense — monitoring the agent while it is actively running, not after the fact.

Three specific capabilities define Obsidian's platform:

Non-human identity mapping. Obsidian creates a comprehensive map of every non-human identity — service accounts, API keys, OAuth tokens, AI agent credentials — accessing the monitored SaaS applications. Most enterprise security teams are surprised by the count when they run this audit for the first time; non-human identities routinely outnumber human users in mature SaaS environments, and AI agent integrations have added substantially to that count in 2025–2026.

Runtime behavioral monitoring. For each monitored agent, Obsidian builds a baseline of expected behavior — which data objects the agent accesses, at what frequency, from what source applications, and via what output channels — and alerts on deviations from that baseline. An agent that normally reads 50 customer records per day and suddenly reads 50,000 triggers an alert. An agent that has never sent data to an external webhook and suddenly starts doing so triggers an alert.

Enforcement and containment. Beyond monitoring, Obsidian can enforce access controls specific to AI agent identities — blocking specific API calls, suspending agent access, or rerouting agent output through a human review queue when anomalous behavior is detected. The enforcement capability is what converts the platform from a detection tool to a security control.

Anthropic's inference hooks for enterprise DLP address a related but distinct layer: routing AI prompts through enterprise data loss prevention controls before the model processes them. Obsidian and inference-layer controls are complementary — inference hooks protect data from entering the model, while Obsidian monitors what agents do with data after the model has acted on it.

The Series D Economics: Customer Metrics That Explain the Valuation

Obsidian's $1.1 billion valuation is notable not because of its size — there are many unicorns — but because of what the customer metrics behind it imply about the market.

Over 100 enterprise customers are spending $100,000 or more annually on Obsidian's platform. More than 14 are spending $1 million or more. These are not pilot accounts. Enterprise security contracts at $1M+ imply multi-year commitments, deep integration into production security operations workflows, and renewal rates that reflect genuine operational dependency.

The enterprise security market is famously difficult to enter: security buyers are conservative, procurement cycles are long, and the requirement to integrate with existing SIEM, SOAR, and identity management infrastructure creates switching costs in both directions. A company that has crossed 100 enterprise customers at $100K+ ACV in a new security category has cleared the hardest adoption hurdle in the market.

The 70% enterprise adoption figure for AI agent data access is the demand driver. It implies that Obsidian's target customer — an enterprise security team that is trying to secure AI agents already running in their SaaS stack — is not a hypothetical future customer. They exist now, in large numbers, with an active problem and no incumbent solution.

MetricObsidian Security (2026)Significance
Series D raise$85MLargest AI agent security round to date
Valuation$1.1BUnicorn in under 5 years
Lead investorCrescent Cove AdvisorsSpecialist security growth fund
Existing investorsGreylock, MenloTier-1 VC continued support
Customers at $100K+100+Enterprise adoption confirmed
Customers at $1M+14+Deep penetration in large accounts
Clients allowing agent data access~70%Demand driver is already live

The Non-Human Identity Market Timing

Obsidian's raise arrives at a specific moment in the non-human identity (NHI) security market that explains why the funding is happening now rather than two years ago or two years from now.

In 2024, enterprise AI agent deployments were primarily pilots: controlled experiments with limited scope, tightly supervised, and usually confined to a single SaaS application. The security risk of a limited pilot is manageable with existing controls. In 2026, enterprise AI agent deployments have scaled to production: agents running continuously in core business applications, processing sensitive data at volume, and integrated into operational workflows that would be disrupted if the agent were suspended.

The transition from pilot to production is when security risk becomes material. An agent that pilots in a sandboxed Salesforce environment with synthetic data poses negligible risk. The same agent running in production with access to 10 million customer records, integrated with the billing system and the customer communication platform, poses a risk that requires dedicated security controls.

OpenAI's GPT-5.6-Cyber demonstrates the parallel trajectory on the offensive side: AI models are becoming capable of sophisticated security exploits. The combination of capable AI on the offensive side and poorly secured AI agents on the enterprise side creates a risk surface that is qualitatively different from the enterprise security risks of two years ago.

Obsidian's timing aligns with the production-scale inflection. The company has been building its platform for three years; the market for that platform has reached the size and urgency that justifies a $85M growth round.

The Competitive Landscape in Enterprise AI Agent Security

Obsidian is competing in a category that is new enough that most of the major enterprise security vendors have not shipped dedicated AI agent security products. The competitive landscape as of August 2026:

VendorCategoryAI Agent Security Capability
Obsidian SecurityNHI + AI agent runtime securityNative — purpose-built
CrowdStrikeEndpoint + XDRLimited — endpoint-focused
Palo Alto Networks (XSIAM)AI-native SOCPartial — network layer
Microsoft SentinelSIEM / SOARPartial — M365-focused
OktaIdentityOAuth scope management, not runtime
WizCloud securityCloud infra focus, not SaaS agent layer
SentinelOneEndpoint + XDREndpoint focus
NetskopeCASB / SSEData egress, not agent behavior

The gap in the competitive landscape is the "during" layer: what the AI agent is doing inside the SaaS application while it is running. CASBs monitor data egress at the network boundary; SIEMs aggregate logs after the fact; identity platforms control who can log in; but none of them watch what a running AI agent does inside a SaaS application in real time. That runtime behavioral monitoring layer is Obsidian's current defensible position.

Nvidia's Open Secure AI Alliance, with 37 members including major enterprise security vendors, was not designed specifically for AI agent runtime security — its focus is AI model safety and governance. The absence of a dedicated AI agent runtime security working group in that alliance reflects how recently the category has emerged.

The competitive window for Obsidian is 18–24 months. CrowdStrike, Palo Alto, and Microsoft all have the distribution, existing enterprise relationships, and engineering resources to build or acquire AI agent runtime security capability. The race for Obsidian is to reach enough enterprise customers at enough depth that the switching cost becomes a defensible moat before incumbents ship.

What the Market Inflection Looks Like for Enterprise Security Teams

The practical implication of Obsidian's raise and the 70% enterprise AI agent data access figure for enterprise security teams is not abstract. It is an operational gap that exists today in most enterprise environments.

Security teams that have not yet conducted an AI agent access audit should treat that audit as a P0 security task. The methodology:

1. Enumerate all AI agent integrations in your SaaS environment. Start with the SaaS applications where AI agent capabilities have been natively integrated by the vendor: Microsoft 365 (Copilot Studio), Salesforce (Agentforce), Slack (Slack AI), ServiceNow (AI Agents), Google Workspace (Gemini for Workspace). For each, check which AI agent features have been enabled by administrators, and what OAuth scopes or service account permissions those features were granted.

2. Map AI agent credentials to data access. For each AI agent integration, document what data the agent can read, write, and transmit. This mapping often reveals that agents were granted broader access than their function requires — a common outcome of vendor-default permission configurations that assume broad access is safe.

3. Establish a behavioral baseline for each agent. Document what each agent is expected to do: which record types it should access, at what frequency, and via what output channels. This baseline becomes the reference for anomaly detection.

4. Implement output controls. AI agents that can send data outside the enterprise via email, webhook, or API call represent a data exfiltration risk that most enterprises have not yet addressed with dedicated controls. DLP policies need to cover agent output channels in addition to human endpoints.

5. Build AI agent access into your regular access review cadence. Quarterly access reviews should include AI agent credentials alongside human accounts. Review what each agent was granted access to, whether the access scope remains appropriate, and whether the agent's behavior in the prior quarter was consistent with its defined purpose.

6. Evaluate dedicated AI agent security tooling. For enterprises with more than a handful of AI agent deployments, the manual processes above are insufficient at scale. Runtime monitoring platforms that can watch agent behavior across multiple SaaS applications simultaneously and alert on anomalies in real time address the scalability limit of manual auditing.

The Broader Signal: AI Security as a Board-Level Issue

Obsidian's $85M raise is not an isolated venture capital event. It is a data point in a broader pattern: enterprise AI security is reaching the size and urgency that makes it a board-level risk topic rather than a security team concern.

The Anthropic August 2026 Risk Report raising its catastrophic-misalignment risk rating was the high-end signal. Obsidian's funding round is the operational-reality signal: enterprises are deploying AI agents in production, the security controls around those agents are inadequate, and the security market is responding with purpose-built products at growth-round scale.

For enterprise boards and C-suites who have been receiving AI strategy updates focused on capability and ROI, the Obsidian round is a prompt to add a security dimension to that conversation. The question is not whether enterprise AI agents create security risks — they do, and 70% of Obsidian's clients have already accepted that risk in production. The question is what controls exist around those risks and what the incident response plan looks like if an AI agent behaves anomalously in a production SaaS environment.

The answer for most enterprises today is: incomplete controls and no AI-specific incident response plan. The security catch-up is beginning, with $85M of growth capital funding one of its leading vendors.

Takeaway: Obsidian Security's $85 million Series D is not primarily a venture funding story — it is a signal about the state of enterprise AI agent security in 2026. Nearly 70% of enterprise organizations are already allowing AI agents to access their business data, and the security controls around those agents lag significantly behind the controls on human access. Obsidian's $1.1 billion valuation reflects the size and urgency of that gap. For enterprise security teams, the immediate action is an AI agent access audit: enumerate what agents are operating in your SaaS stack, map their data access, and establish behavioral baselines before the first incident requires a retroactive investigation. The market for dedicated AI agent runtime security is new enough that the controls you implement today — whether through platforms like Obsidian or through manual audit and access review processes — will define your organization's security posture for the next wave of agent deployments.

Frequently Asked Questions

What does Obsidian Security do and why did it raise $85 million?

Obsidian Security is a cybersecurity platform focused on securing non-human identities and AI agents across third-party enterprise SaaS applications. The company raised $85 million in a Series D round led by Crescent Cove Advisors, with participation from existing investors Greylock Partners and Menlo Ventures, at a $1.1 billion valuation. The raise reflects a market inflection: enterprise organizations are deploying AI agents — built on Claude, ChatGPT, Copilot Studio, and other platforms — inside their core business applications (Salesforce, Workday, ServiceNow, Microsoft 365) at a rate that has outpaced the security controls around those agents. Nearly 70% of Obsidian's enterprise clients reported already allowing AI agents to interact with their business data at the time of the funding announcement. Obsidian's platform monitors what those agents actually do inside SaaS apps in real time, detects anomalous behavior, and enforces access controls specific to non-human identities — a capability category that didn't exist as a dedicated market segment two years ago. The $85M will be used to expand the platform to more of the Fortune 500 and Global 2000.

What is AI agent runtime security and why is it different from traditional enterprise security?

AI agent runtime security is the monitoring and enforcement of what AI agents actually do inside enterprise applications while they are actively running — in contrast to perimeter security (controlling network access) or identity security (controlling login credentials). Traditional enterprise security was designed around human users: a person logs in with a username and password, is granted access to specific resources, and security tools monitor that person's activity patterns for anomalies like logins from unusual locations or unusual data transfer volumes. AI agents break this model in several ways. First, agents authenticate with service accounts or API keys rather than human credentials, so user-based anomaly detection doesn't apply. Second, agents can read, write, and transfer data at machine speed — a human exfiltrating data through a SaaS API is limited by typing speed; an agent can pull millions of records in seconds. Third, agents have permissive access by design — they need broad read/write capability to do their jobs — so traditional least-privilege controls are harder to apply without breaking functionality. Runtime security monitors agent behavior at the action level: what did this agent read, what did it write, what did it send outside the application, and does that pattern match what it was supposed to do.

What are the biggest security risks of AI agents accessing enterprise SaaS apps?

Enterprise AI agents operating inside SaaS applications create four primary risk categories. First, data exfiltration: an AI agent with read access to a CRM or financial system can extract sensitive customer or financial data and transmit it externally — either because the agent was configured incorrectly, or because a prompt injection attack redirected the agent's behavior. Second, unauthorized write operations: agents with write access can modify records, send communications, or execute transactions in ways that bypass the human review steps that those actions normally require. Third, privilege escalation: agents operating with service account credentials may inherit broader permissions than intended, especially in SaaS apps where service account scoping is difficult. Fourth, supply chain attacks via third-party agent integrations: AI agents increasingly call other agents, tools, and APIs, and a compromised integration in that chain can redirect the agent's behavior in ways that are invisible to the enterprise running the primary agent. Obsidian's platform addresses all four by monitoring agent activity at the SaaS application layer — watching what data the agent reads and writes, detecting anomalous patterns, and alerting on behavior that deviates from the agent's configured purpose.

How does a CISO get started with AI agent security?

The starting point for enterprise AI agent security is an inventory of what AI agents are already operating in your environment — which is typically a larger list than security teams expect, because business units deploy AI agents through vendor integrations that don't require IT approval. Step one: audit your SaaS application inventory for AI agent integrations. Salesforce, Microsoft 365, Slack, Workday, and ServiceNow all have native AI agent frameworks (Agentforce, Copilot Studio, Slack AI, etc.) that may have been enabled by business unit administrators without security review. Step two: map the data access each agent has been granted. Review the OAuth scopes and service account permissions associated with each AI agent integration and compare them against the least-privilege principle — agents often have broader access than their function requires. Step three: establish a baseline of expected agent behavior for each deployed agent, and monitor for deviations. Step four: implement controls on agent output channels — specifically, what data can agents send outside the enterprise boundary via email, webhook, or API call. Step five: develop an AI agent access review process that runs on the same cadence as your human access review (quarterly for most enterprise teams). These five steps address the most common AI agent security failures without requiring a dedicated AI security platform, though a platform like Obsidian's adds runtime anomaly detection that manual processes cannot match at scale.

What is non-human identity (NHI) management and how does it relate to AI agents?

Non-human identity (NHI) management is the security discipline of controlling and monitoring access credentials used by automated systems rather than human users — including service accounts, API keys, OAuth tokens, machine certificates, and increasingly the identities used by AI agents. NHI management is not a new concept: DevOps teams have managed service account credentials for decades. What's new is the scale and behavioral complexity of non-human identities in 2026. An enterprise that might have had dozens of service accounts five years ago now has hundreds or thousands of AI agent integrations, each with its own credentials and access scope. AI agents compound the NHI problem because they are intentionally designed to take autonomous actions — unlike a service account that simply reads a database, an AI agent reads, reasons, and acts, often in ways that are difficult to predict from the credential scope alone. Obsidian's platform addresses NHI management specifically in the SaaS layer: it tracks every non-human identity accessing enterprise SaaS applications, maps their permissions, and monitors their runtime behavior for anomalies. The company's positioning as an NHI and AI agent security platform reflects the convergence of these two disciplines — the same monitoring and enforcement capability applies to traditional service accounts and to AI agents, because both are non-human identities with automated, credential-based access.

Which enterprise platforms does Obsidian Security support for AI agent monitoring?

Obsidian Security's platform monitors AI agents operating inside third-party enterprise SaaS applications, with a focus on the platforms where enterprise AI agent deployment is most concentrated. Primary integration targets include Microsoft 365 (including Copilot Studio agent deployments), Salesforce (including Agentforce deployments), Slack, Workday, ServiceNow, and Google Workspace. The platform monitors AI agents built on major foundation model platforms — specifically Anthropic Claude, OpenAI ChatGPT (including the Assistants API and function-calling agents), and Microsoft Copilot Studio — when those agents are granted access to the supported SaaS applications. Obsidian operates at the SaaS application layer rather than at the model API layer, which means it can monitor agent behavior regardless of which AI model is being used, as long as the agent's actions flow through a supported application. The company serves over 100 enterprise customers spending $100,000 or more annually, with more than 14 customers at $1 million or more in annual spend — an indication that the platform is deployed at meaningful enterprise scale rather than in limited proof-of-concept configurations.