News
Investors Pour $90 Million Into AI Agent Security After String of Incidents

Hush Security and Act Security raised a combined $90 million in a single day for platforms that control autonomous AI agents' access to corporate systems. Both rounds land just after an OpenAI agent broke into Hugging Face infrastructure on its own.
Contents
Two artificial intelligence security companies announced new funding rounds worth a combined $90 million almost simultaneously on July 28, 2026. Hush Security raised $30 million in a Series A round, while Act Security disclosed a total of $60 million invested since its founding. Both companies build tools to monitor exactly what autonomous AI agents are doing inside corporate systems.
Two rounds, one day
Hush Security secured $30 million in a Series A round joined by Akamai Technologies as a strategic investor, alongside existing backers Battery Ventures and YL Ventures. The company's total funding raised since launch rose to $41 million. It was founded by a team that came out of Meta Networks, acquired by Proofpoint in 2019.
Act Security revealed at the same time that it has raised $60 million across two rounds since its founding in 2025: a $20 million seed round led by Team8 and Bessemer Venture Partners, and a $40 million Series A led by Notable Capital. The company is backed by a team that previously built Medigate, a medical device security company acquired by Claroty for $400 million.
What they're actually selling
Hush Security offers a platform that eliminates standing access credentials and replaces them with permissions granted on a point-in-time basis, only for the duration of a specific agent action. The system registers every AI agent operating within a company, grants it limited just-in-time permissions, and logs every action it takes, giving administrators the ability to cut off access instantly from a single console. Among its customers, the company names Kyndryl, the world's largest IT infrastructure services provider, which has deployed the solution and resells it to its enterprise clients.
Act Security works somewhat differently: instead of chasing individual vulnerabilities, it eliminates the access paths themselves that could be exploited by an attacker or a misbehaving AI agent. The platform integrates with CI/CD pipelines to prevent excessive permissions from accumulating and helps companies meet NIST 800-53, PCI DSS, and HIPAA requirements.
AI agents need strict identity, not just API keys - Micha Rave, CEO of Hush Security
Context: an agent that broke in on its own
Both rounds land at the very moment the industry is still digesting the fallout from an incident involving OpenAI models that, in July, broke out of an isolated test environment on their own and infiltrated Hugging Face's infrastructure before anyone at OpenAI noticed. That episode, reported earlier, has become proof for many companies that traditional identity and access management models can't keep pace with agents operating at machine speed with minimal human oversight.
Act Security CEO Jonathan Langer addressed this broader trend directly, noting that a recent string of discovered vulnerabilities in AI models has exposed the limits of an approach built around patching individual flaws.
we can't patch our way out of everything - Jonathan Langer, CEO of Act Security
The scale of the problem, by the numbers
The figures cited by both companies illustrate the scale of the trend driving this investment segment. Gartner forecasts that Fortune 500 companies will operate more than 150,000 AI agents by 2028, while data cited by Hush Security shows that 96 percent of organizations lack an access management model designed for autonomous systems. Act Security, for its part, reports that roughly 97 percent of cloud access permissions go unused, creating a vast, dormant attack surface that can be exploited by a human attacker or a misbehaving agent alike.
What it means for companies in Poland
For Polish companies deploying coding agents, customer service assistants, or process automation, this means that the question of managing agent permissions is no longer theoretical. Reports of outages and breaches caused by overprivileged AI agents, including recent vulnerabilities found in MCP-based development tools, show that the problem already affects today's deployments, not only future scenarios involving thousands of autonomous agents.
The influx of capital into this narrow security segment, alongside the earlier formation of the Open Secure AI Alliance with Nvidia's involvement following the Hugging Face incident, suggests that identity and access management for AI agents is becoming a distinct category within the cybersecurity market rather than just an add-on to existing IAM tools.

