The Market Just Valued the Agent Security Gap at $1.1 Billion
Obsidian Security just raised $85M at a $1.1 billion valuation to secure AI agents operating inside enterprise SaaS platforms. That is not just a funding round. That is the market putting a number on the gap your agents are running through.
For a while, the governance conversation with clients has been framed as a risk management story. You should care about this because something might go wrong. This week changes the frame. The VC market just told enterprise risk committees exactly what the agent security gap is worth, and that is a different conversation to walk into.
Here is what makes this credible, not just a valuation headline. Obsidian has over 100 customers spending $100K annually and 14 spending over $1M. The product works and the market is buying it. That is category validation. But the data underneath the funding is more alarming than the headline. Okta's 2026 enterprise agent report shows 88% of organizations confirmed or suspected a security incident involving AI agents this year. 86% don't enforce access policies for AI identities. As I wrote about in Your Agents Have Keys. Nobody Changed the Locks., the access and permissions side of this problem is already live in your environment. These are not lagging-indicator problems. They are happening right now, at scale, probably inside your business.
The consulting angle here is concrete. Most clients I talk to are still having the 'should we think about AI governance?' conversation, if they're having it at all. The right conversation is this: a venture-backed unicorn exists specifically because your agents are operating without access controls. What does that mean for your liability, your compliance posture, and your board's next AI briefing?
If agent security is a billion-dollar market problem, what is your organization's dollar figure for ignoring it?