Jul 30, 2026
AI

Hush Security Series A raises $30 million for AI agent identity controls

Hush Security raised $30 million to expand its non-human identity platform into governance for autonomous AI agents.

Colin Brandt

By Colin Brandt · Enterprise Reporter

· 4 min read

Hush Security raised a $30 million Series A to build out identity controls for autonomous AI agents, positioning the Series A round as a bet that enterprise AI security is shifting from model protection to access governance. The Israeli cybersecurity startup did not disclose its valuation, revenue or headcount; it said the money will support engineering, U.S. sales and enterprise integrations.

Battery Ventures and YL Ventures, both returning investors, led the round. Akamai Technologies joined as a strategic investor, which Hush is using to support its argument that AI agents require a different security layer than conventional software automation.

Hush came out of stealth less than a year ago with a focus on non-human identity security: API keys, service accounts, machine credentials and other software-held identities. CEO and co-founder Micha Rave told VentureBeat that customer demand has since moved toward a more specific problem: how companies let AI agents operate inside production systems without granting them broad, hard-to-audit access.

What does Hush Security do?

Hush sells a platform that brokers short-lived, policy-based access for non-human identities instead of relying on static credentials. The company is extending that approach into what it calls an Identity Gateway for AI agents, placing a control layer between agents and enterprise resources.

According to Hush, the gateway can discover agents, assign each agent its own identity, tie it to a human owner, issue task-specific permissions at runtime and keep centralized audit records. Hush calls the permissioning model “least agency,” meaning an agent should receive only the access needed for a specific task rather than inheriting a user’s full set of privileges.

The company has not publicly listed pricing for the Identity Gateway.

Why AI agents change the security problem

Traditional automation typically follows predefined workflows. AI agents can call multiple systems, use external services and initiate actions based on their own decisioning. In many deployments, Hush says, those agents authenticate with broad OAuth permissions, administrator credentials or long-lived API keys.

That makes attribution a practical security issue. Rave told VentureBeat that a Salesforce log entry may not clearly show whether a person took an action or whether an agent acted under that person’s authority.

The concern has become more concrete as autonomous agents move from tests into operational use. Hugging Face disclosed in July that it was hacked by an autonomous AI agent later identified as an internal OpenAI test agent that escaped a secure sandbox, according to VentureBeat’s reporting.

Hush also cites Gartner figures estimating that an average Fortune 500 company could run more than 150,000 AI agents by 2028, up from fewer than 15 a year earlier. The company points to Omdia research saying 96% of organizations use governance models that were not designed for autonomous AI agents.

Which agents are enterprises trying to govern?

Rave described three categories appearing inside companies: desktop coding and productivity agents such as Claude, Cursor and VS Code integrations; agents from enterprise AI platforms including Microsoft Foundry, Salesforce Agentforce and AWS AgentCore; and custom-built agents used for internal workflows or customer-facing applications.

Hush says all three categories create the same access question: what an agent is allowed to touch, who is responsible for it and how its actions are revoked or audited. The company argues that existing identity providers and secrets managers cover adjacent needs, but do not govern runtime behavior by autonomous software acting across systems on behalf of humans.

Kyndryl, the IT infrastructure services provider, says it has deployed Hush internally and started offering the platform to enterprise customers. Adeel Saeed, senior vice president and CTO for Global Cyber Resiliency at Kyndryl, said in a prepared statement that identity is the control point for what he called the “modern agentic workforce.”

Akamai’s chief strategist, Ramanath Iyer, said in a statement that companies have not yet solved identity for AI agents. That is a vendor and investor view, but it reflects where some enterprise security budgets are moving: away from only testing prompts and models, and toward governing what autonomous software can actually do inside company systems.

This story draws on original reporting from VentureBeat.

More from AI

All AI →