Israeli startup Onyx Security, which helps secure and manage AI agents' operational risks, raised a $35M Series A led by Conviction, after a $5M seed in 2024
The Israeli startup develops a platform to secure and manage AI systems as they become integral to business operations.
Context & Ripple Effects
Onyx’s round arrives as AI agents are moving into enterprise workflows, creating a need to govern the operational risks of systems that can act rather than merely generate content. The related coverage spans both AI-enabled endpoint defense and AI agents used to protect enterprise devices, underscoring how agent adoption is expanding security’s attack surface and its tooling.
The $35M Series A materially follows Onyx’s $5M 2024 seed, giving the company a larger financial base in a category that also includes defenses against AI-powered social-engineering attacks.
First-order effects
- Onyx Security receives $35M in Series A financing, with Conviction leading, after its earlier $5M seed round.
- The round strengthens Onyx’s ability to build and sell its platform for securing and managing AI agents’ operational risks as those systems become part of business operations.
Second-order effects
- Enterprises evaluating AI agents gain another specialist supplier focused on controls and risk management, rather than only on deploying agent capabilities.
- The funding raises the competitive bar for adjacent AI-security vendors, including providers securing AI-powered attacks or AI-enabled enterprise endpoints, to show how their tools address agent-specific operational exposure.
Third-order effects
- If enterprise agents continue to move from pilots into operational roles, operational controls are likely to become a distinct buying layer alongside agent platforms and conventional cybersecurity tools.
- The category’s durability will depend on whether buyers standardize on dedicated agent-risk platforms or absorb those functions into broader security and governance suites.
The trend: AI adoption is shifting security demand from protecting models and endpoints alone toward governing the actions, permissions, and operational risks of autonomous agents.