Enterprise AI crossed a line in the past twelve months. AI adoption is a board-level priority, top concern for CISOs, and while only 17% of enterprise organizations have deployed AI agents so far, more than 60% expect to within two years — the most aggressive adoption curve of any emerging technology Gartner measures.
AI agents change the nature of risk entirely. Employees are building and deploying agents through various platforms that security teams never get the chance to review or inventory for permissions. AI adoption is outpacing governance and shadow AI is the new shadow IT, only the AI agents work autonomously.
The architecture layers of SIEM, IAM, DLP, and EDR were all built to see events, identities, and traffic generated by humans. No paradigm built for humans covers an actor that is software, operates at machine speed, and reasons for itself – especially when the threat model now includes the agent itself.
No paradigm built for humans covers an actor that is software, operates at machine speed, and reasons for itself.
AI agents can be hijacked, go rogue, or exceed their intended scope to solve a problem they encounter. When an agent is manipulated and moves data across internal systems to complete its task, the pre-existing architecture layers only see them as unrelated events. Nobody sees the intent behind them.
The scale and growth are unprecedented. Industry leaders are already talking about a billion agents in production. By the end of 2026, Gartner predicts 40% of enterprise applications will integrate task-specific AI agents, up from less than 5% in 2025, representing an eightfold jump in a single year.
We believe this is the defining security problem of the agentic era: the agent is the new perimeter, and the perimeter needs a platform of its own. Today, we’re excited to share that Norwest is leading Zenity’s $125 million Series C to secure AI agents everywhere.
Why Zenity is Built to Lead the Growing Agentic AI Security Market
Zenity pioneered AI agent security before the category had a name. Even though it’s early, the market that’s now forming is large. Agentic AI security is projected to grow from $1.65 billion in 2026 to $13.5 billion by 2032, a 42% CAGR — and that likely understates it, with Gartner’s best case putting agentic AI at roughly 30% of enterprise application software revenue by 2035, above $450 billion. As in cloud a decade ago, security spend follows adoption spend with a short lag and this adoption curve is steeper than cloud’s ever was.
To defend against increasingly sophisticated threats and ensure nothing falls between the cracks or outside of the context of the stack, security leaders are looking for a comprehensive platform rather than develop an array of point solutions.
In the next 12–18 months, every organization will need to define its AI strategy, and Zenity’s platform approach, together with its proven product, puts the company in an exceptional position to lead the category.
In the next 12–18 months, every organization will need to define its AI strategy, and Zenity’s platform approach, together with its proven product, puts the company in an exceptional position to lead the category.
Zenity has the most advanced and mature solution in the market, purpose-built end to end, not retrofitted from a prior paradigm.
The platform runs a continuous loop:
- Discovery and observability: a live inventory of every agent, who owns it, what it can reach, how it behaves
- Governance and posture: secure-by-design policies enforced before deployment and validated continuously as agents evolve
- Detection and response: step-level runtime monitoring that stops unsafe actions before they complete, with every incident feeding back into the detection engine
What ties the loop together is intent. Zenity correlates how an agent was built, configured, and connected with how it behaves at runtime, providing a single picture of what the agent was actually trying to accomplish.
Coverage is the other half and includes SaaS-managed, endpoint, and homegrown agents. Platforms covered include, but are not limited to, Microsoft Copilot, ChatGPT Enterprise, Claude Enterprise, Salesforce Agentforce, ServiceNow, AWS Bedrock AgentCore, Google Vertex AI, and custom-built applications, with Zenity serving as a core enabler of flexible AI adoption in the organization.
With the AI stack still being invented, Zenity’s platform breadth is beyond just a feature, helping them carve the moat.
What We Heard from CISOs During Due Diligence
The signal from security leaders was unusually consistent for a market this young. Zenity is the only vendor offering unified coverage at the required standard across every agent type. We also heard that AI agent security is now non-discretionary spend and Zenity’s platform step-level visibility is unmatched.
We talked with market participants and prospective customers through Norwest’s Operator Collective, a dynamic community of AI, Data, CISO, and CXO leaders, and most potential enterprise customers echoed the imminent need and asked to meet Zenity.
Public outcomes back this up. A Fortune 20 technology company remediated 90% of vulnerabilities with two FTEs while its tenant grew 280% in a year. A Fortune 50 financial services firm cut risk 80% across 150,000+ resources as agent volume grew 180%. A Fortune 200 consulting firm reduced violations by 90%, with 95% of high-risk cases auto-remediated.
Fortune 500, Global 2000, and other leading global organizations, including SoftBank Corp, rely on Zenity to adopt Al at scale, securely. The growth inside those accounts show the surface Zenity secures is compounding, and expansion follows it.
Zenity Labs: The Research Engine Behind the Product
In a market where today’s differentiation becomes tomorrow’s table stakes, durability comes from Zenity Labs, a research organization wired directly into product and R&D, and outward into customers, partners, the AI labs, and the builder community.
Zenity Labs uncovers and responsibly discloses vulnerabilities across the agent ecosystem; its research is considered seminal in the field. That work feeds the standards the industry runs on — the OWASP Top 10 for Agentic Applications, MITRE ATLAS, NIST, and CSA — so Zenity helps define the very problems enterprises then hire it to solve.
In 2025, Gartner recognized Zenity as a Cool Vendor in its Agentic AI Trust, Risk and Security Management (TRiSM) report. This year, Zenity was named the Company to Beat in AI Agent Governance by Gartner. According to the research, “Zenity’s purpose-built agentic-centric architecture, intent-aware detection and continued end-user interest put it at the forefront of the AI agent governance race.”
Why We Invested
Ben Kliger and Michael Bargury founded Zenity on an insight they earned at Microsoft; tools that let anyone build automations, which now includes agents, created a governance gap no incumbent would close. They built for it before the category existed, and the market came to them. Michael remains one of the field’s most recognized researchers and thought leaders, keeping the company at the front of a continuously evolving threat landscape.
We’ve been following the company since its earliest days, and have deep admiration for what Ben and Michael have built. We have no doubt Zenity will continue to lead the future of security for AI agents, and enable enterprises to build stronger cyber safeguards.
The promises are anchored in performance that’s already happening: accelerating growth, the world’s largest enterprises expanding deployments, and a wave still in its first innings. We believe the AI-first transformation of the enterprise depends on platforms like Zenity — a core enabler, not just a control — and we’re proud to back the team defining the category. Here’s to what’s next and to what agents come next.
