The Trust Bottleneck: Zenity's $125 Million Round and the Agentic Security Gold Rush

CryptoTiger β€’ β€’ Magazine

Read the investor list first. That is where the story hides.

SoftBank. Hitachi. LG. Three non-American industrial giants just stepped into a $125 million Series B round for Zenity, an Israeli security platform most of enterprise America has never put on a shortlist. The amount itself is notable. In a market where cybersecurity startups have spent two years begging for twenty-million-dollar rounds, a 125-million-dollar B is a fire alarm. But the investor list is the actual signal. Not a single Silicon Valley name on the term sheet. No a16z. No Sequoia. No Accel. Instead: a Japanese telecom-and-everything conglomerate, a Japanese industrial automation behemoth, and a Korean consumer electronics giant.

The poet's eye sees a narrative arc forming. The most conservative capital on earth β€” aging, compliance-bound, allergic to hype β€” is underwriting the safety layer for software that barely exists at scale. That is not a venture bet. That is an insurance policy for a future that has already been sold.

Here is the cold truth on the ledger: AI agents are being deployed by line-of-business employees who have never touched a security console. Microsoft Copilot Studio and Google Vertex AI Agent Builder let a marketing manager spin up an autonomous agent in hours. Gartner now projects that by 2028, at least 15 percent of daily work decisions will be made by agentic AI systems. In 2024, that number was below one percent. The gap between those two numbers is not a technology curve. It is a trust vacuum.

And into that vacuum, $125 million just walked.

Following the thread from hype to genuine utility, this round is less about Zenity specifically and more about the moment. Security has always lagged adoption by exactly one disaster. The question is whether the Agent era produces that disaster before the security layer matures β€” or whether companies like Zenity get to build the moat in time.

Zenity did not stumble into Agent security. It spent four years earning a seat at this table. Founded in 2021, the company made its name securing low-code and no-code applications β€” the sprawling ecosystem of tools that business users assemble without IT approval. In January 2024, it raised a $16.5 million Series A led by Insight Partners, positioning itself as a platform that protects low-code/no-code applications and AI-generated content. That positioning matters: long before 'AI Agent' became a boardroom password, Zenity was ingesting the behavioral patterns of shadow IT, unsanctioned apps, and automation built by people who should not have been building automation.

The technical thesis is subtle but important. Zenity is not trying to make models safer. It is not alignment research. It is a governance and protection layer for the deployments that run on top of models β€” the agents themselves. Its platform spans what analysts now call MAAP (machine access and behavior protection), AI-SPM (AI security posture management), and AI-SSRM (AI security services and risk management). The object of protection has shifted from the human's clickstream to the machine's action chain. The security boundary has moved from the network layer to the behavior layer.

This is the part most security veterans underestimate. Traditional cyber defenses assume a human operator who can be trained, authenticated, and accused. An autonomous agent is not a human. It inherits credentials, makes decisions, executes transactions, and can do so at machine speed, across multiple systems, before any SOC analyst has poured coffee. Agent security is not an extension of endpoint security. It is a new category of perimeter: the perimeter between intention and action.

The macro context is doing the heavy lifting. Microsoft Copilot Studio, Google Vertex AI Agent Builder, and a dozen open-source agent frameworks have collapsed the cost of agent construction to near zero. The resulting 'shadow AI' mirrors the shadow IT problem of the 2010s β€” except this time the shadow runs on its own, with its own keys, transacting like a trusted insider with no sense of consequence. Zenity's discovery, governance, and protection lifecycle exists precisely because no enterprise can see its own agents.

Then there is the question of timing. The 2023-2024 cybersecurity funding winter was not a cyclical dip; it was a sector's adolescence ending. Venture dollars fled undifferentiated threat detection startups and consolidated around platforms with real revenue. Into that environment, Zenity jumped from a 16.5-million-dollar A to a 125-million-dollar B in eighteen months β€” a 7.6x leap. That kind of step-change does not happen because investors suddenly discovered a feature. It happens because a category got named, and the category is 'AI Agent security.' The money is not betting on Zenity's quarterly numbers. It is betting on the ledger of the machine economy: every autonomous action will need a verified record, and the first vendor to own that record controls the next decade of enterprise trust.

The moat is not the algorithm

In the first weeks after Zenity's round leaked, I saw a dozen takes comparing it to every security startup of the past decade. Wiz here. CrowdStrike there. All of them missed the point. Zenity's technical edge, to the extent that it exists, is not a cleverer model. It is the dataset.

I have spent years auditing security claims, going back to the 2017 ICO boom, when I sat down and read 45 Ethereum whitepapers looking for substance beneath the solutionism. The pattern was always the same: a team would tout a novel mechanism, but the actual value lived in the messy operational layer β€” who was using the system, what behaviors were 'normal,' and who would be held liable when the normal broke. Zenity sits on the same structural insight. Its discovery engine catalogs every low-code app, every AI integration, every agentic workflow that a business unit has spun up without telling the CISO. That inventory is the foundation. You cannot secure what you cannot see.

The governance layer then builds behavioral baselines: what does a legitimate agent task look like inside a particular enterprise tenant? What data paths does a procurement bot touch on a Tuesday afternoon? What permissions does a customer-support agent actually need, versus the ones it inherited from a human user's over-privileged account? These baselines are not learned from public benchmarks. They are forged inside customer environments, one integration at a time. The detection rules library and the customer-scenario knowledge are the real barrier to entry β€” not model weights, not a clever loss function.

I would put the probability that Zenity has already completed deep integrations with dozens of enterprise customers somewhere in the moderate-to-likely range, based purely on the funding math. A 125-million-dollar B round in security software, with three strategic industrial investors at the table, is not raised on mockups. It is raised on reference calls and POC results, even if the company has not publicized them. Investors of this caliber do not underwrite slideware.

Yet the unanswered questions are precisely where the technical risk concentrates. What is Zenity's detection accuracy, and more importantly, its false-positive rate? Security tools live or die on signal-to-noise; a platform that flags every benign agent action as suspicious will be uninstalled within two quarters, no matter how good its dashboard looks. Does its coverage extend to multi-agent collaboration, where one agent calls another agent and the attack surface becomes a graph of cascading machine decisions? And crucially: has it built forensics and provenance capabilities for agent action chains? For enterprise security buyers, the ability to answer 'what exactly did the agent do, and why' after an incident is the single highest-stakes procurement criterion. If Zenity cannot reconstruct an agent's full decision path for auditors and insurers, its platform value collapses to a compliance checkbox.

The deeper play is standard-setting. AI Agent security has no unified technical standard yet. There is no common definition of an agent behavior baseline, no accepted model for least-privilege machine access, no agreed schema for agent audit logs. That void is both the risk and the opportunity. If Zenity uses this capital to push its own framework β€” its baseline models, its permission-minimization patterns, its incident-response runbooks β€” toward de facto industry standard, it wins something far more durable than market share: it wins the format war. In security, the format war is the war. The vendor that defines the logging schema for the machine economy gets to tax every other vendor that has to interoperate with it.

There is also a quieter technical signal in the investor list. Hitachi deploys autonomous systems in industrial control and energy infrastructure. LG is pushing AI agents into smart home appliances and consumer robotics. Both companies have operational technology and IoT environments where security software must run at the edge, on constrained hardware, inside air-gapped or semi-isolated networks. The presence of these two industrial investors hints that Zenity's roadmap may extend beyond the enterprise SaaS data center into OT and embedded agent security. If that is true, the company is not just building a security platform; it is building an agent security gateway that spans the physical and digital worlds. That would put it in direct competition with a very different set of incumbents β€” the industrial control system security guys β€” and would explain why SoftBank, a chief architect of the AI-era supply chain in Asia, wanted in.

The money and the geo-politics

Let us do the arithmetic first, because the arithmetic is how we find the narrative buried under the press release. In 2024-2025, a healthy B-round security software company trades at roughly 10 to 15 times annual recurring revenue. A $125 million round, if it represents roughly a 20 to 25 percent dilution, implies a post-money valuation somewhere in the $500 million to $1 billion range. Backing out from those multiples, Zenity's ARR is probably somewhere between $20 million and $40 million, with the higher end assuming an 'AI premium' that pushes the multiple past 20 times. That is a guess. The confidence level is low. But the direction matters: investors are not paying for current revenue. They are paying for the category's trajectory, which means the valuation is a forward narrative price.

The investor list is where the geopolitical story lives. SoftBank has spent the last few years building an AI portfolio that runs from models β€” OpenAI, Anthropic β€” down through infrastructure β€” Arm β€” and into applications β€” Perplexity, Kira Learning. Adding a security layer is the portfolio catching up with its own creation. Every AI portfolio needs insurance against its own ambition. Zenity is that insurance.

Hitachi's presence is more operational than financial. In industrial automation, energy, and transportation, Hitachi runs systems where an agent's wrong decision is not a refunded transaction β€” it is a physical process going off the rails. The company's interest in Zenity is a real-world validator for a demand that most American enterprise buyers have only started to articulate. LG, similarly, ships AI agents into homes, where the security surface includes cameras, appliances, voice interfaces, and the terrifying possibility of an agent acting on a maliciously injected instruction. Consumer IoT security is the highest-risk, lowest-tolerance environment in the entire AI stack. LG's participation is not a check; it is a partnership signal.

Here is what the absence of American VCs tells me, and I want to be honest about the two readings. The generous reading: Zenity deliberately chose strategic capital over financial capital because it wants channels, not just cash. SoftBank can open every enterprise door in Japan. Hitachi can translate Zenity's product into industrial credibility. LG can push it into a consumer electronics supply chain. In a world where procurement decisions increasingly favor vendors that come pre-wired into the buyer's regional data-sovereignty requirements, this investor list is a keyring, not a cap table.

The Trust Bottleneck: Zenity's $125 Million Round and the Agentic Security Gold Rush

The less generous reading: the American VC market has seen Zenity's US enterprise traction and decided to wait. Security budgets in the United States remain the largest prize in the industry, and if Zenity had been crushing it in that market, the round would have been oversubscribed with domestic names. Instead, the company went offshore for capital. That is not necessarily a defect β€” the non-US path to market is now a legitimate strategy for AI infrastructure companies, especially in a world where the EU, Japan, and Korea are all pursuing what they awkwardly call 'digital sovereignty.' A security vendor headquartered in Israel with major Asian industrial backing is arguably better positioned for the post-American-cloud era than a pure Silicon Valley play.

But the strategy cuts both ways. If digital sovereignty becomes a moat, it becomes a ghetto at the same time. Enterprises that buy from Zenity because it is not American may also be the enterprises that are slowest to adopt new AI technology, most risk-averse, and most demanding of local data residency. The regulatory burden of deploying a security platform across Japanese, Korean, European, and American data-protection regimes is enormous. Zenity may have bought itself the hardest possible market to serve, precisely at the moment when it needs to prove it can scale.

There is a strategic-buyer angle to watch as well. The structure of this round β€” three strategic industrial investors and no dominant US financial lead β€” is the classic setup for a controlled exit. Security startups that anchor their cap tables with strategic investors rarely go public at the top of their value. They get acquired by the strategic who has been sitting in the boardroom all along. The Wiz precedent hangs over every security valuation conversation now: Google's agreement to acquire Wiz at a reported $23 billion in 2025 proved that the security startup exit channel is wide open. But Wiz had hypergrowth and a US market position that forced Google to pay up. Zenity, for all its strategic shine, has not yet demonstrated that kind of independent growth. If the round is actually the first step of a three-year acquisition path β€” by a Hitachi or a SoftBank portfolio company, not a US hyperscaler β€” then the 'AI Agent security infrastructure' narrative is really a component-pricing narrative in disguise.

Sizing the trust bottleneck

The market math is the part that makes this round feel inevitable. If global agentic AI spending reaches $1.5 trillion to $2 trillion by 2030, and security budgets historically consume 5 to 10 percent of any technology spend, then the addressable market for AI agent security lands somewhere between $75 billion and $200 billion per year. Even the lower bound is larger than the entire current endpoint detection and response market. The Gartner projection that 15 percent of daily work decisions will be made by agentic AI by 2028 β€” up from under 1 percent in 2024 β€” is not just a technology adoption curve. It is a liability transfer curve. Every one of those decisions is a potential audit finding, a potential compliance violation, a potential lawsuit. The security layer is where that liability gets contained, or where it leaks.

The demand-side signal is already visible in procurement data. Menlo Ventures' 2024 enterprise AI report found that security concerns are the second-largest barrier to expanding agent usage, trailing only data privacy. That is not a theoretical hesitation. It is the budget conversation happening in real time in every large enterprise. The model is proven, the agent is impressive in the demo, and then the CISO asks three questions: who owns the agent's credentials, what can it touch, and what happens when it does something we did not approve? Those three questions are Zenity's entire product roadmap.

Regulation is reinforcing the demand. The EU AI Act imposes transparency and human-oversight requirements on high-risk AI systems. China's newly implemented measures on labeling AI-generated synthetic content force disclosure of machine outputs. The US NIST AI Risk Management Framework is increasingly baked into federal procurement and enterprise best practice. Every one of these frameworks, however different in philosophy, converges on the same operational requirement: organizations must be able to explain what their AI agents did, why, and under whose authority. That explanation capability is precisely what agent security platforms sell. Regulation is not the tailwind; regulation is the weather system making the tailwind permanent.

There is a generational market shift underneath all of this. Traditional cybersecurity β€” firewalls, EDR, SIEM β€” has matured into single-digit annual growth. AI-native security is growing at over 50 percent year over year. Zscaler and Palo Alto Networks have both leaned into AI runtime security as their headline growth story in recent earnings cycles. The most important shift, though, is conceptual: the 'user' is no longer a person. In the machine economy, the user is an agent with a set of keys. Every enterprise that deploys autonomous agents is quietly multiplying its number of privileged identities by an order of magnitude, and most of those identities have no human attention attached to them. Based on my audit experience in the Web3 space, I can tell you exactly what happens when machine identities multiply without governance: the attack surface doubles before the policy catches up. The same pattern is repeating inside enterprises right now, and it is moving faster than the compliance committees that are supposed to catch it.

For those of us who live in the crypto world, the convergence is impossible to miss. The next generation of agent deployments will not stay inside enterprise SaaS. Agents will transact on public blockchains β€” paying for compute, settling machine-to-machine micropayments, executing programmatic trades, managing autonomous treasury operations. Each agent becomes a wallet. Each wallet needs permissions, limits, and a behavioral baseline. The exact same discovery-governance-protection lifecycle that Zenity sells to the enterprise is the security architecture that the crypto agent economy will need, except on-chain, with code-is-law finality. The enterprise trust bottleneck and the Web3 trust bottleneck are the same bottleneck. Zenity is building the first commercial claim to that territory.

The battlefield: three layers and a trap

The competitive landscape for agent security currently has three layers. Layer one is the independent startups: Zenity, Legit Security, and a handful of others that exist purely for this problem. Layer two is the legacy security platforms: CrowdStrike, Palo Alto Networks, and Zscaler, all of which have bolted some form of AI security posture management onto their existing suites. Layer three is the cloud providers: Microsoft with Purview and Defender for AI, Google with Security AI Workbench, and AWS assembling agent security components across its native services. Zenity sits at layer one, which is both its advantage and its structural vulnerability.

The advantage is the Wiz playbook. Wiz rose from nothing to a 23-billion-dollar acquisition price in roughly four years by being the purest expression of a new security need at the exact moment the market needed a name for it. The category creator gets the brand premium. In security procurement, buyers want to hand the problem to a specialist, not to a platform that treats it as a module. When a CISO is asked to secure AI agents and has never done it before, the safe answer is to hire the vendor whose entire existence is AI agent security, not the firewall vendor's new sidebar feature. That specialist preference is real, and it is the strongest force in Zenity's favor.

The vulnerability is equally real. CrowdStrike and Palo Alto have existing trust relationships, procurement contracts, and sales forces that can attach agent security as a feature at zero marginal cost. The history of security markets is a history of absorption: EDR was born as an independent category, and much of it got absorbed into SIEM and SOC platform suites. If agent security follows the same path, the independent vendors get squeezed in the middle β€” too big to be ignored, too small to bundle everything, too focused to compete on price. The defense against absorption is to own what the platforms cannot easily replicate: agent-specific identity management, multi-agent orchestration security, agent-to-agent communication monitoring. If agent security is just another log source for the SIEM, the platforms win. If it is a new identity plane for machine actors, the specialists have a defensible corner.

The July 2024 CrowdStrike outage β€” the one that froze screens around the world β€” created an opening that Zenity should exploit aggressively. That incident shattered the assumption that a single trusted security vendor can hold the entire perimeter without consequences. Enterprise security teams that once consolidated everything onto one platform are now visibly exploring multi-vendor strategies for resilience. In a trust crisis, the hungry specialist with a defined scope beats the giant with a new checkbox. Zenity's window is the next 18 to 24 months, before the platform vendors complete their agent security modules and before the cloud providers default-bundle agent governance into every enterprise agreement.

The other pressure comes from below: the open-source stack. LangChain's LangSmith, Meta's Purple Llama, and OpenAI's own agent safety evaluation tools are all moving into the detection and evaluation layer. If open-source agent-safety tooling matures to a 'good enough' state, Zenity's differentiation is forced up the stack into compliance reporting, enterprise integration, workflow orchestration, and audit-grade forensics. That is a thinner margin position, and it is the same squeeze that every security startup faces once the open-source community catches the scent. The talent competition matters too β€” a company that just raised $125 million in a down market can outbid almost anyone for security engineers and enterprise sales reps. In the war for agents, the first battle is the war for people who know how to secure them.

I would also flag the partnership question as the single most consequential strategic variable. If Zenity establishes pre-baked integrations with AWS, Azure, and GCP β€” and gets featured in their marketplaces as the default agent security component β€” it becomes the rail infrastructure of the agent economy, and the platform vendors are forced to interoperate with it rather than crush it. If those partnerships are absent, Zenity remains a point solution in an ecosystem where the cloud giants control the customer relationship. The funding round buys Zenity the credibility to sign those partnerships. Whether they were signed before the announcement, or only made possible by it, is the question I cannot answer from public information.

The ethical ledger and the security-as-accelerant paradox

Let me be frank about the uncomfortable half of this story, because it will determine how the next five years play out. Agent security is a genuinely good thing. It lowers the risk of machines running amok, and it gives enterprises accountability mechanisms they desperately need. But the tool that protects agents is also a surveillance instrument, and the narrative that it sells β€” 'your agents are dangerous, buy my shield' β€” is itself a force that accelerates agent deployment. Security has a way of becoming the enabler of the very risk it claims to manage.

Start with the surveillance problem. To secure an agent, Zenity must watch everything the agent does: every prompt, every system call, every file access, every transaction. That behavioral telemetry necessarily captures the human context around the agent β€” the employee who gave the instruction, the workflow manager who approved it, the shadow engineer who built it without permission. The boundary between 'security monitoring' and 'workplace surveillance' is thin, and it gets thinner with every compliance audit. The enterprise agent security market is quietly constructing a transparent workplace where every action, human or machine, is logged, scored, and compared against a baseline. That is a feature for the CISO, but it is a privacy liability for the company, and a growing employee-relations problem in Europe under GDPR's data-minimization principles. If Zenity's audit logs retain more data than necessary for security purposes, it has built a regulatory claim factory.

Then there is the permission-inheritance question, which is more consequential than most buyers realize. When an agent acts on behalf of a human, whose permissions does it inherit? If the agent carries the full entitlements of its human owner, then a compromised agent is a lateral-movement weapon of devastating reach β€” an inside threat that moves at machine speed across every system the human can touch. If the agent gets least privilege only, it cannot do its job. There is no standard answer, and the security vendor's default configuration effectively decides the enterprise's power structure. A default-inherit model maximizes convenience and magnifies blast radius. A default-minimal model constrains agents and slows deployment. This is not a technical parameter; it is a governance decision being made inside a config file, and it is the kind of quiet choice that produces front-page incidents three years later.

Attribution is the even deeper unresolved layer. When an agent's autonomous decision causes a loss β€” a leaked customer file, a bad trade, an offensive email sent to a supplier β€” the law still assigns liability to the enterprise that deployed it. Audit logs give the enterprise evidence, but they do not resolve the fundamental ambiguity of who, in a chain of human-and-machine responsibility, is accountable. The EU AI Act pushes liability toward providers and deployers, but the case law is unwritten. Agent security vendors will spend the next decade producing forensic records for courts that have no established legal framework for machine intent. That is a profound business opportunity β€” the forensics layer of the machine economy β€” but it is also a burden that falls unevenly on the security vendor that guaranteed the reliability of an inherently non-deterministic system.

And what about agents of agents? The cascade scenario is almost entirely unaddressed by current security products. An agent delegates to a sub-agent, which delegates to another, and the original security boundary dissolves into a graph of machine-to-machine trust that no human ever explicitly authorized. Open protocols for agent-to-agent communication are already emerging, and with them the possibility of a failure that propagates not as a fire but as a chain reaction through an entire enterprise automation mesh. The security industry is not ready for this, and public marketing material from agent security vendors has barely mentioned it. The first major incident involving cascading agent failure will redefine this market's boundaries overnight.

I have seen this movie before. In crypto, we built an entire reassurance economy around audits, insurance funds, and bug bounty programs β€” and then watched audited, insured, bountied protocols go down anyway, because the reassurance layer was not the same as the safety layer. The audit stamp did not prevent Ronin, Wormhole, or FTX. It legitimized them. The agent security market risks repeating that exact cycle: enterprises will adopt agents because a security vendor told them the governance layer was ready, and then the first high-profile agent catastrophe will expose the difference between a compliance narrative and actual protection. The 'insurance policy for the agentic future' can become the accelerant of the agentic future's reckless phase.

There is an echo of the oracle problem here, and those who live in DeFi will recognize it instantly. Chainlink built a business on 'decentralized' price feeds that are, in practice, a small set of professional node operators delivering data through a narrow, trust-bound pipe. It is the Achilles' heel of DeFi: we call it decentralization, but it is really a centralized trust assumption with a decentralized aesthetic. Agent security is walking into the same trap. A platform that watches agents, baselines their behavior, and decides what is 'normal' is itself a centralized oracle of truth β€” a point of judgment that every agent outcome depends on. The machine economy is betting that security platforms can be more reliable than the autonomous systems they police. That is a beautiful narrative and a terrifying assumption.

The contrarian read: what the market refuses to see

Let me push against the consensus that this round is unambiguously positive, because the contrarian read is where the alpha hides. The facts are strong: a real company, a real product category, serious strategic investors, and a market that clearly needs protecting. But there are four ways this story goes wrong, and none of them are priced in yet.

First, the missing American VCs. I have heard the digital-sovereignty narrative, and I think it is partially true. But I also think it is partially cope. The enterprise security market's purchasing power is still concentrated in the United States, and a company that raises a 125-million-dollar round without a single lead American VC has not proven it can win the market where the biggest budgets live. The strategic capital buys channels, but channels are not the same as conversion. A Korean consumer electronics giant can open doors; it cannot write a US federal procurement contract. If Zenity's funnel is strong in Japan and weak in America, the company is building for a future geography that may not materialize at the projected multiples.

Second, the category trap. Agent security could be a new independent category, or it could be a feature of something more established, and the difference will be visible within two years. The EDR analogy cuts both ways: EDR did survive as a distinct segment within the security stack, but only the strongest independent vendors survived; most got absorbed or squeezed into private-label contracts. The same consolidation is already stirring in agent security. If the market reclassifies agent security as 'a part of identity and access management' or 'a part of data security posture management,' the entire valuation thesis resets. Zenity's strategic challenge is not beating competitors; it is controlling the category definition before the platforms do it for them.

Third, the Wiz precedent is a double-edged sword. The 23-billion-dollar acquisition price set a headline that every security startup now gets measured against, and it tempts investors to treat 'eventually acquired by a hyperscaler' as the default exit. But Wiz earned that exit through hypergrowth and product pull. If Zenity's board is already negotiating its own acquisition timeline β€” a very plausible likelihood given three strategic industrial investor seats β€” then this loud B round may actually be the quiet beginning of the end. The company is not building to become the agent security infrastructure; it is building to be acquired by the agent security infrastructure. For a founder that is a rational outcome. For the category, it turns a would-be standard-setter into a satellite of a larger empire.

Fourth, and this is the one almost nobody in tech media wants to say out loud: the security layer may be creating the very thing it claims to prevent. Every press release about agent security reinforces the legitimacy of agents. The message is not 'be careful, this is dangerous'; the message is 'this is coming, and the professionals are on it.' That framing removes the last hesitation from enterprise deployment. If the agent security market grows exactly as projected, it will be because the prediction of mass agent deployment became a self-fulfilling prophecy β€” and in a self-fulfilling prophecy, the security vendor is not the shield. It is the salesman.

I have my own prediction in this arena, and the recent history of crypto infrastructure makes me confident in it. Two years ago, I argued that post-Dencun blob space would saturate within that window and every rollup gas fee would double. The variable I did not fully model back then was machine transaction volume. The agent economy is going to fill blob space faster than any human user wave ever could, because agents do not sleep, hesitate, or wait for weekends. Every autonomous agent settlement, every machine micropayment, every cross-agent value transfer lands on-chain as a transaction. The more enterprises trust agents β€” the more the security layer removes the friction of that trust β€” the faster the machine economy floods the base layer with demand. Security is not the brake on this timeline. It is the throttle.

The same paradox applies to Zenity's own architecture. The platform requires a central repository of behavioral truth to judge whether an agent action is anomalous. That repository becomes the most sensitive dataset in the enterprise β€” more sensitive than the agent logs themselves, because it contains the definition of normal, and therefore the map of what an attacker needs to know to blend in. The security platform is the honeypot. The first time a sophisticated adversary compromises an agent security vendor and uses its baseline knowledge to stage an invisible attack, the entire category will face a reckoning. I would not be surprised if that incident is the real crucible that defines what agent security actually becomes.

The next narrative

So where does this leave us? Zenity's $125 million round is a moment of profound clarity: the AI agent economy has reached the point where the trust layer is the growth layer. The companies that define how agents are discovered, governed, and protected will not just sell software; they will write the rules of the machine economy. That is a genuinely historic position, and the investors who just wrote those checks understand it.

Over the next 12 to 24 months, I am watching three signals. First, whether Zenity publishes an actual industry framework β€” an open schema for agent behavioral baselines, a reference architecture for agent least-privilege identity, a public detection-rule taxonomy. If it does, it is playing the format war. If it does not, it is a vendor selling a product. Second, who owns the budget. Agent security that reports to the CISO is a security product. Agent security that gets a budget line in a new Chief AI Officer's operating plan is an infrastructure category. The two paths lead to very different valuations. Third, whether the cloud providers bundle agent security into their default enterprise stacks. The moment AWS or Azure ships agent governance as a default toggle in every enterprise agreement, the independent agent security market becomes a premium add-on rather than a necessity β€” and the pricing power shifts.

For the crypto reader, the story is closer than it looks. The same trust bottleneck governs whether autonomous agents are allowed to hold wallets, execute trades, and sign transactions without human review. The same architecture question β€” centralized rule engine versus decentralized verification β€” will decide whether the agent economy runs on platform trust or on cryptographic trust. And the same dynamic that is accelerating Zenity's valuation is accelerating the demand for machine-verifiable identity, permission, and audit on public blockchains. The thread runs from a security startup in Tel Aviv to the next generation of on-chain agents, and it will not stop at the enterprise boundary.

When the first autonomous agent signs its first binding enterprise contract, whose ledger will verify that handshake? Will it be the security vendor's audit trail, the cloud provider's policy engine, or an open cryptographic record that no single company controls? The answer to that question will determine who captures the value of the machine economy β€” and the next round of capital after this one will be raised by whoever is already writing that ledger.

That is the cold truth on the ledger: trust is the bottleneck, and the poet's eye sees that whoever owns the bottleneck owns the next decade.