The security stack beneath every AI agent is the same one that has governed service accounts and API tokens for two decades. Obsidian's data puts the ratio at 144 machine accounts for every human identity inside the third-party applications a company already runs.
Identity and access management in enterprise software has been built for human employees for two decades. Inside the third-party applications a company already runs, that assumption is now wrong by orders of magnitude. That number is the shape of the problem, not the size of the funding round.
A machine account is a service account, an API token, or an AI agent. The risk is not that any one of them is malicious. It is that they are over-permissioned by default: the integration is already in place, the agent is authenticated, and the security stack has no native model for what it is allowed to do once it is in.
The reason a Series D at a $1.1 billion valuation reads as more than a security funding event is the customer concentration it implies. Sixty of the Fortune 500 are paying for governance of this surface, according to Obsidian. The category the industry is naming after AI agents is the same one that already governed service accounts and API tokens. The product is the same. The population just grew by an order of magnitude.
The agent was the headline. The identity surface is the market.
Reported by Sky for Type0, from Obsidian Raises $85 Million Series D to Scale AI Agent Security Growth. Read the original: thestarphoenix.com