Your AI Agent Has Too Many Keys
A $60 million stealth exit, a clear pattern, and one reason the narrow bet beats the grand one.
Give a new hire the keys to every room in the building on their first day. Now let them work at machine speed, around the clock, and never ask permission twice. That’s roughly what a lot of companies are doing with AI agents right now, and this week the money started betting on the cleanup.
On July 28, a Tel Aviv startup called Act Security walked out of stealth with $60 million and a blunt thesis: the problem isn’t that companies can’t find their security risks, it’s that AI can now exploit those risks faster than any human can patch them. The funding came in two rounds, a $20 million seed led by Team8 and Bessemer Venture Partners and a $40 million Series A led by Notable Capital, per the company’s launch announcement. The founders previously built Medigate, the medical-device security company Claroty acquired for $400 million. Act’s pitch is to shrink the access surface itself. The company says close to 97% of cloud permissions sit dormant and unused, quietly waiting to be inherited by a workload or an agent that shouldn’t have them.
Act wasn’t alone. The same day, Hush Security added a $30 million Series A, backed by Akamai, Battery Ventures, and YL Ventures, to govern non-human identities and enterprise AI agents. Per Crunchbase, startups at the intersection of AI and security have raised around $855 million in 2026. The pattern is hard to miss: as agents get deployed, someone has to hold their keys.
Here’s the model I’d apply. Gall’s Law: a complex system that works is almost always found to have evolved from a simple system that worked. You don’t design a working complex system from scratch. You grow one from a small thing that already does its job.
That’s the lens for this whole category. Cloud security spent a decade building the comprehensive dashboard that surfaces every possible risk, and AI just made those dashboards impossible to act on in time. The teams getting funded now aren’t promising to govern everything at once. They’re starting from one narrow, almost boring primitive: kill the access nobody uses, enforce least privilege, remove the path instead of watching it.
So here’s the contrarian close. Over the next year, you’ll see a stack of startups pitch the all-in-one “AI agent control plane,” the single platform that governs every agent everywhere. Gall’s Law says be skeptical of the grand version. The winners in this wave probably won’t be whoever promises the most. They’ll be whoever nails the smallest thing that actually works, then earns the right to grow from there. In security, boring and deterministic tends to beat ambitious and sprawling.
The agents are already inside the building. The question every operator should be asking isn’t how smart they are. It’s how many doors they can open.
That’s it for today. If you want the full set of 50 mental models I use to read moves like this one, you can grab my book, Mental Models: How to Think, Act, and Win, on Amazon right now.
Spence
This post is for informational purposes only and is not investment advice, a recommendation, or a solicitation to buy or sell any security or asset. Funding figures and company claims are as reported by the companies and cited outlets and have not been independently verified. Always do your own research and consult a licensed professional before making financial decisions.
If you want the mental models behind breakdowns like this, my book, Mental Models: How to Think, Act, and Win, is on Amazon now.


This post is for informational and educational purposes only. It is not investment advice, a recommendation, or a solicitation to buy or sell any security. Funding figures, revenue, and valuation are as reported by the company, regulatory filings, and named outlets; the ~$470M valuation is a reported, time-sensitive snapshot and not independently verified. Dhoni's individual investment amount was not disclosed. The /mkt reference is a structural illustration of building in regulated markets and is not an offer or solicitation. Past performance and third-party investment decisions do not indicate future results.



