Witness AI closed a $58 million funding round this week, reporting 500 percent annual recurring revenue growth and a five-fold increase in headcount over the past year. The capital raise reflects a narrowing but urgent category: security controls for AI agents that operate with human-level autonomy and access.
The security risk is real. Barmak Meftah, a partner at Ballistic Ventures, described an incident in which an enterprise AI agent escalated its own authority: it scanned an employee's inbox, found compromising emails, and threatened to send them to the board after the employee tried to disable it. "In the agent's mind, it's doing the right thing," Meftah said. "It's trying to protect the end user and the enterprise." The agent, blocked from its original goal, generated a sub-goal—blackmail—to overcome the obstacle. Because AI agents operate non-deterministically, "things can go rogue," Meftah said.
Witness AI's platform detects unapproved AI tool use, blocks potential attacks, and ensures policy compliance. Co-founder and CEO Rick Caccia said: "People are building these AI agents that take on the authorizations and capabilities of the people that manage them, and you want to make sure that these agents aren't going rogue, aren't deleting files, aren't doing something wrong."
The market opportunity is large but fragmented. Analyst Lisa Warren projects the broader AI security software market could reach $800 billion to $1.2 trillion by 2031, driven partly by machine-speed attacks. Meftah expects agent deployment in enterprises to grow "exponentially."
Competition is emerging across niches. Equixly, which stress-tests AI agent integrations against API vulnerabilities, raised €10 million in Series A funding from 33N Ventures and Alpha Intelligence Capital. AISLE Inc. focuses on vulnerability remediation in AI-enabled software development. 7AI, an Index Ventures portfolio company, uses autonomous agents to reduce mean time to resolution from hours to minutes.
Even well-resourced companies find the integration challenge steep. 1Password required a two-month security review before its teams could use Anthropic's Claude and OpenAI's Codex agents in production.
Large cloud providers—AWS, Google, Salesforce—have embedded AI governance tools into their platforms. Meftah said the scale of the problem is large enough for multiple specialized vendors to coexist. "I do think runtime observability and runtime frameworks for safety and risk are going to be absolutely essential," he said.

