LeadPrysmTry it free →
← All posts
September 9, 2026

AI security funding is shifting from model risk to agent control

HiddenLayer, AIR, Resect AI, and Velatir show buyers now pay for controlling agent behavior—not just model outputs.

AI startup raises by country (last 30 days)United States30Israel6Denmark3Canada2India2Source: LeadPrysm — leadprysm.com · original tracking data
Original data from LeadPrysm's tracking of newly funded AI startups.

AI security funding for agentic systems is making one thing clear: buyers are no longer paying just to catch bad model outputs. They’re paying to control what agents can do, where they can go, and how much trust they earn at runtime.

That shift shows up in recent rounds from HiddenLayer, AIR Security, Resect AI, Velatir, and TrustedRouter. Together, they point to a market moving from hallucination detection toward governance, routing, and enforcement layers built for production AI agents. HiddenLayer announced a $100 million Series B on September 2, 2026, led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, M12, Microsoft’s venture fund, and Booz Allen Ventures. Resect AI launched out of stealth on September 3, 2026 with $25 million in funding from private equity investors. AIR Security came out of stealth on September 1, 2026 with $50 million across two seed rounds. Velatir announced a €5 million seed round on August 20, 2026, co-led by Spintop Ventures and Ugly Duckling Ventures, and TrustedRouter disclosed a $1.25 million seed round to keep building its routing layer. (hiddenlayer.com)

AI security funding trends for agentic systems are moving up the stack

The old AI security question was simple: “Is the model saying something unsafe?” The new one is harder: “Can this agent access the right tool, follow policy, and stay within bounds while it acts across systems?”

That’s why the current funding window looks different from the first wave of model-safety tooling. Buyers still care about output quality, but the budget is increasingly going to control points around the model:

  • Runtime policy enforcement
  • Agent and tool access governance
  • Model routing and trust selection
  • Visibility into prompt, tool, and action chains

LeadPrysm data shows the market backdrop is broad enough to support this shift: 84 AI startup raises tracked in the last 30 days, spanning 13 countries. Among the most active sub-verticals were Vertical SaaS AI (14) and AI Infrastructure (10), which is exactly where governance-heavy products tend to land once teams start shipping agents into real workflows.

Why HiddenLayer’s $100M Series B matters

HiddenLayer’s $100 million Series B is the clearest signal that enterprise buyers are spending on AI security as infrastructure, not as a feature. The company says it secures agentic, generative, and predictive AI applications, and its latest round was backed by a broad set of enterprise and security investors. (hiddenlayer.com)

That matters because production risk is no longer confined to a single model response. In agentic systems, a bad action can come from a prompt injection, a compromised tool call, a misrouted model, or an over-permissive workflow. HiddenLayer’s raise suggests security buyers want a platform that can watch those failure modes together. That is a different buying motion from “detect hallucinations.” It is closer to cloud security: continuous monitoring, policy control, and incident response. (hiddenlayer.com)

AIR Security and the firewall era for AI agents

AIR Security’s $50 million seed financing makes the same point more explicitly. TechCrunch reported that the startup is building a product to vet the skills and add-ons AI agents use, while the company itself describes the category as a firewall for AI agents. The startup’s investors included Sequoia Capital and Greenoaks Capital, according to Dealroom. (techcrunch.com)

That framing is important. A firewall is not a detector; it is a control plane. It decides what can pass, what gets blocked, and what needs inspection. For agentic AI security, that implies buyers are asking questions like: Which tools can this agent invoke? Which data sources can it touch? Should this action require approval? How do we stop prompt injection from turning into unauthorized behavior? (techcrunch.com)

Resect AI reflects the lingering importance of model risk

Resect AI’s $25 million raise shows the market has not abandoned model-risk concerns. The company says it is building “the accountability layer for AI,” and its launch materials position that layer around transparency and factual reliability. (resect.ai)

That is the older category, but it still matters because governance starts with trust. Enterprises cannot control agent behavior well if they cannot first measure where the system is drifting. The difference is that model-risk tools are becoming one layer in a broader stack, not the whole story. In an agentic environment, a hallucination matters most when it becomes an action. (resect.ai)

Velatir shows governance is becoming a runtime product

Velatir’s €5 million seed round is another strong datapoint. The company says it helps enterprises see and control the AI their employees are already using, and its investors include Spintop Ventures, Ugly Duckling Ventures, Norrsken Evolve, EIFO, and angels Jan Oberhauser and Thomas Visti. (publicnow.com)

This is where the market gets practical. Enterprises do not only need guardrails for autonomous agents; they need governance for the humans deploying them too. That includes shadow usage, unapproved tools, and inconsistent policy enforcement across teams. Velatir’s pitch suggests the winning category may be less about one specific model defense and more about control surfaces that unify employee AI usage, agent permissions, tool-level policy, and auditability. (publicnow.com)

Model routing is becoming part of the security stack

TrustedRouter is a smaller but telling round. Axios reported the AI routing startup raised $1.25 million from investors including Sam Lessin, Bill Tai, Linda Avey, and George Xing. The company says it is building an open source, encrypted router with verifiable trust evidence and live hardware attestation. (axios.com)

Routing used to be a cost and latency decision. Now it is also a trust decision. If one model is better for summarization, another for code, and another for policy-sensitive tasks, then routing becomes a control point for risk segmentation, policy enforcement, workload isolation, and cost-aware governance. (axios.com)

What this means for the category

The funding pattern across HiddenLayer, AIR Security, Resect AI, Velatir, and TrustedRouter suggests a new buying philosophy:

  1. Detecting hallucinations is table stakes.
  2. Controlling agent behavior is the budget line.
  3. Routing and governance are becoming the enterprise differentiators.

That also explains why adjacent categories are heating up in parallel. Vertical software teams want AI that owns the workflow, not just the model; defense buyers want procurement-ready autonomy, not demo-stage capability.

Takeaway for sellers

If you sell into AI startups, stop leading with “model safety” as a generic concept. Buyers are increasingly shopping for runtime control, governance infrastructure, and model routing that make agents safe enough to deploy. Position around policy enforcement, auditability, and tool control—or risk sounding like yesterday’s hallucination-detection vendor.

Sell to AI startups?

LeadPrysm tracks every newly funded AI startup — with founder contacts. Free to browse, no card.

Browse free →