This week the biggest checks in venture didn't go to AI agents. They went to the layer that watches them. Ent ↗ raised a $100 million seed — an extraordinary figure for a first round — to secure how AI agents behave inside the enterprise; NewCore ↗ took $66 million to give those agents identities; Arcade ↗ raised a $60 million Series A to control what they're allowed to do; and NeuralTrust ↗ closed €17.2 million for the same problem in Europe. Four of the week's largest rounds, one job: governing software that now acts on its own.
The signal underneath the noise is a shift in what the market will pay for. Agents stopped being a demo this week and started transacting — Alchemy and Visa gave them a way to pay, Adyen built the rails to sell to them. The moment software can spend money and take actions, the control layer stops being a feature and becomes the product. What changed is not enthusiasm for agents. It's that the guardrails, not the agents, became the investable category — and capital tends to fund the brakes right before the car gets fast.
Barcelona-based NeuralTrust raised €17.2 million (about $20 million), led by Alstin Capital, in what the company bills as the largest cybersecurity seed ever raised by a European company — to inspect the traffic AI agents generate and block malicious or runaway calls in real time. Read past the single round and the week's pattern is the story: NeuralTrust is one of four large rounds — alongside Ent's $100M ↗, NewCore's $66M ↗, and Arcade's $60M ↗ — that all funded the same thing: the layer that secures, identifies, and governs autonomous agents. Capital isn't betting on which agent wins; it's betting that whoever controls them gets paid. And the timing isn't accidental. The same week these rounds closed, Uber capped what its engineers can spend on agentic coding and Meta started metering AI by the token — the enterprises buying agents are demanding control over them in the same breath. When a capability spreads, the right to govern it becomes the business.
Ent left stealth with a $100 million seed — an extraordinary first round — led by Decibel Partners with Sequoia, Craft, and Crosspoint. Built by operators out of RiskIQ and Microsoft's Security Copilot, the company reads intent across both human and AI-agent behavior to stop threats before they execute. The size is the signal: investors are treating agent-aware workspace security not as a feature inside someone else's suite, but as a standalone, platform-scale category. When a seed is priced like a Series B, the market is saying the problem is already big.
NewCore came out of stealth with a $66 million seed led by Cyberstarts, at a reported ~$300 million valuation, to build identity infrastructure designed for AI agents rather than people. The premise, from a team that previously built Dome9: every agent should be a first-class identity with its own permissions, lifecycle, and revocation — the way employees are, not the way shared API keys are. As agents proliferate inside companies, the old model of shared service credentials breaks, and someone has to own who each agent is and what it can touch. Identity, not the model, becomes the control point.
Arcade raised a $60 million Series A (about $72 million total), led by SYN Ventures with Morgan Stanley and Wipro, to run the layer that lets AI agents actually do things in production — authorization, scoped access, and governance across more than 8,000 connected tools. The founding team, out of Okta, authored the authorization spec for the Model Context Protocol, the emerging standard for how agents call tools. That it's a Series A, not a seed, says the governance thesis has graduated from experiment to infrastructure. An agent doesn't create value until it acts — and Arcade is betting the money is in controlling the action.
Tenet Security launched with a $6 million seed, led by The Westly Group and MizMaa, from founders who helped build Cisco's AI Defense. Its approach — "agent-side simulation" — predicts and simulates an agent's next action to block risky paths before they execute, defending against what it calls "agentjacking," where an attacker hijacks an autonomous agent mid-task. It's the smallest round in this week's security cluster, but it names a concrete new attack surface that didn't exist before agents could act on their own. New capability, new exposure, new market.
Magnitude came out of stealth with a $10 million seed led by Ballistic Ventures, deploying a workforce of AI agents to handle third- and Nth-party risk management — continuous vendor risk assessment in place of the point-in-time security review. The founder previously built at Abnormal and Proofpoint. It's the week's pattern from the other side: agents aren't just the thing being governed, they're the thing doing the governing. The control layer is being automated as fast as it's being funded.
Andera raised a $37 million Series A led by Lightspeed to automate internal audit and compliance-control testing — using long-context models to read PDFs, screenshots, and ledgers, run control tests, and assemble the workpapers auditors used to build by hand. It points at a quieter front in the agent shift: the back-office knowledge work that was too unstructured to automate is now in range. For founders, it reframes where defensibility lives — when the testing is automated, the value moves to the judgment and the accountability, not the manual labor.
Alchemy launched AgentCard, a payments-and-identity stack built on Visa Intelligent Commerce that hands an AI agent its own Visa payment token — plus an email, phone, and wallet — through a single API, with spend controls and merchant limits so the agent can buy on a person's behalf. It's not a funding round; it's infrastructure, and that's what makes it a signal. When a network like Visa gives agents a sanctioned way to transact, autonomous commerce stops being a thought experiment. The rails are being laid for software to be a customer.
Adyen introduced Adyen Agentic — a set of modular APIs (Agentic Feed, Agentic Cart, Agentic Payments) that position the payments giant as a "universal translator" between merchants and conversational, agent-led commerce, with early partners including Amex, Mastercard, Visa, and Salesforce. Coming the same week as Alchemy's AgentCard, it's the second major signal that the payments layer is being rebuilt for buyers that aren't human. The distribution channel of the next few years may not have a face — and the incumbents are already building for it.
The same week capital flooded into agent infrastructure, the companies buying it started rationing. A widely-shared analysis framed the shift from "tokenmaxxing to ROI-maxxing": Uber now caps what each employee can spend per agentic coding tool at $1,500 a month after burning its annual AI budget in four months, and Meta is building centralized spend controls and usage dashboards as token consumption spikes, with formal per-department budgets on the way. The era of unmetered AI experimentation is closing. Enterprises will keep spending — but now they're counting, and they expect a return on each dollar.
Tensordyne said it expects more than $200 million in orders for Napier, a new AI inference system built with Broadcom and Juniper and manufactured by TSMC, with the CEO citing more than a dozen letters of intent. It's the durable counterweight to a week dominated by security software: every agent that gets secured still has to run, and the cost of running it is set at the silicon layer. Cheaper, denser inference is what makes always-on agents economically viable in the first place. The control layer gets the headlines; the compute layer sets the budget.
Europe's Seedcamp closed $320 million across two funds — a roughly $220 million flagship and a $100 million follow-on vehicle — pushing its assets toward $1 billion and expanding its US footprint, with a notable thesis on AI in the physical world. The takeaway for founders isn't the headline number; it's what it confirms. Seed capital is not scarce — there is fresh, dedicated money looking for early companies. It is selective, and increasingly willing to back atoms, not just bits. The room has money; it's deciding what to spend it on.
Two of the largest strategic deals in memory landed in the same week: SpaceX agreed to acquire Anysphere, the company behind the AI coding tool Cursor, for roughly $60 billion in stock — described as the largest venture-backed acquisition ever — while Salesforce agreed to buy Fin (formerly Intercom) for about $3.6 billion all-cash. Last week SpaceX completed the largest IPO in history; this week it spent that new currency on AI. The exit window we flagged as opening last week ↗ hasn't just opened for listings — it's open for acquisitions, and strategic buyers are using fresh public stock to move.
The easy read of this week is that AI agents are taking over — paying, buying, coding, auditing. The more useful read is the opposite: the market just decided the agents aren't the valuable part. The biggest checks went to the companies that decide what agents are allowed to do.
Look at where the money actually went. Ent raised a $100 million seed and NewCore $66 million to identify and watch agents; Arcade took $60 million to authorize their actions; NeuralTrust closed €17.2 million for the same problem in Europe. Meanwhile Alchemy and Visa handed agents a way to pay, and Adyen built the rails to sell to them. Capability went one way; control went the other — and control is where the capital pooled.
Most people will read a week of security rounds as defense — a tax you pay to deploy AI safely. The sharper read is that control is the product. The same enterprises funding the guardrails are the ones capping their own AI spend — Uber at $1,500 a seat, Meta by the token. They're not buying agents and hoping. They're buying agents and demanding to govern them, and they'll pay whoever lets them.
Last week the ground moved under the model ↗, when a government switched off capability that live products were built on. This week the market answered — not with fear, but with a category: the layer that controls what gets built on top. That's the pattern worth holding. Dependency created a problem, and capital turned it into an industry.
Read it forward. The control layer isn't a brake on ambition; it's what lets you floor it — autonomy you can govern is autonomy you can actually ship. SpaceX took the public-market currency it raised last week and spent $60 billion on AI this week; the giants are moving. Your move isn't to match them. It's to build the specific piece of this control layer they're too broad to touch — and to govern your own agents well enough that you're free to make them do more. Belief becomes capital — and this week, the belief getting funded is that what you can control, you can finally trust.