The Control Layer Got Funded

This week the biggest checks in venture didn't go to AI agents. They went to the layer that watches them. Ent ↗ raised a $100 million seed — an extraordinary figure for a first round — to secure how AI agents behave inside the enterprise; NewCore ↗ took $66 million to give those agents identities; Arcade ↗ raised a $60 million Series A to control what they're allowed to do; and NeuralTrust ↗ closed €17.2 million for the same problem in Europe. Four of the week's largest rounds, one job: governing software that now acts on its own.

The signal underneath the noise is a shift in what the market will pay for. Agents stopped being a demo this week and started transacting — Alchemy and Visa gave them a way to pay, Adyen built the rails to sell to them. The moment software can spend money and take actions, the control layer stops being a feature and becomes the product. What changed is not enthusiasm for agents. It's that the guardrails, not the agents, became the investable category — and capital tends to fund the brakes right before the car gets fast.

$100M
Largest Seed of the Week — Ent, Agent Security
$300M
Raised to Govern AI Agents in One Week
€17.2M
Largest EU Cybersecurity Seed, Per NeuralTrust
$1,500
Uber's Monthly Cap, Per AI Coding Tool
⚡ Signal of the Week

NeuralTrust Raises €17.2M to Secure and Govern Enterprise AI Agents — the Week the Control Layer Became the Category

Barcelona-based NeuralTrust raised €17.2 million (about $20 million), led by Alstin Capital, in what the company bills as the largest cybersecurity seed ever raised by a European company — to inspect the traffic AI agents generate and block malicious or runaway calls in real time. Read past the single round and the week's pattern is the story: NeuralTrust is one of four large rounds — alongside Ent's $100M ↗, NewCore's $66M ↗, and Arcade's $60M ↗ — that all funded the same thing: the layer that secures, identifies, and governs autonomous agents. Capital isn't betting on which agent wins; it's betting that whoever controls them gets paid. And the timing isn't accidental. The same week these rounds closed, Uber capped what its engineers can spend on agentic coding and Meta started metering AI by the token — the enterprises buying agents are demanding control over them in the same breath. When a capability spreads, the right to govern it becomes the business.

✦ Founder Signal
This is the week to look at agents as a surface, not just a tool. If your product lets an AI agent take actions — move money, write to a database, call an API on a user's behalf — write down exactly what it is allowed to do and what stops it when it misbehaves. If that answer is "nothing formal yet," you've just found either your biggest risk or your next feature. The capital flowing to NeuralTrust, Ent, and NewCore is paying for the answer you're missing — build the cheap version of it into your own product before a customer makes it a requirement.
Filter:
Showing 12 of 12 signals
💰 Fundraising Reality ⏳ Context

Ent Emerges From Stealth With a $100M Seed to Put Security in Front of AI Agents

A seed priced like a Series B says agent-aware security is a platform bet, not a feature.

Ent left stealth with a $100 million seed — an extraordinary first round — led by Decibel Partners with Sequoia, Craft, and Crosspoint. Built by operators out of RiskIQ and Microsoft's Security Copilot, the company reads intent across both human and AI-agent behavior to stop threats before they execute. The size is the signal: investors are treating agent-aware workspace security not as a feature inside someone else's suite, but as a standalone, platform-scale category. When a seed is priced like a Series B, the market is saying the problem is already big.

✦ Founder Signal
Ent's $100M seed marks where security budgets are about to move: toward watching what agents do, not just who logs in. If you sell into security or IT, expect "how do you govern AI agents" to enter your buyers' questions within a quarter — have a real answer ready. If you build with agents, assume enterprise customers will soon require agent-level audit logs and behavior controls; start capturing that telemetry now so you're not retrofitting it under a procurement deadline.
💰 Fundraising Reality ⏳ Context

NewCore Emerges With $66M to Give AI Agents Their Own Identities

Agents are becoming employees — give each one its own identity, permissions, and off-switch.

NewCore came out of stealth with a $66 million seed led by Cyberstarts, at a reported ~$300 million valuation, to build identity infrastructure designed for AI agents rather than people. The premise, from a team that previously built Dome9: every agent should be a first-class identity with its own permissions, lifecycle, and revocation — the way employees are, not the way shared API keys are. As agents proliferate inside companies, the old model of shared service credentials breaks, and someone has to own who each agent is and what it can touch. Identity, not the model, becomes the control point.

✦ Founder Signal
NewCore's bet is that "who is this agent and what can it do" becomes a board-level question fast. If your product deploys agents into customer environments, stop giving them shared credentials and give each one a scoped, revocable identity now — it's a security story you can sell, not just debt you carry. If you're building internal agents, write down today which systems each one can reach; the company that can answer that in a single table will pass enterprise security review, and the one that can't will stall in it.
💰 Fundraising Reality ⏳ Context

Arcade Raises $60M Series A to Be the Secure "Action Layer" Behind Production AI Agents

Separate what an agent can do from what it's allowed to do — and log every action.

Arcade raised a $60 million Series A (about $72 million total), led by SYN Ventures with Morgan Stanley and Wipro, to run the layer that lets AI agents actually do things in production — authorization, scoped access, and governance across more than 8,000 connected tools. The founding team, out of Okta, authored the authorization spec for the Model Context Protocol, the emerging standard for how agents call tools. That it's a Series A, not a seed, says the governance thesis has graduated from experiment to infrastructure. An agent doesn't create value until it acts — and Arcade is betting the money is in controlling the action.

✦ Founder Signal
Arcade's round tells you "the agent can do it" and "the agent is allowed to do it" are becoming two separate products. If your agent takes real actions, separate capability from authorization in your own architecture: every consequential action should pass through a check you can see, log, and revoke. Buyers moving agents to production will ask who approved a given action before they ask how smart it was — design that audit trail in now, while it's a small change instead of a rebuild.
🤖 Build Reality ⏳ Context

Ex-Cisco AI Defense Builders Launch Tenet With $6M to Stop "Agentjacking"

An agent that can act can be hijacked mid-task — gate every irreversible action before it runs.

Tenet Security launched with a $6 million seed, led by The Westly Group and MizMaa, from founders who helped build Cisco's AI Defense. Its approach — "agent-side simulation" — predicts and simulates an agent's next action to block risky paths before they execute, defending against what it calls "agentjacking," where an attacker hijacks an autonomous agent mid-task. It's the smallest round in this week's security cluster, but it names a concrete new attack surface that didn't exist before agents could act on their own. New capability, new exposure, new market.

✦ Founder Signal
Tenet exists because an agent that can act can be tricked into acting against you. If your product runs autonomous agents, treat prompt injection and tool misuse as security threats, not edge cases: add a check before any irreversible action, and assume any input an agent reads could be hostile. The teams that designed for this before shipping will sell into security-conscious enterprises; the ones who didn't will learn about agentjacking from an incident report.
💰 Fundraising Reality ⏳ Context

Magnitude Launches With $10M to Put an "Autonomous AI Workforce" on Third-Party Risk

Point-in-time vendor reviews are dying — expect continuous, always-on risk monitoring instead.

Magnitude came out of stealth with a $10 million seed led by Ballistic Ventures, deploying a workforce of AI agents to handle third- and Nth-party risk management — continuous vendor risk assessment in place of the point-in-time security review. The founder previously built at Abnormal and Proofpoint. It's the week's pattern from the other side: agents aren't just the thing being governed, they're the thing doing the governing. The control layer is being automated as fast as it's being funded.

✦ Founder Signal
Magnitude is a sign the annual vendor security questionnaire is becoming a live, always-on assessment. If you sell software to enterprises, assume your security posture will be monitored continuously, not just at procurement — keep your SOC 2, sub-processor list, and incident history current, because a buyer's AI agent may re-check them monthly. The vendors who stay continuously clean will sail through; the ones who scramble once a year will start failing reviews they used to pass.
🌐 Regulatory Reality ⏳ Context

Andera Raises $37M Series A to Automate Audit and Compliance Testing With LLMs

If audit or compliance labor is your moat, automation just lowered the wall — move to judgment.

Andera raised a $37 million Series A led by Lightspeed to automate internal audit and compliance-control testing — using long-context models to read PDFs, screenshots, and ledgers, run control tests, and assemble the workpapers auditors used to build by hand. It points at a quieter front in the agent shift: the back-office knowledge work that was too unstructured to automate is now in range. For founders, it reframes where defensibility lives — when the testing is automated, the value moves to the judgment and the accountability, not the manual labor.

✦ Founder Signal
Andera's round is a warning and an opening. If your business sells the manual version of a compliance, audit, or review workflow, assume an AI-native competitor will undercut the labor cost within a year — move your value toward judgment, accountability, and outcomes you can stand behind. If you're a founder in a regulated space, this is the week to ask which of your own compliance tasks could be automated now, and reinvest the saved hours into the parts a model can't sign its name to.
🤖 Build Reality 📡 Developing

Alchemy and Visa Give AI Agents a Way to Pay, With "AgentCard"

An agent may soon check out on your site — decide whether you're a seller or a buyer to it.

Alchemy launched AgentCard, a payments-and-identity stack built on Visa Intelligent Commerce that hands an AI agent its own Visa payment token — plus an email, phone, and wallet — through a single API, with spend controls and merchant limits so the agent can buy on a person's behalf. It's not a funding round; it's infrastructure, and that's what makes it a signal. When a network like Visa gives agents a sanctioned way to transact, autonomous commerce stops being a thought experiment. The rails are being laid for software to be a customer.

✦ Founder Signal
AgentCard means an AI agent may soon be the one checking out on your site — or buying on behalf of your user. Decide which side you're on: if you sell, start thinking about how an agent evaluates and purchases your product (structured data, machine-readable pricing, clean APIs); if you build for consumers, ask whether letting an agent transact for your user is a feature you should own before a platform owns it for you. The buyers in your funnel are about to include software.
📊 GTM Reality 📡 Developing

Adyen Launches "Adyen Agentic" to Plug Merchants Into Agent-Led Commerce

Make sure an agent can actually transact with you — or fall out of its consideration set.

Adyen introduced Adyen Agentic — a set of modular APIs (Agentic Feed, Agentic Cart, Agentic Payments) that position the payments giant as a "universal translator" between merchants and conversational, agent-led commerce, with early partners including Amex, Mastercard, Visa, and Salesforce. Coming the same week as Alchemy's AgentCard, it's the second major signal that the payments layer is being rebuilt for buyers that aren't human. The distribution channel of the next few years may not have a face — and the incumbents are already building for it.

✦ Founder Signal
Adyen building for agent checkout tells you the discovery-and-purchase path is being rewired around machines. If you run an e-commerce or marketplace product, make sure an agent can complete a purchase with you without a human-only UI — expose your catalog and checkout in ways software can consume. The merchants who are agent-readable will get bought from; the ones whose only path is a human clicking through will quietly fall out of the agent's consideration set.
📊 GTM Reality ⏳ Context

Enterprises Put a Price on AI: Uber Caps Agentic Coding at $1,500 a Seat, Meta Meters the Token

Your buyers now budget AI by the dollar — sell return per seat, not raw capability.

The same week capital flooded into agent infrastructure, the companies buying it started rationing. A widely-shared analysis framed the shift from "tokenmaxxing to ROI-maxxing": Uber now caps what each employee can spend per agentic coding tool at $1,500 a month after burning its annual AI budget in four months, and Meta is building centralized spend controls and usage dashboards as token consumption spikes, with formal per-department budgets on the way. The era of unmetered AI experimentation is closing. Enterprises will keep spending — but now they're counting, and they expect a return on each dollar.

✦ Founder Signal
If you sell an AI product to enterprises, the budget you're selling into just got a ceiling and a scoreboard. Price and pitch around return per seat, not raw capability — show a buyer what one employee gets back for $1,500 a month, because that's the number they now track. And instrument your own cost-per-outcome before a customer's finance team does it for you: the products that can prove ROI will survive the metering, and the ones that can only show usage will get capped.
🤖 Build Reality 🔥 Breaking

Chip Startup Tensordyne Expects $200M in Orders for Its "Napier" AI Inference System

Inference economics are the floor under every agent — watch where cost-per-call goes next.

Tensordyne said it expects more than $200 million in orders for Napier, a new AI inference system built with Broadcom and Juniper and manufactured by TSMC, with the CEO citing more than a dozen letters of intent. It's the durable counterweight to a week dominated by security software: every agent that gets secured still has to run, and the cost of running it is set at the silicon layer. Cheaper, denser inference is what makes always-on agents economically viable in the first place. The control layer gets the headlines; the compute layer sets the budget.

✦ Founder Signal
Tensordyne is a reminder that your agent's unit economics are decided below your code, at the inference layer. Track cost-per-completed-task as a first-class metric, and watch where inference pricing moves over the next few quarters — a step-change in efficiency can turn a workflow that's too expensive to ship today into a viable product next year. Don't permanently rule out the use cases the current cost makes uneconomic; some of them are one hardware cycle away from working.
🏦 Capital Structure 📡 Developing

Seedcamp Raises $320M Across Two Funds, Pointed at Physical AI and the US

Seed capital is abundant and selective — bring a sharp wedge, not a broad AI story.

Europe's Seedcamp closed $320 million across two funds — a roughly $220 million flagship and a $100 million follow-on vehicle — pushing its assets toward $1 billion and expanding its US footprint, with a notable thesis on AI in the physical world. The takeaway for founders isn't the headline number; it's what it confirms. Seed capital is not scarce — there is fresh, dedicated money looking for early companies. It is selective, and increasingly willing to back atoms, not just bits. The room has money; it's deciding what to spend it on.

✦ Founder Signal
Seedcamp's new $320 million is proof the seed market is open — which means the constraint on your raise is rarely the capital, it's the clarity. Walk in with one sentence on the specific problem you own and who pays for it, not a general AI narrative, because abundant capital makes investors more selective, not less. If you're building in the physical world, note that "physical AI" is now an explicit thesis at a fund this size — there is money looking for you, if you can name your wedge.
🏦 Capital Structure ⏳ Context

SpaceX Buys Cursor-Maker Anysphere for $60B as Salesforce Takes Fin for $3.6B

The exit lane reopened at the top — keep your books clean enough to move when a buyer does.

Two of the largest strategic deals in memory landed in the same week: SpaceX agreed to acquire Anysphere, the company behind the AI coding tool Cursor, for roughly $60 billion in stock — described as the largest venture-backed acquisition ever — while Salesforce agreed to buy Fin (formerly Intercom) for about $3.6 billion all-cash. Last week SpaceX completed the largest IPO in history; this week it spent that new currency on AI. The exit window we flagged as opening last week ↗ hasn't just opened for listings — it's open for acquisitions, and strategic buyers are using fresh public stock to move.

✦ Founder Signal
These deals confirm the exit market is live at the top — and credible exits up there tend to loosen acquirer appetite below them over the following quarters. You can't engineer a $60 billion outcome, but you can be ready when a strategic comes calling: keep a current cap table, clean financials, and documented IP in one place a buyer's team can diligence in days, not months. The founders who get acquired cleanly are the ones who were organized before the inbound, not the ones who scrambled after it.

Fund the Brakes

The easy read of this week is that AI agents are taking over — paying, buying, coding, auditing. The more useful read is the opposite: the market just decided the agents aren't the valuable part. The biggest checks went to the companies that decide what agents are allowed to do.

Look at where the money actually went. Ent raised a $100 million seed and NewCore $66 million to identify and watch agents; Arcade took $60 million to authorize their actions; NeuralTrust closed €17.2 million for the same problem in Europe. Meanwhile Alchemy and Visa handed agents a way to pay, and Adyen built the rails to sell to them. Capability went one way; control went the other — and control is where the capital pooled.

Most people will read a week of security rounds as defense — a tax you pay to deploy AI safely. The sharper read is that control is the product. The same enterprises funding the guardrails are the ones capping their own AI spend — Uber at $1,500 a seat, Meta by the token. They're not buying agents and hoping. They're buying agents and demanding to govern them, and they'll pay whoever lets them.

"The most fundable companies this week weren't the agents doing the work — they were the ones deciding what the agents are allowed to do."
— JD Audena · The VC Concierge · June 2026

Last week the ground moved under the model ↗, when a government switched off capability that live products were built on. This week the market answered — not with fear, but with a category: the layer that controls what gets built on top. That's the pattern worth holding. Dependency created a problem, and capital turned it into an industry.

Read it forward. The control layer isn't a brake on ambition; it's what lets you floor it — autonomy you can govern is autonomy you can actually ship. SpaceX took the public-market currency it raised last week and spent $60 billion on AI this week; the giants are moving. Your move isn't to match them. It's to build the specific piece of this control layer they're too broad to touch — and to govern your own agents well enough that you're free to make them do more. Belief becomes capital — and this week, the belief getting funded is that what you can control, you can finally trust.

JD
JD Audena
⚡ The VC Concierge