Here’s what I’m seeing in boardrooms across the Fortune 500: executives who spent 2023 chasing ChatGPT demos are spending 2024 cleaning up security incidents. The ones who moved fast without governance frameworks are now explaining to regulators why their AI agents accessed systems they shouldn’t have. Some are facing seven-figure remediation costs.
So when Onyx Security raises $113 million in Series B funding at a $640 million valuation—just four months after leaving stealth—it tells me the market has finally caught up to what security leaders have been screaming about for eighteen months. The gold rush phase is over. The governance phase has begun.
The Billion-Dollar Question Nobody Was Asking
Every CISO I’ve worked with in the past year has asked me the same question: “How do we know what our AI agents are actually doing?” Not what they’re supposed to do. Not what the vendor promised they’d do. What they’re actually doing, right now, in production, with real customer data and real system access.
Until recently, the honest answer was: you don’t.
The organizations getting this right have built elaborate monitoring systems, custom logging frameworks, and manual review processes that cost millions and scale poorly. The rest are running blind, hoping their prompt engineering is bulletproof and their API keys don’t leak. Hope, as any board member will tell you, is not a control framework.
Onyx’s control plane approach represents the first serious attempt I’ve seen at solving this at scale. They’re positioning themselves between AI agents and enterprise systems—a chokepoint architecture that lets security teams see, approve, and audit every action an AI agent takes. Think of it as a firewall for AI behavior, except instead of blocking ports, you’re blocking an agent from, say, modifying financial records without human approval.
Why Bessemer Wrote the Check
Bessemer Venture Partners doesn’t throw $113 million at problems that might exist. They invest in problems that are already costing enterprises millions and will cost them billions if left unsolved. The speed of this raise—from stealth to $640 million valuation in four months—tells you everything about market urgency.
What Bessemer sees that many enterprises don’t yet grasp: we’re about to deploy millions of AI agents with the equivalent of admin access to critical systems. These aren’t chatbots answering customer questions. These are autonomous systems making decisions about credit approvals, medical diagnoses, supply chain routing, and hiring recommendations. The blast radius of a compromised or misbehaving agent isn’t a bad customer experience—it’s regulatory violations, discrimination lawsuits, and catastrophic business decisions made at machine speed.
I’ve sat in incident response meetings where a single misconfigured AI agent cost more than Onyx’s entire Series B. One financial services client discovered their loan approval agent had been systematically discriminating against protected classes for three months before anyone noticed. The remediation, legal costs, and regulatory fines exceeded $200 million. The reputational damage was incalculable.
The Governance Gap That’s Killing Enterprise AI
Here’s the pattern I see repeatedly: Company deploys AI agents. AI agents work beautifully in controlled environments. AI agents hit production and encounter edge cases. AI agents make decisions that would get a human fired. Company scrambles to add governance retroactively. Damage is already done.
According to recent data, roughly a quarter of CISOs fully own AI governance, while more than half co-lead with another function. This fractured ownership creates accountability gaps that sophisticated threat actors and compliance auditors will exploit. When I ask boards who’s responsible when an AI agent violates GDPR, I usually get silence followed by finger-pointing.
The organizations successfully deploying AI at scale have learned three things:
First, runtime governance beats design-time governance. You can’t prompt-engineer your way to compliance. The agent’s behavior in production, under stress, with real data, facing adversarial inputs—that’s what matters. Everything else is theater.
Second, human oversight doesn’t mean human bottlenecks. The successful implementations I’ve seen use graduated autonomy: AI agents get more freedom as they prove trustworthy, but critical actions always require human approval. Onyx’s control plane enables this without forcing humans to review every trivial decision.
Third, auditability is non-negotiable. When the EU AI Act auditors show up—and they will—you need to prove not just what your AI did, but why it did it, who authorized it, and how you prevented it from doing what it shouldn’t. The companies treating this as an afterthought are accumulating technical debt that will crush them when regulations tighten.
The Hard Economics of AI Control
Let me share some numbers from the field. A global pharmaceutical company I advised spent $3.2 million building internal AI governance tools. They scraped them six months later for Onyx’s predecessor solution because maintaining custom governance infrastructure was eating 40% of their AI team’s capacity.
Another client, a major retailer, calculated that manual review of AI decisions was costing them $50,000 per day in delayed operations. They needed automated governance that could keep pace with thousands of daily AI-driven inventory decisions while still maintaining control over high-stakes choices.
This is the economic reality Onyx is betting on: the cost of ungoverned AI will always exceed the cost of governance, but only if the governance layer doesn’t destroy the value prop of AI in the first place. It’s a narrow corridor to navigate. Make governance too heavy, and you’ve negated AI’s speed advantage. Make it too light, and you’re one incident away from congressional hearings.
What This Means for Your AI Strategy
For CISOs and CTOs, Onyx’s funding is validation that the board-level concerns you’ve been raising are real. You’re not being paranoid; you’re being prudent. Use this news to push for proper AI governance budget before, not after, your first major incident.
For CEOs and boards, understand that AI governance isn’t optional overhead—it’s table stakes for enterprise AI. The question isn’t whether you need an AI control plane; it’s whether you build, buy, or partner to get one. Given the complexity and stakes, I’m seeing more enterprises choosing to buy or partner rather than build.
For legal and compliance teams, solutions like Onyx’s control plane offer something you’ve been desperately seeking: evidence. When regulators ask how you ensure AI compliance, you can point to concrete controls, audit logs, and approval workflows rather than hand-waving about “responsible AI principles.”
The Patterns of Success
The enterprises successfully scaling AI while maintaining control share several characteristics:
They treat AI agents as privileged users, not tools. Just as you wouldn’t give a new employee admin access on day one, AI agents earn privileges through demonstrated competence and compliance.
They instrument everything. Every AI decision, every data access, every system interaction gets logged, analyzed, and retained. Storage is cheap; lawsuits are expensive.
They practice graduated autonomy. Start with human-in-the-loop for everything, then gradually expand autonomous operation for proven use cases. The path to full autonomy goes through partial autonomy, not around it.
They separate execution from governance. The teams building AI capabilities shouldn’t be the same teams governing them. You need tension between innovation and control—productive tension that keeps you in that narrow corridor of value.
What the Next 18 Months Hold
Based on what I’m seeing in enterprise AI deployments, here’s what’s coming:
First, expect a high-profile AI governance failure that triggers regulatory acceleration. We’re one major incident away from emergency regulations that will make GDPR look permissive. The companies with mature governance frameworks will have a massive competitive advantage when this happens.
Second, the control plane will become the new battleground for enterprise AI. Just as every company needed a cloud strategy five years ago, every company will need an AI governance strategy by 2026. Vendors like Onyx who establish themselves as the governance layer will have enviable market positions.
Third, AI insurance will become mandatory and expensive. Insurers are already asking detailed questions about AI governance in cyber policies. Companies without demonstrable controls will face prohibitive premiums or coverage exclusions.
Fourth, we’ll see the emergence of AI-specific compliance frameworks and certifications. SOC 2 for AI is coming. ISO 27001 for AI is coming. The companies who get certified early will win enterprise deals while their competitors scramble to catch up.
The Board-Level Conversation You Need to Have
If you’re in the C-suite or advising boards, here’s the conversation you need to initiate: “What happens when our AI agents do something we didn’t intend?”
Not if. When.
Because they will. The question is whether you’ll know about it immediately or discover it during litigation. Whether you can stop it instantly or watch it cascade through your systems. Whether you can prove compliance or hope the auditors don’t look too closely.
Onyx’s massive funding round isn’t just about one company’s growth trajectory. It’s a $113 million signal that the market has recognized what some of us have been saying for two years: ungoverned AI is an existential risk to the enterprise. The companies that recognize this and act accordingly will thrive in the age of autonomous AI. The ones that don’t will become cautionary tales at conferences.
The organizations getting this right aren’t slowing down their AI adoption. They’re accelerating it—but with proper controls in place. They understand that governance isn’t the enemy of innovation; it’s what makes innovation sustainable at enterprise scale.
Your move, board. The clock is ticking, the agents are learning, and the regulators are watching. What’s your control plane strategy?
