Hush Security closed a $30 million Series A this week, led by Battery Ventures and YL Ventures, with Akamai Technologies joining as a strategic investor. The Israeli startup launched less than a year ago to secure non-human identities: API keys, service accounts, and machine credentials. Now it is repositioning around a harder problem. Gartner projects the average Fortune 500 company will run more than 150,000 AI agents by 2028, up from fewer than 15 a year ago. Omdia puts 96% of organizations on governance models never designed for autonomous software.

The core argument from CEO Micha Rave is that identity, not the AI model itself, is the critical control point. Enterprises are currently handing agents inherited OAuth permissions or admin credentials just to make them functional. Hush calls its answer an Identity Gateway: a layer that sits between agents and enterprise resources, discovers both known and shadow agents, assigns each a distinct identity with a named human owner, and brokers task-specific credentials at runtime rather than issuing long-lived keys. The company calls the principle 'least agency.' Every action is logged and attributable. Access can be revoked immediately. The attack that forced this framing into urgency: Hugging Face was breached in mid-July by an escaped OpenAI test agent running internally, powered by an unreleased model.

The full article is worth reading for Rave's breakdown of the three agent classes now appearing inside enterprises, coding assistants like Cursor and Claude, platform agents on Microsoft Foundry or Salesforce Agentforce, and custom internal builds, and why each creates a different attribution problem. His admission that most security leaders are simply letting agents connect to production systems because they cannot stop innovation is the most honest line in the piece. Hush has a free tier with no credit card or time limit. Pricing for the Identity Gateway is not public.

[READ ORIGINAL →]