The enterprise security pitch has become almost rhythmic in its cadence: identify the emerging threat, sound the alarm, build the tooling. But when Tal Baron describes the problem his startup is tackling, there's an edge of genuine unease that cuts through the usual founder polish.
"We're watching enterprises deploy dozens, sometimes hundreds of autonomous AI agents," Baron says, "and most security teams have no idea they exist."
That anxiety—part observation, part bet—is what convinced Hetz Ventures to lead an $8 million seed round in Arrakis Security, a New York–based startup that emerged from stealth on August 2 with a straightforward thesis: the AI agent is the enterprise's next unmanaged identity crisis. And traditional security controls, built for humans clicking buttons, weren't designed for software that writes code, queries databases, and makes decisions on its own.
The Shadow Agent Problem
Baron, along with co-founders Omer Efrat and Ron Shani, spent years at companies—Torq, Palantir—that specialize in orchestrating intricate workflows across sprawling data operations. Efrat logged 4.5 years at Torq before jumping ship to build Arrakis. Shani's eight years at Palantir took him across four continents, managing systems where visibility and control weren't optional luxuries.
Which is to say: they've seen what happens when enterprises lose track of what's running where.
The concern isn't entirely hypothetical. This past April, a breach at Vercel exposed customer data after a third-party AI tool's OAuth credentials were compromised. It was a warning shot—agents with overly permissioned access, operating in the gaps between IT oversight and departmental autonomy. NIST noticed, launching its AI Agent Standards Initiative on February 17. Surveys from the Cloud Security Alliance in early February and others throughout the year have echoed the same refrain: adoption is racing ahead of governance.
Arrakis wants to be the brakes, or at least the visibility layer before the collision.
Behavioral Governance, Not Just Access Control
The company's platform does something the founders describe as "behavioral governance," a term that sounds like consultant-speak until you dig into what it actually means. Instead of merely tracking which agents have access to what—a permissions model borrowed from human identity management—Arrakis monitors what agents do.
It's a subtle shift. One that assumes agent outputs can't be trusted by default.
The architecture rolls out in three stages, each a little more interventionist than the last. First comes AI Observability: inventory and ownership tracking for every agent, sanctioned or otherwise, lurking in an organization's SaaS stack, cloud footprint, and endpoints. Then AISPM—AI Security Posture Management—which applies pre-execution static analysis, data loss prevention rules, and allow-lists through what Arrakis calls an MCP gateway. Detections get mapped to OWASP, NIST, and MITRE ATLAS frameworks, the acronyms security teams already speak fluently.
The third stage, AIDR (AI Detection and Response), handles runtime anomalies: cross-agent contagion tracking, kill-switches if things go sideways, behavioral remediation. The platform connects to Claude, ChatGPT, Gemini, and Cursor, deployed through OpenTelemetry collectors and hooked into existing identity providers.
It's ambitious, maybe. Or it's table stakes, depending on how worried you are.
Validation Through Research

Before Arrakis officially launched, the team was already publishing research—posts from May through July exploring agent-generated insecure code, OAuth supply-chain vulnerabilities, AI compute theft. Practical problems that doubled as product validation, building credibility in security circles before asking for anyone's money.
That groundwork seems to have helped. Beyond Hetz Ventures, the seed round pulled in a roster of security-world angels: the CEOs of ElevenLabs, Torq, and Pentera, plus several senior Palantir executives. The company now has a team of 20, including former Microsoft security researchers contributing to Arrakis Labs, its threat research arm.
The founders claim design partners are already using the platform to secure agents on n8n, Make.com, and Salesforce's Agentforce. Specifics on customer traction? Undisclosed. Valuation? Also undisclosed. The broader syndicate beyond Hetz and the named angels? You guessed it.
A Crowded, Noisy Space
Arrakis isn't alone in this. Not by a long shot.
Oasis Security raised $120 million in April for agentic access governance. Capsule Security, Willow, Onit Security, and Manifold Security all announced seed rounds this year, each staking out slightly different territory in what's rapidly becoming a land grab. Hetz Ventures, notably, has backed several of these companies—a firm-level bet that the agent security category is real, large, and probably here to stay.
Whether there's room for all of them is another question entirely. The market feels frothy, perhaps more than the founders would care to admit. But the underlying problem—autonomous software operating with limited oversight—feels genuine enough that enterprises are starting to pay attention.
What Comes Next

The $8 million will fund product development and go-to-market efforts. Arrakis is hiring full-stack engineers in Tel Aviv, scaling from stealth to production as it tries to convert anxiety into revenue. Offices span New York and Israel, a split that mirrors the team's heritage.
For now, the bet is simple: that the agent security problem is both urgent and unsolved. That behavioral governance, not just access control, is how enterprises will eventually wrangle the autonomous workforce they're rapidly assembling.
Whether Arrakis becomes the governance layer between promise and chaos, as Baron puts it, or just another entrant in an overcrowded category, depends on how quickly CISOs decide they need an answer. And how soon the next Vercel-style breach reminds them why they probably should've acted sooner.
