Twelve rounds. Five months. Four hundred and thirty-five million dollars. All of it pointed at one job: stopping an AI agent from doing something you'll spend the next quarter apologizing for.
The cluster closed across early 2026. AIR pulled a $50 million seed from Sequoia and Greenoaks. Zenity stacked a $125 million Series C led by Norwest, with SoftBank, Hitachi and LG riding along. Arga Labs raised for enterprise digital twins. And Alice — the quiet one — took $140 million led by Apax, sits near $100 million ARR on roughly 500% growth, and counts eight of the top ten model labs as users.
That's not a sector cooling into a category. That's a stampede. And when capital moves this fast, the market's chaos is the only honest data set you have.
If you run an agent that touches money, you already know the shape of the problem. IDC and Lenovo put a number on it: 88% of enterprise AI agent projects never leave the building. Gartner's forecast cuts the other way — 40% of agentic projects cancelled by the end of 2027, with inadequate risk controls named as the primary cause.
The pitch writes itself. The models got good enough to act. Nobody trusted them enough to let them. So a category filled the gap: application-layer guardrails. Not new model architectures. Not better reasoning. Runtime monitoring, pre-deployment simulation, and a filter sitting between the model's intention and the outside world.
Three flavors emerged fast. AIR sells an inline firewall that discovers and vets skills, plugins and MCP servers before an agent can call them; CEO Yair Saban cites a 27% risky-plugin filter rate. Zenity watches the production action stream and blocks or rewrites a step when intent drifts from policy. Arga Labs builds digital twins of Salesforce, Workday and email so agents fail against a replica instead of your live tenant.
Here's what the press releases skip. None of this is model innovation. Every product here is a module-level engineering layer that assumes the underlying LLM will occasionally hallucinate its way past the guardrails. That is the design premise. The firewall doesn't make the model safer. It makes the blast radius smaller.
Which is a defensible business — just not the one being sold.
Look at where the money concentrated. Alice and Zenity together account for roughly 61% of the $435 million. Alice's position is the strangest, because it doesn't sell to enterprises at all; it sells to the labs. Eight of ten top model labs on your platform is a de facto standard, and de facto standards in infrastructure don't lose to better features. They lose to a decision to rebuild, which almost never happens.
Arga's digital twin play is the sleeper. Testing agents against a replica of Salesforce isn't glamorous, but it's the only category here that produces something you can hand an auditor. Real-time blocking is reactive. Pre-deployment simulation is architecture. A firewall rule you wrote in January is a hypothesis; a test suite you wrote in January is still protecting you in June.
I built a live IBIT flow dashboard in 2024 — hourly net inflows, correlated against spot in real time. That desk taught me something that applies exactly here. When institutions enter a market, the infrastructure they demand is never the cool thing. It's the thing that survives an audit. Liquidity flows like adrenaline, not like water: it goes where the fear is managed, not where the yield is highest.
Now the number nobody is stress-testing. AIR's 27% filter rate comes from AIR. There is no third-party benchmark for plugin risk, no independent measure of how often real-time blocking catches a genuine intent deviation versus a false positive. Speed is the only metric that survived the crash, and this sector is selling speed without a scoreboard.
I've watched this pattern since 2017, when I was reading block heights during the Ethereum chain split and publishing in twelve minutes because waiting for editorial consensus meant losing the trade. The lesson held during the 2020 DeFi summer, and it holds now: adoption curves are real, audits are theater until someone independent signs them.
The uncomfortable read is that this funding wave is a tax, and the tax is being formalized.
Every layer sits in the request path. Inline firewall, intent monitor, twin simulation — each adds latency, each adds a failure mode, each adds a line item. Call it the alignment tax, and expect it line-itemed into every agent deployment by 2027. The 88% that can't ship aren't blocked by a missing firewall. They're blocked because the workflow underneath was never defined tightly enough for a firewall to protect.
Then lock-in. If Alice is the default governance layer for eight labs, a startup building on those labs inherits Alice's policy whether it wants to or not. That isn't a security posture — it's a toll booth with a login page. We watched this movie in cloud security: first vendors won on integration, then on inertia, then on pricing. Social capital outpaced code in the ape arcade, and it's outpacing it again here. Alice's moat is adoption, not architecture.
And the quiet gap. The twins cover Salesforce, Workday, email. They don't cover a DeFi vault agent executing a multi-hop swap at 3am while a bridge is draining. Hallucination-driven out-of-bounds behavior in an open, adversarial, money-native environment is still unsolved. Reading the room while the order book burns, you notice the security layer was built for the office, not the chain. The sprint doesn't end when the block confirms.
Watch ARR, not round size. Alice's ~$100 million and Zenity's 3x growth are the only hard numbers in this story. If the next twelve months bring third-party benchmarks for filter accuracy — and a digital twin that can simulate an on-chain workflow — the security layer becomes infrastructure. If they bring another $435 million and no scoreboard, it becomes a bubble with excellent PR.

