AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News

Hush Security's $30M Series A Puts NHI Credential Governance and Agent Registries on the Enterprise Compliance Agenda

What happened

Hush Security announced the close of a $30 million Series A backed by Akamai Technologies, Battery Ventures, and YL Ventures, bringing total funding to $41 million. The Tel Aviv-based company offers a machine access platform designed specifically for the governance of AI agents operating within enterprise environments. The platform maintains a central agent registry, eliminates static credentials in favor of just-in-time scoped permissions issued at runtime, and generates a full audit trail for every agent action. This approach directly targets what compliance teams increasingly recognize as a structural gap: as agentic AI moves from pilots to production, the credential and identity frameworks built for human users are failing to contain agent access, a problem highlighted by the Meta Sev-1 agent incident and reinforced by the Entrust program's focus on NHI credential governance. The funding will be used to extend platform capabilities and expand go-to-market reach as enterprise demand for purpose-built agentic governance tooling accelerates.

Why it matters

  • ·The growing investment in NHI-specific governance tooling reflects a real control gap: most enterprise identity and access management programs were designed for human users and lack the agent registration, credential lifecycle, and runtime scoping capabilities that agentic deployments require. Compliance teams relying on legacy IAM frameworks alone are exposed as agent counts grow.
  • ·Regulators and security authorities are moving toward explicit agent access requirements. The DHS and CISA guidance on mandatory minimum security rules for AI agents in critical infrastructure specifically names prompt injection and blast-radius risks as enforcement priorities, putting organizations without least-privilege agent controls in a difficult position when auditors or regulators begin asking for evidence.
  • ·Vendor concentration risk is an emerging concern in this category. As specialized agentic governance platforms attract institutional capital and consolidate capabilities, compliance teams evaluating these tools need to apply the same third-party AI vendor due diligence standards they apply to model providers, including contractual audit rights, incident notification requirements, and financial stability assessments.

Governance controls affected

What to do now

  • Audit your current AI agent deployments to determine how many agents are operating with static credentials rather than just-in-time, scoped permissions, and document the exposure.
  • Confirm that your agent registry, if one exists, captures the identity, permission scope, and audit trail for every deployed agent, including those provisioned by business units outside central IT.
  • Evaluate purpose-built agentic governance platforms against your existing IAM and PAM tooling to identify capability gaps, specifically around runtime permission enforcement and agent-level audit log generation.
  • Apply your third-party AI vendor due diligence framework to any NHI governance tooling under evaluation, including review of the vendor's own security posture, incident notification commitments, and data handling practices.
  • Review AGT-022 (Agentic AI Governance Tooling Attestation) requirements and determine whether your current or prospective tooling can satisfy attestation obligations for regulators or auditors.

What to watch next

Compliance teams should monitor whether DHS, CISA, or financial regulators such as the Bank of England translate their current agentic AI guidance into binding access control requirements that would mandate agent registries or runtime permissioning by a specific deadline. The Bank of England's signaling of bespoke agentic AI rules for financial services suggests sector-specific mandates could arrive before horizontal AI legislation is finalized. As the vendor market for agentic governance tooling consolidates, teams should also track whether dominant platforms introduce interoperability or lock-in conditions that affect long-term governance program flexibility.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-08-03

Two-Thirds of Enterprises Lack Agent Governance Policies as Network-Layer Controls Emerge

Zero Networks has launched a capability called Least Agency Enforcement that applies the OWASP Least Agency principle at the network and identity layers to constrain AI agent autonomy. The offering uses identity-based micro-segmentation and just-in-time authentication to limit agents to explicitly authorized systems and block lateral movement if an agent is compromised. Zero Networks' own research found that roughly two-thirds of enterprises deploying AI agents have no governance policies covering them.

Standards2026-08-15

CISA Agentic AI Guidance Sets Binding Identity and Approval Standards

The Cloud Security Alliance has published a compliance analysis of CISA's agentic AI adoption guidance, translating federal security expectations into concrete enterprise requirements. The guidance mandates cryptographically verified agent identities, short-lived credentials, encrypted agent-to-agent communications, and least-privilege enforcement. It also establishes that human-in-the-loop approval must be mandatory for irreversible or high-impact actions.

Corporate Policy2026-08-15

Microsoft's MCP Agent Guidance Makes Every Tool Server a Governed Dependency

Microsoft published formal security guidance on June 30, 2026, requiring enterprise teams to treat every Model Context Protocol server as a production dependency subject to allowlisting, identity controls, and runtime monitoring. The guidance establishes concrete requirements for non-human identity assignment, least-privilege access, tool metadata review, output inspection, and human approval gates for high-impact agent actions. Compliance and security teams can use the document directly as a control checklist for agentic AI deployments.