AI Governance Institute
← News

Hush Security's $30M Series A Puts NHI Credential Governance and Agent Registries on the Enterprise Compliance Agenda

What happened

Hush Security announced the close of a $30 million Series A backed by Akamai Technologies, Battery Ventures, and YL Ventures, bringing total funding to $41 million. The Tel Aviv-based company offers a machine access platform designed specifically for the governance of AI agents operating within enterprise environments. The platform maintains a central agent registry, eliminates static credentials in favor of just-in-time scoped permissions issued at runtime, and generates a full audit trail for every agent action. This approach directly targets what compliance teams increasingly recognize as a structural gap: as agentic AI moves from pilots to production, the credential and identity frameworks built for human users are failing to contain agent access, a problem highlighted by the Meta Sev-1 agent incident and reinforced by the Entrust program's focus on NHI credential governance. The funding will be used to extend platform capabilities and expand go-to-market reach as enterprise demand for purpose-built agentic governance tooling accelerates.

Why it matters

  • ·The growing investment in NHI-specific governance tooling reflects a real control gap: most enterprise identity and access management programs were designed for human users and lack the agent registration, credential lifecycle, and runtime scoping capabilities that agentic deployments require. Compliance teams relying on legacy IAM frameworks alone are exposed as agent counts grow.
  • ·Regulators and security authorities are moving toward explicit agent access requirements. The DHS and CISA guidance on mandatory minimum security rules for AI agents in critical infrastructure specifically names prompt injection and blast-radius risks as enforcement priorities, putting organizations without least-privilege agent controls in a difficult position when auditors or regulators begin asking for evidence.
  • ·Vendor concentration risk is an emerging concern in this category. As specialized agentic governance platforms attract institutional capital and consolidate capabilities, compliance teams evaluating these tools need to apply the same third-party AI vendor due diligence standards they apply to model providers, including contractual audit rights, incident notification requirements, and financial stability assessments.

Governance controls affected

What to do now

  • Audit your current AI agent deployments to determine how many agents are operating with static credentials rather than just-in-time, scoped permissions, and document the exposure.
  • Confirm that your agent registry, if one exists, captures the identity, permission scope, and audit trail for every deployed agent, including those provisioned by business units outside central IT.
  • Evaluate purpose-built agentic governance platforms against your existing IAM and PAM tooling to identify capability gaps, specifically around runtime permission enforcement and agent-level audit log generation.
  • Apply your third-party AI vendor due diligence framework to any NHI governance tooling under evaluation, including review of the vendor's own security posture, incident notification commitments, and data handling practices.
  • Review AGT-022 (Agentic AI Governance Tooling Attestation) requirements and determine whether your current or prospective tooling can satisfy attestation obligations for regulators or auditors.

What to watch next

Compliance teams should monitor whether DHS, CISA, or financial regulators such as the Bank of England translate their current agentic AI guidance into binding access control requirements that would mandate agent registries or runtime permissioning by a specific deadline. The Bank of England's signaling of bespoke agentic AI rules for financial services suggests sector-specific mandates could arrive before horizontal AI legislation is finalized. As the vendor market for agentic governance tooling consolidates, teams should also track whether dominant platforms introduce interoperability or lock-in conditions that affect long-term governance program flexibility.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-29

NHIMG Sets OAuth Registration Standard for AI Agent Identities

The Non-Human Identity Management Group (NHIMG) has published guidance requiring AI agents to be treated as non-human identities subject to explicit OAuth client registration before credentials are issued or refreshed. The guidance mandates publisher-controlled metadata, signed statements, or software attestations as prerequisites for onboarding any new agent OAuth client. Narrow scope assignment and pre-issuance verification are the central operational requirements.

Corporate Policy2026-08-28

Open-Source Runtime Enforcer Exposes the Gap Between Agent Policy and Practice

Conduct, an open-source AI agent governance framework published on GitHub by independent developer sseshachala, enforces compliance policy before LLM or shell tool calls execute rather than logging behavior after the fact. The project ships with more than 20 pre-mapped compliance packs covering frameworks including the EU AI Act, NIST AI RMF, HIPAA, PCI DSS 4.0, SOC 2, and ISO 42001. It uses a fail-closed default and SHA-256 hash-chained audit logs designed to produce auditor-ready evidence.

Research2026-09-05

Microsoft: Agentic Security Requires Tool-Layer Controls, Not Just Model Guardrails

Microsoft's Security Blog published guidance on June 30, 2026, arguing that security controls for AI agents must be applied at the tool layer rather than relying solely on model-level guardrails. The guidance covers allowlisting MCP publishers, inspecting tool metadata, applying data loss prevention at the tool call parameter level, and correlating telemetry across agent actions. It directly implicates third-party risk programs, DLP frameworks, and agent audit trail requirements.