The week of July 27 had a single most interesting pattern, and it was not the $5 billion Nvidia committed to Ilya Sutskever's Safe Superintelligence. It was quieter: in the span of 72 hours, Okta acquired Permiso Security for $200 million and Cyera acquired Oasis Security for $1 billion, while three separate venture firms invested $171 million across Onyx Security ($113 million Series B), Inforcer ($50 million Series C), and Cantina ($8 million funding round). Five distinct capital allocations, by buyers and investors who do not coordinate, all landed on the same narrow problem: who controls the AI agents running inside enterprise systems?
The exits tell a specific story. Oasis Security had built a non-human identity and agentic access governance platform, meaning it tracked and controlled the credentials, permissions, and behaviors of AI agents operating within enterprise environments. Cyera, which had just raised $600 million at a $12 billion valuation weeks earlier, paid $1 billion for it: roughly $700 million in cash and the remainder in shares. Okta, the market's dominant enterprise identity company, spent $200 million for Permiso Security, which built identity analytics for cloud environments. Both acquisitions were announced within 48 hours of each other. Neither was planned around the other. The strategic logic was identical: the enterprise identity perimeter now includes non-human principals, and the existing tooling was not designed for them.
What makes this week's cluster analytically interesting is that the VC-backed rounds happened simultaneously with the exits, not after them. In a normal market rotation, acquisitions by incumbents signal a validated category, and the VC rounds follow. Here, three new companies were raising growth capital for the same problem at the exact moment incumbents were paying nine figures to buy their way in. That configuration typically precedes a category becoming a line item on every enterprise security budget. StartupHub.ai data shows agentic AI investment reached $8.1 billion across 80 tracked rounds in 2026 to date, compared to $324 million across 16 rounds for the full year of 2025, a roughly 25-fold increase year over year.
The numbers
| Metric | Jul 27-Aug 2, 2026 | Jul 20-26, 2026 | Change |
|---|---|---|---|
| Total capital raised (disclosed) | $6.8B | $11.8B | -42% |
| Rounds with disclosed amounts | 33 | 44 | -25% |
| Median check size | $20M | $25M | -20% |
| Seed rounds | 10 | n/a | - |
| Series B and C rounds | 8 | n/a | - |
| Total exit consideration (verified) | $7.8B | n/a | - |
Both headline totals are distorted by single large transactions. SSI's $5 billion accounts for 73% of this week's disclosed funding; strip it and the underlying market raised $1.8 billion. Last week's $11.8 billion included a $4 billion round for a tunneling infrastructure company. Median check size, $20 million this week versus $25 million last week, is a more reliable indicator: it reflects a market with active seed and early-stage deal flow but fewer late-stage blockbusters. The most notable number is the $7.8 billion in verified exit consideration, which exceeded non-SSI new funding by more than four to one. That inversion is unusual.
Five AI agent control deals in seven days is not coincidence
Onyx Security had been in stealth for four months before announcing its $113 million Series B on July 29. In those four months, it quadrupled revenue. The company describes its product as "AI control": a platform that sits between enterprise AI deployments and the systems they interact with, monitoring what AI agents do, enforcing policies, and blocking behaviors outside defined parameters. The framing is not traditional vulnerability-scanning security. It is governance: the organizational question of who decides what AI agents are permitted to do, and how those decisions get enforced at runtime.
