Here is the whole week in one sentence, citable from the top: **on July 28, 2026, two identity-security startups — Hush Security and Act Security — raised roughly $90 million on the same day to solve the same problem, which is not that you can't see your AI agents, but that the ones you can see are holding standing access nobody can revoke.**

That framing matters because it's a deliberate move down the stack. One week earlier, on July 20, Neo left stealth with $100M to inventory and control every agent, app, and browser that quietly went agentic — the visibility bet. This week's money assumes you've done that and asks the harder question: now that you can see the agents, what are they actually allowed to touch, and for how long?

The same Tuesday, the same sentence#

Hush Security raised a $30M Series A — backers include Battery Ventures and YL Ventures, with Akamai joining as a strategic investor — putting it near $41M total less than a year out of stealth. Hush calls its product a "machine access platform." In plain terms: instead of an agent holding a persistent credential, it requests scoped, just-in-time access for the specific job in front of it, from a central registry that logs every grant and can pull it back with a kill switch. Standing privilege becomes a transaction with an expiry.

Act Security emerged from stealth the same day with $60M — a $20M seed led by Team8 and Bessemer, and a $40M Series A led by Notable Capital — built by the team behind Medigate. Its pitch is a single uncomfortable statistic: roughly 97% of granted cloud access is never used. Humans accumulate permissions they forget; agents inherit that bloat wholesale and at machine speed. Act's "action-centric" model watches what identities actually do and shrinks the granted surface down to it.

Two companies, two decks, one thesis: the agent problem is an access problem. Not a smarter model, not a better firewall — the standing, over-broad permission an agent carries between tasks.

Inventory tells you the agent exists. Access governance decides what it's allowed to touch this minute — and takes it back when the minute is over.

Why the money is here now#

The reason is a ratio that broke. Machine identities now outnumber humans by about 109 to 1, up from 82:1 a year earlier, and — the number that reframes everything — roughly 79 of every 109 are AI agents, according to the CyberArk / Palo Alto 2026 Identity Security Landscape. Ninety percent of surveyed organizations reported an identity-related breach in the past year. Gartner's projection that a large enterprise will run six figures of agents within two years is the same curve pointed forward.

Every one of those agents needs a credential. The default credential — a long-lived API key with broad scope, pasted into an environment variable — is exactly the wrong instrument at that volume: it never expires, it's scoped to everything, and it's revocable only if someone remembers it exists. Multiply that by 79-of-109 and you have standing privilege accumulating faster than any human review can keep pace with. The investors are betting the durable control point is not the model or the network. It's the grant.

What a founder does about it without a platform#

You don't need Hush's registry or Act's platform to act on the thesis they just raised on. The pattern is adoptable by hand, and it's the highest-leverage security move you can make in an agent stack:

The venture market spent July telling you the same thing twice. The first week it funded seeing the agents. The second week it funded cutting what they can reach. Both are describing a gap you can close at your own scale, this afternoon, with a credential that expires on its own.