AI News Feed
Market watch
Cybersecurity

Rein Security raises $25M for AI agent defense as Darwinium adds intent intelligence

Rein Security raised a $25 million Series A to protect enterprises from risks posed by autonomous AI agents. Darwinium launched two capabilities to detect fraud and suspicious behavior by AI agents, SiliconANGLE reported.

Rein’s Series A round was backed by Glilot Capital, Sienna Venture Capital, Corner Ventures, Atlacle and RNP Capital Advisors and brings the company’s total raised to $35 million. Rein argues that autonomous agents create two new types of risks enterprises have not dealt with, meaning existing cybersecurity platforms cannot protect them. For companies adopting AI agents, the challenge is securing those digital workers so they do not cause problems or leak secrets. For everyone else, even organizations that are not using agents, the need is to protect IT infrastructure from sophisticated, hacker-controlled agents capable of continuously probing defenses for vulnerabilities.

Rein co-founder and Chief Executive Matan Bar-Efrat told SiliconANGLE the main issue with autonomous AI agents is that the risks are new and hidden from most security teams. For companies working with AI agents, the main danger is the downstream actions taken by those autonomous systems, which are usually based on instructions received from other systems and agents rather than their human operators. When AI agents are given a task to complete, Bar-Efrat said, they will strive to finish it no matter what, without thinking of the negative consequences their actions may have. To secure these agents, companies need a way to understand every action they take so they can prevent harmful ones from happening.

“Enterprise AI agents are becoming essential to how businesses operate, but security hasn’t kept pace with the autonomy these systems now have,” Bar-Efrat said. “This funding enables us to keep building the infrastructure enterprises need to deploy AI agents with visibility, control and confidence.”

Rein Security tries to secure AI agents with a proactive approach that prioritizes prevention and protection at the execution layer with a platform that operates directly at runtime. Its platform is deployed as a lightweight sidecar that analyzes everything from user prompts to application programming interface calls and database access. It works by creating a baseline of each agent’s behavior so it can understand what is normal and what is not, then applies contextual, action-level controls that prevent deviations in real time without shutting down the agent completely.

“Our approach is to micro-segment the resources that an agent can interact with and enforce controls at the point of execution,” Bar-Efrat said. “We aren’t terminating the agent process, thread or the request, we only prevent the specific malicious action from taking place while allowing the rest of the workflow to continue uninterrupted.”

Bar-Efrat said understanding agents’ baseline behavior is key because there are so many ways AI agents can be compromised that it is basically impossible to prevent them all. Most agentic security tools focus on identifying specific techniques and payloads used to compromise AI agents, such as indirect prompt injections, zero-day vulnerabilities in their code and misconfigurations that can allow unauthorized access or actions. As far as Bar-Efrat is concerned, the method used by the attacker is irrelevant. What matters more is being able to understand an agent’s legitimate or normal behavior so that deviations can immediately be flagged.

“Attackers will continue to find new ways to manipulate AI systems, so rather than trying to predict every possible attack technique, Rein focuses on the agent’s behavior at runtime and the impact that an action could have on the enterprise,” he said.

Rein’s platform has been deployed by Flex Ltd., Swimlane Inc., Lemonade Inc. and Dun & Bradstreet Holdings Inc. to secure thousands of new AI agents that are executing millions of actions each week. At Black Hat USA 2026 in August, its research team Agent Breakers showed how it was able to compromise the AI shopping agents of a top-five U.S. retailer and then detailed how that vulnerability can be prevented. Rein said its customer base has grown more than fivefold this year.

Darwinium’s new capabilities make intent intelligence the foundation of its platform. Journey Transition Probability flags unusual changes in the steps a person, bot or AI agent takes on the way to a login, account change or payment. MCP Protection watches the tools agents use to carry out tasks. The release targets a problem agentic commerce is making harder to manage, since only about one in four agentic transactions on Darwinium’s network self-declares, and purchases involving agents are rejected nine times as often as others.

In a Darwinium survey of 500 fraud, risk and security leaders in the U.S. and the U.K., 97% reported an increase in AI-driven attacks, while only 36% believed they had effective fraud coverage across the full customer journey. Michael Rodriguez, Darwinium’s chief operating officer, said an authorized AI agent “can start out doing exactly what a customer asked, then take an unexpected turn.” He made the same point about authenticated human customers, who can still be coached into sending money to a scammer. Darwinium has spent years mapping the full customer journey for that reason, Rodriguez said, and making intent intelligence central lets businesses assess an interaction while it is still unfolding.

Darwinium launched its agent intent tools in March. Its existing Agent Intent Detection product identifies AI agents even when they do not announce themselves. The update folds the tool calls an agent makes over the Model Context Protocol into the same journey as a customer’s web and mobile activity. One model assesses every step, and risk decisions run through the content delivery network the business already uses for its website traffic. Journey Transition Probability measures the order and timing of actions against the customer’s typical behavior, factoring in the business’s own traffic and the type of journey underway. A step that looks ordinary on its own can read as suspicious once the full path is considered. MCP Protection links each tool call to the journey that led to it, allowing businesses to verify an agent’s credentials and monitor what the agent does once it is working. A payment or other higher-risk action can be held for additional checks.

Jon Ferrari, senior manager of fraud prevention and application security at Darwinium customer Apollo.io, said web traffic has reached “an inflection point where user-agent declarations and even statements of intent are becoming moot.” His team needs to track whether behavior matches stated intent over time, he said, including aggregate activity where many requests can add up to an outcome no individual request disclosed. Darwinium is a venture capital-backed startup whose investors include U.S. Venture Partners, Blackbird Ventures Pty. Ltd., Airtree Ventures Pty. Ltd. and Accomplice. The company announced an $18 million round in October 2023.

Editor’s Summary: Rein Security raised $25 million in Series A funding to build runtime security for enterprise AI agents, bringing its total funding to $35 million. Darwinium launched new intent-intelligence tools to detect unusual agent activity and fraud across login, account and payment journeys. Both moves address growing security and fraud risks from autonomous AI systems that can act without direct human control, according to SiliconANGLE.