Defining AI Agent Governance as a New Infrastructure Layer
AI agent governance is the set of policies, controls, and monitoring systems that manage how autonomous AI agents access tools, handle data, and make decisions within an enterprise. In the past 18 months, this has shifted from an abstract risk topic to a concrete infrastructure category. As AI agents move from pilots to always-on “digital employees”, enterprises have discovered that traditional identity tools and observability stacks do not cover agentic behavior. The result is a wave of startups aiming to provide agentic access control, autonomous agent security, and AI failure detection as a dedicated layer between agents and core systems. Rather than being treated as a feature bolted onto existing identity and access management, AI agent governance is now emerging as its own platform market, with investors and security teams treating it as critical plumbing for enterprise AI oversight.
Willow and the Rise of Agentic Access Control
Willow, founded by former Wix engineers, is one of the clearest signs that agent-specific access control is becoming mandatory. The company has raised USD 7 million (approx. RM32.2 million) in seed funding to build an agentic access governance platform that sits between AI agents and internal systems. With 79% of companies introducing AI agents and 73% running multi-agent systems, Willow argues that these agents now form a new backbone of business operations—and a fast-growing, least-governed attack path. Its platform discovers which agents employees are already using, maps their connections to tools such as Claude, ChatGPT, Cursor, Gemini, and Codex, and enforces granular permissions across more than 1,000 pre-built connectors. A key proof point: Willow has already been deployed internally for over 5,000 employees at Wix, suggesting that agent-specific access policies can scale across a large, active workforce.

Opal Security Extends Identity Governance to Agentic AI
Opal Security shows how identity governance is widening to cover not only people and services, but also AI agents. The company has secured USD 23 million (approx. RM106 million) in new funding to expand its AI-native access governance platform, which manages identity security across human, service, and agentic AI credentials. Customers such as Databricks, Notion, Cloudflare, and Scale AI treat Opal as a central access graph; Databricks alone runs 86,000 just-in-time access requests through the platform. As AI agents are deployed faster than security teams can track them, Opal brings agent identities into the same reviews, ownership structures, and policy-as-code as every other identity. According to Opal Security, teams “now need to see every agent alongside their human and service identities, scope each one to the task, and contain the blast radius when something breaks.”
ChatSee.ai and the Missing Layer of AI Failure Detection
If Willow and Opal focus on who an agent is and what it can access, ChatSee.ai focuses on what happens when that agent goes wrong. The company has raised USD 6.5 million (approx. RM30 million) to build a failure intelligence layer for autonomous AI systems. As enterprises deploy custom agents on OpenAI, Gemini, and Anthropic models—and adopt embedded agents inside products such as Microsoft 365 Copilot, Salesforce Agentforce, Snowflake, and Databricks—behavioral failures are emerging in production. Many failures depend on intent, policy interpretation, and business outcomes, which traditional monitoring or static rules struggle to catch. Observability tools can replay interactions but do not store the institutional memory of how failures were detected and fixed. ChatSee.ai aims to capture that context so organizations can detect recurring errors, from missed escalations to unintended disclosures and workflow drift, and improve autonomous agent security over time.
A New Control Plane for Enterprise AI Oversight
Taken together, Willow, Opal Security, and ChatSee.ai show enterprises are treating AI agent governance as a standalone control plane. These startups have raised a combined USD 36.5 million (approx. RM168 million), not to extend existing identity and monitoring products, but to build infrastructure tailored to autonomous agents. That shift signals a view that agents are neither ordinary users nor traditional applications: they act continuously, chain tools, and can make decisions in ambiguous contexts. Enterprises therefore need dedicated agentic access control, unified identity governance across human and non-human actors, and runtime AI failure detection that preserves organizational memory. As AI agents continue to spread across workflows, this emerging platform layer is likely to become the default place where security teams define policies, watch behavior, and contain the impact when autonomous systems misfire.







