Security1 publisher2 min readPublished
Rig Security raises $12M to separate AI agent actions from the humans whose accounts they use
Rig Security raised $12 million in seed funding to separate an AI agent's actions from those of the employee whose identity it borrows. The standard way to stop a misbehaving agent, disabling its account, locks out the person as well.
The Watch · Security desk

What happened
- Ten Eleven Ventures and Brightmind Partners led the round, with the CrowdStrike Falcon Fund and a group of angel investors participating.
- Rig is based in Tel Aviv and was founded in 2025 by CEO Guy Kozliner, who previously worked on the CTO team at Wiz.
- The RICE engine resolves one identity across identity providers, cloud, on-premises systems, network edges and endpoints, and maps how accounts, permissions and sessions connect.
- A sensor called Bifrost tells an agent's session from the user's own on the endpoint and blocks the agent's risky action without disrupting the person.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A subverted agent can do anything the account that launched it is allowed to do, so excess permissions on developer and service accounts pass straight to every agent started from them.
- decision Taken at Rig's own figure, up to one identity match in 25 can be wrong, a rate buyers would need to measure in their own estate before letting Bifrost block actions.
- precedent With agent identity, agent authentication and agent runtime controls each drawing separate rounds, buyers are likely to assemble agent coverage from several small vendors.
"Security teams can see that an account did something dangerous," Guy Kozliner, Rig's founder and CEO, said. "What they cannot see is whether a person did it or an agent did, and they cannot stop the agent without blocking the person." [7] SecurityWeek describes the same gap from the log side. The agent takes on the identity of the developer or service that launched it, so a SIEM cannot separate the legitimate user's action from a rogue or subverted agent's [5]. SecurityWeek adds that such agents act at machine speed and independent of their creator [6]. "The problem is access that is broader than intended, ungoverned, and hiding behind human activity," Kozliner said [8].
Rig puts the attribution on the endpoint, where the session originates, because the downstream record shows only the account [10][5]. The correlation graph comes from Kozliner's time at Wiz. He concluded the graph approach he used there could be applied to the human and AI identity problem [17]. Wiz co-founder and CTO Ami Luttwak is one of Rig's angel investors [4].
The architecture and the investors are on the record; the performance and adoption figures come from Rig. The company says the platform is in production at Fortune 200 organizations in financial services, insurance, healthcare and technology [12]. The >96% correlation accuracy is a claimed figure [9]. The report does not describe a real incident, name a customer, or say how that accuracy was measured.
SecurityWeek has covered two other agent-focused raises. Kontext Security launched with $4 million for AI agent runtime controls [14], and Scalekit raised $5.5 million to secure AI agent authentication [15]. Counting Rig, the three rounds total $21.5 million [1]. The Linux Foundation is set to govern TRACE, an open standard for AI runtime attestation [16].
Investor money is going to tools built specifically for agents. Rig, though, sells its platform as identity security posture management and identity threat detection and response across AI and non-human identities [11]. On this evidence, agents are a new type of identity that identity-security vendors are competing to cover. The sources do not show a market that stands apart from identity security.
Rig will spend the seed money on research and engineering, particularly detection and enforcement, on a larger U.S. go-to-market team, and on partners and channels [13].
What to watch
- A named Fortune 200 customer or an independent test of RICE's claimed >96% correlation accuracy.
- Whether identity or endpoint vendors, including CrowdStrike, add agent-session attribution to existing products.
- How TRACE develops under Linux Foundation governance as a standard for attesting what an AI runtime did.