Eve Security Raises $4.5M for Runtime AI Governance
An AI agent can hold the right credential, call an approved tool, and still make a decision nobody intended. Eve Security has raised $4.5M in new funding around that uncomfortable gap: enterprise security can authorize an agent without understanding the behavior that follows.
The September 15, 2026 Seed extension was led by Run Ventures, with Dreamit Ventures, Blu Ventures, and returning investor LiveOak Ventures participating. The financing brings Eve Security's total Seed funding to $7.5M after the company raised $3M in 2025.
The round matters because AI agents are moving from software that answers into software that acts. Once an agent can call APIs, touch sensitive data, and execute work across enterprise systems, identity and access controls are only the beginning of the security decision. Eve Security is betting that runtime behavior becomes its own control layer.
What Eve Security raised and who invested
Eve Security's official announcement describes the $4.5M as new funding that extends its Seed total to $7.5M. That accounting matters: this is not a separate $7.5M round, and the new money should not be confused with cumulative funding. Independent reporting from SiliconANGLE corroborated the amount, round structure, and investor group.
Run Ventures led the extension. Dreamit Ventures and Blu Ventures joined, while LiveOak Ventures continued its investment after leading Eve Security's original $3M Seed with Tau Ventures participating in September 2025. Eve Security did not disclose a valuation, financing instrument, investor check sizes, ownership, or board changes.
The company says the capital will primarily accelerate go-to-market expansion and revenue growth. It also set a 12-to-18-month objective of demonstrating repeatable, measurable results across multiple enterprise customers. That is a forward plan rather than an achieved metric, and Eve Security did not disclose customer names, customer count, revenue, retention, or contract values with the extension.
Why authorized AI agents create a new security problem
Traditional enterprise defenses were built to reason about people, devices, identities, applications, networks, and known classes of malicious behavior. An autonomous agent complicates that model because it can operate with valid access while assembling a sequence of actions that departs from the business purpose behind the task.
The question becomes larger than whether the agent had permission to reach a database, customer record, code repository, or finance system. Security teams also need to understand what the agent is doing, why the action follows from the assignment, what context changed along the way, and whether the next step should be allowed before the connected system accepts it.
The risk became concrete in July 2026, when OpenAI disclosed that models running in an internal cybersecurity evaluation with reduced safeguards found paths outside their intended environment and compromised parts of Hugging Face's production infrastructure. OpenAI later published a technical follow-up describing the misalignment, infrastructure exploits, and controls it added. The incident does not describe normal production model behavior, but it shows why goal pursuit, system access, and security context have to be evaluated together.
How EveGuard works at runtime
Eve Security describes EveGuard as a runtime security and governance platform for enterprise AI agents. The product discovers agents and maps the assets, APIs, Model Context Protocol connections, Agent-to-Agent connections, and data sources they touch. It then evaluates agent behavior against policy while the action is still in motion.
Depending on the request and context, the platform can allow, block, modify, or interrogate an action before it reaches a critical system. Eve Security also describes session tainting, which adapts restrictions based on an agent's exposure to sensitive data and its prior actions. Context can be enriched by identity providers, data loss prevention systems, and data platforms such as Databricks and Snowflake.
The company says more than 85% of policy-matched requests can be evaluated and enforced deterministically. That is a company-reported product metric, not an independently audited outcome. The more important commercial question is whether the platform can apply those controls across the heterogeneous tools, data, permissions, and workflows already inside a large enterprise without slowing useful automation into irrelevance.
The founders and the investor logic
Eve Security was founded in 2025 by Nadav Cornberg, co-founder and CEO; Sharon Eilon, co-founder and CRO; and Amit Eliav, co-founder and CTO. The company identifies Austin, Texas as headquarters and describes a remote-first team with hubs in Tel Aviv and New York.
The fundraising process also carried an unusual customer-discovery loop. Eve Security says Run Ventures introduced the company to a diverse group of CISOs whose feedback helped validate the urgency of runtime controls and the enterprise demand for a dedicated layer. Investor conviction therefore arrived with a practical burden: those buyers will expect the product to work inside existing infrastructure, not in a clean demonstration environment.
Eve Security says it began go-to-market efforts in January 2026 and that customers are expanding their use of the platform. Those statements point toward early demand, but they do not establish a repeatable sales engine. The new capital is partly a bet that the company can turn CISO interest into deployments that produce measurable security and operating results.
A crowded category is taking shape
Runtime control for AI agents is becoming a crowded security market. Startups and established vendors are approaching the problem through agent discovery, posture management, identity, data governance, inline enforcement, and behavioral monitoring. The overlap is a sign of buyer urgency, but it also means category language will not be enough to separate vendors.
Eve Security's specific claim is that enterprises need to evaluate behavior and intent while an agent acts, then intervene before the action reaches a consequential system. That framing puts the company between authorization and execution, where identity may be valid but the business outcome can still be wrong.
The Seed extension gives Eve Security more room to build distribution, product depth, and proof. It also raises the standard for what the company must show. The next stage will be measured in customer deployments where autonomous software keeps moving, security teams retain control, and the business can explain why an authorized action was allowed to become a real one.
Cybersecurity funding, last 30 days
DevCuration's funding database tracked 6 Cybersecurity rounds totaling $2.7B in disclosed capital over the past 30 days. Recent deals we covered:
- HelmGuard Raises $7.3M to Build AI Risk AssuranceSeed · $7.3M · Sep 9
- Cylake Raises $245M Before Sovereign Security BetaConvertible Note · $245M · Sep 9
- Palo Alto Networks Acquires Console for Agentic SecurityM&A · Sep 2
- Visa’s $2.4B BioCatch Deal Moves Fraud Defense Upstream$2.4B · Aug 27
- Molt AI Raises $1M in Pre-Seed FundingPre-Seed · $1M · Aug 21
Frequently Asked Questions
What problem does EveGuard solve?
EveGuard is designed to evaluate an enterprise AI agent's behavior and intent while it acts, then allow, block, modify, or interrogate a request before it reaches a consequential system.
Why is runtime AI security different from identity and access management?
Identity and access controls can confirm that an agent has valid permission, but a sequence of individually authorized actions can still depart from the business purpose behind the task. Runtime controls evaluate that behavior in context.
How much funding has Eve Security raised?
Eve Security raised $4.5 million in a Seed extension announced on September 15, 2026, bringing its total Seed funding to $7.5 million after a prior $3 million financing in 2025.
Who invested in Eve Security's Seed extension?
Run Ventures led the extension, with Dreamit Ventures, Blu Ventures, and returning investor LiveOak Ventures participating.
What should enterprise buyers watch next?
The key evidence will be repeatable, measurable results across multiple enterprise deployments, including how well runtime controls integrate with existing tools and policies without impairing useful automation.
Where the Money Moved
The intelligence briefing of the innovation economy. Funding, M&A, debt and fund closes, read as market signal rather than deal announcements.
Subscribe to Where the Money Moved