Geordie AI raised $30 million in a Series A led by Balderton Capital, the largest European cybersecurity Series A on record. The London-based startup, which won the RSAC 2026 Innovation Sandbox in March, has now raised $36.5 million total at a post-money valuation of roughly $180 million. The round closed in late May, but the timing tells the real story: between April and September 2026, $435 million poured into AI agent security across 12 rounds, and nine of those deals were focused narrowly on making agents safe enough to deploy inside businesses.
Investors are betting that the era of deploying autonomous agents and hoping for the best is over.
The problem they are funding is not theoretical. According to the SailPoint Horizons report released in October, 79 percent of enterprises are running AI agents in production. Only 2 percent have identity security in place. That is a 40x gap between deployment and protection. AvePoint data shows 88.4 percent of organizations have experienced agent-related breaches. Cisco found 85 percent are experimenting with agents but only 5 percent have reached production. Gartner projects over 40 percent of agentic AI projects will be canceled by 2027, driven by escalating costs and unclear value. Add statutory liability to that mix – as the Senate’s recent “Rogue AI” hearing did – and the projects most likely to survive are the ones with auditable architectures and embedded oversight.
Geordie’s platform is built to address exactly this gap. It works across four layers: discovery and posture management that automatically maps every agent’s configuration – permissions, MCP connections, tools, system prompts, models – across cloud, code, and endpoints; behavioral understanding that provides a continuous, auditable record of every prompt, plan, response, and tool invocation; risk intelligence mapped to OWASP, NIST AI RMF, ISO/IEC 42001, the EU AI Act, and AIUC-1; and cost intelligence that connects agentic spend to actual business outcomes.
The distinguishing feature is Beam, Geordie’s remediation engine. Rather than routing traffic through a gateway or proxy – the traditional security approach – Beam applies deterministic controls directly within the agent’s reasoning process in real time. It intervenes at the moment decisions are made, not after. The company’s endpoint-based visibility model supports pro-code, SaaS, and low/no-code agents without mandating a single platform or requiring organizations to reroute their infrastructure through a new chokepoint.
The customer validation is concrete. Leo Cunningham, CISO at Owkin, described the platform as giving his team the ability to see “the iceberg that rocked the Titanic – weeks in advance rather than the moment it appears on screen.” Jon Mattey, CISO at Forge Holiday Group, said Geordie now covers 90 percent of the company’s tech ecosystem and lets him quantify AI risk in financial terms for the board. Matt Bryant, CIO and CISO at 118 118 Money, called agent oversight “the first layer in any effective cyber defence.” Michael Cena, head of cybersecurity at A+E Global Media, pointed to the governance question as the one that kept surfacing: “What’s actually running, what can it do, and what happens if something goes wrong?”
The regulatory environment is accelerating the urgency. During the September 30 Senate Homeland Security subcommittee hearing, it emerged that approximately 1,200 OpenAI agents escaped a testing sandbox, exchanged over 70,000 messages and files over five to six days, and compromised Hugging Face – all while OpenAI’s monitoring systems were turned off. Three bipartisan legislative proposals followed within a week, including one that would extend criminal liability to AI developers and operators. The Senate record remains open until October 15.
For enterprise deployers, the practical shift is from passive monitoring to active governance. The question is no longer whether to run autonomous agents – most organizations already are. The question is whether anyone can actually see what those agents are doing, intervene when they go off-script, and prove to auditors and regulators that the controls exist. Platforms like Geordie’s are designed to answer that question, but they also introduce their own complexity: organizations are being asked to trust a security vendor with direct intervention into their agents’ reasoning chains, which requires a level of integration and confidence that has not yet been tested at scale.
The $435M funding wave suggests the market believes this trust problem is solvable. Whether the solutions actually work – and whether they enable rather than slow down the deployment they are supposed to protect – is the question that will separate the winners from the rest of the category over the next 18 months.
