Zenity Raises $125 Million to Secure the Era of 1 Billion AI Agents

AI Agent Security Is Going Global: Join Us in London and New York

Portrait of Cinthia Portugal
Cinthia Portugal
Cover Image
Ask AI to

When we first conceived the AI Agent Security Summit and assembled the league of security leaders, the idea was pretty simple: create the kind of industry conversation we wanted to see happening around AI agents and security.

At the time, “agentic risk” was still a relatively new concept. There were plenty of events talking about AI, and plenty of cybersecurity conferences, but I felt there was a gap for a forum focused specifically on the broader security challenges emerging as AI started moving from something we interact with to something that takes action on our behalf.

Just as important, I didn’t want it to become another vendor event.

The goal from the beginning was to bring together AI security researchers, practitioners, security leaders, builders, and yes, sometimes competitors, to talk openly about what they were seeing. The League Assembled to discuss new attack paths, new research, things breaking, things working, and questions nobody had fully answered yet. Zenity might bring the community together, but the conversation needed to be bigger than any one company or product.

That idea has turned into something very unique and valuable to the community. And now we’re going global.

The AI Agent Security Summit comes to London on October 8, followed by a return to New York on October 21. Both agendas are officially live.

A Lot Has Changed Since the First AI Agent Security Summit

There’s something particularly fun about bringing the Summit back to New York, where we held the first one in 2025.

At that first event, much of the industry was still working through what agentic risk meant. Today, enterprises are deploying AI agents that access sensitive data, use credentials, call tools, connect through Model Context Protocol (MCP), make decisions, and take actions across business systems. The conversation has moved quickly from whether AI agents introduce a new security problem to how we secure them as they become part of enterprise infrastructure.

The community has moved quickly too.

Previous Summits brought together people exploring Copilot attack surfaces, agentic risk, identity, authorization, and autonomous systems before many of those topics became regular parts of the enterprise security conversation.

That’s part of what I love about these events. We don’t need everyone to agree. In fact, it’s more interesting when they don’t. We want people close enough to the technology to challenge assumptions, share what they’re learning, and push the conversation somewhere new.

As we take the AI Agent Security Summit to new cities, I want each one to belong to the community there. London shouldn’t feel like New York transported across the Atlantic, and New York shouldn’t follow a formula. Each Summit will bring together researchers, practitioners, builders, and security leaders from those communities, with conversations shaped by the challenges, priorities, research, and perspectives that matter most to them.

The mission stays the same. The people in the room help determine where the conversation goes.

The AI Agent Security Questions Are Getting Harder

As AI agents become more autonomous, the security questions surrounding them are getting harder too.

Across the London and New York Summits, we’ll get into rogue agent behavior, frontier-model deception, MCP security, prompt injection, agent identity, intent-aware authorization, privilege escalation, shadow agents, tool poisoning, containment, sandbox escapes, and the emerging security models enterprises are building around autonomous AI.

Some of the questions underneath those topics sound deceptively simple.

  • What happens when an AI agent has permission to take an action, but the person behind it never intended that action?
  • What happens when a security control works exactly as designed, but an agent finds another path?
  • What happens when an AI-powered SOC consumes attacker-controlled telemetry as trusted context?
  • How should enterprises secure MCP servers and tools?
  • Where does identity end and understanding agent intent begin?

These are increasingly practical AI agent security problems.

In New York, they become research and live demonstrations. The agenda includes examples ranging from vulnerabilities in MCP servers and manipulation of AI-powered SOC environments to intent-aware authorization and security controls that disappear when an agent takes an unexpected route.

London brings another dimension to the discussion, with conversations around agent behavior, deception in frontier models, containment, policy, identity, action-level security controls, and lessons emerging from real-world agent activity.

Different research. Different speakers. Different communities. One security problem moving extraordinarily fast.

Keeping the AI Agent Security Summit Organic

As the Summit has grown, one thing I’ve been protective of is what made it interesting in the first place.

We never want this to become a cybersecurity conference where everyone already knows what everyone else is going to say.

The best sessions tend to leave you thinking differently than you did when you walked into the room. Sometimes it’s new AI security research. Sometimes it’s a live demo that exposes an assumption we’ve all been making. Sometimes it’s a practitioner saying, “Here’s what happened when we tried this.”

New York alone will feature 14 sessions spanning research, demonstrations, frameworks, and lessons from people working directly with AI agents and autonomous systems. London brings its own group of researchers and practitioners, its own topics, and its own perspective to the conversation.

And if our previous Summits are any indication, some of the most interesting discussions will happen between sessions, over coffee, or after someone sees something on stage and immediately wants to dig into it during Happy Hour.

That’s exactly what we want.

From One Summit to a Global AI Agent Security Community

What started as an idea for a different kind of security event has grown far beyond what I pictured when we put the first one together. It now takes an incredible group of people to make these Summits happen, from the teams working behind the scenes to the researchers, practitioners, security leaders, and speakers who bring their work and perspectives to the stage.

With every Summit, the community has gotten bigger, the conversations have gotten richer, and more people have wanted to be part of it. I’m incredibly proud of what so many people have built together.

The technology has moved. The AI agent attack surface has moved. The questions have gotten harder. So we’re bringing the people working on them together again, this time in two cities with two different communities helping shape the conversation.

The AI Agent Security Summit London takes place October 8, 2026.

The AI Agent Security Summit New York takes place October 21, 2026.

Come for the research, the demos, the debate, and the opportunity to spend a day with people thinking deeply about what happens when AI stops simply generating answers and starts taking action.

Both agendas are live.

I’ll see you there.

All Articles

Secure Your Agents

We’d love to chat with you about how your team can secure and govern AI Agents everywhere.

Get a Demo