ThreatLocker Raises $190M to Put AI Agents on a Leash
ThreatLocker raised $190 million to expand a security model in which software and AI agents are blocked unless explicitly allowed.

AI agents are gaining access to corporate systems faster than many security teams can decide what those agents should be allowed to do.
ThreatLocker has raised $190 million in Series F funding to expand a model built around a simple rule: block software and automated actions unless they have been explicitly approved.
What happened
The round was led by Elephant, with participation from D. E. Shaw Ventures, Arthur Ventures and Koch Disruptive Technologies.
ThreatLocker plans to use the capital to develop its Zero Trust platform, add AI-focused security controls and expand internationally. Its next step includes opening a UK office in Reading.
Why it matters
Traditional security tools often try to identify malicious activity after something starts running. ThreatLocker’s deny by default approach reverses that logic. Applications, scripts and agents cannot act simply because they look legitimate; they need permission first.
That becomes more relevant as AI agents receive access to files, browsers, cloud applications and internal tools. An agent does not need malicious intent to cause damage. It can make a bad decision, follow a manipulated instruction or use access that was broader than necessary.
The bigger picture
AI-agent security is splitting into several layers: discovering agents, monitoring their behaviour, managing their identities and limiting their permissions. ThreatLocker is positioning itself at the enforcement layer.
The company says it protects more than 70,000 organisations, but that figure has not been independently verified. The stronger signal is the funding itself: investors are treating permission controls for AI agents as a serious enterprise-security market, not a niche add-on.
