Today, I’m proud to announce that Cisco Investments is our newest strategic investor, extending our oversubscribed Series A round.

Enterprises are deploying AI agents across their organizations faster than ever, but control over the actions these agents take, and on whose behalf, has not advanced at the same pace. As agents interact with core systems and execute real actions with tangible consequences, teams require robust governance to enforce precise, real-time boundaries. Solving that critical gap is why Cisco Investments has backed Arcade.

Building on the $60 million Arcade received earlier this year, led by SYN Ventures with participation from Morgan Stanley and Wipro, the extension enables us to establish AI agent governance as a fundamental component of enterprise infrastructure.

Over the past twelve months, nearly every organization I’ve consulted has experienced a consequential security incident, most originating from within their own walls. Unreviewed, over-permissioned agents operating across production systems are increasingly becoming a source of operational risk.

“Our enterprise customers are seeking real-time visibility, governance and accountability for agent actions,” according to Janey Hoe, vice president, Cisco Investments. “We are thrilled to welcome Arcade to the Cisco Investments portfolio and look forward to working with their team as part of Cisco’s broader commitment to help our customers scale Agentic IT with necessary security and controls.”

The potential for AI governance presents significant upside for the enterprise. The ROI stakeholders are pursuing is realized when agents perform meaningful work in production: closing tickets, updating records, or managing financial transactions. As agents take real-world actions, they create opportunities and risks. Consequently, enterprises must ensure that governance, authorization, policy, and audit trails are enforced at the precise moment of every tool call.

While many teams attempt to address this by building guardrails within their agents, these filters and prompt instructions reside inside the model and cannot deterministically enforce behavior. The July Hugging Face breach highlighted this limitation. Despite OpenAI’s guardrails, more than 17,000 agent actions occurred over a single weekend, hitting production infrastructure without external verification. Governance must reside outside the reasoning loop, positioned at the point where an agent meets or interacts with a system.

We developed Arcade’s action runtime to serve as this enforcement point. Every agent action passes through a centralized control plane that validates whether a specific agent, on behalf of this user, is authorized to perform requested actions on a given resource in real time. Authorization is verified at the intersection of the user’s identity and the agent’s scope, ensuring an agent never exceeds the permission of the individual behind it.

Existing policies across DLP, IdP, compliance, and SIEM tooling integrate directly into the runtime, firing on every action as it occurs. These policies can prevent unauthorized data infiltration, enforce human-in-the-loop approvals for sensitive actions, and block bulk-deletion requests. Because this is enforced at a single chokepoint, every action is captured, logged, and audited, providing full visibility into what was done, on whose behalf, and under which policy. With this secure foundation, every agent, regardless of the model, client, or framework, is cleared to run safely in production.

We are excited to work with Cisco Investments, our partners, investors, and customers to build a future where teams can safely deploy agents and unlock ROI through governed, secure action. The future is evolving, one deployed agent at a time, and we’re just getting started.

Want to dive deeper into how we’re thinking about governance and its critical role in underpinning agents at scale? Book a demo here.