An employee or AI? A $12M Israeli startup wants to tell the difference

As AI agents increasingly operate through human accounts, Israeli startup Rig Security has raised $12 million to help companies distinguish between people and AI and stop risky agent activity without blocking employees

As AI agents take on more work inside companies, from writing code to investigating problems and automating routine tasks, they are creating a surprisingly basic security problem: Companies may no longer know whether a person or a piece of software is actually using an employee’s account.
Israeli cybersecurity startup Rig Security is betting that the distinction will become one of the defining security challenges of the AI era.
Rig team. The company has grown to 20 employees
Rig team. The company has grown to 20 employees
Rig Security team. The company has grown to 20 employees
(Photo: Courtesy of Rig)
The Tel Aviv-based company emerged from stealth Tuesday with $12 million in seed funding for a platform designed to identify AI agents operating through human and machine accounts — and, when necessary, stop them without blocking the people whose credentials they are using.
Ten Eleven Ventures and Brightmind Partners co-led the funding round, with participation from the CrowdStrike Falcon Fund and cybersecurity executives including Wiz co-founder and CTO Ami Luttwak.
The technology addresses a problem that barely existed a few years ago but is quickly becoming familiar inside large organizations. Companies have spent decades building systems to decide which employees can access which databases, applications and cloud environments. AI agents complicate that model because they frequently operate using access already granted to a person or service account rather than through a separate identity of their own.
That can create an unusual blind spot.
If an employee gives an AI coding agent access to a system, for example, the agent may begin performing tasks using that employee’s existing permissions. Traditional security logs can show that the account accessed a file, changed code or performed some other sensitive action. But they may not make clear whether the employee performed the action or an AI agent working on the employee’s behalf did.
“Identity used to mean people’s credentials. Today the most active identities in an enterprise are AI agents, and they are acting under human names,” Rig founder and CEO Guy Kozliner said.
That distinction matters as companies increasingly experiment with autonomous software capable not merely of answering questions but of taking actions. An agent with excessive permissions could potentially expose sensitive information, alter systems or make an unwanted change at machine speed.
The broader problem goes beyond AI. Compromised credentials and other identity-related attacks have already become a major focus of cybersecurity teams. Google Cloud has reported that compromised identities are involved in roughly three-quarters of breaches, making the arrival of another class of actors using existing credentials particularly significant.
Rig’s approach is to build a map of the identities and permissions spread across a company’s infrastructure and then add another layer: determining what is actually acting through those identities.
Its platform correlates human, machine and AI identities across cloud infrastructure, corporate networks, identity providers and endpoints. The company says its technology can identify when an AI agent is using a person’s session and separate that activity from the employee’s own actions.
Rig Security founder and CEO Guy Kozliner
Rig Security founder and CEO Guy Kozliner
Rig Security founder and CEO Guy Kozliner
(Photo: Noi Arkobi)
That could allow a company, for example, to stop an AI agent from carrying out a prohibited action while allowing the employee whose account it is using to continue working normally.
At the center of the platform is what Rig calls the Rig Identity Correlation Engine, or RICE. The company says the machine-learning system matches identities across otherwise disconnected corporate systems with more than 96% accuracy in internal testing. The underlying technology is in the patent process, according to Rig.
The company also offers a lightweight piece of software that can be installed on employee devices to identify activity at its source. Rig says that allows it to distinguish an AI agent’s session from the employee’s own activity and apply security rules before a potentially risky action reaches a cloud service or other corporate system.
For businesses adopting AI rapidly, that could become increasingly important because the security question is shifting from simply “Who has access?” to “What is using that access right now?”
New American Funding, one of Rig’s customers, said its employees are already using AI agents across engineering, marketing, operations and other departments.
“When an agent acts on behalf of an employee, traditional identity security tools cannot reliably distinguish the agent’s activity from the person’s,” said Bill Harper, the company’s associate vice president for digital identity.
Rig says it is already being used by Fortune 200 companies in financial services, insurance, health care and technology, though it did not identify most of those customers. The company says its systems currently protect tens of millions of identity activities.
The startup has also attracted attention from some of the biggest names in Israeli and American cybersecurity.
Before launching Rig, Kozliner worked at Israeli cloud security company Wiz on a team led by Luttwak. Wiz helped popularize the use of interconnected graphs to show how seemingly separate vulnerabilities and permissions could combine into an attack path through cloud infrastructure. Rig is applying a related idea to identity, mapping the relationships among accounts, permissions, sessions and AI agents.
Luttwak is now an investor in the company.
Rig was also one of two runners-up in the 2025 AWS and CrowdStrike Cybersecurity Startup Accelerator, run in collaboration with NVIDIA’s Inception program. The CrowdStrike Falcon Fund subsequently invested in its seed round.
The company has grown to 20 employees. Its leadership team also includes CTO Nokky Goren, who was the first engineer at Axis Security before its acquisition by Hewlett Packard Enterprise, and head of product Michal Haikov, a veteran of the Israeli military’s Unit 8200 and Flow Security, which was acquired by CrowdStrike.
For Rig, however, the larger bet is not simply that companies will deploy more AI. That already appears well underway. It is that the familiar concept of digital identity will have to change with it.
For years, cybersecurity systems have largely operated on the assumption that an authenticated employee or machine account represents the actor using it. AI agents are beginning to break that assumption.
The account may still belong to a person. The entity clicking, coding, querying and changing things behind it increasingly may not.
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""