The problem with letting an AI agent loose inside a company is not that it might forget who it is. It is that it has no reason to hold back.

A human employee is restrained by the fear of being fired. An agent, as one investor in Arcade.dev put it, “will exhaustively exploit every permission it inherits” to reach its goal. Arcade has raised $60mn to make sure that, by design, it cannot.

The Series A was led by SYN Ventures, with strategic cheques from Morgan Stanley and Wipro. Added to a $12mn seed last year, it brings the San Francisco startup to $72mn in total funding.

Identity is easy. Authorisation is the wall

Most companies can already verify that an agent is what it claims to be. What they cannot do, according to Arcade chief executive Alex Salazar, is prove that a given agent, acting for a given user, is allowed to perform a given action on a given system.