From the ‘Cyber Spring’ to the ‘Trust Economy’: Why We Invested in Onyx by Iren Reznikov, Partner

August, 2026

Iren Reznikov
Partner

About a year ago, I wrote a two-part series called The Cyber Spring. At the time, my argument was that AI is not just an incremental change in cybersecurity; it is reshaping the classic cyber triangle of the attacker, the defender, and the buyer. New attack surfaces are emerging, buyer expectations are changing, and cybersecurity companies are being re-architected to meet new buyer needs and new attack vectors. The companies that will define the next decade will not be the incumbents that simply added AI features to existing products, but the ones built from day one for the modern Enterprise Security Stack- where AI is embedded across every layer, from infrastructure to delivery and outcomes.

Since then, AI adoption has quickly accelerated. According to McKinsey, 88% of organizations now report regular AI use in at least one business function, and AI agents are already moving from theory to deployment: 23% of organizations say they are scaling an agentic AI system somewhere in the enterprise, while many more are experimenting with them.

Today, the biggest question for enterprises is no longer whether AI can create value. Anyone who has spent time with modern models, coding agents, or enterprise copilots already knows the answer. The real question is whether organizations can trust these systems enough to deploy them at scale.

This is what I call the beginning of the Trust Economy.

Every major economic system in history has been built on trust. Markets function because buyers and sellers trust each other and the value of a $. Financial systems function because people trust institutions. Entire economies depend on invisible layers of confidence that most of us rarely think about. In many ways, the AI era is built on a similar concept. As organizations increasingly rely on AI, and AI agents, to make decisions, automate workflows, interact with customers, write code, and execute tasks on their behalf, trusting AI is becoming one of the most important factors for adoption.

And as enterprises adopt these AI systems, they are discovering that many of the controls they spent decades building were never designed for a world where software itself becomes an actor. If the first generation of solutions in AI security focused on putting static guardrails around AI systems, that is no longer enough in a world where autonomous agents make a series of decisions across enterprise environments. It is no longer sufficient to know only what the AI is doing; enterprises need to understand its intent when doing it.

This is when we met the Onyx team.

What immediately resonated with us in what Maxim Bar Kogan and Gil Elbaz are building was not only the strong execution, impressive customer momentum, or the size of the market opportunity. It was how the team defines the underlying problem. While much of the first wave of AI security approached the category through the lens of traditional cybersecurity-securing prompts, protecting data, managing permissions, or adding static controls around AI systems- Onyx approached the problem first as an AI problem, and only then as a cybersecurity problem. The team’s belief is that if autonomous agents are becoming a new class of actor inside the enterprise, then governing them requires understanding how they reason, make decisions, and behave in real-world environments.

For the last two decades, enterprise security has largely focused on controlling access: who is allowed into a system, what data they can see, and which actions they are permitted to perform. But autonomous agents introduce a new challenge. As agents become responsible for writing code, interacting with internal systems, and making operational decisions, understanding intent becomes just as important as understanding permissions.

This is where Onyx stood out to us. The company’s vision is built around helping enterprises understand what their agents are trying to accomplish, evaluate actions in the context of policies and security requirements, and maintain control without slowing down adoption. Rather than relying solely on static rules, Onyx uses AI to monitor AI, applying context aware oversight to agents operating across SaaS applications, cloud environments, endpoints, code, and internal workflows. And in many cases, when an agent is about to take an action that creates risk, Onyx can redirect it toward a safer path rather than simply shutting it down.

That philosophy feels deeply aligned with the Trust Economy thesis: the goal is not to slow down AI adoption, but to create enough trust that organizations can accelerate it.

Trust has always been the catalyst for adoption. We trusted cloud providers when moving critical workloads into the cloud. We trusted SaaS vendors as they became the backbone of the modern enterprise. AI adoption has to follow the same path; we simply do not have another choice.

We need to create accountability for autonomous systems, governance for AI driven decision making, and trust in a world where software increasingly acts on behalf of people.

A year ago, I argued in The Cyber Spring that AI would fundamentally reshape cybersecurity. Looking back, I would take that thesis one step further.

AI is not only reshaping cybersecurity; it is elevating cybersecurity into the trust infrastructure of the AI economy itself.

As enterprises move from experimenting with AI to operationalizing AI, trust becomes the enabling factor. The organizations that can govern, understand, and control autonomous intelligence will be the ones that unlock its full potential.

To us, that is exactly where Onyx sits: building the infrastructure that enables enterprises to securely adopt AI agents and models at scale, and helping define the trust layer for the AI economy.

 

To the Onyx team: we are proud to back you alongside a list of incredible investors: Cyberstarts Bessemer Venture Partners Conviction FirstMark TCV

Get in touch with Iren Reznikov:

Share

Skip to content