As CEO of Onyx Security, Maxim Bar Kogan is building infrastructure to govern autonomous AI agents in the enterprise. Drawing on his background in military intelligence and offensive cyber operations, he argues that traditional security tools fail against unpredictable AI systems. This profile details his strategy for keeping humans in control as these agents take on critical roles in energy, finance, and healthcare.

Visual summary of operating lessons from Maxim Bar Kogan.

Part 1: The Transition to Agentic Operations

  1. On the tipping point of enterprise automation: "A year ago, almost nothing inside the enterprise was done by an agent. A year from now, most actions inside the enterprise will be." — Source: Onyx’s $113M Series B: Keeping Humans in Control as AI Becomes Smarter | Onyx Blog
  2. On the future of corporate decision-making: The trajectory of AI adoption suggests that eventually entire organizations will run as autonomous operations, with agents handling decisions regarding capital allocation, patient care, and energy grids. — Reference: Onyx’s $113M Series B: Keeping Humans in Control as AI Becomes Smarter | Onyx Blog
  3. On the fundamental question of reliance: "when something smarter than you is responsible for the things you depend on, how do you stay in control?" — Source: Onyx’s $113M Series B: Keeping Humans in Control as AI Becomes Smarter | Onyx Blog
  4. On the pace of AI deployment: Because less than one percent of actions in 2025 were executed by AI, the impending shift where autonomous systems take over the majority of digital actions requires entirely new methods of validation. — Reference: Onyx Security raises $113 million as demand grows for tools to manage AI agents
  5. On the spark of agentic imagination: Early open-source experiments like AutoGPT provided the first real glimpse into a future where models would stop generating text and start executing loops of autonomous actions. — Reference: Building an AI Guardian for Enterprise with Onyx Security CEO Maxim Bar Kogan - YouTube
  6. On the necessity of early adoption: Holding AI back is not the solution for keeping it safe; organizations must govern it effectively so they can safely embed it into critical industries. — Reference: Onyx’s $113M Series B: Keeping Humans in Control as AI Becomes Smarter | Onyx Blog
  7. On the stakes in critical infrastructure: When AI agents operate in healthcare, energy, or finance, a poor decision made at production speed does not just create bad press, it causes outages, market events, or puts lives at risk. — Reference: Onyx’s $113M Series B: Keeping Humans in Control as AI Becomes Smarter | Onyx Blog
  8. On who sets the governance standard: The standards for AI safety are not being driven by theoretical debates, but rather by the Fortune 500 companies in heavily regulated sectors that are actively deploying agents in production environments. — Reference: Onyx’s $113M Series B: Keeping Humans in Control as AI Becomes Smarter | Onyx Blog
  9. On the competitive advantage of AI: The future promises that small teams will be able to rival massive organizations simply by orchestrating AI agents effectively. — Reference: Introducing Onyx Security: The Secure AI Control Plane for Enterprises | Onyx Blog
  10. On embracing non-deterministic workflows: While some systems like encryption and authentication must remain strictly deterministic, the operational flexibility offered by non-deterministic AI now outweighs the limitations of rigid software. — Reference: Catch the full pod with Maxim Bar Kogan of Onyx Security this week. 🎧… | Inflection Point: Digital Intelligence Podcast
  11. On treating agents as a new class of enterprise actor: Agents can write code, triage IT work, manage customer workflows, and make decisions across platform, tool, and identity boundaries at machine speed, so governance must follow the actor rather than a single application. — Reference: Onyx Security — Introducing the Secure AI Control Plane
  12. On governing agents where they operate: Because agents act across browsers, endpoints, SaaS products, and cloud systems, effective control has to inspect actions where the agent lives and before those actions take effect. — Reference: Onyx Security — Keeping Humans in Control

Part 2: The Inadequacy of Traditional Security

  1. On the obsolescence of deterministic tools: "The security tooling that exists today was built for a world of deterministic software and human-driven workflows. It cannot see this new surface, let alone control it." — Source: Introducing Onyx Security: The Secure AI Control Plane for Enterprises | Onyx Blog
  2. On the unique nature of AI actions: Unlike traditional software, AI agents are non-deterministic, meaning they never behave exactly the same way twice because their actions are shaped by dynamic context and untrusted inputs. — Reference: Introducing Onyx Security: The Secure AI Control Plane for Enterprises | Onyx Blog
  3. On the failure of human-in-the-loop oversight: Relying on human review as a safety backstop is no longer practical when the volume of autonomous agent actions grows exponentially by thousands or millions. — Reference: Maxim Bar Kogan | No Priors Summary
  4. On the limitations of API monitoring: "Unfortunately, our endpoint providers or API security tools, they don't know what Cloud was thinking. Why is it doing what it's doing." — Source: Maxim Bar Kogan | No Priors Summary
  5. On the speed of the AI attack surface: A decade ago, AI-powered attacks felt like a distant threat, but they are arriving rapidly, requiring a complete rebuild of the security stack, including firewalls and identity management. — Reference: No Priors — Maxim Bar Kogan on the AI security stack
  6. On the disruption of incumbent security vendors: Artificial intelligence is fundamentally changing the cybersecurity landscape, making established companies vulnerable and giving smaller startups the chance to redefine the market. — Reference: AI security startup Onyx raises $113 million Series B at $640 million valuation | Ctech
  7. On evaluating intent over action: Because agents are empowered with access to critical systems, security can no longer just block malicious requests; it must analyze the agent's reasoning and intent before an action takes effect. — Reference: No Priors — Building an AI Guardian for Enterprise
  8. On the widening governance gap: "The gap between what advanced AI can do and what humans can govern is widening, not narrowing." — Source: Onyx’s $113M Series B: Keeping Humans in Control as AI Becomes Smarter | Onyx Blog
  9. On defining the limits of autonomy: AI governance must do more than detect threats; it should make explicit what an agent is allowed to do and what remains outside its authority. — Reference: CTech — Onyx Security raises $35 million

Part 3: The Architecture of AI Oversight

  1. On the strategy of using AI to watch AI: The sheer volume of AI activity requires training specialized models and deploying guardian agents specifically designed to oversee, evaluate, and control other AI agents in an environment. — Reference: Building an AI Guardian for Enterprise with Onyx Security CEO Maxim Bar Kogan - YouTube
  2. On the tiered model approach: "You don't want to spend too much intelligence where you don't have to and you want to spend a lot of intelligence, overwhelmingly a lot in situations where there's high risk." — Source: Maxim Bar Kogan | No Priors Summary
  3. On avoiding frontier models for everything: Using massive, intelligent models to oversee every action is economically unviable; the better architecture uses small, hyper-specialized models that act as gatekeepers to determine when to escalate to a smarter agent. — Reference: Maxim Bar Kogan | No Priors Summary
  4. On specialized gatekeepers: "You want to train very smart models that are — actually, let me correct myself — very not smart models. But models are just good at one thing. They're very small. They almost can't do anything else other than be able to say, should I have a smarter agent look at this?" — Source: Maxim Bar Kogan | No Priors Summary
  5. On real-time enforcement: An effective AI control plane must be able to discover all agents, interpret their reasoning, and either block, approve, or redirect their actions at runtime before they reach downstream infrastructure. — Reference: Introducing Onyx Security: The Secure AI Control Plane for Enterprises | Onyx Blog
  6. On the composition of successful AI teams: Building effective oversight requires blending deep cybersecurity DNA with frontier AI research experience, placing security researchers alongside model trainers. — Reference: Introducing Onyx Security: The Secure AI Control Plane for Enterprises | Onyx Blog
  7. On the necessity of speed and safety: By implementing robust infrastructure that actively governs AI agents, organizations are empowered to deploy AI aggressively and move fast without sacrificing safety. — Reference: Introducing Onyx Security: The Secure AI Control Plane for Enterprises | Onyx Blog
  8. On inventorying the whole AI surface: A useful enforcement layer must discover not only agents, but also models, AI-powered applications, and MCP-connected tool ecosystems, then turn governance policy into runtime controls. — Reference: Onyx Security — Introducing the Secure AI Control Plane
  9. On making oversight a data-scale problem: Governing agents in production depends on continuous telemetry at operational scale; Onyx reports securing more than 1.1 million agents and inspecting more than 66 million AI sessions in real time. — Reference: Onyx Security — Keeping Humans in Control

Part 4: Alignment and Independent Governance

  1. On the paradox of smarter models: As AI models grow more capable, alignment becomes harder, not easier, because advanced models develop independent, semi-conscious perspectives that may diverge from what the user intended. — Reference: Maxim Bar Kogan | No Priors Summary
  2. On the conflict of interest in self-governance: "If you're a security team, you're not going to trust the vendor of a product to tell you that this product is not going to mess your environment." — Source: Maxim Bar Kogan | No Priors Summary
  3. On the need for third-party auditing: You need an independent organization whose entire business model relies on accurately assessing whether an AI model is behaving correctly, rather than relying on the foundation labs themselves. — Reference: Maxim Bar Kogan | No Priors Summary
  4. On the risks of relying on a single AI provider: Given how rapidly capabilities fluctuate between providers like OpenAI and Anthropic, standardizing on a single AI platform leaves enterprises strategically vulnerable. — Reference: Maxim Bar Kogan | No Priors Summary
  5. On shifting vendor dominance: Because model capabilities change so quickly, organizations must maintain the flexibility to adopt multiple tools safely rather than locking into one ecosystem. — Reference: Maxim Bar Kogan | No Priors Summary
  6. On the danger of phased model rollouts: Slowly rolling out access to frontier models can backfire geopolitically; if domestic companies are kept isolated from advanced AI, they may end up defenseless against adversaries who deploy highly capable models sooner. — Reference: Maxim Bar Kogan | No Priors Summary
  7. On data privacy with foundation labs: Enterprises are wary of allowing foundation labs to retain their historical agent data, knowing these providers will likely use that sensitive information for future model training. — Reference: Building an AI Guardian for Enterprise with Onyx Security CEO Maxim Bar Kogan - YouTube
  8. On the scale of the AI control market: "Our mission is to control AI. Trillions of dollars are being invested in AI, and the companies that help enterprises deploy it safely will be worth billions." — Source: AI security startup Onyx raises $113 million Series B at $640 million valuation | Ctech

Part 5: Navigating the Competitive Landscape

  1. On focusing amid intense competition: In the hyper-competitive space of AI cybersecurity, the best strategy is to largely ignore competitors and focus entirely on listening to and solving problems for your customers. — Reference: Catch the full pod with Maxim Bar Kogan of Onyx Security this week. 🎧… | Inflection Point: Digital Intelligence Podcast
  2. On customer-driven growth: "our guide for company has always been to actually not care about the competition. We care about only one thing. We care about our customers." — Source: Catch the full pod with Maxim Bar Kogan of Onyx Security this week. 🎧… | Inflection Point: Digital Intelligence Podcast
  3. On early market skepticism: When initially pitching the concept of an AI control plane, many security experts felt the idea was too early, betting that startups would run out of money before enterprises actually adopted autonomous agents. — Reference: Building an AI Guardian for Enterprise with Onyx Security CEO Maxim Bar Kogan - YouTube
  4. On early validation and momentum: Rapidly raising significant funding rounds post-stealth indicates that demand for AI control mechanisms has far exceeded initial market expectations, validating the urgency of the problem. — Reference: AI security startup Onyx raises $113 million Series B at $640 million valuation | Ctech
  5. On building an enduring company: The ultimate objective is not simply to build a cybersecurity startup to sell it off, but to establish a durable, independent, and global category leader. — Reference: AI security startup Onyx raises $113 million Series B at $640 million valuation | Ctech
  6. On making AI returns visible: Adoption becomes easier to govern when companies can connect agent activity to measurable business outcomes; Bar Kogan points to coding and customer interactions as areas where returns are becoming clearer. — Reference: CTech — Onyx Security raises $35 million