Over the past few days, I've been grateful to see Xybern's inclusion in Blossom Capital's inaugural portfolio covered across a growing number of technology, business and investment publications.

For me, however, this milestone means much more than the coverage. It represents another step toward something I have become increasingly convinced will be fundamental to the next generation of artificial intelligence:

AI systems are becoming capable of acting. We now need infrastructure that determines whether they have the authority to act.

That is the problem we are building Xybern to solve.

From AI Systems to Autonomous Actors

For much of the recent history of artificial intelligence, the primary conversation has been about capability. Can a model understand this? Can it generate that? Can it reason about this problem? Can it write this code?

But AI is undergoing an important transition. We are moving from systems that primarily generate information toward autonomous agents capable of interacting with the real world.

Agents can increasingly call APIs, access enterprise systems and sensitive data, interact with MCP servers and tools, initiate workflows, execute transactions and delegate tasks to other agents.

Once AI can act, the security problem fundamentally changes. The question is no longer simply what can this AI do? It becomes what is this AI authorised to do?

Those are very different questions.

Why I Believe Authorisation Will Become Fundamental to AI Infrastructure

Authentication tells an organisation who or what is attempting to access a system. But autonomous agents create a much deeper problem: an authenticated agent should not automatically have unlimited authority.

Its permissions may depend on its identity, its mandate, the action being requested, the resource involved, the authority delegated to it, organisational policy, environmental context and the potential consequences of the action.

  • An agent might be permitted to read financial information but not initiate a payment.
  • It might be authorised to use one MCP tool but not another.
  • It might be allowed to delegate a task to another agent without being allowed to delegate all of its own authority.
  • A high-risk action might require human approval.

And when something happens, the organisation should be able to establish not simply what happened, but why that agent had the authority to do it.

This is the security boundary we are building at Xybern. Our Authorisation Layer sits between agent intent and execution, enabling organisations to evaluate autonomous actions before they reach the systems on which they operate.

Autonomous capability should never imply autonomous authority.

Why Saudi Arabia Matters

This is also why I'm particularly excited about the opportunity in Saudi Arabia. The Kingdom is making significant investments in artificial intelligence, digital infrastructure, entrepreneurship and emerging technologies.

But the next phase of AI adoption will not be defined only by access to increasingly capable models. It will also depend on whether organisations can deploy those systems securely, responsibly and at scale.

That becomes particularly important in government, financial services, healthcare, critical infrastructure and other regulated or mission-critical environments. These organisations cannot simply give autonomous systems unrestricted access and hope that monitoring after execution will be sufficient. Security must increasingly become part of the execution path itself.

For Xybern, Saudi Arabia therefore represents much more than another geographic market. It represents an opportunity to help build the security infrastructure around an emerging autonomous AI economy.

Blossom and the Next Stage for Xybern

Joining Blossom Capital's inaugural portfolio gives Xybern the opportunity to become more deeply connected to this ecosystem. Blossom's model combines investment with commercialisation, market access, strategic relationships and support for companies building in and expanding into Saudi Arabia.

For us, this comes at an important point in Xybern's development. We are continuing to develop our authorisation infrastructure across areas including agent identity, runtime authorisation, agent-to-agent delegation, MCP and tool security, human approval, external-agent federation and cryptographic provenance.

Our objective is to make it possible for organisations to deploy increasingly autonomous AI while maintaining meaningful control over what those systems are permitted to do.

More Than the Headlines

Seeing Xybern covered by publications across the region and internationally has been encouraging. But ultimately, coverage is temporary. What matters is what we build next.

There are difficult questions ahead for the entire AI industry:

  • Who owns an agent's identity?
  • Who grants its authority?
  • Can one agent delegate authority to another?
  • How far should that authority propagate?
  • Who determines which tools an agent can use?
  • When should an autonomous action require human approval?
  • How do we revoke authority immediately?
  • And how can an organisation cryptographically prove the authority behind an action after it occurs?

I believe questions like these will become increasingly important as autonomous agents move from experiments into production infrastructure. They are also the questions that motivate much of my work today.

The Next Chapter

I'm grateful to the team at Blossom and to everyone who has supported Xybern to this point. Joining Blossom Capital's inaugural portfolio is an important milestone, but I see it primarily as another starting point. There is still a tremendous amount to build.

As AI becomes increasingly autonomous, I believe the infrastructure governing identity, authority, delegation and execution will become a fundamental component of enterprise AI security. That is the future we are building toward at Xybern.

The future of AI isn't only about what machines become capable of doing. It is also about how we maintain authority over what they are allowed to do.

Dr. Charalambos TheodorouFounder & CEO, Xybern

In the News

Independent coverage of Blossom Capital's launch and inaugural portfolio: