Outerlimit Raises $16M to Build Zero Trust Security Layer for Autonomous AI Agents
Outerlimit raised $16 million to build a zero-trust authorization layer for autonomous AI agents.
London- and New York-based Outerlimit emerged from stealth on September 22, 2026, with $16 million in pre-seed funding from AlbionVC, Evolution Equity Partners, and Crane Venture Partners. It plans a zero-trust layer that fragments credentials and reconstructs them only after an agent's identity, policy, and execution context are verified, so off-policy tool calls are denied. Adoption is staged as discovery of agents, tools, MCP servers, and shadow AI, then observation, then enforcement. Founders Tony Pepper and Neil Larkins previously led Egress, acquired by KnowBe4 in 2024; the announcement included no independent tests or customer deployments.
- $16 million pre-seed from AlbionVC, Evolution Equity Partners, and Crane Venture Partners.
- Credentials are reconstructed only after identity, policy, and context checks.
- Rollout is discovery of agents and shadow AI, then observation, then enforcement.
- Provable control and zero credential exposure remain unverified vendor claims.
Full article525 words · extracted from cybersecuritynews.com · click to collapse
Outerlimit has emerged from stealth with $16 million in pre-seed funding to develop a decentralized security and authorization layer for autonomous AI agents.
Announced on September 22, 2026, the round was backed by AlbionVC, Evolution Equity Partners, and Crane Venture Partners, making it one of cybersecurity’s largest pre-seed raises, according to the company.
The London- and New York-based startup is targeting an enterprise security gap. Agentic AI systems can call tools, query sensitive data, use APIs, and execute workflows.
That autonomy creates risk when an agent is manipulated, misconfigured, or changes behavior after consuming untrusted content. Conventional identity and access management may authenticate an agent and grant access, but it does not necessarily constrain the precise action taken at execution time.
Outerlimit says its architecture extends Zero Trust to this “agent action layer.” Instead of keeping credentials, cryptographic keys, or secrets in one repository, the platform fragments them across the agent ecosystem.
They are reconstructed only when a tool is invoked and the agent’s identity, policy, and execution context have been verified. The intended result is deterministic authorization: an off-policy action should be denied before the underlying tool executes it, even if the agent is misaligned.
This model separates security enforcement from probabilistic AI reasoning. “Agents can change their behavior based on what they read, or how they interact with other agents, while acting at machine speed,” said co-founder and CTO Dr Peter Vincent. He argued that identity, authorization, and action must be bound into one operation at execution.
According to the launch announcement published by Outerlimit, the company is positioning adoption as a three-stage process. Discovery identifies agents, tools, Model Context Protocol servers, and unsanctioned “shadow AI.”
Observation provides visibility while preserving integrity across multi-hop agent chains. Enforcement applies policy controls to every agent action. This progression should help organizations inventory deployments before introducing controls that could disrupt legitimate automation.
CEO Tony Pepper said blocking agentic AI adoption could push teams toward unapproved tools outside enterprise oversight.
However, Outerlimit’s strongest assertions including provable observation, zero credential exposure, and deterministic control remain vendor claims; the announcement included no independent test results, performance benchmarks, or detailed customer deployments.
The company was founded by Pepper and Neil Larkins, who led email security vendor Egress Software through its 2024 acquisition by KnowBe4, alongside Vincent, a theoretical neuroscientist trained at University College London.
For defenders, the launch reflects a shift in agentic AI security: monitoring model output is insufficient when software agents can directly alter systems. Security teams need controls at the tool boundary, where actions can be evaluated, logged, and blocked.
Outerlimit’s funding gives it substantial resources to pursue that architecture, but enterprise confidence will depend on transparent technical validation, integration coverage, and evidence that enforcement remains reliable at machine speed.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.