Outerlimit Raises $16M to Build Zero Trust Security Layer for Autonomous AI Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Outerlimit has emerged from stealth with $16 million in pre-seed funding to develop a decentralized security and authorization layer for autonomous AI agents.

Announced on September 22, 2026, the round was backed by AlbionVC, Evolution Equity Partners, and Crane Venture Partners, making it one of cybersecurity’s largest pre-seed raises, according to the company.

The London- and New York-based startup is targeting an enterprise security gap. Agentic AI systems can call tools, query sensitive data, use APIs, and execute workflows.

That autonomy creates risk when an agent is manipulated, misconfigured, or changes behavior after consuming untrusted content. Conventional identity and access management may authenticate an agent and grant access, but it does not necessarily constrain the precise action taken at execution time.

Outerlimit says its architecture extends Zero Trust to this “agent action layer.” Instead of keeping credentials, cryptographic keys, or secrets in one repository, the platform fragments them across the agent ecosystem.

They are reconstructed only when a tool is invoked and the agent’s identity, policy, and execution context have been verified. The intended result is deterministic authorization: an off-policy action should be denied before the underlying tool executes it, even if the agent is misaligned.

This model separates security enforcement from probabilistic AI reasoning. “Agents can change their behavior based on what they read, or how they interact with other agents, while acting at machine speed,” said co-founder and CTO Dr Peter Vincent. He argued that identity, authorization, and action must be bound into one operation at execution.

According to the launch announcement published by Outerlimit, the company is positioning adoption as a three-stage process. Discovery identifies agents, tools, Model Context Protocol servers, and unsanctioned “shadow AI.”

Observation provides visibility while preserving integrity across multi-hop agent chains. Enforcement applies policy controls to every agent action. This progression should help organizations inventory deployments before introducing controls that could disrupt legitimate automation.

CEO Tony Pepper said blocking agentic AI adoption could push teams toward unapproved tools outside enterprise oversight.

However, Outerlimit’s strongest assertions including provable observation, zero credential exposure, and deterministic control remain vendor claims; the announcement included no independent test results, performance benchmarks, or detailed customer deployments.

The company was founded by Pepper and Neil Larkins, who led email security vendor Egress Software through its 2024 acquisition by KnowBe4, alongside Vincent, a theoretical neuroscientist trained at University College London.

For defenders, the launch reflects a shift in agentic AI security: monitoring model output is insufficient when software agents can directly alter systems. Security teams need controls at the tool boundary, where actions can be evaluated, logged, and blocked.

Outerlimit’s funding gives it substantial resources to pursue that architecture, but enterprise confidence will depend on transparent technical validation, integration coverage, and evidence that enforcement remains reliable at machine speed.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Outerlimit Raises $16M to Build Zero Trust Security Layer for Autonomous AI Agents appeared first on Cyber Security News.