A new startup called Outerlimit has emerged with a $16 million pre-seed investment to tackle security risks posed by autonomous AI agents. The London- and New York-based company is building what it describes as a zero-trust, decentralized authorization layer designed to better control what AI agents actually do once deployed in enterprise environments.
What problem is Outerlimit solving?
As organizations adopt agentic AI systems—software agents that can call APIs, automate workflows, use tools, and access sensitive data—there’s a growing concern that conventional identity‐and‐access tools aren’t enough. Even when an agent is authenticated, its actions—especially if misconfigured or manipulated—can run wild. Outerlimit’s view is that today’s systems verify who or what an agent is, but not what it ends up doing.
Outerlimit aims to close this gap by extending zero-trust principles to the “agent action layer.” Rather than giving an agent broad credentials or secret keys, the startup fragments those pieces across its ecosystem. The credentials are only rebuilt at runtime—when an agent calls a tool—and only after verifying its identity, policy compliance, and execution context. If an agent tries to take a prohibited action—one that’s off policy—it can be blocked before damage is done.
How the system works & funding outlook
The company is rolling out its system in phases. First comes Discovery, which lets organizations map agents, tools, and context as well as spot unsanctioned or “shadow” AI instances. Next is Observation, giving visibility into agent chains without jeopardizing workflow integrity. Finally, Enforcement steps in, ensuring every action by an agent is controlled by policy before execution.
Outerlimit’s $16M funding round was announced on September 22, 2026, and backed by AlbionVC, Evolution Equity Partners, and Crane Venture Partners. For a pre-seed round, this is notably large for the cybersecurity space. Founders include CEO Tony Pepper, Neil Larkins (both previously involved with Egress Software), and Dr. Peter Vincent, a theoretical neuroscientist trained at University College London.
Promises and claims still need proof
While Outerlimit asserts it can provide provable observation, ensure zero credential exposure, and enforce deterministic control, the announcement does not include independent benchmarks or detailed customer use cases. It remains unclear how well the system performs under realistic operational speed and scale.
The core value proposition is that security teams must move beyond output monitoring toward controlling tools at the edge—where agents’ actions can be evaluated in real time. Traditional alerts based on logs or outputs may come too late when agents have already pushed changes.
With $16M in hand, Outerlimit is well-positioned to build out its architecture. But for enterprises to adopt this new layer, the promises must be matched by transparent technical validation and evidence that enforcement can work at machine speed without breaking legitimate automation.
What this means: As autonomous AI agents become more capable and embedded in business operations, identity checks alone won’t prevent misuse. Securing the action layer—where agents perform tasks—is the next front in AI security. Companies evaluating agentic AI should watch how Outerlimit’s policies, benchmarks, and real-world deployments evolve. Success here could redefine how AI is trusted in enterprise settings.