Outerlimit raises $16m for agentic AI security

Outerlimit raises m for agentic AI security

Outerlimit has raised $16m to secure increasingly autonomous AI agents. The Egress founders’ new cybersecurity business is building controls designed to govern agent actions as enterprises connect AI systems directly to operational tools.


Outerlimit has emerged from stealth with $16m in pre-seed funding to build security infrastructure intended to control what autonomous AI agents are permitted to do inside enterprise technology environments.

The round was backed by AlbionVC, Evolution Equity Partners, and Crane Venture Partners and is among the larger pre-seed financings completed in the cybersecurity market.

Outerlimit was founded by Tony Pepper and Neil Larkins, who previously led UK email-security company Egress before its acquisition by KnowBe4 in 2024, alongside theoretical neuroscientist Dr Peter Vincent.

The company is targeting a security problem created by the development of agentic AI. Unlike conventional AI tools that primarily generate text, code, or other outputs for a user, agents can be authorised to interact with applications, retrieve information, call software tools, and complete actions across business systems.

That ability changes the access-control problem facing security teams. Traditional identity and access management is generally designed around people, service accounts, and relatively predictable software processes. Autonomous agents can make decisions dynamically and interact with several systems as part of a single task.

Tony Pepper, chief executive of Outerlimit, said: “Blocking adoption isn’t a strategy, it simply drives the use of unsanctioned AI outside of enterprise oversight.”

Outerlimit’s approach is designed to extend zero-trust security principles to the point at which an agent attempts to execute an action. Its architecture combines identity, policy, execution context, and authorisation before allowing a tool to be used.

The company says credentials, keys, and other secrets are fragmented rather than stored in a single location and reconstructed only when an authorised action takes place. The approach is intended to reduce the amount of standing access available to an AI agent and make individual actions independently controllable.

The platform is structured around discovery, observation, and enforcement. Discovery is intended to provide an inventory of agents, models, tools, and connections operating within an organisation, including unsanctioned AI usage. Observation records actions across those systems, while enforcement applies policies when an agent attempts to execute a tool.

The funding arrives as businesses connect generative AI models to operational systems rather than limiting their use to standalone experimentation. Greater integration can increase productivity because software can complete more of a workflow without people manually transferring information between applications.

It also raises the consequence of error. An AI assistant producing an inaccurate paragraph creates one type of risk; an autonomous system that can alter a customer record, execute code, approve a process, query confidential data, or trigger an external application creates another.

Security teams have to consider malicious use as well as unintended activity. An agent may operate as designed but hold excessive permissions, follow manipulated instructions contained within data it reads, interact with a compromised system, or take an action that falls outside an organisation’s compliance policies.

That challenge is contributing to a new category of enterprise security products focused on AI discovery, model governance, prompt and data security, runtime controls, and agent permissions. Established cybersecurity suppliers are also extending existing platforms to address AI workloads, giving start-ups new competition from businesses with established customer relationships.

Outerlimit’s founders bring experience from Egress, which developed technology to protect email and data before its acquisition by KnowBe4. Their new business is starting with substantial capital but has entered the market before establishing a publicly disclosed customer base.

The size of the pre-seed round therefore reflects investor expectations around the development of agentic AI security rather than an established revenue profile. Outerlimit will have to demonstrate that its architecture can operate across varied enterprise systems without introducing unacceptable latency, integration complexity, or new operational weaknesses.

The distinction between probabilistic AI reasoning and deterministic security enforcement is central to its proposition. Outerlimit’s policies are intended to make an allow-or-deny decision at execution time rather than ask another AI model to decide whether an action is safe.

As organisations give AI systems greater operational authority, that control layer is becoming a more visible part of enterprise architecture. The $16m round gives Outerlimit significant early capital to compete for that position as security teams adapt to software that can increasingly act rather than simply advise.

—



  • UK corporate tax receipts pass £100bn

    UK corporate tax receipts pass £100bn

    UK corporate tax receipts passed £100bn in the latest year. HMRC recorded £100.4bn across corporate taxes, with stronger financial-sector receipts offsetting falling energy levies and a small number of large companies accounting for most liabilities.


  • Accessibility push highlights £446bn spending market

    Accessibility push highlights £446bn spending market

    Accessibility can unlock substantial commercial opportunity for smaller City businesses. SMEs have been urged to remove customer and workplace barriers as updated research values the potential spending power of UK disabled households at £446bn annually.


  • Technology leaders report growing management complexity

    Technology leaders report growing management complexity

    Technology leaders report mounting complexity as management demands keep expanding. An AMBS study found 85% of technology-sector respondents believe their roles have become more complicated, while AI skills, team engagement, and commercial strategy lead training priorities.