The funding will support the development of Outerlimit’s security architecture, which extends Zero Trust principles beyond identity and access management to the individual actions AI agents perform when interacting with enterprise systems, applications, data, and APIs.
Outerlimit was founded by Tony Pepper, Neil Larkins, and Dr. Peter Vincent, combining enterprise cybersecurity experience with research in computational neuroscience.
Pepper and Larkins previously led Egress Software, a cybersecurity company acquired by KnowBe4, a Vista Equity Partners portfolio company, in 2024. Vincent is a theoretical neuroscientist who earned his PhD through University College London’s Sainsbury Wellcome Centre and Gatsby Computational Neuroscience Unit.
Together, the founders are developing technology intended to address security challenges associated with the growing deployment of autonomous AI agents in enterprise environments.
Unlike traditional software applications, AI agents can independently select tools, interact with other agents, access sensitive information, and execute actions based on their interpretation of instructions and external data.
Outerlimit argues that existing identity and access management systems, runtime security controls, and AI governance tools do not provide sufficient visibility or authorization controls for these increasingly autonomous activities.
Its platform addresses this problem by establishing cryptographically enforced authorization when an AI agent executes an action.
Rather than relying solely on which applications or information an agent can access, Outerlimit evaluates whether an individual action is authorized based on the agent’s identity, applicable security policies, and the context in which the action is performed.
The company’s decentralized architecture avoids storing credentials, encryption keys, and other secrets in a single centralized location.
Instead, these credentials are fragmented across the agent ecosystem and can only be reconstructed when an agent invokes a tool. Decryption occurs only after the required identity, policy, and execution context have been verified.
This approach is designed to prevent unauthorized agent actions before execution, rather than relying solely on monitoring activity and identifying security problems afterward.
Outerlimit describes its technology as an extension of Zero Trust security to the agent action layer, providing organizations with controls that apply to individual operations performed by AI systems.
The platform also provides a structured approach to introducing these capabilities into existing enterprise environments.
Organizations can begin by discovering AI agents, connected tools, Model Context Protocol (MCP) servers, and unauthorized or previously unidentified AI applications.
The platform then provides visibility into agent activities, including interactions involving multiple agents and connected systems.
Its observability capabilities are designed to preserve the integrity of these multi-step interactions, allowing security teams to understand how actions were initiated and executed.
The final stage introduces deterministic enforcement, applying authorization controls to individual agent actions as they occur.
This phased approach lets organizations identify and monitor AI deployments before introducing more extensive enforcement requirements.
Outerlimit’s development strategy addresses a challenge facing enterprises as AI agents become increasingly integrated into business operations.
Organizations deploying autonomous systems must balance the productivity benefits of AI with the need to maintain control over sensitive data, financial transactions, business applications, and other critical resources.
The company believes traditional security systems need to evolve to address software that can make decisions and initiate actions without continuous human supervision.
By combining identity verification, authorization, and execution controls, Outerlimit intends to provide a common security architecture for organizations adopting agentic AI.
The startup reports that it is already partnering with Fortune 500 and FTSE 100 companies, although it has not disclosed the identities of those customers or the commercial terms of their relationships.
In addition to its institutional investors, Outerlimit has attracted several strategic angel investors with backgrounds in cybersecurity, financial services, venture capital, and artificial intelligence.
These include Charles Gorintin, co-founder and CTO of Alan and a co-founding advisor at Mistral; Brian Murphy, founder and CEO of ReliaQuest; and Scott Price, founder and CEO of A-LIGN.
Other investors include Sam Morgan, Global Head of Client Coverage for Global Banking and Markets at Goldman Sachs; Kyle Griswold, a partner at FTV Capital; Nicola Sinclair, a partner at Twin Track Ventures; David Garfield, founder and CEO of Garrison; and Manish Madhvani, co-founder and managing partner at GP Bullhound.
With offices in London and New York, Outerlimit plans to use its financing and industry relationships to develop its security platform and support enterprise adoption.
The company is positioning its technology as an infrastructure layer for organizations seeking to deploy AI agents while maintaining control over the actions those systems can perform.
KEY QUOTES:
“We’ve spent decades building security systems around human qualities such as loyalty, trust, compassion, and even fear which drive predictable decision-making. In this new agentic era, where agents use reasoning models with access to tools that can impact the world, they simply don’t operate within these human constructs. Agents can change their behavior based on what they read, or how they interact with other agents, while acting at machine speed. Harnessing this powerful intelligence requires a fundamentally new security architecture – one that binds identity, authorization, and action into a single operation at the moment of execution.”
Dr. Peter Vincent, Founder And CTO Of Outerlimit
“The demand to deploy agentic AI is unparalleled, but security teams are being asked to sign off on risks they cannot adequately control. Blocking adoption isn’t a strategy, it simply drives the use of unsanctioned AI outside of enterprise oversight. Today’s launch of Outerlimit represents a paradigm shift to securing agentic AI, creating a world where AI agents can be trusted implicitly because every action is provably observed, controlled, and compliant without limiting their expressiveness.”
Tony Pepper, CEO Of Outerlimit
“We are excited about what Outerlimit is building, which represents a significant opportunity to disrupt and reframe the agentic AI security market. Tony, Neil, and Peter bring a rare combination of deep security expertise and proven founder pedigree. The strength of this funding round reflects our conviction in both the company and the scale of the market opportunity ahead.”
Ed Lascelles, Partner At AlbionVC