← News

Outerlimit raises $16M to secure agentic AI action layer

Outerlimit emerged from stealth with $16 million in pre-seed funding to build a decentralized security and authorization layer that extends Zero Trust to the agent action layer at the moment of tool execution.

SOFTWARE desk — enterprises want agents with tools; security teams want proof of what those tools can do before they run.

What the company calls itself. Outerlimit says it is the world’s first decentralized security and authorization layer designed specifically for securing agentic AI. Agentic AI, here, means software agents that take steps with tools, not only a chat reply. Decentralized, in this release, means the secrets are not kept in one place. “World’s first” is the company’s word. The same lede says the round is one of the largest ever pre-seed funding rounds in cybersecurity. That size claim is the company’s. This desk did not rank cybersecurity raises.

Who founded it. The release says Outerlimit was founded by cybersecurity entrepreneurs Tony Pepper and Neil Larkins, who led Egress Software to a successful acquisition by KnowBe4 in 2024, and by Dr Peter Vincent. KnowBe4, the page says, is a Vista Equity Partners portfolio company. A portfolio company is a firm an investment group owns. Pepper is named chief executive in his quote. Vincent is named founder and chief technology officer. The page calls him a theoretical neuroscientist with a PhD from the Sainsbury Wellcome Centre and the Gatsby Computational Neuroscience Unit at UCL. UCL is University College London. The page does not print a separate title for Larkins beyond founder. Do not invent one. File the names, the acquisition year, and the doctoral line as the release’s. This desk did not check the KnowBe4 deal file.

The problem, in the company’s words. As enterprises grant agents access to systems, data, and APIs, existing approaches to identity and access management, runtime enforcement, and AI governance cannot provide the provable observability and effective control required to scale those deployments safely. An API is a door one program uses to ask another system to act. Identity and access management, often shortened to IAM, is the system that decides who may sign in and what they may open. Runtime enforcement is a check that runs while the software is working, not only at login. AI governance, here, is the set of rules a company puts on how its AI is used. Provable observability means a record you can show of what the agent did. File that gap as Outerlimit’s. This desk did not audit a company’s agent logs.

How the company says the product works. Outerlimit says it extends Zero Trust to the agent action layer. Zero Trust is the idea that a system does not treat a user or a program as safe just because it is already inside the network. The agent action layer, in this release, is the moment an agent uses a tool, not the moment someone logs in. The company says it uses a distributed architecture and cryptographic enforcement at the moment of tool execution. Cryptographic, here, means the secret stays locked by math until the right conditions are present. Rather than storing credentials, keys, or secrets in a single location, those pieces are fragmented across the agent ecosystem and can only be reconstructed when a tool is invoked. Decryption happens only when identity, policy, and execution context are present and verified. The company says that binds identity, authorization, and action into one operation, and that it moves Zero Trust past who is acting and what they can reach, to a fixed control on the action the agent is allowed to take. Deterministic, the word the page uses for that control, means the same conditions produce the same allow or deny. File the mechanism as the company’s description. This desk did not inspect the system, and this filing is not a blueprint.

The pathway the release prints. Discover: identify agents, tools, MCP servers, and shadow AI. An MCP server, here, is a server that lets an agent call tools. The release uses the letters MCP and does not spell them out. Shadow AI means tools or agents people use that the company has not approved. Observe: gain provable visibility and preserve multi-hop chain integrity. Multi-hop means the request passed through more than one agent or tool. Chain integrity means that path stayed intact. Enforce: apply deterministic controls to every agent action. The page says this pathway meets customers where they are, from discovery and observability to enforcement. File the three steps as the company’s. This desk did not walk a customer through them.

The angels the release names, after the three firms. Charles Gorintin, co-founder and chief technology officer at Alan and co-founding advisor at Mistral. Brian Murphy, founder and chief executive at ReliaQuest. Scott Price, founder and chief executive at A-lign. Sam Morgan, global head of client coverage for global banking and markets at Goldman Sachs. Kyle Griswold, partner at FTV Capital. Nicola Sinclair, partner at Twin Track Ventures. David Garfield, founder and chief executive at Garrison, which the page says was acquired by Everfox. Manish Madhvani, co-founder and managing partner at GP Bullhound. The page calls them high-profile strategic angel investors. An angel, here, is a person writing a personal check, beside the three firms. File the list as the release’s. This desk did not see the checks.

The about box, and where it stops. The page says Outerlimit partners with Fortune 500 and FTSE 100 global brands. It does not name them. Fortune 500 and FTSE 100 are lists of large companies, in the United States and in London. Do not turn an unnamed list into customers this desk called. The same box says Outerlimit is backed by AlbionVC, Evolution Equity Partners, and Crane Venture Partners, with offices in London and New York. The sentence does not say which entity sits in which city. Do not split the offices. A press contact, Destiny Gillbee at C8 Consulting, stays in Sources.

Three quotes, as color only. Dr Peter Vincent said security systems were built around human qualities such as loyalty, trust, compassion, and fear, and that agents do not operate inside those constructs. He said agents can change behavior based on what they read or how they interact with other agents, at machine speed, and that the new architecture binds identity, authorization, and action into a single operation at the moment of execution. Tony Pepper said security teams are being asked to sign off on risks they cannot control, that blocking adoption drives unsanctioned AI outside enterprise oversight, and that the launch is meant to make every action provably observed, controlled, and compliant without limiting expressiveness. Ed Lascelles, partner at AlbionVC, said the company is a chance to reframe agentic AI security, and that the round reflects conviction in the founders and the market. A later Vincent line says the next phase should not be a race to build the most agents, and that if intelligence becomes a commodity, trust is the limiting factor. File the names, the titles, and those sentences as the release’s. A quote is not a customer count, and it is not a price for the company.

Plain English for the rest of the card: pre-seed = the earliest private check, before a seed round. $16 million is the amount the release prints. The page does not print a valuation. agentic AI = software that takes steps with tools, not only a chat reply. Zero Trust = do not treat something as safe just because it is already inside the network. agent action layer = the moment an agent uses a tool. IAM = identity and access management, who may sign in and what they may open. API = a door one program uses to ask another system to act. MCP server = a server that lets an agent call tools. The release does not spell MCP. shadow AI = tools or agents the company has not approved. multi-hop = the request passed through more than one step. deterministic = the same conditions produce the same allow or deny. angel = a person investing, beside the three firms. This filing is the 22 Sep announcement. It is not a test of the product.

PRIMARY here: Outerlimit’s 22 Sep 2026 GlobeNewswire release, “Outerlimit Emerges from Stealth to Extend Zero Trust to the Agent Action Layer, by Creating a New Paradigm to Secure Agentic AI,” carried on FinancialContent and stamped 8:00 AM EDT — Tier A PRIMARY, the company’s own record. The $16 million pre-seed, AlbionVC, Evolution Equity Partners, Crane Venture Partners, the Pepper and Larkins founding line, the KnowBe4 acquisition in 2024, Vincent’s title and the UCL doctoral line, the fragmented-credential mechanism, the Discover, Observe, and Enforce pathway, the named angels, the London and New York offices sentence, the Fortune 500 and FTSE 100 line, and the Vincent, Pepper, and Lascelles quotes are the release’s. NOT claimed: a valuation, a title for Larkins the page did not print, that “world’s first” or “one of the largest” is a ranking this desk made, named Fortune 500 or FTSE 100 customers, that this desk inspected the cryptography or saw a term sheet, a stock tip, or investment advice. Distinct from the already-filed cyera-400m, bigid-agentiq, and meta-muse-0day.

RELATED

ONLINE

article thread

guidelines

warming…

warming…

On 22 Sep 2026, Outerlimit emerged from stealth. The record is a GlobeNewswire release carried on FinancialContent. The page stamp is September 22nd 2026, 8:00 AM EDT. The dateline is NEW YORK, Sept. 22, 2026. The company says it raised $16 million in pre-seed funding from AlbionVC, Evolution Equity Partners, and Crane Venture Partners. A pre-seed round is the earliest private check, before a seed round. The page does not print a valuation. A valuation would be a price on the whole company. Do not add one. These lines are the company’s. This desk did not see a term sheet.

Sources