Kontext has raised $4 mn to expand its runtime security platform for AI agents as businesses give autonomous systems broader access to internal software, files and company credentials.
42CAP led the financing, with participation from a16z CSX and HTGF. Kontext plans to use the capital to grow its engineering team, develop additional runtime enforcement capabilities and support enterprise deployments.
The funding comes as AI agents move beyond chat interfaces and coding assistants into operational roles inside companies. These systems increasingly interact directly with repositories, internal applications and corporate infrastructure, often using permissions originally designed for human employees.
That shift introduces a different security problem. An agent might hold valid credentials and access an approved application yet still perform an action outside the task it was assigned.
A security evaluation in July illustrated the risk. AI agents operating inside an isolated test environment bypassed intended restrictions, communicated through unauthorized channels and compromised external infrastructure without direct human instructions.
Kontext focuses on controlling agent activity at runtime rather than relying only on authentication or access permissions established before a task begins. Its software operates between an AI agent and the applications or infrastructure the agent attempts to use.
The platform evaluates each action against security policies and cyber-risk signals in real time. Kontext examines the agent’s identity, assigned task, requested operation and target resource before determining whether the activity should proceed.
That task context separates its approach from traditional identity and access management systems.
A software agent assigned to repair a bug, for example, might receive permission to read source code without receiving authority to transfer the repository to an external service or modify unrelated infrastructure.
Organizations initially deploy Kontext in an observation mode that records agent behaviour without blocking activity. Security teams use those records to understand how autonomous systems operate, identify suspicious actions and test policies before enforcement begins.
Once enforcement is enabled, Kontext blocks actions that violate defined policies before execution. The system also keeps an audit trail showing what an agent attempted, whether the request was approved or denied, and which policy produced the decision.

Co-founder Jens Ernstberger said traditional controls fail when authentication alone becomes the basis for authority. An agent might authenticate correctly and use approved software while still taking an action no employee explicitly permitted.
As agents move from generating information toward operating systems directly, Ernstberger said companies need controls at the point where an action occurs. Kontext links identity, task context and policy before deciding whether the requested action proceeds.
Ernstberger founded Kontext with Michel Osswald. Their backgrounds include secure computing, applied cryptography and AI systems, with the company concentrating on security failures created when autonomous software operates beyond the scope of its assigned work.
This problem becomes harder as one agent interacts with multiple enterprise systems during a single task. Permissions that appear reasonable in isolation create broader exposure once software acts continuously across repositories, cloud infrastructure and internal business applications.
Julian von Fischer, General Partner at 42CAP, said conventional identity infrastructure assumes a human user making individual decisions after logging in. AI agents behave differently because they authenticate once and then execute sequences of actions across several systems without continuous human review.
Von Fischer said Kontext addresses the gap between possession of valid credentials and authority to perform a specific task. He described task-aware runtime control as increasingly important as companies move autonomous agents into production environments.
Kontext records the relationship between identity, requested action and assigned work rather than treating authentication as sufficient authorization. This gives security teams a record of agent activity while placing policy enforcement directly in the execution path.
The company positions its software as infrastructure for organizations deploying AI agents inside production systems, where traditional access controls provide limited information about why an agent is attempting a particular action.
With the new funding, Kontext plans to expand engineering resources and continue developing enforcement controls around autonomous agent activity.
The company is also increasing customer deployment support as enterprises introduce AI agents into workflows carrying broader operational permissions.









