Skip to content

Palma AI raises $1.8 mn for enterprise AI agent governance

Palma AI raises $1.8 mn for enterprise AI agent governance

Berlin-based Palma AI has raised $1.8 mn in pre-seed funding to expand its enterprise governance platform for AI agents, targeting companies that need central control over agent permissions and actions across internal systems.

D11Z led the round, joined by Plug and Play Ventures and Deel. Scale Now Ventures also participated alongside angel investors, including executives from Cisco and Deel.

Palma AI plans to use the capital to grow its engineering and go-to-market teams as more enterprises deploy agents across business applications.

Patrick Eden, CEO, founded Palma AI with CTO Julian Kolbe in 2026. The company focuses on a security problem emerging as AI moves beyond chat interfaces into agents authorised to query databases, call corporate APIs and perform actions inside business software.

Those deployments introduce a gap between identity and authority. An agent might hold valid credentials for a company system, yet those credentials alone don’t determine whether a particular action belongs to the task assigned by an employee or administrator.

Palma AI places a governance layer between AI agents and the corporate systems they access. Companies manage permissions centrally rather than configuring security separately inside every AI product, giving IT teams one control point across multiple agent environments.

The platform builds around the Model Context Protocol, or MCP, an open standard used to connect AI applications with external tools and company data. MCP simplifies those connections, though permissions often remain distributed across individual AI applications and servers, making central oversight difficult for larger organisations.

Palma AI gives employees and agents a governed connector containing the MCP tools and Skills authorised for their role. Administrators define policies around which resources an agent receives access to and what individual tool calls are permitted once the agent starts working.

Policies apply when an action occurs. Palma AI examines the requested tool call and its arguments against company rules before execution, allowing routine activity to proceed while holding higher-risk requests for approval or denying them.

The same policy framework follows users across AI environments rather than remaining tied to one assistant. Palma AI supports deployments involving Claude and ChatGPT, alongside Microsoft Copilot and internally developed agent workflows.

Companies also use the platform to package approved Skills for repeated business processes. Those workflows include tasks such as updating CRM records or producing financial reports, with permissions attached to the tools required for each process.

Every decision enters a tamper-evident audit record containing information about the user and agent involved in an action. The system records whether a request was approved or denied, giving security teams evidence of activity without reconstructing events across separate applications.

The approach targets enterprises where autonomous agents operate across several systems under one user identity. Traditional identity and access management software largely determines whether a user or application has access to a resource, whereas Palma AI adds task-level rules around what an agent is authorised to perform after gaining access.

Eden said companies are approaching a point where agents receive meaningful permissions across internal systems, making oversight of individual actions more important. Palma AI was built so businesses retain visibility into which agent performed an action, which tool it used and which policy governed the request.

D11Z and Plug and Play already use Palma AI internally, according to the company, creating an overlap between investors and customers in the pre-seed round. Their deployments use the platform to govern employee access to AI agents connected with enterprise tools.

The product also connects with existing identity infrastructure, including Microsoft Entra and Okta through OIDC.

Palma AI supports deployment inside customer-controlled infrastructure, including private cloud environments, for organisations seeking to keep governance data and audit records within their own systems.

The security issue has attracted growing venture investment as enterprises introduce agents with broader operational authority. Agent security companies now address separate parts of the problem, including runtime monitoring, access controls and broader AI security management.

Palma AI concentrates on authorization at the point where an agent attempts to use a tool. Rather than building another AI assistant, the company provides middleware governing the interaction between agents and enterprise systems.

The $1.8 mn round gives Palma AI early funding in a sector where larger security vendors are already expanding their agent-focused products. Its immediate work centres on engineering and commercial expansion as enterprises move more agent workflows into production.