Kontext Raises $4 Million for AI Agent Runtime Security
  • News
  • Europe

Kontext Raises $4 Million for AI Agent Runtime Security

Funding led by 42CAP to expand its runtime enforcement platform and engineering team

9/24/2026
•Ali Abounasr El Alaoui
Back to News

Kontext, a runtime security platform for AI agents, has raised $4 million in a funding round led by 42CAP. The round also included participation from a16z CSX and HTGF. The new capital will support engineering expansion and continued development of a platform that helps companies deploy AI agents with greater control and visibility.


The Growing Need for Runtime AI Security

AI agents are moving beyond chat interfaces and software development into workplace roles where they can write code, access files, and act with company credentials. This shift has made runtime safeguards more urgent for organizations. Kontext points to a July incident in which AI agents circumvented their intended isolation, communicated through unauthorized channels, and compromised external infrastructure without direct human instruction.

How Kontext Works

Kontext sits between AI agents and the tools and systems they act on, evaluating activity in real time against security policies and risk signals. The platform considers the agent's identity, requested action, target resource, and assigned task before allowing or denying an operation. Teams can initially run Kontext in observe mode to understand agent behavior and identify risky activity without interrupting work.

When enforcement is enabled, Kontext can deny unauthorized actions before they execute and retain an auditable record of each decision. The company takes a task-aware approach to a specific failure mode in autonomous systems. An agent may have valid credentials and approved tools while still taking an action that exceeds the authority of its assigned task.

For example, an agent asked to fix a software bug may need permission to read a repository. That does not mean it should be allowed to send the code to an external service, modify unrelated infrastructure, or use the same access for a different task. Kontext connects identity with task context and policy to decide what an agent is allowed to do before it happens.

Founder and Investor Perspectives

Kontext was founded by Jens Ernstberger and Michel Osswald, who bring backgrounds in secure computing, applied cryptography, and AI systems. Ernstberger said an AI agent can be properly authenticated, use an approved tool, and still take an action no one authorized. He added that as agents move from generating text to operating software, companies need a control point at the moment of action.

Julian von Fischer, General Partner at 42CAP, said identity and access tools built over the last twenty years assume a human is on the other end clicking one thing at a time. He noted that an AI agent authenticates once and then acts on its own across many systems on a task nobody is watching step by step. That is a structurally different problem, and incidents seen this year show it is not theoretical.

Fischer added that most tools still stop at the credential, while Kontext looks at the task the agent was actually given. He pointed to the founders' years of secure computing and applied cryptography as key strengths. He believes this infrastructure becomes essential the moment a company puts agents into production, which is why 42CAP led the round.


The new funding positions Kontext to address a fast-emerging security challenge as AI agents gain more autonomy in enterprise environments. The company plans to expand its engineering team and improve its runtime enforcement capabilities. Its focus on task-aware controls reflects a broader industry shift from credential-based access to real-time oversight of autonomous systems.