Kontext raises $4M to control what AI agents are allowed to do inside businesses
German artificial intelligence security startup Kontext today announced $4 million in new funding for software that controls what AI agents are allowed to do once they are running inside a business.
Kontext’s software sits between an agent and the systems it acts on. Every action the agent requests is checked against security policy before it runs, with the agent’s identity and the resource it wants both factored in. What the company calls a task-aware approach comes from also weighing the job the agent was actually given.
The company gives the example of an agent assigned to fix a software bug. Reading the code repository is fair game for that job. Sending the code to an outside service, or reusing the same access to modify unrelated infrastructure, is not, even though the agent’s credentials might let it do both.
Teams can run Kontext in an observe mode first to see how a policy would apply to their agents without blocking any work. Once enforcement is switched on, unauthorized actions are denied before they execute. Every decision is logged in an auditable record.
Kontext pointed to a July incident to show how quickly that kind of risk can become real. Agents in a cybersecurity evaluation broke out of their isolation and compromised outside infrastructure without human instruction. OpenAI Group PBC disclosed an incident matching that description on July 21, when it said two of its models escaped a cyberattack test environment and got into Hugging Face Inc. servers to reach benchmark answer keys.
An agent “can be properly authenticated, use an approved tool, and still take an action no one authorized,” said Chief Executive Jens Ernstberger. He started the company with Michel Osswald after completing a doctorate in cryptography and computer security at the Technical University of Munich. The two aimed the product at exactly that problem.
The Munich company plans to use the money to expand its engineering team. 42CAP led the round. Andreessen Horowitz’s crypto startup accelerator, a16z CSX, invested as well, and so did High-Tech Gründerfonds Management GmbH.
Julian von Fischer, a general partner at 42CAP, said identity and access tools built over the last two decades assume “a human is on the other end, clicking one thing at a time.” An agent authenticates once and then works across many systems with nobody checking each step, he said. Most tools still stop at the credential, according to von Fischer.
Kontext’s software currently works with coding agents including Anthropic PBC’s Claude Code and OpenAI’s Codex. Individual developers can use it free of charge, and paid team plans start at $149 a month.
Photo: Kontext
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.