Summary
- Kontext has raised $4m for a runtime-security layer aimed at agents with access to enterprise tools and data.
- Its product evaluates identity, task context, resources, and policy before an agent action is allowed to execute.
- The approach addresses the gap between an agent holding valid credentials and being authorised to perform a particular action.
Munich-based Kontext has raised $4 million to develop runtime security for enterprise AI agents, focusing on the moment software with legitimate access attempts an action that may fall outside the task it was given.
The financing is led by 42CAP, with participation from a16z CSX and High-Tech Gründerfonds. Kontext is targeting organisations moving agents beyond chat interfaces and into environments where software can read files, write code, use credentials, and operate business systems directly.
That creates a control problem conventional access management does not fully address. Identity systems establish which resources a user or service may access, but an agent can hold valid credentials and still take an action that is inappropriate for the job it is meant to perform.
Kontext inserts an enforcement point between the agent and the resource, evaluating identity, task context, security policy, and the requested action. Organisations can first observe behaviour before activating controls that block requests and record the reason for the decision.
Authentication does not answer every question
The distinction becomes more important as agents gain wider operational authority. A coding agent may legitimately need access to a repository to fix a software defect, for example, while the same credentials should not necessarily permit it to copy unrelated source code into an external service.
Traditional permissions can establish that the agent is allowed to read or write the repository. They are less well suited to determining whether the specific action makes sense within the task the organisation has assigned.
Runtime controls attempt to add that missing context without forcing every agent and application team to build a bespoke security layer. Policies can be applied across organisational units, users, agents, repositories, or resources while the system retains an audit trail of allowed and rejected actions.
The approach does not replace identity management, application security, network controls, or human accountability. Instead, it adds another policy decision close to execution, where the organisation can ask whether an authenticated agent should be allowed to perform this particular action now.
Agent security is becoming its own software layer
The market around that problem is becoming crowded. Identity vendors, cloud providers, cybersecurity companies, data-governance platforms, and startups are all building controls around autonomous systems as agents gain access to production applications.
Some products concentrate on finding agents and monitoring their activity, while others apply permissions to tools, data, and workflows. Kontext is positioning itself around enforcement at runtime rather than simply recording what happened afterwards.
That could become useful if organisations deploy agents from several providers. Coding agents, workplace assistants, customer-service systems, and internal automations may otherwise arrive with separate permission models and different approaches to auditing.
A shared control layer promises consistency, although it introduces another dependency into workflows where latency and reliability matter. If every tool call must cross an enforcement system, the control layer has to operate quickly enough that useful agents do not become sluggish or fragile.
Policy design also determines whether runtime security improves safety or merely creates another queue of approvals. Requiring a person to authorise every meaningful action would undermine much of the value of autonomy, while overly broad permissions would recreate the original problem.
Organisations will therefore need to distinguish between routine actions, higher-risk operations, and events that justify human escalation. That makes observability and policy ownership as important as the enforcement technology itself.
Kontext’s funding round is modest beside the capital moving into foundation models and AI infrastructure, but the problem sits much closer to deployment. As organisations give agents authority to alter code, move information, or operate applications, security has to determine not only who the agent is, but whether the action it is about to take belongs to the job it has actually been asked to do.












