Outerlimit, a London and New York startup building security infrastructure for autonomous AI systems, said Monday it has raised $16 million in a pre-seed round co-led by AlbionVC, Evolution Equity Partners, and Crane Venture Partners. The company's pitch: extending traditional Zero Trust security controls to the precise moment AI agents actually do things in corporate networks.
The funding marks one of the larger pre-seed rounds in cybersecurity, though the company declined to provide comparative figures. Strategic angels backing the round include Charles Gorintin, co-founder and CTO of French health insurance startup Alan and an early advisor to Mistral; Brian Murphy, founder and CEO of security operations firm ReliaQuest; and Manish Madhvani, co-founder and managing partner at investment firm GP Bullhound.
For CEO Tony Pepper and COO Neil Larkins, it's a second act. The pair previously co-founded Egress Software, a British email security firm that KnowBe4 acquired in July 2024. Their technical co-founder, CTO Peter Robert Vincent, brings a PhD in theoretical neuroscience from University College London's Sainsbury Wellcome Centre, an unusual credential in a field dominated by traditional computer science backgrounds.
According to UK Companies House filings, the three founders each control between 25 and 50 percent of the parent entity, Outerlimit Group Ltd. AlbionVC partner Ed Lascelles joined the board as a director last month.
Already Live, Not Vaporware
Unlike many pre-seed announcements that amount to a deck and a demo, Outerlimit says its platform is already running in production environments. "We're not announcing ahead of the product," Vincent said in an interview last fall. "The platform is generally available and already deployed in live enterprise environments."
The company says it is partnering with Fortune 500 and FTSE 100 companies but would not name customers, citing standard confidentiality agreements. That kind of reticence is typical for enterprise security vendors, though it makes third-party validation difficult.
The technical architecture centers on fragmenting credentials and secrets across what Outerlimit calls the "agent ecosystem." Those fragments reassemble only after identity, policy, and execution context clear validation at the moment an AI agent actually invokes a tool. The company is enforcing authorization at the tool-call boundary rather than earlier in the chain, at the prompt or agent layer where most current controls sit.
In practice, the platform inventories agents, models, and tool interfaces; logs tool calls with what Outerlimit describes as "provable multi-hop chain integrity;" and applies binary controls at execution. Think of it as identity and access management, but for software that makes decisions on its own.
A Market Still Finding Its Shape

Outerlimit is wading into a category that barely existed 18 months ago. As enterprises move from experimenting with large language models to deploying autonomous agents that can book meetings, process invoices, or modify code without direct human oversight, the security implications have begun to register.
Ory launched what it called the first IAM control plane for AI agents in June. Yubico, Delinea, and StrongDM integrated cryptographic human-in-the-loop approvals for agent accountability around the same time. Akamai unveiled an "Agentic Security Framework" in June; Broadcom released AgentMinder governance tools for its Private AI Cloud in September. Box, Proofpoint, and Obsidian Security have all announced agent governance features in recent months.
Evolution Equity Partners, one of Outerlimit's co-leads, also backs Noma Security, which raised $100 million earlier this year to secure AI and agents. The investment overlap suggests VCs are placing multiple bets in a space where the winners remain unclear.
Hiring and Scaling in Two Geographies

Vincent said the funding will flow primarily into product development and engineering to scale the platform, along with customer success and go-to-market efforts split between the UK and North America.
"The demand to deploy agentic AI is unparalleled, but security teams are being asked to sign off on risks they cannot adequately control," Pepper said in a statement. "Blocking adoption isn't a strategy; it simply drives the use of unsanctioned AI outside of enterprise oversight."
Lascelles, the AlbionVC partner now on Outerlimit's board, framed the investment in market-opportunity terms. "This round reflects our conviction in both the company and the scale of the market opportunity ahead," he said.
Whether that opportunity materializes depends partly on how quickly enterprises actually deploy autonomous agents at scale, and whether early security incidents create urgency or caution. For now, Outerlimit is betting that companies will want the safety rails in place before the accidents happen.
