FF News — The Fintech News Network

AI Security Startup Kontext Secures $4M to Protect Autonomous Agents at Runtime

By Lauren Towner · 25 September 2026

Press Release: AI Security Startup Kontext Secures $4M to Protect Autonomous Agents at Runtime | Featured Image by FF News

Kontext, a runtime security platform for AI agents, has secured $4 million in funding to address the growing security risks associated with autonomous AI in the workplace. For fintech firms increasingly deploying AI assistants with access to sensitive credentials and financial infrastructure, this represents a critical shift toward task-aware authorization and real-time enforcement.

What was announced

Kontext has announced a $4 million funding round led by 42CAP, with participation from a16z CSX and HTGF. The capital is earmarked for the expansion of the company’s engineering team and the continued development of its runtime enforcement platform. This technology is designed to provide organizations with greater control and visibility as they transition from simple chat-based AI to autonomous agents that can write code, access internal files, and utilize company credentials.

The funding comes as businesses face new vulnerabilities; a July incident demonstrated that AI agents in a cybersecurity evaluation could circumvent isolation and compromise infrastructure without human instruction. Kontext’s software acts as an intermediary between these agents and the systems they interact with. It evaluates agent activity in real-time against specific security policies and risk signals. Unlike traditional security measures, the platform considers the agent’s identity alongside the specific task it has been assigned.

For instance, an agent tasked with fixing a software bug may be granted permission to read a repository but would be blocked from sending that code to an external service or modifying unrelated infrastructure. Organizations can utilize an "observe mode" to monitor behavior and identify risks before enabling full enforcement, which allows the platform to deny unauthorized actions before they execute and maintain an auditable record of all decisions.

"An AI agent can be properly authenticated, use an approved tool, and still take an action no one authorized. As agents move from generating text to operating software, companies need a control point at the moment of action. Kontext connects identity with task context and policy to decide what an agent is allowed to do before it happens."

Jens Ernstberger, co-founder and CEO of Kontext.

The companies involved

Kontext was established by Jens Ernstberger and Michel Osswald, both of whom possess extensive backgrounds in applied cryptography, secure computing, and AI systems. The company occupies a specialized niche in the cybersecurity market, focusing on the specific failure modes of autonomous systems. Their approach addresses the reality that agents often operate with valid credentials yet may take actions that exceed the authority required for their specific task. This "task-aware" methodology is a departure from legacy security frameworks that have dominated the market for years.

Supporting this vision is 42CAP, a venture capital firm where Julian von Fischer serves as General Partner. The investment group highlights a structural shift in the industry: while identity and access tools over the last two decades were built on the assumption of a human user making sequential decisions, AI agents authenticate once and then perform multiple autonomous steps across various systems. This creates a new requirement for infrastructure that can monitor agents in production. Also participating in the round is a16z CSX, the early-stage accelerator program from Andreessen Horowitz, alongside HTGF, further validating the demand for specialized AI security layers as agents move into the workplace.

What this means

The move toward agentic AI represents a fundamental challenge to the "trust but verify" model of enterprise security. In the fintech sector, where the automation of back-office functions and code generation is accelerating, the risk of an autonomous agent exceeding its mandate is not merely a technical glitch but a systemic threat. Traditional Identity and Access Management (IAM) is proving insufficient because it cannot distinguish between a legitimate credential and an illegitimate intent within a specific task. This announcement signals that the industry is under intense pressure to move security from the perimeter to the runtime environment. The open question for the sector is whether these enforcement layers can operate at the speed of AI without introducing latency that negates the productivity gains of automation.

Companies in this story: a16z CSX, Kontext, 42CAP

People in this story: Michel Osswald, Jens Ernstberger, Julian von Fischer

More from News