This article covers Outerlimit, a cybersecurity startup that has emerged from stealth with £12m in a growth funding round to build a decentralised security and authorisation layer aimed at agentic AI. The development aims to bind identity, authorisation and action at the moment of tool execution to provide deterministic control over agent actions and support enterprises granting AI agents access to systems and data.
Outerlimit, a London and New York-based cybersecurity startup, has emerged from stealth with £12m in a growth funding round to build a decentralised security and authorization layer aimed at agentic AI. The company says its technology binds identity, authorization and action at the moment of tool execution — a response to what it describes as gaps in existing identity and access management as enterprises give AI agents access to systems and data.
Agentic AI — systems that can plan, take actions and use tools autonomously — changes the risk profile for enterprises. Traditional access controls and runtime enforcement were designed around human behaviour and predictable decision making. When agents can act and adapt at machine speed, organisations face new challenges in observability, provenance and enforceable controls.
Outerlimit’s approach attempts to move beyond verification of identity and access to deterministic control of agent actions. If it works at scale, the technology could reduce one barrier that currently slows sanctioned enterprise adoption of agentic AI and pushes teams towards unsanctioned workarounds.
Outerlimit describes a distributed architecture that uses cryptographic enforcement at the moment a tool is invoked. Instead of storing credentials, keys or secrets in a single location, those materials are fragmented across an agent ecosystem and reconstructed only when the required identity, policy and execution context are present and verified. Decryption therefore occurs at execution time, not beforehand, and the company frames this as an extension of Zero Trust to the agent action layer.
The startup says its product guides customers through discovery and observability to deterministic enforcement: identifying agents and shadow AI, preserving multi-hop chain integrity, then applying controls to each agent action. Outerlimit also highlights existing partnerships with Fortune 500 and FTSE 100 brands and says it operates from offices in London and New York.
Outerlimit has raised £12m from lead and participating investors including AlbionVC, Evolution Equity Partners and Crane Venture Partners, alongside a group of strategic angel investors.
Strategic angels named in the announcement include Charles Gorintin (Co-Founder and CTO at Alan; co-founding advisor at Mistral), Brian Murphy (Founder and CEO at ReliaQuest), Scott Price (Founder and CEO at A-lign), Sam Morgan (Global Head of Client Coverage, Global Banking and Markets at Goldman Sachs), Kyle Griswold (Partner at FTV Capital), Nicola Sinclair (Partner at Twin Track Ventures), David Garfield (Founder and CEO at Garrison, acquired by Everfox) and Manish Madhvani (Co-Founder and Managing Partner at GP Bullhound).
In the announcement, Ed Lascelles, Partner at AlbionVC, said:
We are excited about what Outerlimit is building, which represents a significant opportunity to disrupt and reframe the agentic AI security market
Tony, Neil, and Peter bring a rare combination of deep security expertise and proven founder pedigree. The strength of this funding round reflects our conviction in both the company and the scale of the market opportunity ahead.
The investor mix combines cybersecurity-focused venture investors and experienced security operators and executives, signalling both financial and domain-specific support for the company’s product-led security thesis.
If you're researching potential backers in this space:
Outerlimit’s team includes Tony Pepper and Neil Larkins, security entrepreneurs who led Egress Software to a sale to KnowBe4 (a Vista Equity Partners portfolio company) in 2024, and Dr Peter Vincent, a theoretical neuroscientist from UCL’s Sainsbury Wellcome Centre and the Gatsby Computational Neuroscience Unit.
In the announcement, Dr Peter Vincent, Founder and CTO at Outerlimit, said:
We've spent decades building security systems around human qualities such as loyalty, trust, compassion, and even fear which drive predictable decision-making.
In this new agentic era, where agents use reasoning models with access to tools that can impact the world, they simply don't operate within these human constructs. Agents can change their behavior based on what they read, or how they interact with other agents, while acting at machine speed. Harnessing this powerful intelligence requires a fundamentally new security architecture - on that binds identity, authorization, and action into a single operation at the moment of execution.
In the announcement, Tony Pepper, CEO at Outerlimit, said:
The demand to deploy agentic AI is unparalleled, but security teams are being asked to signoff on risks they cannot adequately control.
Blocking adoption isn't a strategy, it simply drives the use of unsanctioned AI outside of enterprise oversight. Today’s launch of Outerlimit represents a paradigm shift to securing agentic AI, creating a world where AI agents can be trusted implicitly because every action is provably observed, controlled, and compliant without limiting their expressiveness.
In the announcement, Dr Peter Vincent, Founder and CTO at Outerlimit, said:
The next phase of enterprise AI should not be a race to build the most agents. Instead, success should be measured by the ability of an organization to safely harness the full power of their agent deployments
If intelligence is to become commoditized, trust will be the limiting factor. As we accelerate into a new era of co-intelligence, getting this right is a fundamental obligation for the sake of individuals, organizations, and international security.
Outerlimit’s claims sit at the intersection of AI safety, enterprise security and cryptography. Whether the company can operationalise deterministic enforcement without adding prohibitive complexity will determine commercial traction. Enterprises already juggling identity sprawl, cloud permissions and regulatory demands will be looking for solutions that integrate with existing workflows and tools.
The funding reflects sustained investor interest in tools that address the security implications of advanced AI. For cybersecurity investors, agent-specific controls represent a potential new market as organisations prepare to deploy more autonomous AI capabilities.
This deal also highlights continued UK involvement in enterprise AI security. As agentic AI moves from research labs into production systems, startups and investors across the UK and Europe will be watching closely for solutions that can deliver provable controls without unduly constraining innovation.
| Investors | Investment Focus | Startup Investments | Round Size | Connect |
|---|---|---|---|---|
![]() AlbionVC( ) AlbionVC focuses on early-stage investments in the UK, specialising in software,... London | ||||
![]() Evolution Equity Partners( ) Evolution Equity Partners is an international venture capital firm focusing on c... NYC, US | FintechCyber Security | |||
![]() Crane Venture Partners( ) Crane VC invests in foundational technologies reshaping the future, focusing on ... London | ||||
| All investors | All investor sectors | All funded startups | All funding rounds |
Click here for a full list of 7,589+ startup investors in the UK