Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm
Outerlimit raises $16M to secure autonomous AI agents from rogue actions.
Summary
Emerging from stealth, Outerlimit has secured $16 million in pre-seed funding to develop a decentralized authorization layer for autonomous AI agents. The company aims to address the challenge of controlling AI agents, which lack human concepts of morality or fear of consequences, by focusing on preventing harm through discovery, observation, and enforcement of pre-defined policies. This approach bypasses the AI alignment problem by treating all agents similarly and enforcing external guardrails at machine speed.
Full text
Autonomous agentic AI has a habit of going destructively rogue. It is unlikely we can stop this. Outerlimit has a solution focused on preventing any harm from rogue agents. New York-based Outerlimit has emerged from stealth with $16 million pre-seed funding raised from AlbionVC, Evolution Equity Partners, Crane Venture Partners and a number of individual angel investors. Founded by Tony Pepper, Neil Larkins, and Peter Vincent, the firm offers a decentralized security and authorization layer to secure autonomous agentic AI. Enterprises are rapidly adopting autonomous agents to increase the speed of decisions and automation of actions. As the underlying AI models become more powerful (but remain built on probability rather than known truth), these autonomous agents are used for more and more complex purposes with wide-ranging access to business identity and credentials. However, as the business purpose of agents becomes more complex, it becomes correspondingly more difficult to define and limit what autonomous actions they can take (a process known as alignment). Historically, cybersecurity is based on curtailing the action of humans through laws (or rules) and the fear of consequences. In the wider world, this is legislation, and the fear of monetary fines or jail time is the consequence of breaking the law. In cybersecurity the ‘law’ is governance, and the consequence of defying governance is being fired. This has been the basis of security throughout history: the fear of consequences. But it doesn’t work with autonomous agents. They have no concept of rules or morality (other than precisely what they have been instructed) nor any fear of consequences. Controlling autonomous AI agents can only be enforced by the internal precision of their coding (aligning capabilities with and limiting them to a defined purpose – and nothing else) and the effectiveness of external guardrails to limit misuse by outsiders. We are failing in both areas and our existing cybersecurity products or attitudes cannot help. “In this new agentic era,” comments Vincent, “where agents use reasoning models with access to tools that can impact the world, they simply don’t operate within these human constructs. Agents can change their behavior based on what they read, or how they interact with other agents, while acting at machine speed. Harnessing this powerful intelligence requires a fundamentally new security architecture – one that binds identity, authorization, and action into a single operation at the moment of execution.” Advertisement. Scroll to continue reading. Since we cannot and probably never will be able to control the AI we have built, security must shift focus from fear of consequences to prevention of harm. Outerlimit uses the tripartite concept of discover, observe and enforce to achieve this. It discovers (locates) agents in the system, it observes their behavior, and it enforces a pre-defined policy of allowed and disallowed autonomous actions. “Using the technology that we’ve developed, and our own research,” explains Outerlimit, “we can then prove that the policy will be followed. A good example: we can guarantee that if an agent is delegated a token, we can guarantee the scope, and the location, and the conditions under which that token can be used. This is important because we completely sidestep the alignment problem of the agent. The agent can still be misaligned and try to do something off policy, but because it’s a tool, its action is now subject to the policy we have specified, and not subject to alignment coded by the developer.” In short, Outerlimit doesn’t care whether an agent is aligned or misaligned — it treats all agents similarly. However, by proving what the agent is most likely to do next, it is effectively one-step ahead of the agent. And since it is operating at the same machine speed as the agent is operating, it is able to get ahead of the autonomy and block any harmful action from taking place. The underlying purpose of this new type of security is the same as traditional cybersecurity: it is to allow business to do what it wants, safely. Outerlimit is no different. “The next phase of enterprise AI should not be a race to build the most agents. Instead, success should be measured by the ability of an organization to safely harness the full power of their agent deployments,” explains Vincent. “If intelligence is to become commoditized, trust will be the limiting factor. As we accelerate into a new era of co-intelligence, getting this right is a fundamental obligation for the sake of individuals, organizations, and international security.” Related: Google Confirms Gemini AI Breached Three Firms Related: Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection Related: Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed Related: Why Agentic AI Systems Need Better Governance – Lessons from OpenClaw Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend CISO Conversations: Noopur Davis – The Accidental Global CISO at ComcastRansomware Attacks on Manufacturers Surge as Supply Chain Risk GrowsFirst Agentic AI Data Breach Reported to Spanish RegulatorEU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media$1 Million Sandbox Challenge Uncovers Linux Kernel FlawsThe Race to Control AI and Protect What Makes Us HumanCISOs Race to Control AI Agents Without Destroying Their ValuePhishing Research Challenges Conventional Security Awareness Testing Latest News Arista Urges Immediate Patching of Exploited VCO Zero-DayCritical F5 BIG-IP Vulnerability Exploited as Zero-DayShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportCheck Point Patches Exploited Management Server Zero-DayBigCommerce Data Stolen via Ribon Apps HackCyera Raises $400 Million at $12+ Billion ValuationNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentityOnly 13% of OT Network Segments Are Fully Isolated: Analysis Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI A