Cybersecurity

Context Receives 3.5 Million Euros to Monitor AI Agents

42CAP is leading the funding round for the Munich-based startup. a16z CSX and HTGF are also investing in the security platform for AI agents.
News by Marc Nemitz Marc Nemitz · München, 24. September 2026

The Munich-based cybersecurity startup Kontext has raised 3.5 million euros, or 4 million U.S. dollars. The funding round is led by 42CAP, with additional participation from a16z CSX and the High-Tech Gründerfonds (HTGF). The company, founded by Jens Ernstberger and Michel Osswald, plans to use the capital to expand its development team and further develop its security platform for autonomous AI agents.

Security checks immediately before an action

Kontext addresses a security issue arising from the increasing autonomy of AI agents. While traditional identity and access management systems primarily control who is allowed to access a system, Kontext aims to additionally verify what an AI agent is actually permitted to do within that system.

To achieve this, the software positions itself between an AI agent and the tools or systems it accesses. Every planned action is checked in real time against security policies and risk signals.

In doing so, Kontext takes into account not only an agent’s identity and access rights, but also its specific task, the requested action, and the affected resource.

Valid credentials are not enough

This distinction becomes relevant as soon as AI agents operate with more extensive permissions.

For example, an agent tasked with fixing a software bug may need access to a code repository. However, permission to read the code does not automatically mean that the agent is allowed to transmit information to an external service or make changes to other infrastructure.

Context is designed to enforce precisely this boundary.

“An AI agent can be properly authenticated, use an approved tool, and still perform an action that no one has authorized,” explains co-founder Jens Ernstberger. Companies therefore need a checkpoint immediately before an action is executed.

From Monitoring to Blocking

Companies can initially use the platform in observation mode. In this mode, Kontext records how AI agents behave, which potentially risky activities occur, and how stored security policies would apply.

This is intended to help companies first understand which actions their agents are actually performing without immediately interfering with their workflows.

Once active enforcement is enabled, Kontext can block unauthorized actions—according to the startup—before they are executed. At the same time, the decisions are logged. This ensures that it will later be possible to trace which action an agent attempted, whether it was allowed or prevented, and which rule was decisive in that decision.

42CAP Leads the Funding Round

The €3.5 million funding round is led by Munich-based investor 42CAP. a16z CSX and HTGF are also participating.

42CAP General Partner Julian von Fischer sees a structural difference between human users and autonomous AI agents. He notes that traditional access management systems were developed for humans who perform individual actions one after another. Agents, on the other hand, can authenticate themselves once and then act independently across multiple systems.

Kontext therefore seeks to link access control to the agent’s specific task.

According to the company, founders Ernstberger and Osswald bring experience in the fields of secure computing, applied cryptography, and AI systems.

New Security Layer for Agent-Based AI

The capital will now be used primarily to expand the development team. At the same time, Kontext aims to further develop the platform technically and support companies in the productive deployment of autonomous agents.

The timing could be favorable for the startup: The more AI agents evolve from simple chat applications into systems that write code, process files, and independently perform actions using corporate access credentials, the more important the question of their actual permissions becomes.

Whether a separate security layer will be established for this purpose will also depend on how quickly companies integrate agent-based systems into critical workflows. Kontext is positioning itself early for this market: Not only should an agent’s identity be verified, but also every specific action related to the task originally assigned to it.


Like it? Please spread the word:


Newsletter

Startups, stories and stats from the German startup ecosystem straight to your inbox. Subscribe with 2 clicks. Noice.

LinkedIn Connect

FYI: English edition available

Hello my friend, have you been stranded on the German edition of Startbase? At least your browser tells us, that you do not speak German - so maybe you would like to switch to the English edition instead?

Go to English edition

FYI: Deutsche Edition verfügbar

Hallo mein Freund, du befindest dich auf der Englischen Edition der Startbase und laut deinem Browser sprichst du eigentlich auch Deutsch. Magst du die Sprache wechseln?

Deutsche Edition öffnen

Similar posts