Context Receives 3.5 Million Euros to Monitor AI Agents
The Munich-based cybersecurity startup Kontext has raised 3.5 million euros, or 4 million U.S. dollars. The funding round is led by 42CAP, with additional participation from a16z CSX and the High-Tech Gründerfonds (HTGF). The company, founded by Jens Ernstberger and Michel Osswald, plans to use the capital to expand its development team and further develop its security platform for autonomous AI agents.
Security checks immediately before an action
Kontext addresses a security issue arising from the increasing autonomy of AI agents. While traditional identity and access management systems primarily control who is allowed to access a system, Kontext aims to additionally verify what an AI agent is actually permitted to do within that system.
To achieve this, the software positions itself between an AI agent and the tools or systems it accesses. Every planned action is checked in real time against security policies and risk signals.
In doing so, Kontext takes into account not only an agent’s identity and access rights, but also its specific task, the requested action, and the affected resource.
Valid credentials are not enough
This distinction becomes relevant as soon as AI agents operate with more extensive permissions.
For example, an agent tasked with fixing a software bug may need access to a code repository. However, permission to read the code does not automatically mean that the agent is allowed to transmit information to an external service or make changes to other infrastructure.
Context is designed to enforce precisely this boundary.
“An AI agent can be properly authenticated, use an approved tool, and still perform an action that no one has authorized,” explains co-founder Jens Ernstberger. Companies therefore need a checkpoint immediately before an action is executed.
From Monitoring to Blocking
Companies can initially use the platform in observation mode. In this mode, Kontext records how AI agents behave, which potentially risky activities occur, and how stored security policies would apply.
This is intended to help companies first understand which actions their agents are actually performing without immediately interfering with their workflows.
Once active enforcement is enabled, Kontext can block unauthorized actions—according to the startup—before they are executed. At the same time, the decisions are logged. This ensures that it will later be possible to trace which action an agent attempted, whether it was allowed or prevented, and which rule was decisive in that decision.
42CAP Leads the Funding Round
The €3.5 million funding round is led by Munich-based investor 42CAP. a16z CSX and HTGF are also participating.
42CAP General Partner Julian von Fischer sees a structural difference between human users and autonomous AI agents. He notes that traditional access management systems were developed for humans who perform individual actions one after another. Agents, on the other hand, can authenticate themselves once and then act independently across multiple systems.
Kontext therefore seeks to link access control to the agent’s specific task.
According to the company, founders Ernstberger and Osswald bring experience in the fields of secure computing, applied cryptography, and AI systems.
New Security Layer for Agent-Based AI
The capital will now be used primarily to expand the development team. At the same time, Kontext aims to further develop the platform technically and support companies in the productive deployment of autonomous agents.
The timing could be favorable for the startup: The more AI agents evolve from simple chat applications into systems that write code, process files, and independently perform actions using corporate access credentials, the more important the question of their actual permissions becomes.
Whether a separate security layer will be established for this purpose will also depend on how quickly companies integrate agent-based systems into critical workflows. Kontext is positioning itself early for this market: Not only should an agent’s identity be verified, but also every specific action related to the task originally assigned to it.

Newsletter
Startups, stories and stats from the German startup ecosystem straight to your inbox. Subscribe with 2 clicks. Noice.
LinkedIn ConnectFYI: English edition available
Hello my friend, have you been stranded on the German edition of Startbase? At least your browser tells us, that you do not speak German - so maybe you would like to switch to the English edition instead?
FYI: Deutsche Edition verfügbar
Hallo mein Freund, du befindest dich auf der Englischen Edition der Startbase und laut deinem Browser sprichst du eigentlich auch Deutsch. Magst du die Sprache wechseln?