Act Security funding reaches $60M for AI agent access controls
Act Security raised $60 million across seed and Series A rounds to launch a cloud security platform for AI agent permissions.
By Colin Brandt · Enterprise Reporter
· 3 min read
Act Security funding now totals $60 million after the cloud security startup disclosed a $20 million seed round and a new $40 million Series A to build controls for AI agent access inside cloud infrastructure. The company says its platform is designed to reduce permissions that attackers or autonomous agents could exploit, rather than only flagging cloud misconfigurations for security teams to review.
The seed round was led by Team8 and Bessemer Venture Partners, with Caltech and Hetz Ventures participating. The Series A was led by Notable Capital, with participation from Startpoint Capital and SVCI. Act Security did not disclose its valuation, revenue, customer count or headcount.
Founded last year, Act Security Ltd. is entering a cloud security market that is being pulled toward identity, permissions and runtime access as enterprises test and deploy AI agents. The company’s core claim is that the access patterns tolerated for human users become a larger problem when software agents can act continuously and at machine speed.
What is agentic access sprawl?
Agentic access sprawl is the accumulation of cloud permissions available to autonomous AI agents, including access they inherit from older human roles and workflows. In practical terms, an agent may be able to reach systems, data or network paths that were approved for a person long ago but are no longer needed for current work.
Act Security points to familiar enterprise cloud hygiene problems: a contractor granted database access for a one-time task, or an employee retaining rights to systems they no longer use. The company argues that those dormant permissions were easier to defer when human attackers moved more slowly, but become more exposed when attackers use AI tools or when agents operate without the judgment of a person.
Jonathan Langer, Act Security’s co-founder and chief executive, said about 97% of cloud access permissions are inactive and unused. He said AI agents are inheriting those old rights and operating continuously, which changes the risk profile for permissions that security teams may previously have treated as low priority.
What is Act Security building?
Act Security describes its product as an “action-centric” security platform for infrastructure-level risk. According to the company, the platform evaluates identities, networks and AI access together, then enforces boundaries around what users and agents can reach and what actions they can take.
The company says the approach is based on least-privilege access and deterministic controls, with the goal of removing the conditions that make a misconfiguration exploitable. That positioning puts Act Security closer to access-surface reduction than conventional alert triage, although the company has not published customer results or independent benchmarks in the disclosed material.
Act Security also says the platform continuously checks whether access boundaries remain intact and connects to continuous integration and continuous deployment pipelines. The stated purpose is to stop access violations before application changes are pushed into production.
The company says tighter access controls can limit lateral movement after a compromise by reducing the paths an attacker can use inside a cloud environment. That is a concrete security outcome if the controls work as claimed, though Act Security has not disclosed deployment scale, false-positive rates or operational overhead for security teams.
Why investors are backing Act Security now
Team8 Managing Partner Liran Grinberg said Act Security identified the AI-agent access problem early and argued that cloud security needs to move beyond showing organizations where risks sit. His view, according to Act Security’s announcement, is that AI can exploit exposure far faster than older security operating models assumed.
The $60 million raise gives Act Security more room to commercialize that thesis as enterprises give agents access to production systems, data stores and internal tools. The hard part will be proving that infrastructure-layer access reduction can be enforced without slowing development teams or breaking legitimate agent workflows.
This story draws on original reporting from SiliconANGLE.