Kontext raises $4M seed to police what AI agents actually do
Munich's Kontext raised a $4M seed led by 42CAP with a16z CSX and HTGF to check every AI agent action against policy before it runs - agentic AI security is now its own funding line.
Also see more funding coverage: /funding/
Founded 2025 · Munich, Germany
Munich-based Kontext has raised a $4M seed round led by 42CAP, with a16z CSX and High-Tech Gründerfonds participating, to build the control point that decides what an AI agent is allowed to do – before it does it.
Announced on 24 September 2026, this is a small cheque with a large implication. Europe has spent the year wiring agents into IT, HR and finance workflows; we covered three such rounds on these pages in the past fortnight alone. Kontext is the other side of that trade: the layer that watches the agents we keep hiring.
A $4M cheque aimed at the moment of action
42CAP, the Munich-based seed fund, led the round. It was joined by a16z CSX, Andreessen Horowitz’s startup accelerator programme, and High-Tech Gründerfonds (HTGF), the Bonn-based public-private seed investor. The money goes to engineering hires, further development of the runtime enforcement platform and support for customer deployments, per the company’s announcement of 24 September.
“An AI agent can be properly authenticated, use an approved tool, and still take an action no one authorized,” said co-founder and CEO Jens Ernstberger in the announcement. “Kontext connects identity with task context and policy to decide what an agent is allowed to do before it happens.”
That sentence is the whole category in miniature. Authentication answers who; authorisation, in the agent era, has to answer what, right now, on which task – and nothing in the classic identity stack was built for software that improvises.
Four people between the agent and production
Kontext was founded in early 2025 by Jens Ernstberger and Michel Osswald, and the team still counts four people (Tech Funding News, 24 September 2026). Ernstberger holds a doctorate in system security and applied cryptography from the Technical University of Munich and passed through a16z Crypto as a research intern – which explains the a16z CSX line on this cap table more naturally than any warm intro. Osswald’s background is electrical engineering and cybersecurity.
The product runs between an agent and the systems it touches. Every tool call is checked against policy – which agent, on what task, against which resource, requesting which action – and either logged, in observe mode, or blocked, in enforcement mode, with an audit trail either way (SiliconANGLE, 24 September 2026). It already sits under coding agents such as Anthropic’s Claude Code and OpenAI’s Codex; individual developers use it free, and team plans start at $149 a month.
Revenue is still at zero, and the design partners are mostly mid-sized and large financial services companies (Tech Funding News, 24 September 2026). That reads less like a red flag than a sequencing choice: regulated industries are where an unauthorised agent action costs the most, and where a full audit trail is not a feature but a licence to operate.
A $13.52bn market growing at 42% a year
The segment Kontext sells into now has a name and a forecast: agentic AI security, sized at $1.65bn in 2026 and projected to reach $13.52bn by 2032, a 42.0% CAGR (MarketsandMarkets, May 2026). Growth rates like that are less a measurement than a bet that every deployed agent becomes a security surface – but the deployment side of the bet is already visible in our own fundraising data.
This month alone, Primo raised €6.9M to send AI agents into corporate IT and 50skills raised €5.3M to run HR workflows with them. Each of those deployments creates precisely the problem Kontext is selling the answer to. At $4M, this seed sits in the same band as the agent rounds themselves – the guardrail is being funded at the same stage, and almost the same week, as the agents.
Guardrails become their own funding line
What does this round signal? First, that the agent stack is separating into layers, and security is the first layer to break out on its own. The good news is that Europe is not waiting for the category to be defined elsewhere: the founder is in Munich, the lead fund is in Munich, and the doctorate behind the product came from TU Munich. When a US accelerator such as a16z CSX shows up on a four-person German seed round, it is Palo Alto buying into Munich, not Munich chasing Palo Alto.
Second, watch the buyers. Financial services as first design partners tells us where enforcement mode will surface first: the strictest rooms adopt the controls early, then the controls become the default everywhere. If the segment compounds at anything like that 42% curve, runtime authorisation will not stay a four-person category for long.
Agents are getting hired across Europe faster than anyone is auditing them. This week, at least, the auditor sits in Munich – keep an eye on the guardrail line, because that is where the agent story gets real.