ProYarn

Deals · Cybersecurity

Kontext raises €3.5M Seed to enforce what AI agents are allowed to do — before they do it

Runtime enforcement layer that sits between an AI agent and every system it touches, checking each tool call against policy — who, on what task, accessing which resource — before authorising or blocking execution.

ProYarn Desk · Read this in French
in𝕏✆
“An AI agent can be properly authenticated, use an approved tool, and still take an action no one authorized. Kontext connects identity with task context and policy to decide what an agent is allowed to do before it happens.”
Jens Ernstberger — co-founder and CEO, Kontext

Kontext (Munich) has raised $4 million (approximately €3.5 million) in a Seed round led by 42CAP, with a16z CSX (Andreessen Horowitz's startup accelerator programme) and High-Tech Gründerfonds (HTGF) participating. Founded in early 2025 by Jens Ernstberger (CEO, doctorate in system security and applied cryptography from TU Munich, former a16z Crypto research intern) and Michel Osswald (electrical engineering and cybersecurity), the company has four employees. The round, announced on 24 September, funds engineering hires, platform development, and customer deployments.

The product sits between an AI agent and every system it touches. Every tool call — a file write, a database query, an API call — is checked against a policy that encodes: which agent, on which task, accessing which resource, requesting which action. In observe mode, Kontext logs and annotates; in enforcement mode, it blocks. Either way, every interaction is traceable to its authorised context.

The authorisation gap

Enterprise AI security has, until recently, mapped cleanly onto identity: authenticate the agent, verify the credentials, allow or deny access. Ernstberger's argument is that this is insufficient for the agent era: "An AI agent can be properly authenticated, use an approved tool, and still take an action no one authorized. Kontext connects identity with task context and policy to decide what an agent is allowed to do before it happens."

The gap he is describing is real. Traditional access control knows who is accessing a system. It does not know what task they are performing, why they need this specific action, or whether the combination of agent + tool + resource + moment is within the scope of any human-defined intent. When the "who" is an autonomous system that improvises across tool chains, the answer to "should this be allowed?" requires a richer policy surface than a role or a credential.

The platform already runs under two of the most widely deployed coding agents: Anthropic's Claude Code and OpenAI's Codex. Individual developers use it free; team plans start at $149 per month. Design partners are primarily mid-sized and large financial services firms — where an agent that touches a customer's account without explicit scoped authorization is a compliance event, not a debugging task.

The timing

This week's European venture activity makes the context explicit: Primo (Paris, €6.9M) deployed AI agents into corporate IT. 50skills (Reykjavík, €5.3M) put AI agents into HR workflows. Spiich (Stockholm, €3M) handed AI agents the administrative work of sales pipelines. Each of those deployments creates an action surface — file systems, employee databases, CRM records — that runtime authorisation now needs to protect.

Palma.ai (Berlin, also covered this week) builds the governance and audit layer that creates the tamper-evident record of what agents did. Kontext is the enforcement layer that decides what they are allowed to do at the moment before they do it. The two are complementary rather than competing: ex-ante enforcement and ex-post audit together close the loop that neither closes alone.

The a16z CSX participation — Andreessen Horowitz's accelerator backing a four-person Munich seed — is not incidental. Ernstberger passed through a16z Crypto as a research intern, which accounts for part of the relationship. But the broader signal is that US venture is watching the European agent security layer with enough conviction to back it at formation stage. That, for a company with zero revenue, is the most durable fact in this round.

Sources

  1. 01Kontext raises $4M seed to police what AI agents actually do — Sesamers

Threaded to this story

Every European round, in your inbox by 8am.

The day's seed and Series A rounds across France and Europe — threaded, sourced, and read in two minutes. Free.

Double opt-in. We'll send one confirmation email. Unsubscribe anytime.