Autonomous agentic AI has a habit of going destructively rogue. It is unlikely we can stop this. Outerlimit has a solution focused on preventing any harm from rogue agents.
New York-based Outerlimit has emerged from stealth with $16 million pre-seed funding raised from AlbionVC, Evolution Equity Partners, Crane Venture Partners and a number of individual angel investors. Founded by Tony Pepper, Neil Larkins, and Peter Vincent, the firm offers a decentralized security and authorization layer to secure autonomous agentic AI.
Enterprises are rapidly adopting autonomous agents to increase the speed of decisions and automation of actions. As the underlying AI models become more powerful (but remain built on probability rather than known truth), these autonomous agents are used for more and more complex purposes with wide-ranging access to business identity and credentials. However, as the business purpose of agents becomes more complex, it becomes correspondingly more difficult to define and limit what autonomous actions they can take (a process known as alignment).
Historically, cybersecurity is based on curtailing the action of humans through laws (or rules) and the fear of consequences. In the wider world, this is legislation, and the fear of monetary fines or jail time is the consequence of breaking the law. In cybersecurity the ‘law’ is governance, and the consequence of defying governance is being fired. This has been the basis of security throughout history: the fear of consequences.
But it doesn’t work with autonomous agents. They have no concept of rules or morality (other than precisely what they have been instructed) nor any fear of consequences. Controlling autonomous AI agents can only be enforced by the internal precision of their coding (aligning capabilities with and limiting them to a defined purpose – and nothing else) and the effectiveness of external guardrails to limit misuse by outsiders. We are failing in both areas and our existing cybersecurity products or attitudes cannot help.
“In this new agentic era,” comments Vincent, “where agents use reasoning models with access to tools that can impact the world, they simply don’t operate within these human constructs. Agents can change their behavior based on what they read, or how they interact with other agents, while acting at machine speed. Harnessing this powerful intelligence requires a fundamentally new security architecture – one that binds identity, authorization, and action into a single operation at the moment of execution.”
Since we cannot and probably never will be able to control the AI we have built, security must shift focus from fear of consequences to prevention of harm. Outerlimit uses the tripartite concept of discover, observe and enforce to achieve this. It discovers (locates) agents in the system, it observes their behavior, and it enforces a pre-defined policy of allowed and disallowed autonomous actions.
“Using the technology that we’ve developed, and our own research,” explains Outerlimit, “we can then prove that the policy will be followed. A good example: we can guarantee that if an agent is delegated a token, we can guarantee the scope, and the location, and the conditions under which that token can be used. This is important because we completely sidestep the alignment problem of the agent. The agent can still be misaligned and try to do something off policy, but because it’s a tool, its action is now subject to the policy we have specified, and not subject to alignment coded by the developer.”
In short, Outerlimit doesn’t care whether an agent is aligned or misaligned — it treats all agents similarly. However, by proving what the agent is most likely to do next, it is effectively one-step ahead of the agent. And since it is operating at the same machine speed as the agent is operating, it is able to get ahead of the autonomy and block any harmful action from taking place.
The underlying purpose of this new type of security is the same as traditional cybersecurity: it is to allow business to do what it wants, safely. Outerlimit is no different. “The next phase of enterprise AI should not be a race to build the most agents. Instead, success should be measured by the ability of an organization to safely harness the full power of their agent deployments,” explains Vincent. “If intelligence is to become commoditized, trust will be the limiting factor. As we accelerate into a new era of co-intelligence, getting this right is a fundamental obligation for the sake of individuals, organizations, and international security.”
Related: Google Confirms Gemini AI Breached Three Firms
Related: Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection
Related: Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed
Related: Why Agentic AI Systems Need Better Governance – Lessons from OpenClaw

