Kontext Raises $4M to Put Guardrails on AI Agents for Banks and Fintechs

Kontext Raises $4M to Put Guardrails on AI Agents for Banks and Fintechs
EuropeFunding
WorkNation
September 25, 2026

Kontext, a Munich-based AI security startup, has raised $4 million in seed funding to help companies control what AI agents are allowed to do before those actions are executed.

The round was led by 42CAP, with participation from a16z CSX and German early-stage investor High-Tech Gründerfonds (HTGF). The company, which currently has a four-person team, is increasingly focusing on financial services, where AI agents are being introduced into environments that require strict controls around permissions, compliance, and access.

Founded around the idea that AI agents fundamentally change traditional software security assumptions, Kontext is building a policy layer that sits directly inside the environment where an agent operates.

Building a permission layer for AI agents

Kontext was founded by Jens Ernstberger and Michel Osswald. Ernstberger, the company's co-founder and CEO, has a background in system security and applied cryptography and recently completed a PhD in the field.

The idea for Kontext emerged in early 2025 as AI agents began moving beyond simply generating text or code and started taking actions on behalf of users.

According to Ernstberger, traditional software security has generally been built around two actors: a user and a system. AI agents introduce another layer because the software can independently make decisions and interact with other tools and systems.

That creates a different security problem.

An AI coding agent, for example, may be able to access files, execute commands, call APIs, modify code, or interact with external services. Giving the agent unrestricted access can create security risks, while restricting it too heavily can prevent it from performing useful work.

Kontext is attempting to address that gap through policy controls.

Osswald, who moved from electrical engineering into cybersecurity, describes the problem as finding the right permission framework for agents. The goal is to give agents enough access to complete useful tasks while preventing them from moving beyond predefined limits.

How Kontext works

Kontext's product operates as a local daemon that can be installed with a single command.

The system examines tool calls made by coding agents such as Claude Code, Codex, and Cowork. Before an action is executed, Kontext checks whether it complies with the organization's policies.

This approach means companies do not need to modify their existing code or introduce another external gateway into their infrastructure.

Deployments initially operate in observe mode. In this configuration, Kontext records potential policy violations without actually blocking the action.

That allows organizations to understand how their AI agents behave before introducing stricter controls.

The company also emphasizes local execution. Because the system operates within the environment where the agent is running, Kontext says it does not require an external network connection to perform its policy checks.

This architecture is particularly relevant for organizations dealing with sensitive information or regulated workflows, where sending additional data to external infrastructure can create another layer of security and compliance concerns.

A shift toward financial services

Kontext initially explored agent security in areas including coding and customer support.

Its focus has increasingly shifted toward helping organizations deploy their own AI agents while maintaining control over what those agents can access and execute.

According to Ernstberger, most of the company's customers now come from financial services, particularly mid-sized and large organizations.

The startup is currently working with unnamed design partners and is not yet generating revenue.

For banks and fintech companies, agent permissions can become particularly important because AI systems may eventually interact with financial systems, customer information, internal databases, compliance processes, and other sensitive infrastructure.

An agent that can authenticate once and then operate across multiple systems creates a different security challenge from software operated manually by a person.

That distinction is central to the problem Kontext is targeting.

AI agents are creating a new security category

The need for agent governance has become more visible as companies increasingly deploy AI systems capable of taking actions rather than simply providing recommendations.

A recent security test involving an OpenAI agent, referenced by Kontext, demonstrated how an agent could escape its sandbox and access external systems during testing.

These incidents have contributed to growing attention around agentic AI security, identity, authorization, and governance.

The market opportunity is also attracting larger startups.

Zenity, an AI agent governance company based in Israel, raised $125 million in August, bringing its reported total funding to approximately $185 million.

Noma Security has raised $132 million across three rounds and has reached a reported $400 million valuation.

Barcelona-based NeuralTrust also raised $20 million in a seed round earlier in 2026.

Against that backdrop, Kontext is entering the market with a much smaller team and a $4 million seed round.

Why financial services could become an important market

Financial institutions have spent decades building identity, access-control, and compliance systems around human users and traditional software.

AI agents challenge some of those assumptions because an agent may authenticate once and then execute multiple actions across different systems without a person reviewing every individual step.

That creates questions around authorization, accountability, auditability, and policy enforcement.

Kontext's approach is to make those controls part of the agent's operating environment rather than relying solely on centralized dashboards or external monitoring systems.

The company believes this could become increasingly important as organizations deploy more autonomous AI workers.

The startup also expects cost to become a significant competitive factor as the AI agent market develops. Ernstberger argues that open-weight models could become capable enough to perform many agent tasks, potentially changing the economics of how companies deploy AI agents.

A small startup entering a growing market

Kontext is currently just four people, making its $4 million seed round notable relative to its team size.

The company now has backing from 42CAP, a16z CSX, and HTGF as it develops its product and works with financial-services design partners.

Its challenge is to turn a security concept into infrastructure that organizations can rely on as AI agents gain more access to real-world systems.

For banks and fintechs, the question is increasingly moving beyond whether AI agents can perform useful work.

It is becoming a question of exactly what those agents should be allowed to do, which actions require approval, and how organizations can enforce those boundaries automatically.

Kontext is positioning its product around that control layer - putting policy between an AI agent's decision and the action it wants to take.

Press Release

Have a Funding Round or Exciting Update to Share?

Submit your press release to get featured on WorkNation and reach founders, investors, and tech leaders.