Act Security raises $60M to take action against agentic access sprawl at the infrastructure layer
UPDATED 07:00 EDT / JULY 28 2026
Cloud security startup Act Security Ltd. says it’s primed and ready to help enterprises safely deploy artificial intelligence agents at large scale after raising $60 million in funding across two rounds.
The company was founded last year and closed on a hefty 40 million Series A investment led by Notable Capital, with participation from Startpoint Capital and SVCI.
Act Security says it’s launching its “action-centric” security platform in response to traditional cloud security models being stretched beyond their limits by the emergence of agentic AI systems. Traditionally, large organizations have enabled massive access across their cloud environments, but the vast majority of the permissions they’ve allowed are unneeded, sitting dormant.
That was less urgent when human attackers operated slowly. With AI models and autonomous AI agents operating at machine speed, misconfigurations and dormant permissions can be exploited in seconds. Many AI agents have inherited outdated human permissions.
Act Security’s platform targets risk at the infrastructure level. Rather than flooding security teams with alerts about misconfigurations, it tries to eliminate the permissions that make them exploitable — systematically reducing the access surface across cloud environments by enforcing strict, deterministic boundaries on what humans and AI agents can reach and do.
Co-founder and CEO Jonathan Langer said roughly 97% of cloud access permissions sit dormant and unused. “They’re inheriting the same old human permissions, running around the clock at machine speed, with none of the judgment a person would apply,” he explained. “Visibility tools surface thousands of findings and leave teams triaging symptoms one by one, while the root cause, the access architecture, goes unaddressed.”
The platform continuously validates access boundaries and extends into the CI/CD pipeline to block violations before application updates reach production. The goal is to deploy autonomous AI agents with tighter least-privilege controls, limiting lateral movement even after a breach.
Team8 Managing Partner Liran Grinberg: “Cloud security has spent a decade telling organizations where their risk is. Act is the first platform that actually removes it, and in an era where AI exploits exposure in minutes rather than months, that’s the new baseline.”