Analysis
Act Security emerged from stealth Tuesday, disclosing $60 million in combined funding as it launched a cloud security platform built around what it calls an 'action-centric' model -- governing not just human user logins but machine workloads and autonomous AI agents operating with standing access to company systems. The funding splits into a $20 million seed led by Team8 and Bessemer Venture Partners, and a $40 million Series A led by Notable Capital.
Founder and CEO Jonathan Langer built the company after previously founding Medigate, a healthcare-IoT security startup that reached a $400 million exit -- giving Act Security a credible, repeat-founder security pedigree in a category now crowded with first-time entrants chasing the same AI-agent-security wave.
The timing reflects a real and rapidly growing gap: identity and access management tooling built over the past decade assumes the entity requesting access is a human with a login, a session, and predictable behavior patterns. As enterprises grant AI agents standing, often broad access to internal systems -- reading data, taking actions, calling other services -- that assumption breaks down, and most existing IAM and cloud security platforms have no native concept of what 'normal' agent behavior even looks like.
Act Security enters a security category already populated by both incumbents extending existing IAM products toward agent use cases and a wave of newer, agent-security-native startups, making differentiation on real detection and governance capability -- rather than just messaging -- the deciding factor for enterprise buyers over the next year.
What to watch: which specific cloud platforms and AI agent frameworks Act Security integrates with first, how it differentiates from incumbent IAM vendors bolting on agent-security features, and whether Langer's Medigate track record translates into early enterprise wins in a crowded field.