Act Security emerges from stealth with $60M; cloud access control for AI agents
Act Security, founded by the team behind Medigate (acquired by Claroty for $400M in 2022), emerged from stealth today with $60 million in total funding—$20M seed led by Team8 and Bessemer Venture Partners, and $40M Series A led by Notable Capital. The Tel Aviv-based startup launched a cloud security platform targeting access sprawl as the primary attack surface in the AI era. The company's core thesis: frontier AI models like Anthropic's Claude Mythos find and exploit access paths at machine speed, making reactive patch management obsolete.
Act's platform enforces deterministic access boundaries for humans, workloads, and AI agents, reducing what any identity can reach. The company cites internal data showing nearly 97% of cloud access sits dormant and unused, yet remains available to compromise. When AI agents inherit those over-permissioned roles, they run unattended, 24/7, at machine speed, with none of the judgment humans would apply. The platform integrates with CI/CD pipelines to prevent new access violations before reaching production and maps compliance to NIST 800-53, PCI DSS, and HIPAA.
For architects: this addresses a structural problem that traditional visibility and compliance tools never touch—the permissions architecture itself. As enterprises scale agentic systems into production, access control becomes the gate between safety and breach. The $60M backing from security-native VCs suggests the market recognizes this as a durable category, not a compliance add-on. Integration depth with existing cloud-native controls and proven founder track record (Medigate's exit) adds execution credibility to the architectural argument.