The News
Act Security just announced a cloud security platform alongside $60 million in total funding, comprising a $20 million seed round led by Team8 and Bessemer Venture Partners and a $40 million Series A led by Notable Capital. Founded in 2025 by the team behind Medigate (acquired by Claroty for $400 million), the Tel Aviv-based company is targeting what it calls “access sprawl” across cloud infrastructure. Rather than surfacing vulnerability findings for teams to triage, Act’s platform enforces deterministic access boundaries for humans, workloads, and AI agents, aiming to structurally remove the conditions that make breaches possible in the first place.
Analyst Take
The cloud security market has spent the better part of a decade building better dashboards. CSPM tools, vulnerability scanners, and posture management platforms have become extraordinarily good at telling organizations what is wrong. What they have not solved is the operational problem that follows: a security team staring at thousands of findings, triaging one by one, while attackers (or increasingly, AI agents) move faster than any human queue can drain. Act Security’s core argument is that the model itself is broken, and the $60 million backing that argument from Team8, Bessemer, and Notable Capital suggests the investment community agrees.
The Access Problem Is Structural, Not Operational
Act’s founding premise is that cloud access sprawl is the root cause most security tooling never actually touches. The company’s CEO cites an internal figure suggesting close to 97% of cloud access sits dormant and unused. That number is consistent with what ECI Research observes in the field: the problem isn’t just that permissions accumulate, it’s that they accumulate invisibly and then get inherited wholesale by AI agents operating at machine speed. This is the architectural gap Act is positioning to close. Instead of patching a vulnerability after it’s been flagged, the platform removes the access path that would make the vulnerability exploitable in the first place. For ITDMs, this reframes security spend from a cost of detection to a cost of prevention, a meaningful shift in how ROI conversations should be structured.
Why AI Agents Change the Threat Calculus
The timing of this launch is not incidental. AI agents are now running inside production environments with real credentials, inherited permissions, and no human judgment filtering their actions. Act’s explicit focus on enforcing boundaries around AI workloads could address an emerging attack surface that most existing cloud security platforms were not designed to handle. The company points to Anthropic’s Claude Mythos as evidence that frontier models can find and exploit access paths faster than any response team can react. That’s a credible argument. For security architects and platform engineers, the implication is clear: least-privilege enforcement can no longer be a periodic audit exercise. It needs to be continuous, automated, and deeply integrated into both identity and network controls simultaneously.
According to ECI Research’s 2026 Application Development: DevSecOps & AppSec survey, 29.1% of respondents selected “AI-generated package risk” as their biggest open-source security concern in 2026. That figure captures only one slice of AI-introduced risk, the dependency layer, but it reflects a broader organizational anxiety about AI expanding the attack surface in ways security tooling hasn’t caught up to. Act is positioning directly into that anxiety, with a product argument that goes beyond scanning to structural remediation.
The Competitive Landscape Is Not Empty
Act will face a well-funded competitive field, but what Act is claiming is architectural differentiation: reasoning across identity, network, and AI access simultaneously, rather than treating them as separate signal streams. That is a harder product to build but a more defensible one if executed well. The CI/CD pipeline integration the company describes, preventing new access violations from ever reaching production, is particularly relevant for developer-centric organizations that have already invested in DevSecOps workflows. ECI Research’s 2026 Application Development: Day 0 survey found that 47.4% of respondents selected “software supply chain security” as one of their top investment priorities for the next 12 months, which places Act’s pipeline enforcement capability squarely in the budget conversations happening right now.
The compliance angle also deserves attention. Act’s platform maps perimeter and data-boundary enforcement to NIST 800-53, PCI DSS, and HIPAA controls. In a regulatory environment where, per ECI Research’s 2026 Application Development: Day 1 survey, 54.7% of respondents cited NIST frameworks as a compliance pressure influencing release engineering, the ability to demonstrate continuous, audit-ready compliance rather than point-in-time attestation has real procurement weight.
Looking Ahead
Act Security’s emergence from stealth with $60 million already deployed signals that this is not a concept company. The founding team’s track record with Medigate, a medical-device security platform that scaled to a $400 million acquisition, suggests operational credibility in converting a novel security category into an enterprise sales motion. The next 12–18 months will test whether Act can translate its architectural argument into measurable outcomes that enterprise security buyers can put in front of a CFO. Customer case studies with quantified reduction in exploitable access paths, not just survey-style satisfaction scores, will be the proof points that determine Series B timing and valuation.
The broader market trajectory favors Act’s thesis. As AI agents proliferate across enterprise cloud environments, the gap between granted permissions and actually-needed permissions will widen, not narrow. Security teams that rely on reactive triage will fall further behind. Vendors that can enforce least privilege continuously and automatically, across the full identity-network-AI stack, are building toward a structural advantage. Act is making a credible bet that access architecture is the next major consolidation point in cloud security. If the AI agent deployment wave accelerates on the timeline most enterprise AI programs are targeting, that bet may pay off faster than the market currently expects.
Stay Ahead of Application Development Trends
Get weekly analyst insights, research notes, event coverage, and AppDevANGLE updates delivered directly to your inbox.
Subscribe for Weekly Insights
Join technology leaders, practitioners, and GTM teams following the trends shaping modern software delivery.
Looking for deeper research access?
Explore ECI Research reports, survey insights, and market analysis through the ECI Research Portal.
