The Tel Aviv startup founded by the Medigate team says 97% of cloud access sits dormant and unused, and AI agents are now inheriting those same bloated permissions at machine speed.
Jonathan Langer and his co-founders completed Medigate's sale to Claroty in January 2022, after Claroty announced a $400 million financing tied to the deal the month before. They spent years building technology to lock down medical devices on hospital networks. When they looked at cloud security in 2025, they saw the same old mess in a faster place: access that nobody was cleaning up.
Now they have put a company around that problem. On July 28, 2026, Act Security emerged from stealth with $60 million in total funding and launched what it calls an action-centric cloud security platform. The bet is clear. If AI can find and exploit access paths faster than a security team can triage tickets, then another dashboard full of findings won't save you.
The $60 million breaks into two rounds: a $20 million seed led by Team8 and Bessemer Venture Partners, with Hetz Ventures and Claltech participating, and a $40 million Series A led by Notable Capital, with Startpoint Capital and SVCI joining. Act says it was founded in 2025 and has operated quietly since then, building the product before making its backers public.
Langer's pitch is blunt. In Act's launch announcement, he said that based on what the company is seeing from customers, close to 97% of cloud access sits dormant and unused. That has always been a problem. Unused permissions are exposed surface, and exposed surface is eventually exploited. What changed is that AI agents are now inheriting those same old human permission sets, running continuously, at machine speed, with none of the contextual judgment a person would apply before clicking something risky.
You can't patch that. By the time a security team identifies a vulnerable access path, remediates it, and pushes the fix, an AI-powered attacker can already be moving through another one. That is the point Act is trying to make with its product, and frankly it is a stronger argument than another promise to make cloud alerts feel more manageable.
Act's platform is built to reduce the access surface itself. Instead of cataloguing vulnerabilities and queuing them for patching, the system reasons across identity, network, and AI access together, enforcing least-privilege boundaries for human users, workloads, and AI agents in the same pass. Compliance mapping to NIST 800-53, PCI DSS, and HIPAA is built in, according to the company's launch materials, so the same action that shrinks attack surface can also produce audit evidence.
The founding team is the same four-person group behind Act's launch: Langer as CEO, Stephan Goldberg as CPO, Itay Kirshenbaum as CTO, and Ilai Fallach as VP of R&D. That repeat-founder detail matters more than it usually does here. Medigate's core problem was access and visibility across hospital infrastructure that central IT didn't fully control. Cloud and AI agent security is a different market, but the pattern is familiar: too many connected systems, too much inherited access, and not enough enforcement at the boundary.
AI agents made an old access problem urgent #
The timing is blunt. On the same day Act emerged from stealth, Globes reported that Cyera signed a letter of intent to acquire Oasis Security for $1 billion, with Oasis continuing as an independent unit focused on non-human identities and AI agents. The Wall Street Journal also reported the cash-and-stock deal, framing it around the same pressure point: enterprise systems now have to govern software, service accounts, tokens, and autonomous AI tools that don't behave like human employees.
This market did not appear overnight. Most cloud security teams have known for years that over-permissioning is endemic and that the tooling to fix it at scale has been inadequate. AI agents didn't create the vulnerability. They made it urgent in a way that budget committees and engineering leads can now feel. An agent that can read an S3 bucket, call internal APIs, and write to a production database because a developer granted broad credentials months ago is a different kind of risk than a stale human account sitting unused. It doesn't get tired. It doesn't take vacations.
Act's launch announcement listed no customers and gave no revenue figures. That is useful to know, because the company is still asking the market to trust a platform claim before it has published the kind of customer list or financial scale that would prove traction on its own.
Still, the problem is concrete enough. Permissions always accumulate faster than anyone cleans them up, and now something can run on top of that accumulation around the clock. That is the business Act Security is in. The $60 million says investors who watched the Medigate team build once believe they may know how to build around this version of the access problem too.
Also read: Cyera acquires Oasis Security for $1 billion to lock down the logins of AI agents • How to Value a SaaS Startup Using ARR Multiples in 2026 • Spur Intelligence raises $200 million from Insight Partners to identify bots and AI agents in real time