Act Security's $60M: AI agents inherit dead permissions
Act Security launched with $60M and a claim worth checking: 97% of cloud access sits unused. Audit dormant permissions before you hand agents the keys.
Act Security came out of stealth on July 28 with $60 million and a pitch aimed at a problem most small teams have and none of them have named: the permissions you granted three years ago never went away, and your AI agents are about to inherit all of them. The company's number — roughly 97% of cloud access sits dormant and unused — is the kind of stat you should verify against your own environment rather than take on faith. Do that this week. It's a one-afternoon audit and the answer is usually worse than you'd guess.
What actually happened
Per the company's launch announcement, Act raised a $20 million seed led by Team8 and Bessemer Venture Partners with Hetz Ventures and Claltech, plus a $40 million Series A led by Notable Capital with Startpoint Capital and SVCI. Founder and CEO Jonathan Langer previously built Medigate, the medical-device security company Claroty acquired for $400 million — so this is a second-time team, not a first swing.
The product is described as action-centric cloud security: instead of chasing vulnerabilities, it reduces the access surface that makes a vulnerability exploitable, enforcing boundaries across humans, workloads, and AI agents, and maintaining continuous compliance against NIST 800-53, PCI DSS, and HIPAA. SecurityWeek framed it as a response to the patch problem: you will never patch everything, so cut the paths instead.
Langer's line is the one to sit with: close to 97% of cloud access sits dormant and unused, "and now AI agents are inheriting those same old human permissions, running around the clock, at machine speed." That figure is Act's own, from a company selling the fix — treat it as a hypothesis, not a fact about your stack.
Why dormant permissions matter for your business
Here's the pattern we keep finding in client environments. Somebody stands up an AI agent to handle invoices or triage support tickets. To make it work fast, they attach an existing service account or an admin's credentials — because that account already has access to everything the agent might need, and scoping it properly would take a day nobody has budgeted. The agent ships. The over-broad permission stays forever.
The difference between a dormant human permission and a dormant agent permission is duty cycle. A human with excessive S3 access uses maybe 2% of it, during business hours, at human speed. An agent with the same grant runs continuously and will use whatever it can reach the moment a prompt, a bad tool definition, or an injected instruction points it there. Same permission, radically different blast radius — and this week's Hugging Face agent intrusion timeline is what the bad version looks like at scale.
You don't need Act's platform to start. Pull the access report from your cloud provider — IAM Access Analyzer on AWS, the equivalent in Azure or GCP — and sort by last-used date. Every role untouched in 90 days is a candidate for deletion. Then give every agent its own identity with its own scoped grant, never a borrowed human account. It's tedious, unglamorous work, and it's the single highest-leverage security hour you'll spend before your next agent goes live.
Key takeaways
- Act Security launched July 28 with $60M total: a $20M seed (Team8, Bessemer) and $40M Series A (Notable Capital)
- Founded by the Medigate team, acquired by Claroty for $400M — repeat operators in the space
- Company claims ~97% of cloud access is dormant. Treat it as a prompt to check your own numbers, not a verified benchmark
- Agents inherit human permissions but run continuously — same grant, much larger blast radius
- Operator move: sort IAM roles by last-used date, delete anything cold for 90 days, and give every agent its own scoped identity
Every agent we deploy gets its own identity and its own scoped grant. No borrowed admin accounts, no credentials that outlive the project, no "we'll tighten it later." That's not an add-on — it's how we build. See how we scope AI agents or have us audit what yours can reach.
Sources: PR Newswire, SecurityWeek.
- #ai-agents
- #cloud-security
- #permissions
- #access-control
- #funding
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Pacing the Frontier letter: model supply is a policy dial
Over 1,200 employees at OpenAI, Anthropic, Google and Meta asked Washington for tools to pace frontier AI. What the Pacing the Frontier letter means for your stack.
Read itMicrosoft hits 30M Copilot seats: measure outcome per seat
Microsoft 365 Copilot crossed 30 million paid seats and Azure passed $100B a year. The number your business should track instead of the seat count.
Read it