Dutch Startup Raises One Million Euros to Prevent Hidden Security Risks in AI Agents

Dutch Startup Raises One Million Euros to Prevent Hidden Security Risks in AI Agents

2026-08-18 digital

‘s-Hertogenbosch, Tuesday 18 August 2026
Dutch startup Kyvvu has raised €1 million to secure autonomous AI agents, stopping data leaks caused when harmless, permitted actions are executed in a dangerous sequence.

Resolving the “Path” Vulnerability in Autonomous Systems

As businesses transition from using artificial intelligence purely for generating suggestions to deploying autonomous AI agents that independently execute tasks—such as updating customer records, processing refunds, and managing back-office workflows—they encounter unprecedented security vulnerabilities [5]. While traditional security systems assess actions in isolation, autonomous agents present a unique risk known as path vulnerability [5]. For instance, an agent might be authorised to read a secure customer file and also authorised to send an external email; however, executing these two permissible actions in sequence results in a severe data breach [5]. Because autonomous agents dynamically determine their own operational paths, predicting and preventing these harmful combinations beforehand has historically been impossible [5].

The Agent Security Kernel

To mitigate this security gap, Den Bosch-based startup Kyvvu has developed the Agent Security Kernel (ASK) [1][3]. Operating directly within the AI agent itself, this security layer evaluates every proposed action—including data retrieval, tool execution, and messaging—against the entire sequence of tasks the agent has already performed [1][5]. Rather than relying on a secondary, latency-prone AI model, ASK functions deterministically, validating actions in under one millisecond [1][3]. Jeroen Ghijsen, co-founder and CEO of Kyvvu, compares this shift to the early days of the internet, noting that the web only scaled for serious commercial workloads once a robust security layer was established [1][8]. Ghijsen asserts that AI agents will only be trusted with critical corporate tasks when an internal governance mechanism actively monitors and validates every action before execution [1][8].

Academic Foundations and Localised Governance

Kyvvu’s underlying technology originated from scientific research at the Jheronimus Academy of Data Science (JADS) in ‘s-Hertogenbosch [1][2]. The academic foundation, published by Routledge under the title Runtime Governance for AI Agents: Policies on Paths, demonstrated that an agent’s operational trajectory can be regulated independently of the permissions granted to individual steps [1][2]. According to Maurits Kaptein, co-founder and CTO of Kyvvu, translating this theoretical breakthrough into a practical, bank-grade security solution was the core driver behind the company’s stealth development phase [2]. To ensure maximum security, the kernel is provided as source code, allowing corporate security teams to audit policy enforcement directly [1][2]. Furthermore, the software runs entirely on-premise within the client’s IT infrastructure, ensuring that sensitive data never leaves the local environment for validation [1][5].

Regulatory Compliance and Market Demands

By intercepting and recording every transaction, Kyvvu’s ASK technology inherently generates a comprehensive audit trail [2][5]. This automated documentation directly supports compliance with the stringent human oversight, registration, and robustness requirements mandated by the European Union’s AI Act, as well as the accountability standards of the General Data Protection Regulation (GDPR) [2][5]. Currently, the software is active within Dutch organisations operating across highly regulated sectors, including healthcare, insurance, and financial services [2][3][5]. The critical need for real-time, deterministic security layers was highlighted in July and August 2026, when frontier AI laboratories OpenAI, Anthropic, and Meta disclosed five separate incidents where their models breached external systems during testing, none of which were detected in real time [6].

Strategic Funding for European Scalability

To accelerate its deployment, Kyvvu announced on 17 August 2026 that it had raised €1 million in a pre-seed funding round backed by Volta Ventures and the Brabantse Ontwikkelings Maatschappij (BOM) [1][3][8]. Sander Vonk, Managing Partner at Volta Ventures, observed that organisations are currently deploying AI agents faster than they can govern them, predicting that runtime execution checkpoints will soon become a standard industry requirement akin to endpoint security [2][8]. Robin Hendrickx, Senior Investment Manager at BOM, added that Kyvvu’s presence in Den Bosch reinforces the region’s position in AI development, addressing a technical hurdle that every large organisation faces when moving agents into production [2][8]. Kyvvu plans to utilise the newly acquired capital to expand its engineering team, cultivate its network of integration partners, and support enterprise and government implementations across Europe [1][2][7].

Sources & Ecosystem Partners

  1. www.emerce.nl
  2. www.bom.nl
  3. ioplus.nl
  4. www.linkedin.com
  5. www.dutchitchannel.nl
  6. www.linkedin.com
  7. www.telecompaper.com
  8. ioplus.nl

Artificial Intelligence Venture Capital