What’s funding like in the AI safety market right now?

In our AI safety market deck, you will find everything you need to understand the market
SUMMARY
AI safety funding is clearly stronger right now: more companies are raising, first financings are still growing, and much more capital is available once a startup reaches the scale-up stage.
The headline nearly doubled, from $853.5 million to $1.69 billion, but the improvement survives the megadeal test. Funding still rose 57.6% after removing every round above $50 million.
The market also broadened rather than narrowing around a few winners. Deals increased 24.6%, unique funded companies rose 20.3%, and first financings climbed from 29 to 37.
The bigger structural change sits above Seed. Series A and Series B now absorb almost two-thirds of AI safety capital, while the median Series B reached $90.5 million.
Follow-on financing has become the real dividing line. First rounds remain available, but follow-ons now capture roughly 83% of known-status capital and their median size jumped from $10.9 million to $29 million.
Money is rotating toward products that control AI in production. Guardrail platforms went from ten to 31 financings and now account for 42.9% of capital, while monitoring also attracted much larger checks.
Standalone evaluation looks weaker. Evaluation deals halved from 14 to seven and capital fell 43%, even though the companies that still raised tended to get larger checks.
The boom is actually less concentrated at the top than it was a year ago. The top five deals fell from 46.3% to 33.1% of total capital even as the number of $50 million-plus rounds rose from four to ten.
Geographic breadth improved, but the biggest checks tilted more heavily toward North America. Europe contributed a larger share of deals while its median round fell, which makes the current split between company formation and scale capital pretty visible.
Regulation is helping demand, especially around governance and assurance, but the faster funding story is enterprise deployment: autonomous agents now touch tools, code, data and workflows, and the largest rounds increasingly fund runtime security, product expansion and go-to-market scale.

This market map, featured in our AI safety market deck, highlights top companies and startups in the AI safety market
All funding deals in the AI safety market over the last 24 months
Below is the table listing all the deals. You can find our methodology at the end of this page.
If you want a deeper understanding of the market and its current dynamics, get our report covering the AI Safety Market.
| Company | Category | Date | Stage | Deal size | What they do | Region | Lead investors |
|---|---|---|---|---|---|---|---|
| HiddenLayer | AI Safety Monitoring | September 2026 | Series B | $100M | Protects AI models, applications and agents through AI asset discovery, supply-chain scanning, attack simulation and runtime threat detection and protection. | North America | Delta-v Capital |
| Lasso Security | AI Guardrail Platforms | September 2026 | Series A | $30M | Provides AI-specific discovery, risk management, automated red teaming and runtime guardrails for models, agents and generative-AI applications. | Middle East | ClearSky Advisors |
| AIR Security | AI Guardrail Platforms | September 2026 | Seed | $10M | Secures enterprise AI agents by continuously vetting skills, plugins, MCP servers and other context inputs and blocking unsafe interactions. | Middle East | Sequoia Capital |
| AIR Security | AI Guardrail Platforms | September 2026 | Seed | $40M | Secures enterprise AI agents by continuously vetting skills, plugins, MCP servers and other context inputs and blocking unsafe interactions. | Middle East | Greenoaks |
| Arga Labs | AI Evaluation Tools | August 2026 | Seed | $10M | Provides realistic stateful sandboxes for testing AI-agent behavior, catching regressions and edge cases before production. | North America | General Catalyst |
| Velatir | AI Risk Platforms | August 2026 | Seed | ≈$5,800,000 | Gives enterprises real-time visibility into AI use, data flows, and agent activity while enforcing centralized AI security and governance policies. | Europe | Spintop Ventures; Ugly Duckling Ventures |
| Kyvvu | AI Guardrail Platforms | August 2026 | Seed | ≈$1,160,000 | Enforces state-aware runtime policies inside AI agents, allowing, warning on, or blocking unsafe action sequences before execution. | Europe | Volta Ventures; Brabant Development Agency (BOM) |
| Lemma | AI Safety Monitoring | August 2026 | Seed | $2.3M | Monitors production AI-agent traces to detect silent failures, diagnose root causes, and generate regression checks and code-level fixes. | North America | Not disclosed |
| Mindgard | AI Red Teaming | August 2026 | Series A | $30M | Automates adversarial red teaming of AI models, agents, and applications to find exploitable failures and support protective controls. | North America | Album VC |
| Molt AI Corp. | AI Red Teaming | August 2026 | Seed | $1M | Runs adaptive adversarial tests against tool-using AI agents, verifies action-level failures, and retests remediations for reproducible assurance evidence. | North America | Not disclosed |
| FriskAI | AI Safety Monitoring | August 2026 | Seed | $3.6M | Records AI-agent tool use in production, builds behavioral baselines, and flags anomalous or unsafe deviations. | North America | MaC Venture Capital |
| Neuromorphic Labs | AI Risk Platforms | August 2026 | Seed | $5.1M | Provides verifiable asset identity, lineage, runtime policy enforcement, traceability, and compute verification across production AI models and agents. | North America | Flying Fish |
| Zenity | AI Guardrail Platforms | August 2026 | Series C | ≈$115,000,000 | Discovers enterprise AI agents and enforces intent-aware security boundaries that allow, modify, or block risky actions before execution. | North America | Norwest |
| Arrakis Security | AI Safety Monitoring | August 2026 | Seed | $8M | Discovers, profiles, monitors, and governs enterprise AI agents to detect and stop unsafe or unauthorized runtime behavior. | North America | Hetz Ventures |
| Onyx Security | AI Risk Platforms | July 2026 | Series B | $113M | Provides a secure AI control plane that discovers, monitors, governs, and enforces runtime controls over enterprise AI agents. | North America | Bessemer Venture Partners |
| Neo | AI Guardrail Platforms | July 2026 | Series A | $75M | Provides a real-time control layer that inventories agentic software, assesses its risks, attributes actions, and enforces policies on AI-agent behavior. | North America | Andreessen Horowitz; Bessemer Venture Partners |
| Runta | AI Guardrail Platforms | July 2026 | Seed | $20M | Provides a policy-enforced execution layer that constrains AI agents' filesystem, network, credential, and spending access while recording their actions. | North America | Andreessen Horowitz |
| Neo | AI Guardrail Platforms | July 2026 | Seed | $25M | Provides a real-time control layer that inventories agentic software, assesses its risks, attributes actions, and enforces policies on AI-agent behavior. | North America | Andreessen Horowitz; Merlin Ventures |
| Naaia | AI Risk Platforms | July 2026 | Series A | ≈$6,860,000 | Provides an AI risk and compliance platform that inventories AI systems, assesses risks, automates controls, and continuously monitors governance obligations. | Europe | Ventech |
| Straiker | AI Guardrail Platforms | June 2026 | Series A | $64M | Discovers enterprise AI agents, continuously adversarially tests them, and applies runtime defenses against agent-specific attacks and unsafe behavior. | North America | Marathon Management Partners; Citi Ventures; Illuminate Financial; Workday Ventures |
| Patronus AI | AI Evaluation Tools | June 2026 | Series B | $50M | Builds evaluation and simulation infrastructure that stress-tests AI models and agents for failures and reliability before production deployment. | North America | Greenfield Partners |
| Coval | AI Evaluation Tools | June 2026 | Series A | $28M | Provides simulation, automated evaluation, monitoring, and regression testing for autonomous voice and chat AI agents. | North America | Norwest |
| NeuralTrust | AI Guardrail Platforms | June 2026 | Seed | $20M | Secures enterprise AI agents with discovery, gateways, runtime threat prevention, governance, monitoring, and red-team testing. | Europe | Alstin Capital |
| Tenet Security | AI Guardrail Platforms | June 2026 | Seed | $6M | Protects autonomous AI agents at runtime by simulating intended actions and blocking malicious or unsafe execution paths before they reach production systems. | North America | The Westly Group; MizMaa Ventures |
| Arcade.dev | AI Guardrail Platforms | June 2026 | Series A | $60M | Provides authorization, policy enforcement, execution controls, and auditing for actions taken by production AI agents. | North America | SYN Ventures |
| Willow | AI Guardrail Platforms | June 2026 | Seed | $7M | Governs enterprise AI agents through identity, scoped permissions, runtime guardrails, centralized controls, and attributable audit trails. | Middle East | Hetz Ventures |
| ZeroDrift | AI Guardrail Platforms | June 2026 | Seed | $10M | Provides a runtime enforcement layer that checks and blocks or fixes AI-generated communications against regulatory and organizational policies before delivery. | North America | Not disclosed |
| Geordie AI | AI Risk Platforms | May 2026 | Series A | $30M | Provides security and governance software that discovers AI agents, monitors their behavior and access, assesses risk, and constrains unsafe behavior at runtime. | Europe | Balderton Capital |
| Gray Swan | AI Red Teaming | May 2026 | Series A | $40M | Provides adversarial testing, continuous red teaming, and runtime protection for AI models and agents. | North America | Wing Venture Capital; Madrona |
| CodeIntegrity | AI Guardrail Platforms | May 2026 | Seed | $5M | Provides a runtime control layer that constrains AI-agent tool calls, data access, and actions before execution. | North America | SYN Ventures |
| White Circle | AI Guardrail Platforms | May 2026 | Seed | $11M | Provides a real-time control layer that checks AI inputs and outputs against policies to detect and prevent unsafe, hallucinatory, injected, or otherwise unwanted model behavior. | Europe | Not disclosed |
| Aigentsphere | AI Risk Platforms | April 2026 | Seed | ≈$2,600,000 | Provides a governance and control layer for registering, monitoring, assessing and enforcing policies across enterprise AI agents. | Asia-Pacific | Main Sequence |
| General Analysis | AI Red Teaming | April 2026 | Seed | $10M | Adversarially tests enterprise AI agents for exploitable failure modes and pairs those evaluations with runtime defenses and guardrails. | North America | Altos Ventures |
| Tynapse | AI Guardrail Platforms | April 2026 | Seed | ≈$3,300,000 | Builds a runtime AI Trust Layer that verifies and controls AI-agent responses and actions while producing audit-ready records. | Asia-Pacific | Mirae Asset Venture Investment |
| Capsule Security | AI Guardrail Platforms | April 2026 | Seed | $7M | Provides a runtime security layer that observes AI-agent behavior and blocks prompt injection, data exfiltration and unsafe actions before execution. | Middle East | Lama Partners; Forgepoint Capital International |
| AIM Intelligence | AI Red Teaming | April 2026 | Series A | ≈$7,000,000 | Provides automated AI red teaming and runtime guardrails for detecting and controlling unsafe or exploitable behavior in AI models and agents. | Asia-Pacific | Samsung Venture Investment |
| Trent AI | AI Safety Monitoring | April 2026 | Seed | $13M | Provides an AI-native security platform that continuously identifies, assesses and mitigates risks in AI agents and agent-generated software. | Europe | LocalGlobe; Cambridge Innovation Capital |
| OpenBox AI | AI Risk Platforms | March 2026 | Seed | $5M | Provides runtime governance, verification, authorization, risk scoring and oversight infrastructure for autonomous enterprise AI agents. | North America | Tykhe Ventures |
| Galtea | AI Evaluation Tools | March 2026 | Seed | $3.2M | Provides evaluation infrastructure that generates tailored test scenarios to measure AI-agent quality, robustness, security and failure modes before deployment. | Europe | 42CAP |
| Manifold Security | AI Safety Monitoring | March 2026 | Seed | $8M | Monitors autonomous AI agents on enterprise endpoints at runtime to detect anomalous behavior and enable security teams to investigate or stop risky actions. | North America | Costanoa Ventures |
| Certiv | AI Guardrail Platforms | March 2026 | Seed | $4.2M | Provides runtime assurance that observes AI-agent actions on endpoints and blocks behavior violating enterprise policies before execution. | North America | Not disclosed |
| Onyx Security | AI Guardrail Platforms | March 2026 | Series A | $35M | Provides a control plane that discovers AI agents, monitors their behavior and enforces runtime policies to prevent unsafe or unauthorized actions. | North America | Conviction |
| JetStream Security | AI Risk Platforms | March 2026 | Seed | $34M | Provides a security-first AI governance control plane for discovering, mapping, governing and monitoring enterprise AI systems and agents. | North America | Redpoint Ventures |
| Evoke Security | AI Safety Monitoring | February 2026 | Seed | $4M | Discovers, monitors and controls enterprise AI agents, detecting and blocking risky agent behavior in real time. | North America | Crosspoint Capital Partners |
| LuminosAI | AI Risk Platforms | February 2026 | Seed | $6M | Automates testing, governance and risk assessment of generative and agentic AI systems for legal and technical liabilities. | North America | M13 |
| Braintrust | AI Evaluation Tools | February 2026 | Series B | $80M | Provides AI evaluation and observability tooling for testing, tracing and detecting failures in models and agents. | North America | ICONIQ |
| Hardshell | Model Robustness Tools | February 2026 | Seed | $1.1M | Protects AI training datasets against poisoning, leakage and integrity failures before they propagate into models. | North America | Not disclosed |
| Overmind | AI Safety Monitoring | February 2026 | Seed | $2.73M | Provides a supervision layer that observes AI-agent behavior, detects anomalies and enables intervention in production. | Europe | Osney Capital |
| Backslash Security | AI Guardrail Platforms | February 2026 | Series A | $19M | Secures AI coding agents, IDEs, MCPs and LLM workflows with governance, guardrails and real-time threat detection. | Middle East | KOMPAS VC |
| Attestable | Model Robustness Tools | February 2026 | Seed | $18.5M | Builds a zero-knowledge verification layer designed to prove the integrity of AI models, inputs and outputs and detect tampering. | Middle East | TLV Partners |
| Goodfire | Model Robustness Tools | February 2026 | Series B | $150M | Builds interpretability tools and research infrastructure to understand, monitor and shape AI model behavior. | North America | B Capital |
| Velatir | AI Risk Platforms | February 2026 | Seed | $1.58M | Provides continuous AI governance, visibility, human review and controls over enterprise AI systems and agents. | Europe | Ugly Duckling Ventures |
| Pallma AI (now Verno Labs) | AI Red Teaming | January 2026 | Seed | $1.6M | Builds AI-native red-teaming and runtime protection for autonomous AI agents, including prompt-injection detection, threat monitoring, and agent hardening. | Europe | Marathon Venture Capital |
| Fiddler AI | AI Safety Monitoring | January 2026 | Series C | $30M | Provides AI observability, evaluation, monitoring, governance, and runtime controls for detecting and managing unsafe or unreliable model and agent behavior. | North America | RPS Ventures |
| WitnessAI | AI Guardrail Platforms | January 2026 | Unknown | $58M | Provides runtime AI security and governance controls that observe AI interactions, enforce policies, and block threats such as prompt injection and unsafe agent behavior. | North America | Sound Ventures |
| Principled Intelligence | AI Risk Platforms | January 2026 | Seed | ≈$2,200,000 | Builds an enterprise control and governance layer that monitors and constrains AI systems against organizational policies, safety requirements, and regulatory rules. | Europe | National Technology Transfer Hub for Artificial Intelligence and Cybersecurity; BlackSheep |
| Ciphero | AI Safety Monitoring | December 2025 | Seed | $2.5M | Provides a real-time AI verification layer that captures, verifies and governs human and agentic AI interactions to detect unsafe or noncompliant use. | North America | Sovereign's Capital; Chingona Ventures |
| Wodan AI | AI Risk Platforms | December 2025 | Seed | ≈$2,350,000 | Enables ML, computer-vision and LLM workloads to run directly on fully encrypted data without exposing plaintext during computation. | Europe | JME Ventures; Swanlaab; Adara Ventures |
| Adaptive Security | AI Risk Platforms | December 2025 | Series B | $81M | Assesses and reduces exposure to deepfake, generative-AI phishing, voice-cloning and other AI-powered social-engineering attacks. | North America | Bain Capital Ventures |
| Alinia AI | AI Guardrail Platforms | December 2025 | Seed | $7.5M | Builds runtime guardrails and AI-compliance controls that audit AI systems, detect policy or model risks and enforce rules in real time. | Europe | Mouro Capital |
| imper.ai | AI Safety Monitoring | December 2025 | Series A | $21.5M | Detects AI-driven impersonation, deepfakes and voice-cloning attacks in real time across enterprise communication channels. | North America | Redpoint Ventures; Battery Ventures |
| Lumia Security | AI Guardrail Platforms | December 2025 | Seed | $18M | Provides network-level AI security and governance that monitors AI and agent interactions, evaluates exposure risk and enforces policies. | North America | Team8 |
| Helmet Security | AI Guardrail Platforms | December 2025 | Seed | $9M | Secures agentic AI and MCP communications through continuous discovery, traffic monitoring, risk detection and policy enforcement. | North America | SYN Ventures; WhiteRabbit Ventures |
| Mirror Security | AI Risk Platforms | December 2025 | Seed | $2.5M | Provides FHE-based encrypted AI inference and secure fine-tuning so sensitive data remains encrypted while models process it. | Europe | Sure Valley Ventures; Atlantic Bridge |
| Vijil | Model Robustness Tools | November 2025 | Series A | $17M | Tests, protects, and continuously hardens AI agents to improve their reliability, security, safety, and resilience in production. | North America | BrightMind Partners |
| Runlayer | AI Guardrail Platforms | November 2025 | Seed | $11M | Provides a security and governance control layer for MCP-connected AI agents, including permissions, threat detection, auditability, and observability. | North America | Khosla Ventures (Keith Rabois); Felicis |
| AI Score | AI Risk Platforms | November 2025 | Seed | $1M | Provides a centralized control layer for enterprise AI governance, compliance, risk visibility, and oversight of generative and agentic AI use. | Europe | Not disclosed |
| Polygraf AI | AI Guardrail Platforms | October 2025 | Seed | $9.5M | Provides AI-specific security controls for detecting and mitigating data leakage, synthetic-content, provenance and governance risks in enterprise AI use. | North America | Allegis Capital |
| Truth Systems | AI Guardrail Platforms | October 2025 | Seed | $4M | Converts organizational AI-use policies into real-time guardrails that monitor, block and audit risky AI interactions. | North America | Gradient |
| Darwin AI | AI Risk Platforms | October 2025 | Series A | $15M | Provides AI governance, policy enforcement, risk controls and compliance infrastructure for government AI deployments. | North America | Insight Partners |
| eRoun&Company | AI Guardrail Platforms | October 2025 | Unknown | $1.4M | Provides AI governance, prompt security, data-leak prevention, usage controls and audit trails for enterprise generative-AI use. | Asia-Pacific | KB Investment |
| Keycard | AI Guardrail Platforms | October 2025 | Seed | $8M | Provides identity, task-scoped permissions and runtime policy enforcement purpose-built to constrain AI-agent access and actions. | North America | Andreessen Horowitz; boldstart ventures |
| Keycard | AI Guardrail Platforms | October 2025 | Series A | $30M | Provides identity, task-scoped permissions and runtime policy enforcement purpose-built to constrain AI-agent access and actions. | North America | Acrew Capital |
| Skyld | Model Robustness Tools | October 2025 | Seed | ≈$1,760,000 | Protects deployed AI/ML models against theft, reverse engineering, unauthorized reuse and model-specific attacks. | Europe | Auriga Cyber Ventures; BNP Paribas Développement |
| Scorecard | AI Evaluation Tools | September 2025 | Seed | $3.8M | Provides high-frequency evaluation and simulated testing infrastructure to identify failures and regressions in AI agents before deployment. | North America | Kindred Ventures |
| Trismik | AI Evaluation Tools | September 2025 | Seed | ≈$2,959,000 | Provides adaptive, science-grade testing that measures LLM capabilities, alignment, safety, bias, and other failure modes. | Europe | Twinpath Ventures |
| Irregular | AI Red Teaming | September 2025 | Unknown | $80M | Adversarially stress-tests frontier AI models for dangerous cyber capabilities and develops defenses for safer deployment. | Middle East | Sequoia Capital; Redpoint Ventures |
| Eve Security | AI Safety Monitoring | September 2025 | Seed | $3M | Monitors AI agents at runtime and enforces intent- and data-aware policies against unsafe or anomalous agent actions. | North America | LiveOak Ventures |
| Geordie AI | AI Safety Monitoring | September 2025 | Seed | $6.5M | Discovers, observes, assesses, and controls autonomous AI agents so enterprises can identify risky behavior and govern deployment. | Europe | Ten Eleven Ventures; General Catalyst |
| ALIGNMT AI | AI Risk Platforms | August 2025 | Seed | $6.5M | Provides healthcare-focused AI governance, continuous risk monitoring, compliance workflows, and model-behavior oversight. | North America | AIX Ventures |
| Bluejay | AI Evaluation Tools | August 2025 | Seed | $4M | Provides simulation, evaluation, testing, and production observability for voice and text AI agents. | North America | Floodgate |
| Confident AI | AI Evaluation Tools | August 2025 | Seed | $2.2M | Provides infrastructure for evaluating, red teaming, monitoring, and governing LLM applications and AI agents. | North America | Not disclosed |
| Nugen Intelligence | Model Robustness Tools | August 2025 | Seed | >$1,000,000 | Builds domain-alignment infrastructure intended to make AI models and agents more reliable and predictable in enterprise-critical applications. | Asia-Pacific | Antler |
| Swept AI | AI Safety Monitoring | August 2025 | Seed | $1.4M | Adversarially evaluates and verifies AI agents before deployment and continuously supervises their behavior in production. | North America | M25 |
| Archestra | AI Guardrail Platforms | August 2025 | Seed | $3.3M | Provides a security and control layer for AI agents and MCP connections, including permissions, guardrails, and governed access to enterprise data and tools. | Europe | Concept Ventures |
| AIM Intelligence | AI Red Teaming | August 2025 | Seed | $1.3M | Provides automated AI red teaming, real-time guardrails, and supervision tools for detecting and controlling unsafe generative-AI behavior. | Asia-Pacific | Mirae Asset Capital |
| Noma Security | AI Risk Platforms | July 2025 | Series B | $100M | Secures AI applications and agents through discovery, posture management, red teaming, runtime protection, guardrails and AI-specific governance. | Middle East | Evolution Equity Partners |
| Promptfoo | AI Red Teaming | July 2025 | Series A | $18.4M | Tests and red-teams generative AI applications to detect prompt injection, jailbreaks, data leakage and other model-specific security failures. | North America | Insight Partners |
| Starseer | AI Safety Monitoring | July 2025 | Seed | $2M | Provides model-agnostic interpretability, security analysis and runtime oversight for detecting AI vulnerabilities and unsafe model behavior. | North America | Gula Tech Adventures |
| Modulos | AI Risk Platforms | July 2025 | Seed | ≈$10,900,000 | Automates AI governance, risk documentation, monitoring and compliance across frameworks including the EU AI Act, ISO 42001 and NIST AI RMF. | Europe | Not disclosed |
| Confident Security | AI Risk Platforms | July 2025 | Seed | $4.2M | Provides privacy-preserving infrastructure that keeps prompts and AI inference data inaccessible to model providers and other third parties. | North America | Not disclosed |
| Warden AI | AI Evaluation Tools | July 2025 | Seed | $1.6M | Continuously audits AI systems used in hiring for bias, fairness, explainability and regulatory compliance. | North America | Eamon Jubbawy; Husayn Kassai; Ruhul Amin; Playfair Capital |
| ZioSec | AI Red Teaming | June 2025 | Seed | $1.2M | Builds an offensive-security platform that continuously attacks AI agents and agent workflows to identify exploitable AI-specific vulnerabilities. | North America | Frank Mendicino of Access Venture Partners |
| Repello AI | AI Red Teaming | June 2025 | Seed | $1.2M | Provides continuous adversarial testing and runtime guardrails for identifying and mitigating vulnerabilities in generative-AI applications. | North America | Venture Highway |
| Trustible | AI Risk Platforms | June 2025 | Seed | $4.6M | Provides AI governance software for inventorying AI systems, assessing AI-specific risks, managing controls and maintaining regulatory compliance. | North America | Lookout Ventures |
| Hirundo | Model Robustness Tools | June 2025 | Seed | $8M | Develops machine-unlearning technology that removes unwanted data and behaviors such as hallucinations, bias and exploitable model behavior from trained AI models. | Middle East | Maverick Ventures Israel |
| Unbound | AI Guardrail Platforms | May 2025 | Seed | $4M | Provides an AI security gateway that enforces data-protection and usage policies on enterprise generative-AI traffic. | North America | Race Capital |
| Traceloop | AI Safety Monitoring | May 2025 | Seed | $6.1M | Provides automated evaluation, observability and production monitoring to detect failures and reliability problems in LLM applications and AI agents. | Middle East | Sorenson Capital; Ibex Investors |
| LMArena | AI Evaluation Tools | May 2025 | Seed | $100M | Runs a community-driven platform for real-world AI model evaluation and benchmarking using human preference comparisons. | North America | a16z; UC Investments |
| Barndoor AI | AI Risk Platforms | May 2025 | Seed | $13.6M | Provides a centralized control plane for governing AI-agent access, enforcing policies and monitoring agent activity. | North America | Crosslink Capital |
| Openlayer | AI Evaluation Tools | May 2025 | Series A | $14.5M | Provides continuous testing, evaluation, monitoring and governance for production AI and machine-learning systems. | North America | Race Capital |
| Etiq AI | Model Robustness Tools | April 2025 | Seed | ≈$1,020,000 | Tests and debugs AI and ML systems to identify robustness, bias, edge-case and model-behavior failures before deployment. | Europe | GapMinder VC |
| Opsin Security | AI Risk Platforms | April 2025 | Seed | $7M | Identifies and mitigates sensitive-data exposure and oversharing risks created by enterprise GenAI systems such as Copilot and Gemini. | North America | Race Capital |
| Pillar Security | AI Guardrail Platforms | April 2025 | Seed | $9M | Secures AI applications across development and runtime with adversarial testing, AI risk detection and adaptive guardrails. | Middle East | Shield Capital |
| Qualifire | AI Guardrail Platforms | April 2025 | Seed | $3.1M | Provides real-time contextual safeguards that monitor LLM behavior and block unsafe, inaccurate or policy-violating outputs. | Middle East | Not disclosed |
| Virtue AI | AI Risk Platforms | April 2025 | Unknown | $30M | Provides an integrated platform for AI red teaming, multimodal guardrails and security/governance of models, applications and agents. | North America | Lightspeed Venture Partners; Walden Catalyst Ventures |
| Straiker | AI Guardrail Platforms | March 2025 | Seed | $21M | Provides AI-native assessment and runtime protection that red-teams AI applications and blocks safety and security threats during operation. | North America | Not disclosed |
| SplxAI | AI Red Teaming | March 2025 | Seed | $7M | Provides automated adversarial testing, continuous security assessment and remediation for AI agents and applications. | North America | LAUNCHub Ventures |
| Darwin AI | AI Risk Platforms | March 2025 | Seed | $5M | Provides AI governance infrastructure for public agencies to inventory AI use, manage risks, enforce policies and maintain oversight. | North America | UpWest; Resolute Ventures |
| AIceberg | AI Guardrail Platforms | March 2025 | Seed | $10M | Provides an AI trust platform that validates AI traffic in real time and enforces safety, security and compliance controls. | North America | SYN Ventures; Sprout & Oak |
| Knostic | AI Guardrail Platforms | March 2025 | Seed | $11M | Provides need-to-know access controls and safety layers for enterprise LLMs to prevent sensitive-information oversharing. | North America | Bright Pixel Capital |
| LangWatch | AI Evaluation Tools | February 2025 | Seed | ≈$1,050,000 | Provides LLM evaluation and quality-control tooling that monitors harmful or inaccurate outputs, runs real-time tests and helps teams optimize AI applications. | Europe | Passion Capital |
| Arize AI | AI Evaluation Tools | February 2025 | Series C | $70M | Provides AI and LLM evaluation and observability software for testing, monitoring, troubleshooting and improving model and agent behavior in production. | North America | Adams Street Partners |
| Safe Intelligence | Model Robustness Tools | February 2025 | Seed | ≈$5,250,000 | Provides deep validation and automated robustification software that detects model fragilities and improves resilience to failure-inducing inputs. | Europe | Amadeus Capital Partners |
| Singulr AI | AI Risk Platforms | February 2025 | Seed | $10M | Provides an enterprise AI governance and security control plane for discovering AI use, scoring risk and enforcing policies against shadow AI and data leakage. | North America | Nexus Venture Partners; Dell Technologies Capital |
| Future AGI | AI Evaluation Tools | February 2025 | Seed | $1.6M | Provides multimodal AI evaluation, observability and optimization tooling to detect failures and improve application reliability. | North America | Powerhouse Ventures; Snow Leopard Ventures |
| Human.org | AI Risk Platforms | February 2025 | Seed | $7.3M | Builds decentralized identity and authority infrastructure that makes AI agents traceable, accountable and verifiably tied to human intent. | North America | Not disclosed |
| Coval | AI Evaluation Tools | January 2025 | Seed | $3.3M | Provides automated simulation, testing, evaluation and production monitoring infrastructure for assessing the reliability and behavior of AI agents. | North America | MaC Venture Capital |
| Mindgard | AI Red Teaming | December 2024 | Seed | $8M | Provides automated AI red teaming and security testing that exposes AI-specific vulnerabilities such as jailbreaks and prompt-injection attacks. | Europe | .406 Ventures |
| Hamming AI | AI Evaluation Tools | December 2024 | Seed | $3.8M | Automates evaluation, red teaming and production monitoring for AI voice agents to identify reliability and safety failures. | North America | Mischief |
| Fiddler AI | AI Safety Monitoring | December 2024 | Series B | $18.6M | Provides AI observability, safety monitoring and explainability for LLM and ML systems to detect behavioral, governance and reliability risks. | North America | Not disclosed |
| AIMon Labs | AI Safety Monitoring | December 2024 | Seed | $2.3M | Monitors generative-AI applications with specialized evaluators that detect hallucinations and other output reliability and safety failures. | North America | Bessemer Venture Partners; Tidal Ventures |
| Gentrace | AI Evaluation Tools | December 2024 | Series A | $8M | Provides collaborative evaluation, testing and monitoring software for generative-AI applications to identify reliability and safety failures. | North America | Matrix Partners |
| Wald.ai | AI Guardrail Platforms | December 2024 | Seed | $4M | Provides an inline data-protection layer for enterprise AI assistants that redacts sensitive information before prompts reach external models. | North America | Not disclosed |
| AIQURIS | AI Risk Platforms | December 2024 | Seed | ≈$3,780,000 | Provides an AI risk-management platform for qualifying, assessing and de-risking enterprise AI solutions against safety, security, quality and governance requirements. | Asia-Pacific | TÜV SÜD |
| Prompt Security | AI Guardrail Platforms | November 2024 | Series A | $18M | Protects enterprise GenAI use and applications by inspecting prompts and model responses, enforcing policies, and blocking data leakage, prompt injection, jailbreaks, and harmful content. | Middle East | Jump Capital |
| Calvin Risk | AI Risk Platforms | November 2024 | Seed | $4M | Provides quantitative AI risk assessment, automated model testing, governance, and continuous monitoring for enterprise AI systems. | Europe | Join Capital; seed + speed Ventures |
| SurePath AI | AI Risk Platforms | November 2024 | Seed | $5.2M | Provides a GenAI governance and security platform that discovers AI use, controls model and data access, and mitigates risks across enterprise AI interactions. | North America | Uncork Capital |
| Noma Security | AI Risk Platforms | October 2024 | Seed | $7M | Secures the AI and data lifecycle through AI asset discovery, posture management, supply-chain controls, governance, and runtime threat detection. | Middle East | Glilot Capital Partners |
| Noma Security | AI Risk Platforms | October 2024 | Series A | $25M | Secures the AI and data lifecycle through AI asset discovery, posture management, supply-chain controls, governance, and runtime threat detection. | Middle East | Ballistic Ventures |
| Verax AI | AI Safety Monitoring | October 2024 | Seed | $7.6M | Monitors LLM applications in production for hallucinations, bias, and other unwanted behavior and can auto-correct risky outputs in real time. | North America | TQ Ventures |
| DAIKI GmbH | AI Risk Platforms | October 2024 | Seed | ≈$1,615,000 | Provides AI-governance software for AI inventories, risk management, documentation, safety checks, and compliance with AI-specific rules and standards. | Europe | Not disclosed |
| Reality Defender | AI Safety Monitoring | October 2024 | Series A | $18M | Detects deepfakes and AI-generated audio, video, images, and text in real time for fraud, disinformation, and other AI-specific threats. | North America | Illuminate Financial |
| Galileo | AI Evaluation Tools | October 2024 | Series B | $45M | Provides enterprise GenAI evaluation and observability with research-backed metrics, production monitoring, and safety guardrails. | North America | Scale Venture Partners |
| Braintrust | AI Evaluation Tools | October 2024 | Series A | $36M | Provides an eval-first platform for testing, scoring, tracing, and improving LLM applications before and in production. | North America | Andreessen Horowitz |
| Distributional | AI Evaluation Tools | October 2024 | Series A | $19M | Automates adaptive testing of AI models and applications to detect behavioral changes, reliability failures, and operational AI risk. | North America | Two Sigma Ventures |
| Harmonic Security | AI Guardrail Platforms | October 2024 | Series A | $17.5M | Provides AI-specific data-loss prevention and usage controls that detect and block sensitive-data exposure through generative-AI tools. | North America | Next47 |

As this chart shows, and as featured in our AI safety market deck, search interest in AI safety has been growing steadily
Is AI safety funding actually healthier than it was a year ago?
AI safety funding looks healthier today: more companies are raising, the typical round is bigger, and the market has developed a much deeper growth-financing layer.
We counted 76 deals between September 20, 2025 and September 19, 2026, up from 61 during the previous 12 months. The number of unique funded companies rose from 59 to 71, while median round size went from $6.75 million to $9.25 million.
If capital had doubled while the number of companies fell, we would be looking at a narrow market dominated by a few winners. That is not what happened here: company breadth increased by 20.3% while deal activity grew 24.6%.
New-company formation also held up. First financings increased from 29 to 37, and the number of identifiable lead or strategic investors we tracked rose from 82 to 102.
The part that has changed most is how far successful companies can now go. Later-stage rounds gained share, Series A and B checks became much larger, and follow-ons absorbed far more capital. AI safety today looks like a young market that has started producing a real group of scale-ups.
| Metric | Latest 12 months | Previous 12 months | Change |
|---|---|---|---|
| Deals | 76 | 61 | +24.6% |
| Unique companies | 71 | 59 | +20.3% |
| Total capital | $1.690B | $853.5M | +98.0% |
| Median round | $9.25M | $6.75M | +37.0% |
| First financings | 37 | 29 | +27.6% |
| Follow-ons | 38 | 29 | +31.0% |
| Captured lead/strategic investors | 102 | 82 | +24.4% |
| Countries represented | 12 | 9 | +33.3% |
| Later-stage deal share | 10.5% | 6.6% | +3.9 pp |
Does AI safety funding still look strong without the biggest rounds?
Yes. Even after stripping out the largest AI safety financings, the market still grew much faster than deal count.
Total capital rose 98%, from $853.5 million to $1.69 billion. But removing every round above $50 million still leaves $793.5 million of current funding, up 57.6% from $503.5 million previously. Excluding rounds above $100 million gives a similar 53.7% increase.
The monthly numbers also look stronger than they did a year ago. Median monthly funding climbed from $69.3 million to $126.3 million, an increase of roughly 82%. Neither period had a zero-deal month.
We can see the shift further down the round-size distribution too. Deals below $5 million fell from 41.0% of transactions to 30.3%, while the $20 million to $50 million bracket jumped from 8.2% to 18.4%. The $50 million to $100 million bracket rose from 3.3% to 9.2%.
So the recent $100 million-plus rounds are sitting on top of a broader increase in normal financing sizes. They are amplifying the boom rather than creating the whole thing.

This chart, featured in our AI safety market deck, shows annual venture capital investment in AI safety startups
Are more AI safety startups getting funded now?
Yes. AI safety funding is reaching more startups now, including more companies raising for the first time.
Unique funded companies increased from 59 to 71, and first financings rose from 29 to 37. First rounds give us a rough view of whether investors are still feeding new companies into the market rather than concentrating entirely on businesses they already know.
The expansion also crossed more borders. We found companies headquartered in roughly 12 countries during the latest period compared with nine previously.
There were more repeat fundraisers at the same time. Five companies completed multiple financings during the latest 12 months versus only one in the previous window. Even with those additional repeat rounds, unique-company growth stayed close to the growth in total deals.
AI safety is therefore adding new funded startups while also producing more companies capable of raising repeatedly.
Is AI safety funding getting concentrated in a few winners?
No. Large AI safety rounds have become much more common, but the market is actually less dependent on its top few deals.
The three largest financings accounted for 22.4% of current capital, down from 32.8% in the previous period. The top-five share fell from 46.3% to 33.1%, and the largest single financing represented 8.9% of the market compared with 11.7% previously.
At the same time, we counted ten rounds above $50 million versus four a year earlier. Three current deals exceeded $100 million.
Goodfire raised $150 million, Zenity's Series C contained roughly $115 million of primary capital, Onyx Security raised $113 million and HiddenLayer raised $100 million. Adaptive Security, Braintrust, Neo, Straiker, Arcade.dev and WitnessAI also landed rounds between $58 million and $81 million.
A much larger group of companies can now raise serious growth capital, rather than the market being carried by one or two giant rounds.

This chart, featured in our AI safety market deck, shows how HiddenLayer is positioned in AI safety
Are investors still backing new AI safety startups, or mostly funding follow-ons?
Investors are still backing new AI safety startups, but the big money has swung hard toward companies that have already raised before.
First financings increased from 29 to 37, and their median size rose from $3.9 million to $5.1 million. The entry point into the market remains active.
Follow-ons changed much more dramatically. We counted 38 versus 29 previously, while the median follow-on jumped from $10.9 million to $29 million. Total follow-on capital reached about $1.395 billion.
Among deals where we could establish financing status, first and follow-on rounds were almost evenly split by count. By dollars, however, follow-ons took roughly 83% of current capital compared with about 68% previously.
Investors are still creating new funded companies. Once a company starts showing enough progress to come back for another round, the amount of money available is now on a completely different scale.
| Measure | Latest 12 months | Previous 12 months |
|---|---|---|
| First financings | 37 | 29 |
| Median first financing | $5.1M | $3.9M |
| Capital in first financings | $293.8M | $240.5M |
| First-financing share of known-status capital | ~17% | ~32% |
| Follow-ons | 38 | 29 |
| Median follow-on | $29M | $10.9M |
| Capital in follow-ons | $1.395B | $521.7M |
| Follow-on share of known-status capital | ~83% | ~68% |
Where is AI safety funding moving right now?
Right now, AI safety money is moving most clearly toward guardrails, agent control and other products that sit close to AI systems running in production.
AI Guardrail Platforms went from ten financings to 31. Their share of all deals rose from 16.4% to 40.8%, while their share of capital jumped from 11.8% to 42.9%.
AI Safety Monitoring also attracted much more money without a comparable jump in deal count. Capital rose from $65.5 million to $195.6 million while its share of deals stayed around 14.5%.
Model Robustness Tools look impressive in headline dollars, but the picture there is much narrower. Goodfire's $150 million Series B accounts for most of the increase.
AI Evaluation Tools went in the opposite direction, with deal count falling from 14 to seven and total capital dropping from $310.1 million to $177.9 million.
The funding rotation is quite clear now: investors are putting much more money into controlling and monitoring deployed AI systems, especially once those systems can act autonomously.
| Category | Current deals | Capital | Deal share | Capital share | What changed |
|---|---|---|---|---|---|
| AI Guardrail Platforms | 31 | $724.1M | 40.8% | 42.9% | Broad surge |
| AI Risk Platforms | 16 | $314.0M | 21.1% | 18.6% | More capital, lower share |
| AI Safety Monitoring | 11 | $195.6M | 14.5% | 11.6% | Bigger rounds |
| Model Robustness Tools | 5 | $188.4M | 6.6% | 11.1% | Goodfire-driven |
| AI Evaluation Tools | 7 | $177.9M | 9.2% | 10.5% | Fewer deals |
| AI Red Teaming | 6 | $89.6M | 7.9% | 5.3% | Losing share |
| Total | 76 | $1.690B | 100% | 100% | Broader market |

This chart, featured in our AI safety market deck, shows annual funding in AI safety startups
Are AI safety investors moving away from evaluation tools?
Yes, AI evaluation funding has cooled sharply even though the companies still getting funded are raising larger rounds.
AI Evaluation Tools dropped from 14 deals to seven. Capital fell about 43%, from $310.1 million to $177.9 million, while the category's share of total funding went from 36.3% to 10.5%.
Yet its median round increased from $6 million to $10 million. Braintrust is a good example of what the surviving end of the category looks like: it raised an $80 million Series B and described its business around the infrastructure needed to evaluate and observe AI once companies move from experiments into production.
We read this as a tougher market for standalone evaluation startups rather than investors abandoning evaluation itself. Evaluation is increasingly becoming part of broader production, observability and security stacks.
The money has moved fastest toward products that can control what AI does after deployment.
Is AI safety finally moving beyond Seed rounds?
Yes. Seed still produces most AI safety deals, but Series A and Series B now control a much larger part of the money.
Seed represented 65.8% of current transactions, down from 75.4%. Series A moved from 14.8% to 21.1% of deals, while Series B rose from 4.9% to 7.9%.
The difference in capital is much bigger. Series A now accounts for 30.1% of funding and Series B for 34.0%. Together they attract nearly two-thirds of the dollars in the market.
Round sizes have moved up with them. Median Series A increased from $18 million to $30 million, while median Series B rose from $45 million to $90.5 million.
Seed still matters enormously for company formation, but these days it no longer tells the whole story of AI safety venture funding. A meaningful growth-stage market now sits above it.
| Stage / grouping | Current deal share | Previous deal share | Current capital share | Previous capital share | Current median |
|---|---|---|---|---|---|
| Seed | 65.8% | 75.4% | 23.8% | 39.3% | $5.45M |
| Series A | 21.1% | 14.8% | 30.1% | 20.4% | $30M |
| Series B | 7.9% | 4.9% | 34.0% | 19.2% | $90.5M |
| Series C | 2.6% | 1.6% | 8.6% | 8.2% | $72.5M |
| Unknown | 2.6% | 3.3% | 3.5% | 12.9% | $29.7M |
| Early stage | 86.8% | 90.2% | 53.9% | 59.7% | — |
| Later stage | 10.5% | 6.6% | 42.6% | 27.4% | — |

This chart, featured in our AI safety market deck, compares the main business model options for AI alignment research labs
Why are AI agent security startups raising so much money now?
AI agent security startups are raising so much money because enterprises increasingly need to control what autonomous AI can access and do, not simply check the quality of its answers.
That shift shows up in several recent rounds. HiddenLayer's $100 million Series B is funding deeper agentic runtime protection and security for autonomous coding agents. WitnessAI raised $58 million while expanding tools for discovering and governing enterprise agents. Straiker's $64 million Series A came after the company reported working with Fortune 500 businesses and frontier AI labs.
Onyx Security gives us an especially recent example. When it announced its $113 million Series B, the company said revenue had quadrupled in the four months since it came out of stealth. It also reported securing more than 1.1 million agents and analyzing tens of millions of AI sessions in real time.
Zenity's latest financing tells a similar story from another angle. The company describes autonomous agents spreading through finance, customer service, engineering, HR and security rather than remaining inside isolated AI experiments.
As of now, the security problem is increasingly about permissions, tools, data access and runtime actions. That is a much broader enterprise problem than testing whether a model gives a bad answer.
Are AI safety investors getting pickier?
AI safety investors look pickier about who gets a large check, even though the investor pool itself has become broader.
We tracked 102 identifiable lead or strategic investors in the latest period, up from 82. There is little sign of investors collectively walking away.
What changed is repeat conviction. Eight investors appeared more than once compared with three previously. Andreessen Horowitz appeared in four captured financings, SYN Ventures in three, while Norwest, Redpoint, Bessemer Venture Partners, Hetz Ventures, LG Technology Ventures and Ugly Duckling Ventures each appeared twice.
The size gap between first rounds and follow-ons reinforces that picture. Early companies can still get funded, but investors are committing much more capital once a company shows enough progress to raise again.
There is more competition for deals across the market while the biggest checks remain concentrated around companies that have already built some credibility.

This chart, featured in our AI safety market deck, shows revenue breakdown by customer segment in the AI safety market
Are corporate investors taking a bigger role in AI safety?
Yes. Corporate and strategic investors are showing up more often in AI safety deals, and they are increasingly joining larger rounds.
Strategic-backed financings increased from 12 to 18. Their participation rate rose from 19.7% to 23.7%, while the median strategic-backed round climbed from $16.25 million to $37 million.
WitnessAI's $58 million round included Samsung Ventures and Qualcomm Ventures. HiddenLayer's $100 million Series B included Microsoft's M12 and Booz Allen Ventures. Arcade.dev's $60 million Series A included strategic investment from Morgan Stanley and Wipro.
Adaptive Security also brought in NVIDIA, Capital One Ventures and Citi Ventures alongside Bain Capital Ventures in its $81 million Series B. The company said at the time that it was already protecting more than 500 enterprise customers.
Corporate investors appear to be following AI safety deeper into actual enterprise deployment. Their role is moving beyond small experimental bets and into companies building infrastructure that sits close to their own technology or customers.
Is AI safety funding becoming more US-centric?
Currently, the biggest AI safety checks are becoming more US-centric even though the overall market is spreading across more countries.
North America's share of deals slipped from 65.6% to 61.8%, while its share of capital jumped from 64.5% to 84.4%. Median financing in the region more than doubled from $7 million to $15 million.
Europe went the other way. Its deal share climbed from 14.8% to 23.7%, but its median round fell from $4 million to roughly $2.84 million.
That suggests Europe is contributing more companies at the early end of the market, while North America is producing most of the large scale-up rounds.
Israel's capital share also fell sharply, from 30.0% to 7.8%, although the earlier period was unusually strong because it contained Noma's $100 million Series B and Irregular's roughly $80 million of funding announced across two closely spaced rounds. Israeli median financing actually increased to $18.5 million in the latest period.
Geographic breadth has improved, but the deepest pools of growth capital are now even more heavily centered in North America.

This chart, featured in our AI safety market deck, shows how prompt injection defense platform technology has evolved over time
Are AI safety startups raising again faster?
For now, we do not see convincing evidence that AI safety startups are returning to market faster.
Among current follow-ons where we could reconstruct a previous financing from another public round, the median gap was about 15.1 months. The comparable figure in the previous period was 9.4 months.
We would put very little weight on that apparent slowdown because coverage is uneven: we could reconstruct 15 current follow-ons but only four from the earlier period. Four companies are nowhere near enough for a confident market-wide conclusion.
What we can say more comfortably is that current follow-ons often involve very large jumps in round size. Fourteen of the 15 reconstructed current rounds were more than twice as large as the company's previous known financing, with a median step-up of about 3.05 times.
Goodfire is the extreme example. It went from a $7 million Seed to a $50 million Series A and then a $150 million Series B. That tells us a lot more about the amount of capital available to breakout companies than the weak year-over-year velocity comparison does.
Do AI safety startups need more proof to raise now?
The biggest AI safety rounds today increasingly come with real customer or deployment proof, although we cannot show that every startup now faces a tougher funding bar.
Company age has barely moved. The median funded business was one year old in both periods, and the median follow-on company was two years old. Current Series A companies are typically around two years old and Series B companies around 2.5 years old.
Yet these young businesses are now raising much larger rounds. The market has managed to push companies further up the financing ladder without waiting for them to become much older.
The recent company evidence points toward commercial proof playing a bigger role at the top end. Straiker reported Fortune 500 and frontier-AI customers around its Series A. Adaptive Security said it had more than 500 enterprise customers when it raised its Series B. Onyx reported rapid revenue growth shortly before its $113 million round.
We cannot turn those examples into a clean market-wide percentage because milestones are not consistently disclosed. Still, the pattern around the largest rounds is fairly clear: young companies can raise huge amounts, but the strongest examples now tend to come with evidence that enterprises are already using the product.

In our AI safety market deck, we identify pain points entrepreneurs should prioritize
Are AI safety companies raising to build products or to scale them?
These days, many of the largest AI safety rounds are funding expansion around products that are already in the market.
WitnessAI said its $58 million financing would accelerate global go-to-market and product expansion. Straiker followed its Series A by hiring a chief revenue officer specifically to scale its international commercial operation. HiddenLayer said its $100 million round would deepen its enterprise platform while expanding runtime protection for agentic systems.
Onyx plans to use its Series B both for new proprietary models and for scaling enterprise sales in the United States and beyond. Zenity's financing also centers on product development and global expansion around customers already deploying autonomous agents.
Arcade.dev offers another useful example. Its $60 million Series A is aimed at building what the company calls the secure action layer for enterprise agents, with Morgan Stanley and Wipro participating strategically.
There are still plenty of early rounds funding product creation and research. But at the upper end of AI safety funding, the language has shifted toward enterprise rollouts, go-to-market expansion, runtime infrastructure and international scale.
Is regulation actually driving AI safety funding?
Regulation is giving AI safety companies another reason for customers to buy, but enterprise AI deployment looks like the bigger funding driver right now.
The EU AI Act became much more concrete during the period we studied. General-purpose AI obligations started applying in 2025, including documentation requirements and, for models with systemic risk, risk assessment, mitigation, serious-incident reporting and cybersecurity duties.
The European Commission's enforcement powers for those GPAI obligations subsequently came into effect, making compliance a more immediate operational issue for affected providers.
That clearly helps companies selling governance, assurance, monitoring and security products. But the deals attracting the most money go well beyond European compliance.
HiddenLayer, Onyx, WitnessAI, Straiker, Zenity and Arcade.dev are all talking about controlling autonomous agents, securing tools, inspecting runtime behavior or governing what AI can do inside an enterprise. Several of the biggest rounds are also going to US companies.
Regulation is reinforcing demand. The faster-moving commercial story is that companies are giving AI access to real systems, real data and real workflows, which creates security problems whether regulators are involved or not.

This chart, featured in our AI safety market deck, shows revenue breakdown by geography across Europe, Asia, North America, Africa, and South America in the AI safety market
What does the $1.69 billion AI safety funding headline miss?
The $1.69 billion AI safety funding headline misses the most interesting change: this market now has a much deeper middle and growth layer than it had a year ago.
Looking only at total capital could make the recent period seem like another venture boom built around a few unusually large rounds. The figures underneath tell a different story. Funding below $50 million still grew by more than half, more companies raised, first financings increased and normal round sizes moved up.
The category mix changed too. As seen above, guardrail and runtime-security companies gained broad deal momentum rather than depending on one blockbuster transaction.
Meanwhile, Series A and B became much more important, and follow-on companies captured the majority of new dollars.
The better description of the last 12 months is that AI safety moved further from an early-stage collection of model-risk startups toward a real enterprise-security market with a growing class of scale-ups.
What really changed over the last 12 months?
The biggest change is that AI safety became broader and deeper at the same time. More startups raised capital, more first financings occurred and more investors participated, while the typical financing also became larger.
The second change is where the money goes once a company starts working. Follow-on companies now have access to dramatically larger checks, which has created a visible separation between getting an AI safety startup funded and scaling one.
The third is the move toward agent security and runtime control. Guardrails, monitoring and production security have taken a much larger share of attention as enterprises give AI systems access to tools, code, data and business processes.
The fourth is the arrival of a proper Series A/B market. Seed remains the most common stage, but the financial center of gravity has moved upward. Very young AI safety companies can now reach financing levels that were much rarer one year earlier.
The fifth is that larger rounds increasingly come with signs of real deployment. Customer counts, enterprise contracts, revenue growth and production usage now appear around several of the biggest financings, even though public disclosure is too uneven for a clean market-wide milestone statistic.
The most misleading takeaway would therefore be that AI safety funding simply doubled. The more useful conclusion is that the market has started maturing quickly while keeping its pipeline of new startups alive.

This chart, featured in our AI safety market deck, shows annual venture capital investment in AI safety startups
OUR METHODOLOGY
We compared two consecutive 12-month periods: September 20, 2025 through September 19, 2026, and September 20, 2024 through September 19, 2025. The objective was to build the most analytically reliable picture of fundraising activity in the AI safety market rather than reproduce the output of a single funding database.
We used a strict market-definition test. A company had to be substantially focused on AI safety, AI security, model risk, evaluation, monitoring, robustness, red teaming or guardrail infrastructure at the time of the financing. Borderline businesses were excluded rather than forced into the market simply because they used security or AI language.
We included qualifying private-company equity financings announced inside the relevant period and meeting our inclusion rules. Debt, grants, loans, public offerings and financing structures where an equity amount could not be separated reliably were excluded. We did not convert non-cash cloud credits, GPU allocations or similar benefits into fundraising dollars.
Each genuine financing was treated separately. Duplicate reports of the same round were consolidated, while additional closes, extensions and tranches were reviewed individually to determine whether they were truly separate transactions. Unusual structures were kept visible rather than simplified: Zenity's $125 million headline included roughly $10 million of secondary shares, Virtue AI's $30 million announcement combined Seed and Series A funding, and Irregular's roughly $80 million announcement appears to combine two rounds completed only weeks apart.
Dates, stages, investors, previous rounds, milestones and use-of-funds information were recorded only when we could support them publicly. We did not infer a Series A or Series B from deal size, assume a prominent investor had led the round, or create a previous-round date where no reliable public record existed. Funding-velocity and round-step-up analysis is therefore treated as directional because previous financing dates and sizes could only be reconstructed for 15 of the 38 current follow-ons and four of the 29 previous-period follow-ons.
After assembling the dataset, we ran a separate quality-control pass to search for missed deals, recheck period boundaries, verify that included transactions were equity financings, reassess company eligibility, check unusual financing structures and remove duplicate reports. Our guiding principle was simple: uncertainty stays visible rather than being filled with unsupported assumptions.
Key sources used for this analysis include the European Commission on general-purpose AI obligations under the EU AI Act, the European Commission's GPAI provider guidelines, and the European Commission's AI Act enforcement framework. Company and financing sources include HiddenLayer, WitnessAI, Straiker, Zenity, CTech on Zenity's primary-versus-secondary split, Onyx Security, Adaptive Security, Braintrust, Arcade.dev, Goodfire, PR Newswire on Goodfire's $150 million Series B, CTech on Irregular's financing structure, and Axios on Virtue AI's combined Seed and Series A financing.

In our AI safety market deck, we like to quantify things to make things easier to understand