AI Safety Funding: A Quarter-by-Quarter Analysis

In our AI safety market deck, you will find everything you need to understand the market
SUMMARY
AI Safety Funding: A Quarter-by-Quarter Analysis shows a market that is genuinely getting stronger underneath the headline volatility: by Q2 2026, ordinary rounds were larger, capital was spread across more companies, and the market depended less on one or two giant financings.
The strongest headline quarter was Q1 2026 at $464.1M, but Q2 2026 was arguably the healthier financing quarter. Capital excluding rounds above $50M reached $249.9M, the highest level in the five-quarter period and more than double Q2 2025.
The real inflection came in Q4 2025. Total capital barely changed, yet the median round more than doubled and funding outside the largest deals jumped sharply, showing that larger checks were finally spreading through the market.
Q3 2025 was much weaker than its $253.0M headline suggested. Noma Security and Irregular accounted for roughly 71% of the quarter's capital, while two-thirds of deals were still below $5M.
Q2 2026 looked softer only because Q1 contained several unusually large rounds. In Q2, the biggest financing represented just 17% of total capital, and seven companies still raised at least $20M.
Series A has become the center of gravity. Six Series A deals raised $229M in Q2 2026, or 61% of quarterly capital, even though the median funded company was still only about one year old.
New companies are not disappearing. First financings still represented 39% of Q2 2026 deals, but follow-on companies captured 81% of the money, showing that investors are rewarding startups that return with more product, customer and technical evidence.
Guardrails and agent security currently have the broadest category momentum. Ten guardrail financings produced $193.3M in Q2, while funding also moved toward authorization, runtime control, red teaming and evaluation for enterprise AI agents.
Corporate investors have become much more visible. Strategic participation rose from roughly 6% to 11% of deals during 2025 to 39% in Q2 2026, with banks, software companies and technology groups increasingly backing the security layer around enterprise AI.
The investor base itself remains fragmented. Larger AI safety rounds are becoming easier to finance without the market collapsing into a tiny club of repeat lead investors.
Geographically, deal activity is spreading faster than capital. North America fell from 64% of deals in Q2 2025 to 50% in Q2 2026, while Europe gained a more consistent presence, although North America still captured 73% of the latest quarter's funding.
The clearest durable trends are follow-on capital, strategic-investor participation and bigger ordinary rounds. Series A, guardrails and deeper European funding look increasingly credible too, while the Middle East spike, model-robustness surge and Q1 later-stage jump still look like one-quarter distortions rather than permanent shifts.

This market map, featured in our AI safety market deck, highlights top companies and startups in the AI safety market
All funding deals in the AI safety market over the last years
Below is the table listing all the deals. You can find our methodology at the end of this page.
If you want a deeper understanding of the market and its current dynamics, get our report covering the AI Safety Market.
| Company | Category | Date | Stage | Deal size | What they do | Region | Lead investors |
|---|---|---|---|---|---|---|---|
| Straiker | AI Guardrail Platforms | June 2026 | Series A | $64M | Discovers enterprise AI agents, continuously adversarially tests them, and applies runtime defenses against agent-specific attacks and unsafe behavior. | North America | Marathon Management Partners; Citi Ventures; Illuminate Financial; Workday Ventures |
| Patronus AI | AI Evaluation Tools | June 2026 | Series B | $50M | Builds evaluation and simulation infrastructure that stress-tests AI models and agents for failures and reliability before production deployment. | North America | Greenfield Partners |
| Coval | AI Evaluation Tools | June 2026 | Series A | $28M | Provides simulation, automated evaluation, monitoring, and regression testing for autonomous voice and chat AI agents. | North America | Norwest |
| NeuralTrust | AI Guardrail Platforms | June 2026 | Seed | $20M | Secures enterprise AI agents with discovery, gateways, runtime threat prevention, governance, monitoring, and red-team testing. | Europe | Alstin Capital |
| Tenet Security | AI Guardrail Platforms | June 2026 | Seed | $6M | Protects autonomous AI agents at runtime by simulating intended actions and blocking malicious or unsafe execution paths before they reach production systems. | North America | The Westly Group; MizMaa Ventures |
| Arcade.dev | AI Guardrail Platforms | June 2026 | Series A | $60M | Provides authorization, policy enforcement, execution controls, and auditing for actions taken by production AI agents. | North America | SYN Ventures |
| Willow | AI Guardrail Platforms | June 2026 | Seed | $7M | Governs enterprise AI agents through identity, scoped permissions, runtime guardrails, centralized controls, and attributable audit trails. | Middle East | Hetz Ventures |
| ZeroDrift | AI Guardrail Platforms | June 2026 | Seed | $10M | Provides a runtime enforcement layer that checks and blocks or fixes AI-generated communications against regulatory and organizational policies before delivery. | North America | Not disclosed |
| Geordie AI | AI Risk Platforms | May 2026 | Series A | $30M | Provides security and governance software that discovers AI agents, monitors their behavior and access, assesses risk, and constrains unsafe behavior at runtime. | Europe | Balderton Capital |
| Gray Swan | AI Red Teaming | May 2026 | Series A | $40M | Provides adversarial testing, continuous red teaming, and runtime protection for AI models and agents. | North America | Wing Venture Capital; Madrona |
| CodeIntegrity | AI Guardrail Platforms | May 2026 | Seed | $5M | Provides a runtime control layer that constrains AI-agent tool calls, data access, and actions before execution. | North America | SYN Ventures |
| White Circle | AI Guardrail Platforms | May 2026 | Seed | $11M | Provides a real-time control layer that checks AI inputs and outputs against policies to detect and prevent unsafe, hallucinatory, injected, or otherwise unwanted model behavior. | Europe | Not disclosed |
| Aigentsphere | AI Risk Platforms | April 2026 | Seed | ≈$2,600,000 | Provides a governance and control layer for registering, monitoring, assessing and enforcing policies across enterprise AI agents. | Asia-Pacific | Main Sequence |
| General Analysis | AI Red Teaming | April 2026 | Seed | $10M | Adversarially tests enterprise AI agents for exploitable failure modes and pairs those evaluations with runtime defenses and guardrails. | North America | Altos Ventures |
| Tynapse | AI Guardrail Platforms | April 2026 | Seed | ≈$3,300,000 | Builds a runtime AI Trust Layer that verifies and controls AI-agent responses and actions while producing audit-ready records. | Asia-Pacific | Mirae Asset Venture Investment |
| Capsule Security | AI Guardrail Platforms | April 2026 | Seed | $7M | Provides a runtime security layer that observes AI-agent behavior and blocks prompt injection, data exfiltration and unsafe actions before execution. | Middle East | Lama Partners; Forgepoint Capital International |
| AIM Intelligence | AI Red Teaming | April 2026 | Series A | ≈$7,000,000 | Provides automated AI red teaming and runtime guardrails for detecting and controlling unsafe or exploitable behavior in AI models and agents. | Asia-Pacific | Samsung Venture Investment |
| Trent AI | AI Safety Monitoring | April 2026 | Seed | $13M | Provides an AI-native security platform that continuously identifies, assesses and mitigates risks in AI agents and agent-generated software. | Europe | LocalGlobe; Cambridge Innovation Capital |
| OpenBox AI | AI Risk Platforms | March 2026 | Seed | $5M | Provides runtime governance, verification, authorization, risk scoring and oversight infrastructure for autonomous enterprise AI agents. | North America | Tykhe Ventures |
| Galtea | AI Evaluation Tools | March 2026 | Seed | $3.2M | Provides evaluation infrastructure that generates tailored test scenarios to measure AI-agent quality, robustness, security and failure modes before deployment. | Europe | 42CAP |
| Manifold Security | AI Safety Monitoring | March 2026 | Seed | $8M | Monitors autonomous AI agents on enterprise endpoints at runtime to detect anomalous behavior and enable security teams to investigate or stop risky actions. | North America | Costanoa Ventures |
| Certiv | AI Guardrail Platforms | March 2026 | Seed | $4.2M | Provides runtime assurance that observes AI-agent actions on endpoints and blocks behavior violating enterprise policies before execution. | North America | Not disclosed |
| Onyx Security | AI Guardrail Platforms | March 2026 | Series A | $35M | Provides a control plane that discovers AI agents, monitors their behavior and enforces runtime policies to prevent unsafe or unauthorized actions. | North America | Conviction |
| JetStream Security | AI Risk Platforms | March 2026 | Seed | $34M | Provides a security-first AI governance control plane for discovering, mapping, governing and monitoring enterprise AI systems and agents. | North America | Redpoint Ventures |
| Evoke Security | AI Safety Monitoring | February 2026 | Seed | $4M | Discovers, monitors and controls enterprise AI agents, detecting and blocking risky agent behavior in real time. | North America | Crosspoint Capital Partners |
| LuminosAI | AI Risk Platforms | February 2026 | Seed | $6M | Automates testing, governance and risk assessment of generative and agentic AI systems for legal and technical liabilities. | North America | M13 |
| Braintrust | AI Evaluation Tools | February 2026 | Series B | $80M | Provides AI evaluation and observability tooling for testing, tracing and detecting failures in models and agents. | North America | ICONIQ |
| Hardshell | Model Robustness Tools | February 2026 | Seed | $1.1M | Protects AI training datasets against poisoning, leakage and integrity failures before they propagate into models. | North America | Not disclosed |
| Overmind | AI Safety Monitoring | February 2026 | Seed | $2.73M | Provides a supervision layer that observes AI-agent behavior, detects anomalies and enables intervention in production. | Europe | Osney Capital |
| Backslash Security | AI Guardrail Platforms | February 2026 | Series A | $19M | Secures AI coding agents, IDEs, MCPs and LLM workflows with governance, guardrails and real-time threat detection. | Middle East | KOMPAS VC |
| Attestable | Model Robustness Tools | February 2026 | Seed | $18.5M | Builds a zero-knowledge verification layer designed to prove the integrity of AI models, inputs and outputs and detect tampering. | Middle East | TLV Partners |
| Goodfire | Model Robustness Tools | February 2026 | Series B | $150M | Builds interpretability tools and research infrastructure to understand, monitor and shape AI model behavior. | North America | B Capital |
| Velatir | AI Risk Platforms | February 2026 | Seed | $1.58M | Provides continuous AI governance, visibility, human review and controls over enterprise AI systems and agents. | Europe | Ugly Duckling Ventures |
| Pallma AI (now Verno Labs) | AI Red Teaming | January 2026 | Seed | $1.6M | Builds AI-native red-teaming and runtime protection for autonomous AI agents, including prompt-injection detection, threat monitoring, and agent hardening. | Europe | Marathon Venture Capital |
| Fiddler AI | AI Safety Monitoring | January 2026 | Series C | $30M | Provides AI observability, evaluation, monitoring, governance, and runtime controls for detecting and managing unsafe or unreliable model and agent behavior. | North America | RPS Ventures |
| WitnessAI | AI Guardrail Platforms | January 2026 | Unknown | $58M | Provides runtime AI security and governance controls that observe AI interactions, enforce policies, and block threats such as prompt injection and unsafe agent behavior. | North America | Sound Ventures |
| Principled Intelligence | AI Risk Platforms | January 2026 | Seed | ≈$2,200,000 | Builds an enterprise control and governance layer that monitors and constrains AI systems against organizational policies, safety requirements, and regulatory rules. | Europe | National Technology Transfer Hub for Artificial Intelligence and Cybersecurity; BlackSheep |
| Ciphero | AI Safety Monitoring | December 2025 | Seed | $2.5M | Provides a real-time AI verification layer that captures, verifies and governs human and agentic AI interactions to detect unsafe or noncompliant use. | North America | Sovereign's Capital; Chingona Ventures |
| Wodan AI | AI Risk Platforms | December 2025 | Seed | ≈$2,350,000 | Enables ML, computer-vision and LLM workloads to run directly on fully encrypted data without exposing plaintext during computation. | Europe | JME Ventures; Swanlaab; Adara Ventures |
| Adaptive Security | AI Risk Platforms | December 2025 | Series B | $81M | Assesses and reduces exposure to deepfake, generative-AI phishing, voice-cloning and other AI-powered social-engineering attacks. | North America | Bain Capital Ventures |
| Alinia AI | AI Guardrail Platforms | December 2025 | Seed | $7.5M | Builds runtime guardrails and AI-compliance controls that audit AI systems, detect policy or model risks and enforce rules in real time. | Europe | Mouro Capital |
| imper.ai | AI Safety Monitoring | December 2025 | Series A | $21.5M | Detects AI-driven impersonation, deepfakes and voice-cloning attacks in real time across enterprise communication channels. | North America | Redpoint Ventures; Battery Ventures |
| Lumia Security | AI Guardrail Platforms | December 2025 | Seed | $18M | Provides network-level AI security and governance that monitors AI and agent interactions, evaluates exposure risk and enforces policies. | North America | Team8 |
| Helmet Security | AI Guardrail Platforms | December 2025 | Seed | $9M | Secures agentic AI and MCP communications through continuous discovery, traffic monitoring, risk detection and policy enforcement. | North America | SYN Ventures; WhiteRabbit Ventures |
| Mirror Security | AI Risk Platforms | December 2025 | Seed | $2.5M | Provides FHE-based encrypted AI inference and secure fine-tuning so sensitive data remains encrypted while models process it. | Europe | Sure Valley Ventures; Atlantic Bridge |
| Vijil | Model Robustness Tools | November 2025 | Series A | $17M | Tests, protects, and continuously hardens AI agents to improve their reliability, security, safety, and resilience in production. | North America | BrightMind Partners |
| Runlayer | AI Guardrail Platforms | November 2025 | Seed | $11M | Provides a security and governance control layer for MCP-connected AI agents, including permissions, threat detection, auditability, and observability. | North America | Khosla Ventures (Keith Rabois); Felicis |
| AI Score | AI Risk Platforms | November 2025 | Seed | $1M | Provides a centralized control layer for enterprise AI governance, compliance, risk visibility, and oversight of generative and agentic AI use. | Europe | Not disclosed |
| Polygraf AI | AI Guardrail Platforms | October 2025 | Seed | $9.5M | Provides AI-specific security controls for detecting and mitigating data leakage, synthetic-content, provenance and governance risks in enterprise AI use. | North America | Allegis Capital |
| Truth Systems | AI Guardrail Platforms | October 2025 | Seed | $4M | Converts organizational AI-use policies into real-time guardrails that monitor, block and audit risky AI interactions. | North America | Gradient |
| Darwin AI | AI Risk Platforms | October 2025 | Series A | $15M | Provides AI governance, policy enforcement, risk controls and compliance infrastructure for government AI deployments. | North America | Insight Partners |
| eRoun&Company | AI Guardrail Platforms | October 2025 | Unknown | $1.4M | Provides AI governance, prompt security, data-leak prevention, usage controls and audit trails for enterprise generative-AI use. | Asia-Pacific | KB Investment |
| Keycard | AI Guardrail Platforms | October 2025 | Seed | $8M | Provides identity, task-scoped permissions and runtime policy enforcement purpose-built to constrain AI-agent access and actions. | North America | Andreessen Horowitz; boldstart ventures |
| Keycard | AI Guardrail Platforms | October 2025 | Series A | $30M | Provides identity, task-scoped permissions and runtime policy enforcement purpose-built to constrain AI-agent access and actions. | North America | Acrew Capital |
| Skyld | Model Robustness Tools | October 2025 | Seed | ≈$1,760,000 | Protects deployed AI/ML models against theft, reverse engineering, unauthorized reuse and model-specific attacks. | Europe | Auriga Cyber Ventures; BNP Paribas Développement |
| Scorecard | AI Evaluation Tools | September 2025 | Seed | $3.8M | Provides high-frequency evaluation and simulated testing infrastructure to identify failures and regressions in AI agents before deployment. | North America | Kindred Ventures |
| Trismik | AI Evaluation Tools | September 2025 | Seed | ≈$2,959,000 | Provides adaptive, science-grade testing that measures LLM capabilities, alignment, safety, bias, and other failure modes. | Europe | Twinpath Ventures |
| Irregular | AI Red Teaming | September 2025 | Unknown | $80M | Adversarially stress-tests frontier AI models for dangerous cyber capabilities and develops defenses for safer deployment. | Middle East | Sequoia Capital; Redpoint Ventures |
| Eve Security | AI Safety Monitoring | September 2025 | Seed | $3M | Monitors AI agents at runtime and enforces intent- and data-aware policies against unsafe or anomalous agent actions. | North America | LiveOak Ventures |
| Geordie AI | AI Safety Monitoring | September 2025 | Seed | $6.5M | Discovers, observes, assesses, and controls autonomous AI agents so enterprises can identify risky behavior and govern deployment. | Europe | Ten Eleven Ventures; General Catalyst |
| ALIGNMT AI | AI Risk Platforms | August 2025 | Seed | $6.5M | Provides healthcare-focused AI governance, continuous risk monitoring, compliance workflows, and model-behavior oversight. | North America | AIX Ventures |
| Bluejay | AI Evaluation Tools | August 2025 | Seed | $4M | Provides simulation, evaluation, testing, and production observability for voice and text AI agents. | North America | Floodgate |
| Confident AI | AI Evaluation Tools | August 2025 | Seed | $2.2M | Provides infrastructure for evaluating, red teaming, monitoring, and governing LLM applications and AI agents. | North America | Not disclosed |
| Nugen Intelligence | Model Robustness Tools | August 2025 | Seed | >$1,000,000 | Builds domain-alignment infrastructure intended to make AI models and agents more reliable and predictable in enterprise-critical applications. | Asia-Pacific | Antler |
| Swept AI | AI Safety Monitoring | August 2025 | Seed | $1.4M | Adversarially evaluates and verifies AI agents before deployment and continuously supervises their behavior in production. | North America | M25 |
| Archestra | AI Guardrail Platforms | August 2025 | Seed | $3.3M | Provides a security and control layer for AI agents and MCP connections, including permissions, guardrails, and governed access to enterprise data and tools. | Europe | Concept Ventures |
| AIM Intelligence | AI Red Teaming | August 2025 | Seed | $1.3M | Provides automated AI red teaming, real-time guardrails, and supervision tools for detecting and controlling unsafe generative-AI behavior. | Asia-Pacific | Mirae Asset Capital |
| Noma Security | AI Risk Platforms | July 2025 | Series B | $100M | Secures AI applications and agents through discovery, posture management, red teaming, runtime protection, guardrails and AI-specific governance. | Middle East | Evolution Equity Partners |
| Promptfoo | AI Red Teaming | July 2025 | Series A | $18.4M | Tests and red-teams generative AI applications to detect prompt injection, jailbreaks, data leakage and other model-specific security failures. | North America | Insight Partners |
| Starseer | AI Safety Monitoring | July 2025 | Seed | $2M | Provides model-agnostic interpretability, security analysis and runtime oversight for detecting AI vulnerabilities and unsafe model behavior. | North America | Gula Tech Adventures |
| Modulos | AI Risk Platforms | July 2025 | Seed | ≈$10,900,000 | Automates AI governance, risk documentation, monitoring and compliance across frameworks including the EU AI Act, ISO 42001 and NIST AI RMF. | Europe | Not disclosed |
| Confident Security | AI Risk Platforms | July 2025 | Seed | $4.2M | Provides privacy-preserving infrastructure that keeps prompts and AI inference data inaccessible to model providers and other third parties. | North America | Not disclosed |
| Warden AI | AI Evaluation Tools | July 2025 | Seed | $1.6M | Continuously audits AI systems used in hiring for bias, fairness, explainability and regulatory compliance. | North America | Eamon Jubbawy; Husayn Kassai; Ruhul Amin; Playfair Capital |
| ZioSec | AI Red Teaming | June 2025 | Seed | $1.2M | Builds an offensive-security platform that continuously attacks AI agents and agent workflows to identify exploitable AI-specific vulnerabilities. | North America | Frank Mendicino of Access Venture Partners |
| Repello AI | AI Red Teaming | June 2025 | Seed | $1.2M | Provides continuous adversarial testing and runtime guardrails for identifying and mitigating vulnerabilities in generative-AI applications. | North America | Venture Highway |
| Trustible | AI Risk Platforms | June 2025 | Seed | $4.6M | Provides AI governance software for inventorying AI systems, assessing AI-specific risks, managing controls and maintaining regulatory compliance. | North America | Lookout Ventures |
| Hirundo | Model Robustness Tools | June 2025 | Seed | $8M | Develops machine-unlearning technology that removes unwanted data and behaviors such as hallucinations, bias and exploitable model behavior from trained AI models. | Middle East | Maverick Ventures Israel |
| Unbound | AI Guardrail Platforms | May 2025 | Seed | $4M | Provides an AI security gateway that enforces data-protection and usage policies on enterprise generative-AI traffic. | North America | Race Capital |
| Traceloop | AI Safety Monitoring | May 2025 | Seed | $6.1M | Provides automated evaluation, observability and production monitoring to detect failures and reliability problems in LLM applications and AI agents. | Middle East | Sorenson Capital; Ibex Investors |
| LMArena | AI Evaluation Tools | May 2025 | Seed | $100M | Runs a community-driven platform for real-world AI model evaluation and benchmarking using human preference comparisons. | North America | a16z; UC Investments |
| Barndoor AI | AI Risk Platforms | May 2025 | Seed | $13.6M | Provides a centralized control plane for governing AI-agent access, enforcing policies and monitoring agent activity. | North America | Crosslink Capital |
| Openlayer | AI Evaluation Tools | May 2025 | Series A | $14.5M | Provides continuous testing, evaluation, monitoring and governance for production AI and machine-learning systems. | North America | Race Capital |
| Etiq AI | Model Robustness Tools | April 2025 | Seed | ≈$1,020,000 | Tests and debugs AI and ML systems to identify robustness, bias, edge-case and model-behavior failures before deployment. | Europe | GapMinder VC |
| Opsin Security | AI Risk Platforms | April 2025 | Seed | $7M | Identifies and mitigates sensitive-data exposure and oversharing risks created by enterprise GenAI systems such as Copilot and Gemini. | North America | Race Capital |
| Pillar Security | AI Guardrail Platforms | April 2025 | Seed | $9M | Secures AI applications across development and runtime with adversarial testing, AI risk detection and adaptive guardrails. | Middle East | Shield Capital |
| Qualifire | AI Guardrail Platforms | April 2025 | Seed | $3.1M | Provides real-time contextual safeguards that monitor LLM behavior and block unsafe, inaccurate or policy-violating outputs. | Middle East | Not disclosed |
| Virtue AI | AI Risk Platforms | April 2025 | Unknown | $30M | Provides an integrated platform for AI red teaming, multimodal guardrails and security/governance of models, applications and agents. | North America | Lightspeed Venture Partners; Walden Catalyst Ventures |

As this chart shows, and as featured in our AI safety market deck, search interest in AI safety has been growing steadily
Is AI safety funding actually getting stronger right now?
AI safety funding is stronger now than the headline quarterly totals make it look.
Across the five complete quarters we studied, funding moved from $203.3M in Q2 2025 to $253.0M in Q3, $243.0M in Q4, a record $464.1M in Q1 2026, then back to $373.9M in Q2. Looking only at that sequence makes the market seem erratic.
The underlying financing environment has improved much more clearly. Once we exclude rounds above $50M, funding reached $249.9M in Q2 2026, more than double Q2 2025 and the highest level in the period. The median round also reached $10.5M.
Q1 2026 produced the biggest headline number, but Q2 had more depth. Money was spread across a wider group of companies raising substantial institutional rounds instead of depending on one $100M-plus financing.
| Period | Deals | Capital | Capital excluding >$50M | Median round |
|---|---|---|---|---|
| Q2 2025 | 14 | $203.3M | $103.3M | $6.55M |
| Q3 2025 | 18 | $253.0M | $73.0M | $3.53M |
| Q4 2025 | 18 | $243.0M | $162.0M | $8.50M |
| Q1 2026 | 19 | $464.1M | $176.1M | $6.00M |
| Q2 2026 | 18 | $373.9M | $249.9M | $10.50M |
| Q2 2025 → Q2 2026 | +28.6% | +83.9% | +141.9% | +60.3% |
| Q1 → Q2 2026 | −5.3% | −19.4% | +41.9% | +75.0% |
When did AI safety funding really start to change?
The AI safety funding market really began to change in Q4 2025.
Q3 initially looked like an acceleration because total funding rose 24%. Yet ordinary financing was getting weaker: the median round fell 46% to $3.53M and capital excluding rounds above $50M dropped 29%.
Q4 flipped that pattern. Total funding barely moved, from $253.0M to $243.0M, while the median more than doubled to $8.5M. Capital outside the very largest rounds jumped from $73.0M to $162.0M.
We also saw a change in what companies were raising money for. Guardrail platforms went from one financing in Q3 to nine in Q4, while follow-on rounds became much more prominent.
Q4 was more important than the raw funding chart suggested. It was the first quarter where bigger checks started appearing across the market rather than mainly at the top.

This chart, featured in our AI safety market deck, shows annual venture capital investment in AI safety startups
Was Q3 2025 basically just two huge AI safety deals?
Yes, much of Q3 2025's apparent AI safety funding strength came from two unusually large rounds.
Noma Security raised $100M and Irregular raised $80M. Together they represented roughly 71% of all capital raised that quarter.
The rest of the market looked very different. Twelve of the 18 financings were below $5M, and the median round fell from $6.55M in Q2 to only $3.53M.
Q3 therefore combined two things that can easily be confused: more companies were getting funded, but most were raising small rounds. The two large transactions then pushed the headline total above Q2.
The same effect distorted the geographic picture. Because both Noma Security and Irregular were classified in the Middle East, the region suddenly accounted for 71% of quarterly capital. That concentration disappeared in the following quarter.
Q3 had plenty of activity, but broad-based funding had not taken off yet.
Did Q1 2026 really mark an AI safety funding boom?
Q1 2026 was a big scaling quarter for a few AI safety companies, while the broader market grew much more modestly.
Goodfire raised $150M, Braintrust raised $80M and WitnessAI raised $58M. Those three financings alone generated about 62% of the quarter's $464.1M total.
Deal count barely changed, moving from 18 to 19. The average financing jumped to $24.4M, yet the median fell to $6M.
A handful of companies had reached the point where investors were willing to write very large growth checks, while the typical deal remained far smaller.
Later-stage funding also reached 56% of quarterly capital, largely because of those larger rounds.
Q1 was important because it showed that some AI safety companies could already support $50M-to-$150M financings. Calling it a market-wide boom would go too far.

This chart, featured in our AI safety market deck, shows how HiddenLayer is positioned in AI safety
Why did Q2 2026 look weaker when the AI safety market was actually healthier?
Q2 2026 was healthier than its 19% drop in headline AI safety funding suggests.
The largest financing in Q2 was $64M and represented only 17% of quarterly capital. In the four earlier quarters, the biggest deal alone accounted for between 32% and 49%.
That gave Q2 a much broader funding base. Seven transactions reached at least $20M, covering companies in guardrails, red teaming and AI evaluation.
At the same time, the market no longer needed a $100M or $150M transaction to produce a large quarterly total.
Q2 currently looks like the strongest underlying quarter in the five-quarter period. The headline number fell because Q1 had several exceptional financings, while the rest of the market kept moving up.
Are AI safety investors writing much bigger checks now?
Yes, ordinary AI safety funding rounds got substantially bigger by Q2 2026.
Only two transactions were below $5M in Q2, down from eight in Q1 and 12 back in Q3 2025. Nine companies raised between $5M and $20M, four raised between $20M and $50M, and three landed in the $50M-to-$100M range.
That distribution is much more useful than a single blockbuster deal. Companies were increasingly able to raise checks in the tens of millions across several parts of the market.
The $20M-to-$50M bucket is especially telling. It represented almost one-third of Q2 capital after being absent altogether in Q3 2025.
The latest quarter also had no $100M-plus financing. Bigger ordinary rounds, rather than one huge outlier, carried the market.
| Round size | Q2 2025 | Q3 2025 | Q4 2025 | Q1 2026 | Q2 2026 |
|---|---|---|---|---|---|
| <$5M | 6 deals | 12 | 7 | 8 | 2 |
| $5M-<$20M | 6 | 4 | 8 | 5 | 9 |
| $20M-<$50M | 1 | 0 | 2 | 3 | 4 |
| $50M-<$100M | 0 | 1 | 1 | 2 | 3 |
| $100M+ | 1 | 1 | 0 | 1 | 0 |
| Deals of $20M+ | 2 | 2 | 3 | 6 | 7 |
| Total deals | 14 | 18 | 18 | 19 | 18 |

This chart, featured in our AI safety market deck, shows annual funding in AI safety startups
Is Series A becoming the main battleground in AI safety funding?
Series A is becoming the key funding stage in AI safety, and companies are reaching those large rounds while they are still remarkably young.
Six Q2 2026 transactions were Series A financings. Together they raised $229M, or 61% of all capital in the quarter, with a $35M median round.
Series A represented only 7% of deals in Q2 2025. By the latest complete quarter it represented one-third.
Yet company age has barely moved. The median company receiving funding has been one year old since Q3 2025. Follow-on companies are generally only two or three years old.
Gray Swan, founded in 2023, raised a $40M Series A. Coval, founded in 2024, raised $28M. Even among younger businesses, investors are increasingly comfortable writing institutional-size checks once commercial or technical traction is visible.
Maturity in AI safety is happening very quickly. Companies do not need to become old businesses before they can raise serious money.
Are first-time AI safety startups getting squeezed out?
No, first-time AI safety startups are still getting funded, but they receive a much smaller share of the money than companies coming back for another round.
Seven of the 18 Q2 2026 transactions were first financings. That is still a meaningful pipeline of new companies.
Capital has moved much more decisively. Follow-on financings accounted for 32% of funding in Q2 2025, then rose to 52% in Q3, 77% in Q4 and just over 81% in both 2026 quarters.
By Q2 2026, first financings represented 39% of deals but only 19% of capital.
We still see plenty of startup formation. What has changed is where investors put the larger checks: increasingly into companies that have already raised once, built a product and returned with more evidence that customers actually want it.
That distinction is more useful than saying investors have simply become less interested in early-stage AI safety.

This chart, featured in our AI safety market deck, compares the main business model options for AI alignment research labs
Are AI guardrail platforms taking over AI safety funding?
AI guardrail platforms currently have the strongest momentum in AI safety funding, with enough separate deals to make the move harder to dismiss as one-company noise.
Guardrails accounted for 10 of 18 Q2 2026 financings and $193.3M of capital. Straiker and Arcade.dev provided two of the largest rounds, while several smaller companies added depth below them.
The category has been volatile. Guardrails represented only one deal in Q3 2025, jumped to nine in Q4, pulled back in Q1 and then reached 10 in Q2.
Still, the latest quarter looks stronger than a typical category spike because several companies raised meaningful amounts at the same time.
Model robustness gives us a useful contrast. Goodfire's $150M round made that category look huge in Q1, then model robustness recorded no Q2 financing at all. AI evaluation has also produced sharp jumps around individual companies such as LMArena, Braintrust and Patronus AI.
Guardrails currently have both deal breadth and capital depth. We need another few quarters before treating that dominance as permanent.
| Q2 2026 category | Deals | Capital | What we see now |
|---|---|---|---|
| AI Guardrail Platforms | 10 | $193.3M | Broadest momentum |
| AI Evaluation Tools | 2 | $78.0M | Large rounds, fewer companies |
| AI Red Teaming | 3 | $57.0M | Re-accelerating |
| AI Risk Platforms | 2 | $32.6M | Clear recent slowdown |
| AI Safety Monitoring | 1 | $13.0M | Still small and uneven |
| Model Robustness Tools | 0 | $0 | Q1 surge did not persist |
| Total market | 18 | $373.9M | — |
Why is agent security suddenly pulling in so much AI safety money?
Agent security is pulling in capital because enterprise AI is moving from systems that answer questions toward systems that can take actions inside real software.
That changes the security problem. Companies now have to think about which tools an agent can call, what data it can access, what permissions it receives and what happens when an autonomous workflow behaves unexpectedly.
The timing lines up closely with the funding shift. The NSA released dedicated Model Context Protocol security guidance in May 2026, pointing to accelerating real-world adoption and risks around tool invocation, trust relationships and context sharing. OWASP has also built a dedicated Agentic Security Initiative around autonomous agents and multi-step workflows.
The companies raising money were working directly on those problems. Arcade.dev's $60M financing centered on authorization and control of actions taken by agents. Straiker's $64M Series A funded a platform combining discovery, adversarial testing and runtime protection, after the company said run-rate revenue had increased more than 15-fold in less than a year.
WitnessAI had already expanded its product toward agent governance earlier in 2026, including visibility into the tools and systems enterprise agents can access.
We cannot prove that agent adoption caused every funding decision. But the match between the new technical problem and the companies receiving large rounds is unusually strong.

This chart, featured in our AI safety market deck, shows revenue breakdown by customer segment in the AI safety market
Are corporate investors becoming a serious force in AI safety funding?
Corporate investors are now a serious part of AI safety funding, especially once startups reach the stage where their products are touching real enterprise infrastructure.
Strategic investors appeared in about 6% to 11% of deals during 2025. That share jumped to 26% in Q1 2026 and 39% in Q2.
Seven Q2 financings included an identifiable strategic investor, and five of those seven were Series A rounds. The median strategic-backed round reached $40M.
The investor mix also makes commercial sense. Samsung Venture Investment backed AIM Intelligence. Datadog and Samsung participated in Patronus AI. Earlier in the year, Qualcomm Ventures and Samsung Ventures joined WitnessAI's strategic round.
These investors sell hardware, enterprise software, observability tools, communications infrastructure or other products sitting close to AI deployment.
Arcade.dev also brought in Morgan Stanley and Wipro, while Straiker attracted Citi Ventures and Workday Ventures. The common thread is practical: companies with direct exposure to enterprise AI are putting money into the controls needed to deploy it safely.
Strategic participation is one of the clearest structural changes we found.
Are the same VCs starting to control AI safety funding?
No, the same small group of VCs is not taking over AI safety funding; lead investors are still spread across a surprisingly wide set of firms.
We identified 14 unique disclosed leads in Q2 2025, followed by 20 in Q3, 26 in Q4, 18 in Q1 2026 and 22 in Q2.
Repeated leadership within a single quarter is unusual. Race Capital appeared on three Q2 2025 rounds, while Q3, Q4 and Q1 2026 had no comparable cluster. SYN Ventures led two transactions in Q2 2026.
A few investors do appear across several quarters. Redpoint Ventures shows up in three consecutive quarters, while Insight Partners and SYN Ventures each recur across two.
The broader picture still looks fragmented. AI safety companies are raising larger rounds without becoming dependent on a tiny circle of specialist investors.
Capital is concentrating around companies that have already proved something, while the firms supplying that capital remain fairly diverse.

This chart, featured in our AI safety market deck, shows how prompt injection defense platform technology has evolved over time
Is AI safety funding becoming less US-centric?
AI safety funding is becoming more geographically spread by deal count, although North America still dominates the money.
North American companies represented 64% of deals in Q2 2025 and 50% in Q2 2026. That is a real change in participation.
Capital is moving more slowly. North America still captured 73% of Q2 2026 funding.
Europe has the clearest momentum outside North America. After a small presence in Q2 2025, European companies accounted for roughly 22% to 28% of deals in every later quarter. By Q2 2026, Europe was also approaching one-fifth of total capital.
France, Spain and the UK all produced financings during the latest quarter, including an $11M round for White Circle.
Asia-Pacific remains much smaller. The Middle East can look large in isolated quarters, but the earlier 71% Q3 capital share came almost entirely from two deals and disappeared immediately afterward.
The market is becoming more international, especially on deal count. North America's funding lead remains comfortable for now.
Which AI safety funding trends are actually real today?
The two clearest AI safety funding trends today are the rise of follow-on capital and the much bigger role of strategic investors.
Both changes develop across several quarters instead of appearing once and disappearing.
Larger ordinary rounds also look increasingly convincing. We first saw that shift in Q4 2025, and Q2 2026 provided much stronger confirmation after the megaround-heavy Q1.
Series A is following the same path. The latest quarter was unusually strong, but we would still want more history before calling the shift permanent.
Guardrail platforms currently have the best category momentum, while Europe's growing capital depth is another development worth watching.
Several dramatic-looking patterns do not survive the same test. The Middle East surge was concentrated in one quarter. Model robustness spiked around Goodfire. Q1's jump in later-stage funding reversed quickly. Lead-investor concentration never really appeared.
| Apparent trend | Our current read |
|---|---|
| More capital going to follow-on rounds | Persistent |
| More strategic-investor participation | Persistent |
| Bigger ordinary round sizes | Emerging, increasingly convincing |
| Series A taking more capital | Emerging |
| Guardrails leading the category mix | Strong current momentum, still volatile |
| Europe attracting deeper funding | Emerging |
| First financings disappearing | Not supported |
| Q1 2026 later-stage surge | Temporary spike |
| Q3 2025 Middle East surge | Temporary spike |
| Model-robustness surge | Temporary spike |
| Lead investors becoming concentrated | Not supported |

In our AI safety market deck, we identify pain points entrepreneurs should prioritize
What is the funding trend actually telling us?
AI safety funding has moved from a market where quarterly totals were easily distorted by one or two huge rounds toward one where a broader group of companies can raise checks in the tens of millions. The path has been messy, but the financing base is stronger than it was at the start of the period.
Capital increasingly follows companies that have already raised once. New startups continue to appear, while repeat fundraisers capture most of the dollars because they can show more product, customer or technical evidence.
Series A has become especially important. Young AI safety companies are reaching large institutional rounds remarkably quickly, so the market is maturing through financing progression rather than through an aging company base.
Guardrails and agent security currently have the strongest category momentum. That funding wave also fits what is happening outside venture capital: autonomous agents introduce new problems around permissions, tool use, runtime behavior and control, which enterprises increasingly need to solve before putting these systems into production.
Corporate money is becoming harder to ignore. Banks, software companies, communications providers and technology groups are investing in the same security layer they may eventually depend on as AI agents spread through enterprise systems.
The raw quarterly funding chart remains the easiest part of this market to misread. Q3 2025 looked healthier than it was, while Q2 2026 looked weaker than it was. Once we separate exceptional rounds from the rest of the market, the direction becomes much clearer.
OUR METHODOLOGY
We studied AI safety fundraising announced from April 1, 2025 through June 30, 2026, covering five complete calendar quarters: Q2 2025, Q3 2025, Q4 2025, Q1 2026 and Q2 2026. The goal was to build a reliable quarter-by-quarter picture of financing activity rather than reproduce the output of a single funding database.
For inclusion, AI safety had to represent the company's core business at the time of the financing. We included companies primarily building AI guardrails, AI risk and governance products, evaluation systems, AI red-teaming tools, safety monitoring or model-robustness technology. Borderline companies were included only when the financing-time product clearly addressed an AI-specific safety or security problem.
We included qualifying private-company equity financings announced during the period. Debt, grants, loans, public offerings, unconverted convertibles and financings where the equity component could not be isolated were excluded. Duplicate reports of the same round were consolidated, while extensions, additional closes and tranches were reviewed individually.
Dates, stages, investors, previous financing history and company milestones were recorded only when public evidence supported them. We did not infer a round stage from its size, assume an investor was the lead because its name appeared prominently, or estimate an undisclosed funding amount.
A few financings required extra care. Virtue AI's $30M announcement combined Seed and Series A capital rather than representing a normal single $30M round. Keycard disclosed an $8M Seed and a separate $30M Series A on the same date, so we treated them as distinct financings. Attestable was assigned to Q1 2026 using its public-announcement date, and ZioSec's Q2 2025 amount reflects the capital demonstrably sold in its June Form D.
After building the dataset, we ran a separate quality-control pass focused on missed deals, date boundaries, financing type, market eligibility, duplicate announcements and unusual round structures. We also tested whether the main conclusions survived after removing rounds above $50M, because several quarters were heavily distorted by a handful of unusually large financings.
Key sources included first-hand company announcements from Arcade.dev, Straiker, WitnessAI, Gray Swan, Patronus AI, NeuralTrust, Braintrust, Adaptive Security, Noma Security, Irregular and LMArena. We also used the U.S. National Security Agency's guidance on AI-driven automation and Model Context Protocol security, the OWASP Agentic Security Initiative and the European Commission's guidance on general-purpose AI obligations under the AI Act.

This chart, featured in our AI safety market deck, shows revenue breakdown by geography across Europe, Asia, North America, Africa, and South America in the AI safety market