What are the current funding trends in AI safety?

In our AI safety market deck, you will find everything you need to understand the market
SUMMARY
AI safety funding is booming in 2026: deal count is up 33%, the number of funded companies is up 24%, and disclosed capital has risen 152% versus the same period of 2025. More importantly, the boom survives even after the largest rounds are removed.
Capital below $50 million rounds has almost tripled year over year, from $221 million to $625 million. The five biggest deals now represent only 38.8% of funding, compared with 65% in 2025 and 85.3% in 2024, so this year's growth is much less dependent on a handful of outliers.
The typical financing is getting materially larger. The median round has climbed from $5.68 million to $10 million, and 22 of the 56 deals completed this year are worth at least $20 million, versus just five of 42 during the comparable 2025 period.
The biggest structural change is the arrival of a real scale-up layer. Seed stayed flat at 36 financings, while Series A jumped from two deals to 12 and Series B from one to five.
New companies are still entering the market, but they are no longer driving most of the capital growth. First financings brought in about $232 million, barely above last year's $222 million, while follow-on capital surged from $262 million to roughly $1.21 billion.
Guardrail platforms are the clearest category winner, with 22 financings and $626 million of capital. Safety monitoring is expanding quickly too, while evaluation has fewer deals but much larger rounds and model interpretability remains concentrated around a small number of high-conviction bets.
AI agent security sits underneath much of this shift. As agents gain access to email, databases, APIs, tools and company systems, investors are putting more money behind platforms that can discover those agents, monitor what they do and restrict their permissions at runtime.
North America still dominates the money rather than the entire deal map. It accounts for 60.7% of deals but 83.1% of capital, while Europe doubled from six to 12 financings without seeing the same jump in median round size.
The investor base is broadening as well. We found 55 unique disclosed lead investors and strategic investors in 16 financings, up from five strategic-backed deals during the same period last year, with most of that corporate activity appearing from Series A onward.
AI safety is therefore moving from startup formation into rapid scaling unusually quickly. The main thing to watch now is Seed: if startup formation stays flat while later-stage rounds keep accelerating, future growth will depend increasingly on the cohort created during the 2023–2025 generative-AI wave.

This market map, featured in our AI safety market deck, highlights top companies and startups in the AI safety market
All funding deals in the AI safety market over the last years
Below is the table listing all the deals. You can find our methodology at the end of this page.
If you want a deeper understanding of the market and its current dynamics, get our report covering the AI Safety Market.
| Company | Category | Date | Stage | Deal size | What they do | Region | Lead investors |
|---|---|---|---|---|---|---|---|
| HiddenLayer | AI Safety Monitoring | September 2026 | Series B | $100M | Protects AI models, applications and agents through AI asset discovery, supply-chain scanning, attack simulation and runtime threat detection and protection. | North America | Delta-v Capital |
| Lasso Security | AI Guardrail Platforms | September 2026 | Series A | $30M | Provides AI-specific discovery, risk management, automated red teaming and runtime guardrails for models, agents and generative-AI applications. | Middle East | ClearSky Advisors |
| AIR Security | AI Guardrail Platforms | September 2026 | Seed | $10M | Secures enterprise AI agents by continuously vetting skills, plugins, MCP servers and other context inputs and blocking unsafe interactions. | Middle East | Sequoia Capital |
| AIR Security | AI Guardrail Platforms | September 2026 | Seed | $40M | Secures enterprise AI agents by continuously vetting skills, plugins, MCP servers and other context inputs and blocking unsafe interactions. | Middle East | Greenoaks |
| Arga Labs | AI Evaluation Tools | August 2026 | Seed | $10M | Provides realistic stateful sandboxes for testing AI-agent behavior, catching regressions and edge cases before production. | North America | General Catalyst |
| Velatir | AI Risk Platforms | August 2026 | Seed | ≈$5,800,000 | Gives enterprises real-time visibility into AI use, data flows, and agent activity while enforcing centralized AI security and governance policies. | Europe | Spintop Ventures; Ugly Duckling Ventures |
| Kyvvu | AI Guardrail Platforms | August 2026 | Seed | ≈$1,160,000 | Enforces state-aware runtime policies inside AI agents, allowing, warning on, or blocking unsafe action sequences before execution. | Europe | Volta Ventures; Brabant Development Agency (BOM) |
| Lemma | AI Safety Monitoring | August 2026 | Seed | $2.3M | Monitors production AI-agent traces to detect silent failures, diagnose root causes, and generate regression checks and code-level fixes. | North America | Not disclosed |
| Mindgard | AI Red Teaming | August 2026 | Series A | $30M | Automates adversarial red teaming of AI models, agents, and applications to find exploitable failures and support protective controls. | North America | Album VC |
| Molt AI Corp. | AI Red Teaming | August 2026 | Seed | $1M | Runs adaptive adversarial tests against tool-using AI agents, verifies action-level failures, and retests remediations for reproducible assurance evidence. | North America | Not disclosed |
| FriskAI | AI Safety Monitoring | August 2026 | Seed | $3.6M | Records AI-agent tool use in production, builds behavioral baselines, and flags anomalous or unsafe deviations. | North America | MaC Venture Capital |
| Neuromorphic Labs | AI Risk Platforms | August 2026 | Seed | $5.1M | Provides verifiable asset identity, lineage, runtime policy enforcement, traceability, and compute verification across production AI models and agents. | North America | Flying Fish |
| Zenity | AI Guardrail Platforms | August 2026 | Series C | ≈$115,000,000 | Discovers enterprise AI agents and enforces intent-aware security boundaries that allow, modify, or block risky actions before execution. | North America | Norwest |
| Arrakis Security | AI Safety Monitoring | August 2026 | Seed | $8M | Discovers, profiles, monitors, and governs enterprise AI agents to detect and stop unsafe or unauthorized runtime behavior. | North America | Hetz Ventures |
| Onyx Security | AI Risk Platforms | July 2026 | Series B | $113M | Provides a secure AI control plane that discovers, monitors, governs, and enforces runtime controls over enterprise AI agents. | North America | Bessemer Venture Partners |
| Neo | AI Guardrail Platforms | July 2026 | Series A | $75M | Provides a real-time control layer that inventories agentic software, assesses its risks, attributes actions, and enforces policies on AI-agent behavior. | North America | Andreessen Horowitz; Bessemer Venture Partners |
| Runta | AI Guardrail Platforms | July 2026 | Seed | $20M | Provides a policy-enforced execution layer that constrains AI agents' filesystem, network, credential, and spending access while recording their actions. | North America | Andreessen Horowitz |
| Neo | AI Guardrail Platforms | July 2026 | Seed | $25M | Provides a real-time control layer that inventories agentic software, assesses its risks, attributes actions, and enforces policies on AI-agent behavior. | North America | Andreessen Horowitz; Merlin Ventures |
| Naaia | AI Risk Platforms | July 2026 | Series A | ≈$6,860,000 | Provides an AI risk and compliance platform that inventories AI systems, assesses risks, automates controls, and continuously monitors governance obligations. | Europe | Ventech |
| Straiker | AI Guardrail Platforms | June 2026 | Series A | $64M | Discovers enterprise AI agents, continuously adversarially tests them, and applies runtime defenses against agent-specific attacks and unsafe behavior. | North America | Marathon Management Partners; Citi Ventures; Illuminate Financial; Workday Ventures |
| Patronus AI | AI Evaluation Tools | June 2026 | Series B | $50M | Builds evaluation and simulation infrastructure that stress-tests AI models and agents for failures and reliability before production deployment. | North America | Greenfield Partners |
| Coval | AI Evaluation Tools | June 2026 | Series A | $28M | Provides simulation, automated evaluation, monitoring, and regression testing for autonomous voice and chat AI agents. | North America | Norwest |
| NeuralTrust | AI Guardrail Platforms | June 2026 | Seed | $20M | Secures enterprise AI agents with discovery, gateways, runtime threat prevention, governance, monitoring, and red-team testing. | Europe | Alstin Capital |
| Tenet Security | AI Guardrail Platforms | June 2026 | Seed | $6M | Protects autonomous AI agents at runtime by simulating intended actions and blocking malicious or unsafe execution paths before they reach production systems. | North America | The Westly Group; MizMaa Ventures |
| Arcade.dev | AI Guardrail Platforms | June 2026 | Series A | $60M | Provides authorization, policy enforcement, execution controls, and auditing for actions taken by production AI agents. | North America | SYN Ventures |
| Willow | AI Guardrail Platforms | June 2026 | Seed | $7M | Governs enterprise AI agents through identity, scoped permissions, runtime guardrails, centralized controls, and attributable audit trails. | Middle East | Hetz Ventures |
| ZeroDrift | AI Guardrail Platforms | June 2026 | Seed | $10M | Provides a runtime enforcement layer that checks and blocks or fixes AI-generated communications against regulatory and organizational policies before delivery. | North America | Not disclosed |
| Geordie AI | AI Risk Platforms | May 2026 | Series A | $30M | Provides security and governance software that discovers AI agents, monitors their behavior and access, assesses risk, and constrains unsafe behavior at runtime. | Europe | Balderton Capital |
| Gray Swan | AI Red Teaming | May 2026 | Series A | $40M | Provides adversarial testing, continuous red teaming, and runtime protection for AI models and agents. | North America | Wing Venture Capital; Madrona |
| CodeIntegrity | AI Guardrail Platforms | May 2026 | Seed | $5M | Provides a runtime control layer that constrains AI-agent tool calls, data access, and actions before execution. | North America | SYN Ventures |
| White Circle | AI Guardrail Platforms | May 2026 | Seed | $11M | Provides a real-time control layer that checks AI inputs and outputs against policies to detect and prevent unsafe, hallucinatory, injected, or otherwise unwanted model behavior. | Europe | Not disclosed |
| Aigentsphere | AI Risk Platforms | April 2026 | Seed | ≈$2,600,000 | Provides a governance and control layer for registering, monitoring, assessing and enforcing policies across enterprise AI agents. | Asia-Pacific | Main Sequence |
| General Analysis | AI Red Teaming | April 2026 | Seed | $10M | Adversarially tests enterprise AI agents for exploitable failure modes and pairs those evaluations with runtime defenses and guardrails. | North America | Altos Ventures |
| Tynapse | AI Guardrail Platforms | April 2026 | Seed | ≈$3,300,000 | Builds a runtime AI Trust Layer that verifies and controls AI-agent responses and actions while producing audit-ready records. | Asia-Pacific | Mirae Asset Venture Investment |
| Capsule Security | AI Guardrail Platforms | April 2026 | Seed | $7M | Provides a runtime security layer that observes AI-agent behavior and blocks prompt injection, data exfiltration and unsafe actions before execution. | Middle East | Lama Partners; Forgepoint Capital International |
| AIM Intelligence | AI Red Teaming | April 2026 | Series A | ≈$7,000,000 | Provides automated AI red teaming and runtime guardrails for detecting and controlling unsafe or exploitable behavior in AI models and agents. | Asia-Pacific | Samsung Venture Investment |
| Trent AI | AI Safety Monitoring | April 2026 | Seed | $13M | Provides an AI-native security platform that continuously identifies, assesses and mitigates risks in AI agents and agent-generated software. | Europe | LocalGlobe; Cambridge Innovation Capital |
| OpenBox AI | AI Risk Platforms | March 2026 | Seed | $5M | Provides runtime governance, verification, authorization, risk scoring and oversight infrastructure for autonomous enterprise AI agents. | North America | Tykhe Ventures |
| Galtea | AI Evaluation Tools | March 2026 | Seed | $3.2M | Provides evaluation infrastructure that generates tailored test scenarios to measure AI-agent quality, robustness, security and failure modes before deployment. | Europe | 42CAP |
| Manifold Security | AI Safety Monitoring | March 2026 | Seed | $8M | Monitors autonomous AI agents on enterprise endpoints at runtime to detect anomalous behavior and enable security teams to investigate or stop risky actions. | North America | Costanoa Ventures |
| Certiv | AI Guardrail Platforms | March 2026 | Seed | $4.2M | Provides runtime assurance that observes AI-agent actions on endpoints and blocks behavior violating enterprise policies before execution. | North America | Not disclosed |
| Onyx Security | AI Guardrail Platforms | March 2026 | Series A | $35M | Provides a control plane that discovers AI agents, monitors their behavior and enforces runtime policies to prevent unsafe or unauthorized actions. | North America | Conviction |
| JetStream Security | AI Risk Platforms | March 2026 | Seed | $34M | Provides a security-first AI governance control plane for discovering, mapping, governing and monitoring enterprise AI systems and agents. | North America | Redpoint Ventures |
| Evoke Security | AI Safety Monitoring | February 2026 | Seed | $4M | Discovers, monitors and controls enterprise AI agents, detecting and blocking risky agent behavior in real time. | North America | Crosspoint Capital Partners |
| LuminosAI | AI Risk Platforms | February 2026 | Seed | $6M | Automates testing, governance and risk assessment of generative and agentic AI systems for legal and technical liabilities. | North America | M13 |
| Braintrust | AI Evaluation Tools | February 2026 | Series B | $80M | Provides AI evaluation and observability tooling for testing, tracing and detecting failures in models and agents. | North America | ICONIQ |
| Hardshell | Model Robustness Tools | February 2026 | Seed | $1.1M | Protects AI training datasets against poisoning, leakage and integrity failures before they propagate into models. | North America | Not disclosed |
| Overmind | AI Safety Monitoring | February 2026 | Seed | $2.73M | Provides a supervision layer that observes AI-agent behavior, detects anomalies and enables intervention in production. | Europe | Osney Capital |
| Backslash Security | AI Guardrail Platforms | February 2026 | Series A | $19M | Secures AI coding agents, IDEs, MCPs and LLM workflows with governance, guardrails and real-time threat detection. | Middle East | KOMPAS VC |
| Attestable | Model Robustness Tools | February 2026 | Seed | $18.5M | Builds a zero-knowledge verification layer designed to prove the integrity of AI models, inputs and outputs and detect tampering. | Middle East | TLV Partners |
| Goodfire | Model Robustness Tools | February 2026 | Series B | $150M | Builds interpretability tools and research infrastructure to understand, monitor and shape AI model behavior. | North America | B Capital |
| Velatir | AI Risk Platforms | February 2026 | Seed | $1.58M | Provides continuous AI governance, visibility, human review and controls over enterprise AI systems and agents. | Europe | Ugly Duckling Ventures |
| Pallma AI (now Verno Labs) | AI Red Teaming | January 2026 | Seed | $1.6M | Builds AI-native red-teaming and runtime protection for autonomous AI agents, including prompt-injection detection, threat monitoring, and agent hardening. | Europe | Marathon Venture Capital |
| Fiddler AI | AI Safety Monitoring | January 2026 | Series C | $30M | Provides AI observability, evaluation, monitoring, governance, and runtime controls for detecting and managing unsafe or unreliable model and agent behavior. | North America | RPS Ventures |
| WitnessAI | AI Guardrail Platforms | January 2026 | Unknown | $58M | Provides runtime AI security and governance controls that observe AI interactions, enforce policies, and block threats such as prompt injection and unsafe agent behavior. | North America | Sound Ventures |
| Principled Intelligence | AI Risk Platforms | January 2026 | Seed | ≈$2,200,000 | Builds an enterprise control and governance layer that monitors and constrains AI systems against organizational policies, safety requirements, and regulatory rules. | Europe | National Technology Transfer Hub for Artificial Intelligence and Cybersecurity; BlackSheep |
| Ciphero | AI Safety Monitoring | December 2025 | Seed | $2.5M | Provides a real-time AI verification layer that captures, verifies and governs human and agentic AI interactions to detect unsafe or noncompliant use. | North America | Sovereign's Capital; Chingona Ventures |
| Wodan AI | AI Risk Platforms | December 2025 | Seed | ≈$2,350,000 | Enables ML, computer-vision and LLM workloads to run directly on fully encrypted data without exposing plaintext during computation. | Europe | JME Ventures; Swanlaab; Adara Ventures |
| Adaptive Security | AI Risk Platforms | December 2025 | Series B | $81M | Assesses and reduces exposure to deepfake, generative-AI phishing, voice-cloning and other AI-powered social-engineering attacks. | North America | Bain Capital Ventures |
| Alinia AI | AI Guardrail Platforms | December 2025 | Seed | $7.5M | Builds runtime guardrails and AI-compliance controls that audit AI systems, detect policy or model risks and enforce rules in real time. | Europe | Mouro Capital |
| imper.ai | AI Safety Monitoring | December 2025 | Series A | $21.5M | Detects AI-driven impersonation, deepfakes and voice-cloning attacks in real time across enterprise communication channels. | North America | Redpoint Ventures; Battery Ventures |
| Lumia Security | AI Guardrail Platforms | December 2025 | Seed | $18M | Provides network-level AI security and governance that monitors AI and agent interactions, evaluates exposure risk and enforces policies. | North America | Team8 |
| Helmet Security | AI Guardrail Platforms | December 2025 | Seed | $9M | Secures agentic AI and MCP communications through continuous discovery, traffic monitoring, risk detection and policy enforcement. | North America | SYN Ventures; WhiteRabbit Ventures |
| Mirror Security | AI Risk Platforms | December 2025 | Seed | $2.5M | Provides FHE-based encrypted AI inference and secure fine-tuning so sensitive data remains encrypted while models process it. | Europe | Sure Valley Ventures; Atlantic Bridge |
| Vijil | Model Robustness Tools | November 2025 | Series A | $17M | Tests, protects, and continuously hardens AI agents to improve their reliability, security, safety, and resilience in production. | North America | BrightMind Partners |
| Runlayer | AI Guardrail Platforms | November 2025 | Seed | $11M | Provides a security and governance control layer for MCP-connected AI agents, including permissions, threat detection, auditability, and observability. | North America | Khosla Ventures (Keith Rabois); Felicis |
| AI Score | AI Risk Platforms | November 2025 | Seed | $1M | Provides a centralized control layer for enterprise AI governance, compliance, risk visibility, and oversight of generative and agentic AI use. | Europe | Not disclosed |
| Polygraf AI | AI Guardrail Platforms | October 2025 | Seed | $9.5M | Provides AI-specific security controls for detecting and mitigating data leakage, synthetic-content, provenance and governance risks in enterprise AI use. | North America | Allegis Capital |
| Truth Systems | AI Guardrail Platforms | October 2025 | Seed | $4M | Converts organizational AI-use policies into real-time guardrails that monitor, block and audit risky AI interactions. | North America | Gradient |
| Darwin AI | AI Risk Platforms | October 2025 | Series A | $15M | Provides AI governance, policy enforcement, risk controls and compliance infrastructure for government AI deployments. | North America | Insight Partners |
| eRoun&Company | AI Guardrail Platforms | October 2025 | Unknown | $1.4M | Provides AI governance, prompt security, data-leak prevention, usage controls and audit trails for enterprise generative-AI use. | Asia-Pacific | KB Investment |
| Keycard | AI Guardrail Platforms | October 2025 | Seed | $8M | Provides identity, task-scoped permissions and runtime policy enforcement purpose-built to constrain AI-agent access and actions. | North America | Andreessen Horowitz; boldstart ventures |
| Keycard | AI Guardrail Platforms | October 2025 | Series A | $30M | Provides identity, task-scoped permissions and runtime policy enforcement purpose-built to constrain AI-agent access and actions. | North America | Acrew Capital |
| Skyld | Model Robustness Tools | October 2025 | Seed | ≈$1,760,000 | Protects deployed AI/ML models against theft, reverse engineering, unauthorized reuse and model-specific attacks. | Europe | Auriga Cyber Ventures; BNP Paribas Développement |
| Scorecard | AI Evaluation Tools | September 2025 | Seed | $3.8M | Provides high-frequency evaluation and simulated testing infrastructure to identify failures and regressions in AI agents before deployment. | North America | Kindred Ventures |
| Trismik | AI Evaluation Tools | September 2025 | Seed | ≈$2,959,000 | Provides adaptive, science-grade testing that measures LLM capabilities, alignment, safety, bias, and other failure modes. | Europe | Twinpath Ventures |
| Irregular | AI Red Teaming | September 2025 | Unknown | $80M | Adversarially stress-tests frontier AI models for dangerous cyber capabilities and develops defenses for safer deployment. | Middle East | Sequoia Capital; Redpoint Ventures |
| Eve Security | AI Safety Monitoring | September 2025 | Seed | $3M | Monitors AI agents at runtime and enforces intent- and data-aware policies against unsafe or anomalous agent actions. | North America | LiveOak Ventures |
| Geordie AI | AI Safety Monitoring | September 2025 | Seed | $6.5M | Discovers, observes, assesses, and controls autonomous AI agents so enterprises can identify risky behavior and govern deployment. | Europe | Ten Eleven Ventures; General Catalyst |
| ALIGNMT AI | AI Risk Platforms | August 2025 | Seed | $6.5M | Provides healthcare-focused AI governance, continuous risk monitoring, compliance workflows, and model-behavior oversight. | North America | AIX Ventures |
| Bluejay | AI Evaluation Tools | August 2025 | Seed | $4M | Provides simulation, evaluation, testing, and production observability for voice and text AI agents. | North America | Floodgate |
| Confident AI | AI Evaluation Tools | August 2025 | Seed | $2.2M | Provides infrastructure for evaluating, red teaming, monitoring, and governing LLM applications and AI agents. | North America | Not disclosed |
| Nugen Intelligence | Model Robustness Tools | August 2025 | Seed | >$1,000,000 | Builds domain-alignment infrastructure intended to make AI models and agents more reliable and predictable in enterprise-critical applications. | Asia-Pacific | Antler |
| Swept AI | AI Safety Monitoring | August 2025 | Seed | $1.4M | Adversarially evaluates and verifies AI agents before deployment and continuously supervises their behavior in production. | North America | M25 |
| Archestra | AI Guardrail Platforms | August 2025 | Seed | $3.3M | Provides a security and control layer for AI agents and MCP connections, including permissions, guardrails, and governed access to enterprise data and tools. | Europe | Concept Ventures |
| AIM Intelligence | AI Red Teaming | August 2025 | Seed | $1.3M | Provides automated AI red teaming, real-time guardrails, and supervision tools for detecting and controlling unsafe generative-AI behavior. | Asia-Pacific | Mirae Asset Capital |
| Noma Security | AI Risk Platforms | July 2025 | Series B | $100M | Secures AI applications and agents through discovery, posture management, red teaming, runtime protection, guardrails and AI-specific governance. | Middle East | Evolution Equity Partners |
| Promptfoo | AI Red Teaming | July 2025 | Series A | $18.4M | Tests and red-teams generative AI applications to detect prompt injection, jailbreaks, data leakage and other model-specific security failures. | North America | Insight Partners |
| Starseer | AI Safety Monitoring | July 2025 | Seed | $2M | Provides model-agnostic interpretability, security analysis and runtime oversight for detecting AI vulnerabilities and unsafe model behavior. | North America | Gula Tech Adventures |
| Modulos | AI Risk Platforms | July 2025 | Seed | ≈$10,900,000 | Automates AI governance, risk documentation, monitoring and compliance across frameworks including the EU AI Act, ISO 42001 and NIST AI RMF. | Europe | Not disclosed |
| Confident Security | AI Risk Platforms | July 2025 | Seed | $4.2M | Provides privacy-preserving infrastructure that keeps prompts and AI inference data inaccessible to model providers and other third parties. | North America | Not disclosed |
| Warden AI | AI Evaluation Tools | July 2025 | Seed | $1.6M | Continuously audits AI systems used in hiring for bias, fairness, explainability and regulatory compliance. | North America | Eamon Jubbawy; Husayn Kassai; Ruhul Amin; Playfair Capital |
| ZioSec | AI Red Teaming | June 2025 | Seed | $1.2M | Builds an offensive-security platform that continuously attacks AI agents and agent workflows to identify exploitable AI-specific vulnerabilities. | North America | Frank Mendicino of Access Venture Partners |
| Repello AI | AI Red Teaming | June 2025 | Seed | $1.2M | Provides continuous adversarial testing and runtime guardrails for identifying and mitigating vulnerabilities in generative-AI applications. | North America | Venture Highway |
| Trustible | AI Risk Platforms | June 2025 | Seed | $4.6M | Provides AI governance software for inventorying AI systems, assessing AI-specific risks, managing controls and maintaining regulatory compliance. | North America | Lookout Ventures |
| Hirundo | Model Robustness Tools | June 2025 | Seed | $8M | Develops machine-unlearning technology that removes unwanted data and behaviors such as hallucinations, bias and exploitable model behavior from trained AI models. | Middle East | Maverick Ventures Israel |
| Unbound | AI Guardrail Platforms | May 2025 | Seed | $4M | Provides an AI security gateway that enforces data-protection and usage policies on enterprise generative-AI traffic. | North America | Race Capital |
| Traceloop | AI Safety Monitoring | May 2025 | Seed | $6.1M | Provides automated evaluation, observability and production monitoring to detect failures and reliability problems in LLM applications and AI agents. | Middle East | Sorenson Capital; Ibex Investors |
| LMArena | AI Evaluation Tools | May 2025 | Seed | $100M | Runs a community-driven platform for real-world AI model evaluation and benchmarking using human preference comparisons. | North America | a16z; UC Investments |
| Barndoor AI | AI Risk Platforms | May 2025 | Seed | $13.6M | Provides a centralized control plane for governing AI-agent access, enforcing policies and monitoring agent activity. | North America | Crosslink Capital |
| Openlayer | AI Evaluation Tools | May 2025 | Series A | $14.5M | Provides continuous testing, evaluation, monitoring and governance for production AI and machine-learning systems. | North America | Race Capital |
| Etiq AI | Model Robustness Tools | April 2025 | Seed | ≈$1,020,000 | Tests and debugs AI and ML systems to identify robustness, bias, edge-case and model-behavior failures before deployment. | Europe | GapMinder VC |
| Opsin Security | AI Risk Platforms | April 2025 | Seed | $7M | Identifies and mitigates sensitive-data exposure and oversharing risks created by enterprise GenAI systems such as Copilot and Gemini. | North America | Race Capital |
| Pillar Security | AI Guardrail Platforms | April 2025 | Seed | $9M | Secures AI applications across development and runtime with adversarial testing, AI risk detection and adaptive guardrails. | Middle East | Shield Capital |
| Qualifire | AI Guardrail Platforms | April 2025 | Seed | $3.1M | Provides real-time contextual safeguards that monitor LLM behavior and block unsafe, inaccurate or policy-violating outputs. | Middle East | Not disclosed |
| Virtue AI | AI Risk Platforms | April 2025 | Unknown | $30M | Provides an integrated platform for AI red teaming, multimodal guardrails and security/governance of models, applications and agents. | North America | Lightspeed Venture Partners; Walden Catalyst Ventures |
| Straiker | AI Guardrail Platforms | March 2025 | Seed | $21M | Provides AI-native assessment and runtime protection that red-teams AI applications and blocks safety and security threats during operation. | North America | Not disclosed |
| SplxAI | AI Red Teaming | March 2025 | Seed | $7M | Provides automated adversarial testing, continuous security assessment and remediation for AI agents and applications. | North America | LAUNCHub Ventures |
| Darwin AI | AI Risk Platforms | March 2025 | Seed | $5M | Provides AI governance infrastructure for public agencies to inventory AI use, manage risks, enforce policies and maintain oversight. | North America | UpWest; Resolute Ventures |
| AIceberg | AI Guardrail Platforms | March 2025 | Seed | $10M | Provides an AI trust platform that validates AI traffic in real time and enforces safety, security and compliance controls. | North America | SYN Ventures; Sprout & Oak |
| Knostic | AI Guardrail Platforms | March 2025 | Seed | $11M | Provides need-to-know access controls and safety layers for enterprise LLMs to prevent sensitive-information oversharing. | North America | Bright Pixel Capital |
| LangWatch | AI Evaluation Tools | February 2025 | Seed | ≈$1,050,000 | Provides LLM evaluation and quality-control tooling that monitors harmful or inaccurate outputs, runs real-time tests and helps teams optimize AI applications. | Europe | Passion Capital |
| Arize AI | AI Evaluation Tools | February 2025 | Series C | $70M | Provides AI and LLM evaluation and observability software for testing, monitoring, troubleshooting and improving model and agent behavior in production. | North America | Adams Street Partners |
| Safe Intelligence | Model Robustness Tools | February 2025 | Seed | ≈$5,250,000 | Provides deep validation and automated robustification software that detects model fragilities and improves resilience to failure-inducing inputs. | Europe | Amadeus Capital Partners |
| Singulr AI | AI Risk Platforms | February 2025 | Seed | $10M | Provides an enterprise AI governance and security control plane for discovering AI use, scoring risk and enforcing policies against shadow AI and data leakage. | North America | Nexus Venture Partners; Dell Technologies Capital |
| Future AGI | AI Evaluation Tools | February 2025 | Seed | $1.6M | Provides multimodal AI evaluation, observability and optimization tooling to detect failures and improve application reliability. | North America | Powerhouse Ventures; Snow Leopard Ventures |
| Human.org | AI Risk Platforms | February 2025 | Seed | $7.3M | Builds decentralized identity and authority infrastructure that makes AI agents traceable, accountable and verifiably tied to human intent. | North America | Not disclosed |
| Coval | AI Evaluation Tools | January 2025 | Seed | $3.3M | Provides automated simulation, testing, evaluation and production monitoring infrastructure for assessing the reliability and behavior of AI agents. | North America | MaC Venture Capital |
| Mindgard | AI Red Teaming | December 2024 | Seed | $8M | Provides automated AI red teaming and security testing that exposes AI-specific vulnerabilities such as jailbreaks and prompt-injection attacks. | Europe | .406 Ventures |
| Hamming AI | AI Evaluation Tools | December 2024 | Seed | $3.8M | Automates evaluation, red teaming and production monitoring for AI voice agents to identify reliability and safety failures. | North America | Mischief |
| Fiddler AI | AI Safety Monitoring | December 2024 | Series B | $18.6M | Provides AI observability, safety monitoring and explainability for LLM and ML systems to detect behavioral, governance and reliability risks. | North America | Not disclosed |
| AIMon Labs | AI Safety Monitoring | December 2024 | Seed | $2.3M | Monitors generative-AI applications with specialized evaluators that detect hallucinations and other output reliability and safety failures. | North America | Bessemer Venture Partners; Tidal Ventures |
| Gentrace | AI Evaluation Tools | December 2024 | Series A | $8M | Provides collaborative evaluation, testing and monitoring software for generative-AI applications to identify reliability and safety failures. | North America | Matrix Partners |
| Wald.ai | AI Guardrail Platforms | December 2024 | Seed | $4M | Provides an inline data-protection layer for enterprise AI assistants that redacts sensitive information before prompts reach external models. | North America | Not disclosed |
| AIQURIS | AI Risk Platforms | December 2024 | Seed | ≈$3,780,000 | Provides an AI risk-management platform for qualifying, assessing and de-risking enterprise AI solutions against safety, security, quality and governance requirements. | Asia-Pacific | TÜV SÜD |
| Prompt Security | AI Guardrail Platforms | November 2024 | Series A | $18M | Protects enterprise GenAI use and applications by inspecting prompts and model responses, enforcing policies, and blocking data leakage, prompt injection, jailbreaks, and harmful content. | Middle East | Jump Capital |
| Calvin Risk | AI Risk Platforms | November 2024 | Seed | $4M | Provides quantitative AI risk assessment, automated model testing, governance, and continuous monitoring for enterprise AI systems. | Europe | Join Capital; seed + speed Ventures |
| SurePath AI | AI Risk Platforms | November 2024 | Seed | $5.2M | Provides a GenAI governance and security platform that discovers AI use, controls model and data access, and mitigates risks across enterprise AI interactions. | North America | Uncork Capital |
| Noma Security | AI Risk Platforms | October 2024 | Seed | $7M | Secures the AI and data lifecycle through AI asset discovery, posture management, supply-chain controls, governance, and runtime threat detection. | Middle East | Glilot Capital Partners |
| Noma Security | AI Risk Platforms | October 2024 | Series A | $25M | Secures the AI and data lifecycle through AI asset discovery, posture management, supply-chain controls, governance, and runtime threat detection. | Middle East | Ballistic Ventures |
| Verax AI | AI Safety Monitoring | October 2024 | Seed | $7.6M | Monitors LLM applications in production for hallucinations, bias, and other unwanted behavior and can auto-correct risky outputs in real time. | North America | TQ Ventures |
| DAIKI GmbH | AI Risk Platforms | October 2024 | Seed | ≈$1,615,000 | Provides AI-governance software for AI inventories, risk management, documentation, safety checks, and compliance with AI-specific rules and standards. | Europe | Not disclosed |
| Reality Defender | AI Safety Monitoring | October 2024 | Series A | $18M | Detects deepfakes and AI-generated audio, video, images, and text in real time for fraud, disinformation, and other AI-specific threats. | North America | Illuminate Financial |
| Galileo | AI Evaluation Tools | October 2024 | Series B | $45M | Provides enterprise GenAI evaluation and observability with research-backed metrics, production monitoring, and safety guardrails. | North America | Scale Venture Partners |
| Braintrust | AI Evaluation Tools | October 2024 | Series A | $36M | Provides an eval-first platform for testing, scoring, tracing, and improving LLM applications before and in production. | North America | Andreessen Horowitz |
| Distributional | AI Evaluation Tools | October 2024 | Series A | $19M | Automates adaptive testing of AI models and applications to detect behavioral changes, reliability failures, and operational AI risk. | North America | Two Sigma Ventures |
| Harmonic Security | AI Guardrail Platforms | October 2024 | Series A | $17.5M | Provides AI-specific data-loss prevention and usage controls that detect and block sensitive-data exposure through generative-AI tools. | North America | Next47 |
| SplxAI | AI Red Teaming | September 2024 | Seed | $2M | Automates offensive security testing and red teaming of GenAI applications to identify prompt-injection, jailbreak and other AI-specific vulnerabilities. | North America | Inovo.vc |
| Acuvity | AI Risk Platforms | September 2024 | Seed | $9M | Provides an AI security and governance platform that discovers GenAI use and risk and enforces access and data-protection controls across models and applications. | North America | Foundation Capital |
| Safe Superintelligence Inc. (SSI) | Model Robustness Tools | September 2024 | Unknown | $1B | Develops a safe superintelligent AI system as its sole product and research mission, treating safety and capabilities as joint technical problems. | North America | Not disclosed |
| ModelOp | AI Risk Platforms | August 2024 | Series B | $10M | Provides enterprise AI-governance software that inventories AI systems, measures risk, automates controls and monitors compliance across the AI lifecycle. | North America | Baird Capital |
| Goodfire | Model Robustness Tools | August 2024 | Seed | $7M | Builds mechanistic-interpretability tools that let developers understand, edit and debug model behavior to reduce unintended failures and improve AI safety. | North America | Lightspeed Venture Partners |
| Aurascape AI | AI Risk Platforms | August 2024 | Seed | $12.8M | Builds security technology specifically for enterprise generative-AI adoption, protecting against AI-specific threats, data leakage and related risks. | North America | Mayfield Fund |
| Protect AI | AI Risk Platforms | August 2024 | Series B | $60M | Provides AI/ML security posture management, model scanning, red teaming and governance to identify and mitigate AI-specific vulnerabilities across the ML lifecycle. | North America | Evolution Equity Partners |
| Credo AI | AI Risk Platforms | July 2024 | Unknown | $21M | Provides purpose-built AI governance, risk-management and compliance software for measuring, monitoring and managing risks across enterprise AI systems. | North America | CrimsoNox Capital |
| Lakera | AI Guardrail Platforms | July 2024 | Series A | $20M | Provides a real-time security and guardrail layer that protects generative-AI applications against prompt injection, data leakage and other AI-specific threats. | Europe | Atomico |
| Vijil | AI Evaluation Tools | July 2024 | Seed | $6M | Provides evaluation and defense services that measure and mitigate reliability, security, privacy and safety risks in generative-AI applications and agents. | North America | Mayfield AIStart; Gradient Ventures |
| Promptfoo | AI Red Teaming | July 2024 | Seed | $5M | Provides open-source AI pentesting, adversarial red-teaming and evaluation tools for finding and fixing security and safety failures in LLM applications. | North America | Andreessen Horowitz |
| trail GmbH | AI Risk Platforms | July 2024 | Seed | ≈$1,576,000 | Provides purpose-built AI governance software that automates risk assessment, governance workflows, technical documentation and transparency for AI systems. | Europe | CapitalT |
| Maxim AI | AI Evaluation Tools | June 2024 | Seed | $3M | Provides an end-to-end platform for evaluating and observing generative-AI applications before and after deployment, including automated quality and safety testing. | North America | Elevation Capital |
| Aim Security | AI Guardrail Platforms | June 2024 | Series A | $18M | Provides an AI-specific enterprise security platform with runtime guardrails against data leakage, prompt injection, jailbreaks, and harmful AI outputs. | Middle East | Canaan Partners |
| FairNow | AI Risk Platforms | June 2024 | Seed | $2.4M | Provides an AI-governance platform for inventorying, assessing, monitoring, and documenting enterprise AI risks and regulatory compliance. | North America | Somen Mondal; Shaun Ricci |
| Liminal | AI Guardrail Platforms | June 2024 | Seed | >$5,000,000 | Provides a model-agnostic GenAI security layer that protects sensitive data and controls enterprise use of generative AI. | North America | Fin Capital |
| Inspeq AI | AI Evaluation Tools | May 2024 | Seed | $1.1M | Provides an LLM testing and reliability platform for evaluation, monitoring, guardrails and AI safety controls across GenAI development and production. | Europe | Sure Valley Ventures |
| Patronus AI | AI Evaluation Tools | May 2024 | Series A | $17M | Automates LLM evaluation, adversarial testing, benchmarking and failure detection to identify hallucinations, security issues and other unsafe model behavior. | North America | Notable Capital |
| WitnessAI | AI Guardrail Platforms | May 2024 | Series A | $27.5M | Provides an enterprise AI security and governance layer for visibility, policy control, data protection and guardrails over AI use. | North America | GV; Ballistic Ventures |
| Monitaur | AI Risk Platforms | May 2024 | Series A | $6M | Provides model-governance software to define policies, manage risk, validate and monitor AI and machine-learning models. | North America | Cultivation Capital |
| Apex | AI Safety Monitoring | May 2024 | Seed | $7M | Provides real-time visibility, policy enforcement, detection, investigation and response for attacks and unsafe enterprise use of AI models and applications. | Middle East | Sequoia Capital; Index Ventures |
| DeepKeep | AI Risk Platforms | May 2024 | Seed | $10M | Provides an AI-native trust, risk and security management platform for assessing, monitoring and mitigating AI-model risks across the AI lifecycle. | Middle East | Awz Ventures |
| TrojAI | AI Guardrail Platforms | April 2024 | Seed | $5.8M | Provides AI-security software that red-teams models before deployment and blocks AI-specific runtime threats through an AI firewall. | North America | Flying Fish |
| SydeLabs | AI Red Teaming | March 2024 | Seed | $2.5M | Provides automated adversarial testing and AI-specific protection to identify security and safety vulnerabilities in generative-AI models and applications. | North America | RTP Global |
| ValidMind | AI Risk Platforms | March 2024 | Seed | $8.1M | Automates validation, testing, documentation, and governance of AI/ML models for regulated financial institutions. | North America | Point72 Ventures |
| Enkrypt AI | AI Guardrail Platforms | February 2024 | Seed | $2.4M | Provides a control layer for enterprise GenAI that monitors LLM use and blocks unsafe behavior, attacks, data leakage and policy violations. | North America | Boldcap |
| Armilla AI | AI Risk Platforms | February 2024 | Seed | $4.5M | Assesses and quantifies AI-model risks to provide independent verification and insurance-backed performance warranties for AI systems. | North America | Mistral Venture Partners |
| Clarity | AI Safety Monitoring | February 2024 | Seed | $16M | Detects deepfakes and other AI-manipulated video, audio and images and authenticates media to reduce synthetic-media threats. | Middle East | Walden Catalyst Ventures; Bessemer Venture Partners |
| Guardrails AI | AI Guardrail Platforms | February 2024 | Seed | $7.5M | Provides runtime validators and guardrails that detect and mitigate hallucinations, policy violations, unsafe outputs and other LLM risks. | North America | Zetta Venture Partners |
| Aim Security | AI Guardrail Platforms | January 2024 | Seed | $10M | Provides an enterprise GenAI security platform with visibility, policy enforcement, guardrails, and protection across employee and production AI use. | Middle East | YL Ventures |
| Reken | AI Safety Monitoring | January 2024 | Seed | $10M | Builds AI-native defenses that detect and block generative-AI-enabled deepfake, impersonation, social-engineering, scam, and fraud threats. | North America | Greycroft; FPV Ventures |
| Prompt Security | AI Guardrail Platforms | January 2024 | Seed | $5M | Provides a GenAI security layer that inspects prompts and model responses to prevent data leakage, harmful outputs, prompt injection, jailbreaks, and other AI-specific risks. | Middle East | Hetz Ventures |
| RagaAI | AI Evaluation Tools | January 2024 | Seed | $4.7M | Provides automated testing to detect, diagnose, and help fix AI failures including hallucinations, bias, drift, adversarial vulnerabilities, and robustness issues. | North America | pi Ventures |

As this chart shows, and as featured in our AI safety market deck, search interest in AI safety has been growing steadily
AI safety funding: what is actually changing in 2026?
Is AI safety funding really booming right now?
AI safety funding is growing fast in 2026, and this time the boom goes well beyond a few giant rounds.
We counted 56 financings in the current year-to-date period, up from 42 over the same months of 2025 and 33 in 2024. The number of funded companies also rose from 42 to 52 in one year. At the same time, disclosed capital reached $1.44 billion, compared with $571 million a year earlier.
The mix is what makes 2026 unusual. More startups are raising, but the companies that do raise are also getting much bigger checks. The median financing climbed from $5.68 million to $10 million, while the average moved from $14.3 million to $25.7 million.
The 2024 comparison is useful because that year included Safe Superintelligence's $1 billion financing. Despite that enormous outlier, 2026 has already produced almost 70% more deals over the comparable period and 62.5% more funded companies.
| Market measure | 2026 YTD | 2025 YTD | 2024 YTD | Change vs 2025 |
|---|---|---|---|---|
| Deals | 56 | 42 | 33 | +33.3% |
| Unique funded companies | 52 | 42 | 32 | +23.8% |
| Total disclosed capital | $1.440B | $571M | $1.323B | +152.1% |
| Capital excluding >$50M rounds | $625M | $221M | $263M | +182.5% |
| Capital excluding >$100M rounds | $1.062B | $571M | $323M | +85.9% |
| Median round | $10.0M | $5.68M | $7.25M | +76.2% |
| Average round | $25.7M | $14.3M | $41.3M | +80.1% |
| First-financing share | 48.2% | 57.1% | 57.6% | -8.9 pp |
| Follow-on share | 51.8% | 38.1% | 42.4% | +13.7 pp |
Would AI safety funding still look strong without the biggest deals?
Yes. AI safety funding actually looks even stronger once we strip out the largest rounds.
Removing every financing above $50 million leaves $625 million of capital in 2026. The comparable figure last year was $221 million, so funding below that threshold has almost tripled.
The same test helps with 2024. Headline capital from that period looks close to today's level because Safe Superintelligence raised $1 billion by itself. Below $50 million, current funding is about 138% higher than the comparable 2024 figure.
Money has also spread much further down the ranking. The five largest deals currently account for 38.8% of capital, versus 65% in 2025 and 85.3% in 2024. Goodfire's $150 million Series B, Zenity's approximately $115 million of primary capital, Onyx Security's $113 million Series B, HiddenLayer's $100 million Series B and Braintrust's $80 million Series B are all large, but together they still leave most of this year's funding elsewhere in the market.
The market is simply much less top-heavy than it was in 2025 or 2024.

This chart, featured in our AI safety market deck, shows annual venture capital investment in AI safety startups
Are normal AI safety rounds getting much bigger?
Yes. The clearest change in AI safety funding right now is happening in the $20 million to $50 million range.
We found 12 financings in that bracket this year. There was only one during the comparable 2025 period. Six more deals landed between $50 million and $100 million, compared with two last year.
Meanwhile, sub-$5 million rounds are becoming less dominant. They represented 42.9% of 2025 deals and now account for 25%.
There are now far more companies raising $20 million, $30 million, $40 million or more. A couple of years ago, the market had a much larger population of small early rounds and an occasional spectacular financing at the top.
Twenty-two of this year's 56 deals are worth at least $20 million. Only five of 42 crossed that mark in the same part of 2025.
| Round size | 2026 deals | 2026 deal share | 2026 capital share | 2025 deals |
|---|---|---|---|---|
| Below $5M | 14 | 25.0% | 2.4% | 18 |
| $5M to <$20M | 20 | 35.7% | 12.4% | 17 |
| $20M to <$50M | 12 | 21.4% | 25.1% | 1 |
| $50M to <$100M | 6 | 10.7% | 26.9% | 2 |
| $100M+ | 4 | 7.1% | 33.2% | 2 |
| At least $20M | 22 | 39.3% | 85.2% | 5 |
| Below $20M | 34 | 60.7% | 14.8% | 35 |
| Median round | $10.0M | — | — | $5.68M |
Is AI safety finally moving beyond Seed?
Yes. AI safety is still full of young startups, but almost all of the extra deal activity this year has appeared after Seed.
Seed financings stayed exactly flat at 36. Total deals still rose from 42 to 56 because Series A jumped from two financings to 12, Series B from one to five and Series C from one to two.
Series A has become especially important. Those 12 deals brought in about $425 million, with a $30 million median round. Five Series B financings raised $493 million between them, more than all 36 Seed deals combined.
The speed is striking. The typical Series A company in our research is only around two years old, while the typical Series B company is roughly three. Startups founded during the recent generative-AI wave are reaching serious institutional funding rounds very quickly.
Seed still represents almost two-thirds of transactions, so startup formation remains active. The big change is that there is now a much larger class of young companies successfully graduating beyond it.

This chart, featured in our AI safety market deck, shows how HiddenLayer is positioned in AI safety
Can brand-new AI safety startups still get funded?
Yes, new AI safety startups are still getting funded, although most of the extra money is now going to companies investors have backed before.
We identified 27 first financings this year, compared with 24 during the same part of 2025. New-company funding has therefore grown slightly in absolute terms.
Follow-ons tell a much more dramatic story. Their count rose from 16 to 29, and the median follow-on increased from $7 million to $30 million.
Capital followed the same path. First financings brought in around $232 million, barely above the $222 million recorded a year earlier. Follow-ons climbed from $262 million to roughly $1.21 billion.
Investors have not stopped funding new teams. They are putting far more money behind companies that have already passed an earlier fundraising and product-development test.
Our first-financing classification comes from a financing-history check rather than a claim that we can reconstruct every private round ever completed by every company. The gap is large enough, however, that the direction is clear.
| Financing profile | 2026 | 2025 | 2024 |
|---|---|---|---|
| First financings | 27 | 24 | 19 |
| First-financing share | 48.2% | 57.1% | 57.6% |
| First-financing capital | $232M | $222M | $1.139B |
| Median first financing | $6M | $4M | $7M |
| Follow-on financings | 29 | 16 | 14 |
| Follow-on share | 51.8% | 38.1% | 42.4% |
| Follow-on capital | $1.208B | $262M | $184M |
| Median follow-on | $30M | $7M | $10M |
| Companies with multiple deals in-period | 4 | 0 | 1 |
Why are AI guardrail startups getting so much money now?
AI guardrails are currently the biggest funding story inside AI safety, with investors backing many more companies and writing much larger checks.
We counted 22 Guardrail Platform financings this year, compared with seven in the same part of 2025. Their share of all deals rose by 22.6 percentage points, while their share of capital increased by 32.7 points.
The median guardrail round has also moved up to $19.5 million from $9 million.
This change has been building for a while. Lakera raised $20 million in 2024 to protect generative-AI applications from prompt injection, data leakage and other AI-specific attacks. Prompt Security also raised Seed and Series A capital around enterprise GenAI controls. Those companies were early signs of the category.
The 2026 market is much bigger. Zenity's latest financing included roughly $115 million of primary capital for a platform designed to discover enterprise agents and put security boundaries around what they can do. Onyx Security raised $113 million after previously raising a $35 million Series A. The company's platform discovers AI agents, watches their behavior and enforces runtime controls.
This is broad category growth rather than one financing distorting the totals.
| AI safety category | 2026 deals | 2026 capital | Median round | Deal-share change vs 2025 |
|---|---|---|---|---|
| AI Guardrail Platforms | 22 | $626M | $19.5M | +22.6 pp |
| AI Risk Platforms | 11 | $212M | $5.8M | -6.5 pp |
| AI Safety Monitoring | 9 | $172M | $8.0M | +4.2 pp |
| AI Red Teaming | 6 | $89.6M | $8.5M | -3.6 pp |
| AI Evaluation Tools | 5 | $171M | $28M | -12.5 pp |
| Model Robustness Tools | 3 | $170M | $18.5M | -4.2 pp |
| All AI safety deals | 56 | $1.440B | $10.0M | — |

This chart, featured in our AI safety market deck, shows annual funding in AI safety startups
Is runtime AI security taking over from evaluation and red teaming?
Runtime AI security is taking a much larger share of funding today, while evaluation and red teaming are evolving in a more uneven way.
Safety Monitoring went from five deals to nine and from roughly $19 million to $172 million of capital. HiddenLayer is a useful example. Its recent $100 million Series B is specifically being used to deepen agentic runtime protection, and the company reported more than tenfold ARR growth plus over 50 new platform customers.
AI Evaluation looks different. We counted five deals this year versus nine last year, but its median financing jumped from $3.3 million to $28 million. Braintrust's $80 million Series B fits that pattern. The company says AI has moved from experimentation into production, where long-running agents now generate complex traces and failure modes that teams need to monitor continuously.
Red Teaming has not vanished either. The number of deals stayed at six, although its share of the expanding overall market declined.
More money is now going toward what happens after an AI system goes live. Testing before deployment still matters, but production observability, agent control and runtime protection are absorbing a larger portion of venture capital.
Is model interpretability having the same funding boom as guardrails?
Model interpretability is attracting serious money, but the current funding spike is concentrated in one standout company.
Model Robustness Tools generated roughly $170 million from only three financings. Goodfire alone raised $150 million in its Series B after previously raising a $50 million Series A.
Goodfire is building interpretability technology designed to understand and shape what happens inside advanced models. Its latest funding will support research as well as applications involving AI agents and life sciences.
Three financings do not give us the same breadth we see in guardrails or monitoring. The category's capital share has risen sharply because Goodfire became a nine-figure company very quickly.
For now, model interpretability looks like a high-conviction pocket of the market rather than evidence that dozens of robustness startups are suddenly breaking out.

This chart, featured in our AI safety market deck, compares the main business model options for AI alignment research labs
Why is money moving toward AI agent security?
Money is moving toward AI agent security because agents can now touch real company data and systems, creating a much harder security problem than a chatbot answering questions.
Microsoft's February 2026 Cyber Pulse research said more than 80% of Fortune 500 companies were deploying active agents built with low-code or no-code tools. Microsoft also warned that agent adoption was moving faster than some companies' ability to observe and govern it.
Google Cloud reached a similar conclusion in its 2026 AI infrastructure research. Among the technology leaders it surveyed, 79% cited security, governance or operations as their biggest challenge to scaling inference. Google also reported that 35% of senior IT decision-makers saw inadequate security for multi-system access as a major obstacle to deploying agents.
An agent may be allowed to read email, query a database, use a tool, call an API or trigger an action. Every additional permission creates something that needs to be identified, monitored and controlled.
Funding is following that problem. Onyx is building an AI control plane, HiddenLayer is pushing further into runtime agent protection, and Zenity is focused on agent discovery, governance and enforcement.
These products are easier to justify when thousands of autonomous or semi-autonomous agents are entering corporate systems than when generative AI mostly lived inside isolated pilots.
Are AI safety startups getting older as the market matures?
No. AI safety startups are reaching bigger rounds remarkably quickly, while the typical funded company remains very young.
The approximate median company age in this year's financing cohort is only one year. It was two years in 2025 and one year in 2024.
That sits oddly beside the stage shift at first. Series A and Series B are much more common, yet the companies raising them are not old cybersecurity vendors that have suddenly repositioned around AI.
The typical Seed company is around one year old, Series A around two and Series B around three. Even within Guardrail Platforms, the median company age is roughly one year.
The market is maturing financially faster than the startups themselves are aging. A recent cohort is moving through the fundraising cycle unusually fast.

This chart, featured in our AI safety market deck, shows revenue breakdown by customer segment in the AI safety market
Is North America taking over AI safety funding?
North America currently dominates AI safety capital, although Europe is producing more funded companies than it did last year.
North America generated 34 deals, giving it 60.7% of total activity. That is actually lower than its 66.7% deal share in 2025. Its capital share moved the other way, from 58.8% to 83.1%.
The median North American round reached $22.5 million, up from around $5 million a year earlier.
Europe doubled from six deals to 12, pushing its deal share to 21.4%. The median European financing remained around $4.5 million, so the region's growth currently comes more from having additional funded startups than from producing many huge rounds.
The Middle East contributed seven deals and $132 million, while Asia-Pacific remained smaller with three deals and about $13 million.
We also found roughly 10 countries represented this year compared with around seven in 2025. AI safety is spreading geographically even as the largest checks cluster more heavily in North America.
Are more venture investors seriously betting on AI safety now?
Yes. More investors are leading AI safety rounds today, and several firms are coming back for multiple deals.
We found 55 unique disclosed lead investors in this year's sample, up from 46 last year. Six leads appeared on more than one financing, compared with only one repeat lead in the comparable 2025 period.
Andreessen Horowitz appeared three times as a lead or co-lead. SYN Ventures, Hetz Ventures, Norwest, Bessemer Venture Partners and Ugly Duckling Ventures each appeared twice.
New investors are still entering the sector, while a group of existing backers is gaining enough conviction to fund several companies.
A year ago, Race Capital was the only lead that appeared repeatedly in our comparable sample. Its absence from this year's lead list tells us only that it did not lead one of the deals we captured during the period; it would be too much to call that a retreat from AI safety.
Overall, venture interest looks broader and more repeatable than it did a year ago.

This chart, featured in our AI safety market deck, shows how prompt injection defense platform technology has evolved over time
Why are corporate investors showing up in more AI safety deals?
Corporate investors are much more visible in AI safety rounds this year, especially once startups reach Series A and beyond.
Strategic investors participated in 16 financings, or 28.6% of all deals, compared with five deals and 11.9% last year.
The more interesting change is where those investments sit. Only four of the 16 strategic-backed rounds were Seed deals. Six were Series A, three Series B and two Series C.
The median strategically backed financing reached $37 million.
Microsoft's M12 and Booz Allen Ventures joined HiddenLayer's $100 million Series B. Zenity's latest round included Hitachi Ventures, LG Technology Ventures and Intel Capital. Goodfire's investor group included Salesforce Ventures. These companies sit close to cloud infrastructure, enterprise software, security or AI deployment, so the strategic link is straightforward.
Corporate participation was already high in 2024 at about 30% of deals, which keeps us from calling the current level unprecedented. What looks different now is the amount of money involved and the maturity of the rounds.
Is regulation actually causing the AI safety funding boom?
Regulation is helping create demand for AI governance and safety tools, but commercial deployment of AI agents looks like the more immediate force behind this year's funding shift.
The regulatory pressure is real. General-purpose AI obligations under the European AI Act began applying in 2025, including requirements around technical documentation, transparency, risk management and safety for the most advanced models.
The framework became more concrete in 2026. New transparency requirements started applying, and the European Commission's enforcement powers expanded under the AI Act.
That gives companies another reason to document, monitor and control their AI systems.
Still, the category changes in our funding research line up more directly with production problems. Guardrails and Safety Monitoring are gaining deals. HiddenLayer talks about securing autonomous coding agents at runtime. Onyx is selling control over enterprise agents. Microsoft's and Google Cloud's latest research both focus heavily on agent permissions, observability and governance.
Regulation adds pressure, especially in Europe. The current financing pattern looks broader than compliance spending alone.

In our AI safety market deck, we identify pain points entrepreneurs should prioritize
Has AI safety funding already passed previous full-year levels?
AI safety funding has already beaten some full-year benchmarks, even before 2026 is complete.
Current year-to-date capital equals roughly 175% of all the funding we recorded during 2025. The 56 deals completed so far are already about 90% of the 62 financings recorded during that entire year.
Activity has also moved past 2024. We counted 52 deals across all of 2024, so the current year has already exceeded that total.
Capital has not yet passed full-year 2024 because Safe Superintelligence's $1 billion round made that year unusually large. Even so, current funding has already reached roughly 91% of the 2024 total.
We would not extend these numbers into a mechanical year-end forecast. Venture funding arrives in bursts, and a couple of large financings can move a yearly total dramatically. What we can say is that the current pace has already crossed benchmarks that previously required a full calendar year.
What is actually changing in AI safety funding?
The biggest change is the arrival of a real scale-up layer. AI safety used to lean much more heavily toward Seed rounds and a few huge outliers. Today, many more companies are raising $20 million to $50 million, Series A activity has surged and Series B is becoming much more visible.
The second change is where the money goes after the first round. New startups continue to enter the market, but follow-on capital has accelerated far faster. Investors are now putting much larger amounts behind companies that have already shown product or commercial progress.
The clearest category rotation is toward guardrails, monitoring and runtime control. These products are closely tied to the move from experimental generative AI toward agents operating inside real enterprise systems. Evaluation remains well funded at the upper end, while model interpretability has produced a few high-conviction bets rather than the same broad expansion.
The outlier test is unusually reassuring here. Capital excluding rounds above $50 million is growing even faster than headline capital, while top-five concentration has fallen sharply. The boom survives once we remove the deals most likely to distort it.
The part we would watch most carefully is startup formation. Seed activity itself has stopped growing, even as later stages accelerate. If first financings and Seed stay flat for much longer, the market could eventually become more dependent on a cohort that was created during the 2023–2025 wave.
For now, AI safety funding is moving from startup formation into fast scaling, with AI agent control becoming the part of the market attracting the broadest investor attention.

This chart, featured in our AI safety market deck, shows revenue breakdown by geography across Europe, Asia, North America, Africa, and South America in the AI safety market
OUR METHODOLOGY
This analysis tracks private AI safety fundraising from January 1 through September 21, 2026 and compares it with the exact same January 1 through September 21 periods in 2025 and 2024. Full-year figures for 2024 and 2025 are used only as secondary context and are not mixed into the direct year-to-date comparisons.
We built the dataset financing by financing rather than relying on a single funding database. We researched company and investor announcements, regulatory and government material, reputable financial and industry reporting, and established funding databases, favoring first-hand sources whenever they were available for round size, stage, investors and use of funds.
Only qualifying private-company equity financings announced during the relevant period and meeting our minimum deal-size threshold were included. Debt, grants, loans, public offerings, unconverted convertibles, SAFEs and financings where the equity amount could not be separated reliably were excluded.
We used a deliberately strict definition of AI safety. AI safety had to represent the company's overwhelming core business at the time of financing. Companies with a peripheral safety feature inside a much broader software or cybersecurity product were excluded when the fit was genuinely borderline.
Each financing was counted separately, while duplicate reports of the same round were consolidated. Extensions, additional closes and tranches were reviewed individually. When a qualifying financing had no reliable disclosed amount, we kept it in deal-count analysis but excluded it from capital and round-size calculations rather than estimating a number.
Stage, investors, founding dates, prior-financing status and strategic-investor participation were recorded only when public evidence supported them. We did not infer stages from round size, assume a lead investor from name order or estimate undisclosed financing amounts. First-financing versus follow-on status comes from a separate financing-history check and should be read directionally rather than as a claim to reconstruct every private transaction in a company's history.
After compiling the dataset, we ran a separate quality-control pass for missed financings, duplicates, date boundaries, equity eligibility, market fit, stage consistency and unusual deal structures. The aim throughout was to keep uncertain information uncertain instead of filling gaps with assumptions.
Key sources used for the company examples and market context include Onyx Security on its $113 million Series B and AI control-plane positioning, HiddenLayer on its $100 million Series B and agentic runtime security, Braintrust on its $80 million Series B and the move from experimentation into production, Goodfire on its $150 million Series B, Zenity on its latest financing and autonomous-AI security, Microsoft Security's Cyber Pulse research on enterprise agents, Google Cloud's 2026 research on agent governance and security, European Commission guidance on AI Act transparency obligations, the European Commission's AI Act enforcement framework, Noma Security on its $100 million Series B, Lakera on its $20 million Series A, Prompt Security on its early Seed financing, Protect AI on its $60 million Series B, Braintrust's earlier $36 million Series A, and Goodfire's earlier $50 million Series A.

This chart, featured in our AI safety market deck, shows annual venture capital investment in AI safety startups