What are the fundraising trends in the AI safety market?

Last updated: 13 July 2026
market research pitch 2026 statistics AI safety market

In our AI safety market deck, you will find everything you need to understand the market

SUMMARY

We analyzed publicly disclosed equity rounds raised by pure-play AI safety companies between January 2024 and July 2026. We only kept disclosed rounds of $300K or more, and we excluded generic MLOps, broad cybersecurity, general compliance, frontier model labs, and content-moderation businesses unless the funded product specifically reduced AI-model behavior risk or AI-specific threats.

The AI safety market has re-accelerated sharply in 2026. After raising about $369M across 20 deals in 2024 and about $265M across 12 deals in 2025, the market had already raised about $675M across 24 deals by early July 2026.

The freshest comparison is even more striking. Between January and early July 2026, AI safety companies raised about $675M, compared with about $105M over the comparable period in 2025. Deal count rose from 6 to 24, so the 2026 surge reflects both more companies getting funded and larger platform rounds.

Capital remains highly concentrated. In 2026 through early July, the top 10 deals captured about 84% of all AI safety funding, while the bottom half of deals captured only about 12%. The average round was about $28M, but the median was only $12M, which means the typical company raised much less than the headline average suggests.

The AI safety market is still early by stage count. Seed rounds represented 58% of 2026 deal count, while Series A rounds captured nearly half of all capital. The category is not yet dominated by Series C, Series D, or growth-equity financings; instead, investors are writing large early and Series A checks into companies that look like potential infrastructure layers.

AI Risk Platforms are the largest 2026 category by both capital and deal count, with about $260M across 10 deals. But AI Evaluation Tools command the strongest capital premium, raising about $233M from only 3 deals, helped by very large rounds for LMArena and Braintrust.

Agentic AI has become the central funding spine of the AI safety market. Many of the largest 2026 rounds focus on AI-agent governance, identity, authorization, guardrails, runtime monitoring, audit trails, evaluation infrastructure, and enterprise control planes.

The market is becoming more global by company formation, but not by capital depth. North America produced 50% of 2026 deal count through early July but captured about 73% of capital. Europe, Asia-Pacific, and the Middle East are now visible in deal count, but the largest checks still cluster around North American companies and U.S.-style enterprise buyer narratives.

New startups are still entering the AI safety market. First financings represented 54% of 2026 deals through early July, but only 28% of capital, which shows that investors are still funding new entrants while reserving the biggest checks for perceived platform winners.

The practical interpretation is that AI safety has moved from a policy-adjacent market to an enterprise-control infrastructure market. Investors are rewarding companies that can measure, govern, block, authorize, monitor, evaluate, or document AI behavior in production.

Chart showing revenue breakdown by customer segment in the AI safety market

This chart, featured in our AI safety market deck, shows revenue breakdown by customer segment in the AI safety market

Is more or less capital going into the AI safety market?

More capital is going into the AI safety market, and the increase is not subtle. The freshest comparison is the strongest one: 2026 through early July produced about $675M of disclosed equity funding across 24 deals, compared with about $105M across 6 deals over the same calendar period in 2025.

That means AI safety capital is up more than 6x, while deal count is up 4x. The AI safety market had already raised far more in the first half of 2026 than it raised in all of 2025, when the full-year total was about $265M.

The cleaner full-year comparison gives useful context because full-year 2025 was actually down versus full-year 2024. Capital fell from about $369M in 2024 to about $265M in 2025, and deal count fell from 20 to 12. So the AI safety market did not grow in a straight line; it cooled in 2025, then accelerated sharply in 2026.

The 2026 total should still be read carefully because a few large rounds drive a meaningful share of the market. LMArena, Braintrust, NewCore, Arcade, and WitnessAI together account for a large share of year-to-date capital. But even after excluding rounds above $50M, 2026 through early July still produced about $261M, almost equal to the entire full-year 2025 total.

The practical takeaway is that more capital is clearly going into the AI safety market. The 2025 decline now looks less like structural abandonment and more like a consolidation year before agentic AI risk pushed the category back into a much stronger funding cycle.

For the full underlying company list and category breakdown, see the full AI safety market report.

Is AI safety funding driven by more deals or larger rounds?

AI safety funding is being driven by both more deals and larger rounds, but the more important 2026 signal is that the market is expanding at the base while also producing more large platform rounds. Deal count rose from 6 deals over the comparable period in 2025 to 24 deals in 2026 through early July, while total capital rose from about $105M to about $675M.

Larger rounds still matter a lot. The average AI safety round increased from about $17.5M over the comparable 2025 period to about $28M in 2026 through early July. But the median round moved only modestly, from $10M to $12M, which means the top of the market expanded much faster than the middle.

The full-year comparison explains why the distinction matters. In 2025, the AI safety market had fewer deals than in 2024, falling from 20 to 12, but the average round rose from about $18M to about $22M. That made 2025 a year of fewer deals but slightly larger average checks. By contrast, 2026 is a year of both more deals and more large rounds.

The median is the better read on the typical financing environment. The median AI safety round was $17.5M in 2024, $13M in 2025, and $12M in 2026 through early July. The typical round has not exploded upward; what has exploded is the number of funded companies and the number of outsized platform financings.

The best interpretation is that the AI safety market is being pulled upward by category-leader rounds while also broadening through new formation. Funding activity is no longer just one or two companies raising large checks; the whole market is more active, but the biggest dollars still concentrate around companies that look like infrastructure.

Is AI safety capital moving toward later-stage or earlier-stage companies?

AI safety capital is moving toward earlier-stage and mid-stage companies, not traditional late-stage companies. In 2026 through early July, Seed and Series A rounds represented 87.5% of all deals, and Seed, Series A, and Unknown-stage rounds together captured nearly 80% of all capital.

The stage mix is especially revealing. Seed rounds were 58% of 2026 deal count and about 30% of capital. Series A rounds were 29% of deals but about 49% of capital. Series B rounds were only 8% of deals and about 20% of capital. There were no Series C, Series D+, or Growth Equity rounds in the 2026 through early July sample.

The full-year history adds nuance. In 2024, Series A and Series B together captured nearly 88% of capital, while Seed captured only about 11%. In 2025, Seed represented half of deals but only 15% of capital, while Series B captured nearly 38% because of Noma Security’s $100M round. In 2026, Series A became the main capital magnet.

This means investors are not waiting for conventional late-stage proof before writing large checks. They are funding AI safety companies earlier when those companies appear positioned to own a control plane, evaluation layer, identity layer, authorization layer, guardrail workflow, or agent-governance system.

The AI safety market is therefore not moving later-stage in the traditional venture sense. It is moving toward early and Series A companies with late-stage-sized strategic ambition.

Chart comparing business model options for AI alignment research labs

This chart, featured in our AI safety market deck, compares the main business model options for AI alignment research labs

Is the AI safety market maturing or still experimental?

The AI safety market is maturing commercially, but it is still experimental structurally. The market is maturing because 2026 through early July produced 24 deals and about $675M of capital, far above the same period in 2025, and because investors are funding operational infrastructure rather than abstract responsible-AI positioning.

The funded products now look like enterprise control infrastructure: evaluation platforms, guardrails, gateways, authorization layers, agent governance, runtime monitoring, identity systems, audit trails, and compliance evidence. That is a much more commercially grounded market than a category defined only by policy, ethics, or model-alignment language.

But the AI safety market is still experimental because most funded companies remain Seed or Series A. In 2026 through early July, 14 of 24 deals were Seed rounds and another 7 were Series A rounds. A mature enterprise software market would usually have a deeper late-stage ladder, more standardized metrics, more repeat category buyers, and more visible consolidation.

The category mix is also still shifting quickly. In 2024, evaluation, risk platforms, monitoring, and guardrails all had visible funding. In 2025, risk platforms and monitoring dominated capital, while standalone evaluation disappeared under the strict taxonomy. In 2026, evaluation returned strongly, while agent governance, identity, authorization, and runtime guardrails became central.

The honest interpretation is that the AI safety market is maturing in buyer urgency but remains experimental in product architecture. Enterprises now appear to have a real budget problem around AI agents and model behavior, but the market has not yet decided whether the winning system of record is evaluation, guardrails, gateways, identity, governance, monitoring, or a full AI control plane.

Are new startups still entering the AI safety market?

Yes, new startups are still entering the AI safety market at a healthy pace. In 2026 through early July, 13 of 24 deals were first financings, representing about 54% of deal count. That is a strong signal that the AI safety market is not only recycling capital into known winners.

The freshest comparison is mixed but positive. Over the comparable period in 2025, first financings represented about 67% of deals and about 61% of capital. In 2026 through early July, first financings represented a lower share of deals and only about 28% of capital. That lower share does not mean new company formation weakened; it means the market expanded and larger follow-on rounds took more of the dollars.

In absolute numbers, new-company formation is much stronger in 2026. The comparable period in 2025 had 4 first financings, while 2026 through early July had 13 first financings. Capital going to first financings also rose in absolute terms, from about $64M to about $190M.

The pattern is clear: new AI safety startups can still get funded, especially around agent security, guardrails, governance, identity, compliance-by-design, and authorization. But the largest checks increasingly go to companies that look like they can become infrastructure platforms rather than narrow point solutions.

For more detail on the new entrants and first-financing mix, see the AI safety market deck.

Are more investors entering the AI safety market?

Yes, more investors appear to be entering the AI safety market in 2026, especially compared with the same period in 2025. The 2026 through early July sample includes 61 unique disclosed investors and 22 unique tier-1 investors, compared with about 38 unique investors and 4 tier-1 investors over the comparable period in 2025.

The full-year comparison is more cautious. Full-year 2024 had 88 unique investors and 41 unique tier-1 investors across 20 deals. Full-year 2025 had 51 unique investors and 8 tier-1 investors across 12 deals. So investor participation narrowed in 2025 after a broader 2024, then expanded again in 2026.

The 2026 investor base already exceeds full-year 2025 on both total unique investors and tier-1 investors, but it has not yet matched full-year 2024 on tier-1 breadth. That means investor entry is clearly recovering, but the market is not necessarily broader than the 2024 peak yet.

The quality of investor participation is strategically important. Andreessen Horowitz, ICONIQ, Lightspeed, GV, Khosla Ventures, Redpoint, Balderton, General Catalyst, Index Ventures, Evolution Equity Partners, Samsung Next, Accenture Ventures, and other major names appear in 2026 rounds. That confirms that AI safety is now attracting mainstream enterprise, cybersecurity, cloud, and AI infrastructure investors.

The better interpretation is that investor entry is increasing again after a 2025 slowdown. The AI safety market is no longer a niche category funded only by AI-safety specialists; it is becoming a mainstream enterprise-infrastructure investment theme.

Chart showing the projected CAGR of the AI safety market

This chart, featured in our AI safety market deck, shows annual funding in AI safety startups

Are top investors getting more or less active in the AI safety market?

Top investors are getting more active in the AI safety market in terms of participation quality, but repeat activity remains shallow. In 2026 through early July, 22 unique tier-1 investors appeared, compared with only 4 over the comparable period in 2025 and 8 across full-year 2025.

That is a meaningful increase in top-tier investor attention. Large 2026 rounds included names such as Andreessen Horowitz, ICONIQ, Lightspeed, GV, Khosla Ventures, Redpoint, Balderton, General Catalyst, Index Ventures, Evolution Equity Partners, Samsung Next, and Accenture Ventures.

But top investors are not yet repeatedly backing many AI safety companies. In 2026 through early July, only a small group appeared more than once: Andreessen Horowitz or a16z, Samsung Next, Kibo Ventures, and Mirae Asset group. In 2025, the repeat-investor list was also thin, led by Insight Partners, Lip-Bu Tan, and strategic angels.

So the right answer depends on what active means. If active means top investors are willing to enter high-conviction AI safety deals, then top investors are clearly more active in 2026. If active means top investors have built repeated, specialized portfolios across the category, then the market still looks early.

The strongest interpretation is that top investors are selectively active, not systematically active. They are showing up in large platform-like financings, especially in evaluation, agent governance, identity, authorization, guardrails, and AI security, but no single top investor has locked up the category.

Which AI safety subcategories are gaining momentum?

The AI safety subcategories gaining momentum are AI Evaluation Tools, AI Risk Platforms, AI Guardrail Platforms, and AI Red Teaming. The strongest 2026 capital momentum belongs to AI Evaluation Tools, which raised about $233M through early July, representing nearly 35% of all capital from only 3 deals.

That evaluation rebound is dramatic because standalone AI Evaluation Tools had no qualifying strict-category deals in 2025. In 2026, LMArena and Braintrust turned evaluation back into a premium infrastructure category, suggesting investors now see continuous evaluation as a system-of-record layer for AI deployment.

AI Risk Platforms continue to gain momentum by deal count and strategic relevance. In 2026 through early July, AI Risk Platforms produced 10 deals and about $260M of capital, making the category the largest by both deals and dollars. The category includes agent governance, AI control planes, compliance-by-design, identity, authorization, and enterprise risk infrastructure.

AI Guardrail Platforms are gaining momentum by formation. Guardrails produced 7 deals in 2026 through early July, compared with 2 deals over the comparable 2025 period and 2 deals across full-year 2025. Capital also rose to about $110M, although the median guardrail round remained around $10M.

AI Red Teaming is smaller but gaining credibility. Red teaming produced 2 deals and $47M in 2026 through early July, compared with 1 small $1.2M deal over the comparable 2025 period. Gray Swan’s $40M Series A is the clearest signal that red teaming can support larger checks when it connects to broader AI security or adversarial evaluation infrastructure.

For the category-by-category funding split, see the deeper analysis of the AI safety market.

Which AI safety subcategories are losing momentum?

The AI safety subcategories losing momentum are Model Robustness Tools and, as a standalone category, AI Safety Monitoring. Model Robustness Tools had no qualifying disclosed pure-play deal in 2024, 2025, or 2026 through early July, which is the clearest negative signal in the category map.

The absence of Model Robustness Tools does not mean robustness is unimportant. It means robustness is not showing up as a standalone venture category under the strict public funding definition. Robustness is being absorbed into evaluation platforms, red-teaming systems, guardrails, model monitoring, and risk platforms.

AI Safety Monitoring is more nuanced. In 2024, AI Safety Monitoring represented about $78M, or 21% of capital, across 3 deals. In 2025, it represented $100M, or nearly 38% of capital, but that was entirely driven by Noma Security’s $100M Series B. In 2026 through early July, AI Safety Monitoring represented only about $25M, or less than 4% of capital, across 2 deals.

That does not mean monitoring is losing relevance. Many 2026 companies mention monitoring as part of a broader product, but fewer companies are primarily categorized as AI Safety Monitoring. Monitoring is being bundled into agent-security platforms, governance layers, guardrails, and control planes.

The better interpretation is that the AI safety market is recombining. Some subcategories are losing momentum as standalone buckets while becoming more important as embedded capabilities inside broader platforms.

Chart showing how HiddenLayer is positioned in the AI safety market

This chart, featured in our AI safety market deck, shows how HiddenLayer is positioned in AI safety

Which regions are gaining momentum in the AI safety market?

North America is gaining the most momentum in the AI safety market by capital, while Europe and Asia-Pacific are gaining momentum by company formation. In 2026 through early July, North America captured about $496M, or 73% of capital, across 12 deals.

North America’s absolute increase is massive. Over the comparable 2025 period, North America had about $105M in AI safety capital. In 2026 through early July, it had almost $496M. Even though North America’s share of global deal count fell, its dollar base expanded sharply.

Europe is gaining momentum in deal count and visibility. Europe had no qualifying deals over the comparable 2025 period and only one qualifying deal across full-year 2025, but it produced 6 deals and about $87M in 2026 through early July. That is a real change, especially across agent governance, guardrails, AI control, and safety monitoring.

Asia-Pacific is gaining formation momentum. Asia-Pacific had no qualifying full-year 2025 deals in the supplied figures, but it produced 4 deals and about $19M in 2026 through early July. The capital base remains small, with an average deal size below $5M, but the number of companies is meaningful.

The Middle East is gaining capital momentum from a small base. It produced 2 deals and $73M in 2026 through early July, mostly driven by NewCore’s $66M Seed. That makes the region important, but the signal is fragile because one deal accounts for nearly all regional capital.

Which regions are losing momentum in the AI safety market?

No region is clearly losing momentum in absolute terms in 2026, but North America is losing relative deal share while still gaining absolute capital. In 2025, North America represented 100% of the strict public AI safety dataset. In 2026 through early July, North America represented 50% of deals and about 73% of capital.

That is not a decline in North American strength. It is a decline in North American exclusivity. The AI safety market is becoming more geographically distributed by company formation, even while capital remains concentrated in North America.

The Middle East is harder to interpret. In 2024, the Middle East had 6 deals and about $86M of capital, representing 30% of deals and 23% of capital. In full-year 2025, the strict dataset classified all qualifying deals as North America. In 2026 through early July, the Middle East reappeared with 2 deals and $73M.

Europe lost momentum in 2025 after having one meaningful 2024 deal, but it regained momentum sharply in 2026. Asia-Pacific was absent in 2024 and 2025 under the strict dataset, then emerged in 2026. Latin America and Africa remain absent across all three periods.

The practical answer is that the region losing relative share is North America, but only because the market is becoming more global by deal count. The regions genuinely missing from momentum are Latin America and Africa, where no qualifying disclosed AI safety equity rounds appear in the supplied evidence.

Is the AI safety market becoming more global or more regionally concentrated?

The AI safety market is becoming more global by deal count, but it remains regionally concentrated by capital. In 2026 through early July, only 50% of deals were in North America, compared with 100% over the comparable period in 2025.

Europe produced 25% of 2026 deals, Asia-Pacific produced nearly 17%, and the Middle East produced about 8%. That is a clear globalization signal. More regions are now producing fundable AI safety companies.

Capital tells a more concentrated story. North America captured about 73% of 2026 through early July capital. Europe captured about 13%, the Middle East about 11%, and Asia-Pacific less than 3%. So the AI safety market is not globally balanced; it is globally distributed in formation but still North American in large-check access.

The full-year history reinforces the point. In 2024, North America had 65% of deals and about 71% of capital, while the Middle East had 30% of deals and about 23% of capital. In 2025, all qualifying disclosed capital was classified as North America. In 2026, geographic diversity returned, but North America still dominated funding.

The AI safety market is therefore globalizing at the edges and concentrating at the top. A company-count view would overstate globalization, while a capital-only view would understate the emergence of non-North American company formation.

For the regional breakdown across North America, Europe, Asia-Pacific, and the Middle East, see the market report covering AI safety geography.

Chart showing how model risk management has driven growth in the AI safety market over time

This chart, featured in our AI safety market deck, shows how model risk management has driven growth in the AI safety market over time

Is AI safety capital moving toward proven winners or new opportunities?

AI safety capital is moving toward both proven winners and new opportunities, but the largest dollars are increasingly favoring perceived platform winners. In 2026 through early July, first financings represented 54% of deals but only 28% of capital.

That means new opportunities are still abundant by count, but follow-on rounds and higher-conviction platform financings capture most of the dollars. Over the comparable 2025 period, first financings represented about 67% of deals and 61% of capital, so the 2026 market is less formation-dominated and more winner-selection-driven.

The full-year history supports the same interpretation. In 2024, first financings were 40% of deals and only 18% of capital. In 2025, first financings rose to 58% of deals and 34% of capital. In 2026 through early July, first financings remained high by count but lost capital share because large follow-on and platform-like rounds became more important.

Large first financings complicate the simple proven-winner versus new-opportunity split. NewCore’s $66M Seed and JetStream Security’s $34M Seed were technically first financings, but they were not small exploratory bets. They looked like preemptive platform bets.

The better interpretation is that AI safety capital is moving toward proven or pre-designated winners. Investors are still funding new companies, but they are reserving the biggest checks for companies that already look like they can own a key layer of the enterprise AI stack.

Is the AI safety market becoming winner-takes-most?

Yes, the AI safety market is becoming more winner-takes-most, but not winner-takes-all. In 2026 through early July, the top 10 deals captured about 84% of all capital, while the bottom half of deals captured only about 12%.

The 2026 concentration is high, but it is less dependent on one company than the comparable 2025 period. Over the comparable period in 2025, the top 3 deals captured about 87% of capital, and the largest deal captured nearly 48%. In 2026 through early July, the top 3 captured about 44%, and the largest deal captured about 22%.

The full-year trend from 2024 to 2025 shows concentration increasing before 2026 broadened the market again. In 2024, the top 3 deals captured about 38% of capital and the largest deal captured about 16%. In 2025, the top 3 captured about 68% and the largest captured about 38%.

The best interpretation is that the AI safety market is becoming winner-takes-most at the platform layer while still allowing many new point-solution entrants. Investors are funding many companies, but the majority of capital is flowing to companies that look like category infrastructure.

This is not winner-takes-all because no single company controls the funding landscape. Evaluation, risk platforms, guardrails, red teaming, identity, authorization, and monitoring are all still active. But the market is clearly not evenly distributed.

Is the next wave of AI safety winners becoming visible?

Yes, the next wave of AI safety winners is becoming visible, but the winners are visible by product-layer importance rather than by final market share. The strongest candidates are companies positioned around AI evaluation infrastructure, agent governance, AI control planes, identity, authorization, runtime guardrails, red teaming, and monitoring.

The 2026 financing pattern makes the next wave clearer. LMArena raised $150M in AI evaluation. Braintrust raised $80M in evaluation and observability. WitnessAI raised $58M in guardrails and enterprise AI security. NewCore raised $66M in agentic identity. Arcade raised $60M in agent authorization and governance. Gray Swan raised $40M in red teaming and AI security.

These rounds point to a clear market thesis: the next winners will own control points in the AI-agent enterprise stack. The market is rewarding companies that help enterprises decide which AI systems can act, what those systems can access, how their outputs are evaluated, and which actions are logged or blocked.

The next wave is less likely to be defined by generic responsible-AI branding. Companies that raised meaningful capital usually had a concrete operational pain: model evaluation, prompt injection, jailbreaks, hallucinations, data leakage, oversharing, agent access, audit trails, identity, authorization, compliance evidence, or runtime enforcement.

Visibility is not the same as proof. The AI safety market still has many early-stage companies, and large Seed and Series A rounds do not yet prove customer retention, pricing power, or category dominance. But the winning product surfaces are now much clearer.

For more context on the emerging company cohort, see the full market view on AI safety winners.

Google Trends chart showing rising interest in AI safety

As this chart shows, and as featured in our AI safety market deck, search interest in AI safety has been growing steadily

Is the AI safety funding landscape fragmenting or consolidating?

The AI safety funding landscape is doing both: fragmenting by company formation and consolidating by capital allocation. The fragmentation signal is obvious in 2026 through early July, with 24 companies raising across AI Evaluation Tools, AI Red Teaming, AI Guardrail Platforms, AI Safety Monitoring, and AI Risk Platforms.

Seed rounds represented 58% of 2026 deal count, which confirms that many new companies are still entering. The category map is also fragmented because AI Risk Platforms, Guardrail Platforms, Evaluation Tools, Red Teaming, and Safety Monitoring increasingly overlap in product claims and buyer workflows.

The consolidation signal is equally strong. The top 10 deals captured about 84% of capital in 2026 through early July, while the bottom half captured only about 12%. The average round was about $28M, but the median was only $12M, which means a small number of large rounds dominate the capital story.

Category boundaries are blurring rather than hardening. AI Risk Platforms include governance, identity, authorization, compliance, control planes, and agent oversight. Guardrail Platforms include prompt-injection defense, runtime controls, output filtering, and agent guardrails. Evaluation Tools overlap with observability, monitoring, and model quality.

The right interpretation is that the AI safety market is fragmented at the product-label level and consolidating at the workflow level. Many startups describe themselves differently, but the money is converging around a smaller set of enterprise control points.

Where is investor attention shifting in the AI safety market?

Investor attention in the AI safety market is shifting toward agentic AI control infrastructure. The most important 2026 themes are AI-agent governance, runtime guardrails, identity, authorization, evaluation, red teaming, audit trails, compliance evidence, and enterprise control planes.

The company mix makes the shift obvious. Guild.ai, Portkey, JetStream, OpenBox AI, Trent AI, Tynapse, Aigentsphere, Geordie, Archestra.AI, Willow, NewCore, Arcade, and NeuralTrust all connect directly to agent governance, AI gateways, agent access, runtime security, auditability, or control-plane infrastructure.

This is not a coincidence. The AI safety market is increasingly organized around the risks created when AI systems stop being passive chat interfaces and start acting inside enterprise workflows. Investors are asking whether enterprises can control what agents see, do, say, access, and execute.

Investor attention is also shifting back toward evaluation, but in a more infrastructure-like form. LMArena and Braintrust together accounted for $230M of follow-on evaluation capital in 2026 through early July. That suggests evaluation is no longer just pre-launch testing; it is becoming part of continuous development, deployment, observability, and model-routing workflows.

The strongest reading is that investor attention is shifting from “is the model safe?” to “can the enterprise control AI behavior in production?” That shift explains why agent security, access control, authorization, audit trails, runtime monitoring, and evaluation infrastructure are attracting capital.

For ongoing tracking of where investor attention is moving, see the AI safety market report.

INSIGHTS

The insights below come from reviewing publicly disclosed equity rounds raised by pure-play AI safety companies between January 2024 and July 2026, with attention to deal count, capital concentration, stage mix, category rotation, geography, and investor participation.

  • The AI safety market has moved from a “why does this matter?” market to a “where does this sit in the enterprise stack?” market. The rise of evaluation, agent governance, identity, authorization, and runtime guardrails shows that investors now care less about safety philosophy and more about infrastructure placement.
  • The 2026 acceleration is too large to dismiss as a few noisy deals. Even excluding rounds above $50M, AI safety companies raised about $261M through early July 2026, nearly equal to full-year 2025’s $265M.
  • The market cooled in 2025 before accelerating in 2026, which means the current boom should be read as a repricing of the category rather than a smooth continuation of 2024 momentum. The trigger appears to be agentic AI risk, not generic responsible-AI enthusiasm.
  • The AI safety market is still early by stage count but increasingly mature by check size. Seed rounds were 58% of 2026 through early July deal count, yet the same period included 5 rounds of $50M or more.
  • Series A is functioning like a pseudo-growth stage in the AI safety market. Series A rounds captured about 49% of 2026 through early July capital, which suggests investors are writing large checks before the market has a normal late-stage proof ladder.
  • The most important dividing line is not safety versus security; it is whether the product controls AI-specific behavior. Companies that secure AI agents, LLM traffic, model outputs, prompts, data access, or audit trails qualify as AI safety infrastructure even when they use cybersecurity language.
  • Standalone model robustness is conspicuously absent as a funded pure-play category. Robustness appears commercially valuable when packaged inside evaluation, guardrail, monitoring, or governance workflows, not as a standalone venture category.
  • Evaluation has become a premium category again in 2026 after disappearing from the strict 2025 category split. The market seems to have revalued evaluation because agents and model proliferation make continuous measurement more important than one-time testing.
  • Guardrails are gaining breadth but not yet commanding premium capital concentration. The category produced 7 deals in 2026 through early July, but its capital-share-to-deal-share ratio was only 0.56.
  • AI Risk Platforms are the broadest and most crowded category, which is both a strength and a risk. The category captures many enterprise-control problems, but its breadth makes it harder to know which companies are true platforms versus repackaged governance tools.
  • The market’s center of gravity is shifting from governance documents to operational enforcement. The strongest funding narratives involve blocking, routing, authorizing, monitoring, evaluating, logging, or proving AI behavior.
  • First financings remain common, but first financings no longer dominate capital. In 2026 through early July, first financings were 54% of deals but only 28% of capital, which means the market is open to new entrants while still concentrating dollars around perceived leaders.
  • The AI safety market is becoming winner-takes-most at the funding layer before it becomes winner-takes-most at the revenue layer. Capital concentration is already visible, but final customer winners are not yet proven.
  • Average round size is a misleading indicator for the AI safety market. In 2026 through early July, the average round was about $28M while the median was only $12M, so the average overstates normal financing conditions.
  • The market is globalizing by company formation but not by capital depth. North America had only half of 2026 through early July deals but captured nearly three-quarters of capital.
  • Europe’s 2026 rebound is credible because it spans multiple companies and product surfaces, not a single outlier. Europe produced deals in guardrails, agent governance, monitoring, and AI control infrastructure.
  • Asia-Pacific’s 2026 presence looks like early technical formation rather than capital leadership. Four APAC deals appeared, but they collectively represented less than 3% of capital.
  • The repeated-investor base is still thin, which shows that the AI safety market has not yet developed a stable specialist financing ecosystem. Many elite investors are entering selectively, but few are repeatedly backing multiple companies.
  • The strongest 2026 companies generally sell to operational risk owners, not abstract ethics teams. Security, IT, compliance, engineering, data, and platform teams are the likely budget holders behind the funding surge.
  • The AI safety market is moving from model-centric safety toward system-centric safety. Investors are funding the surrounding control layers that govern how models and agents interact with tools, data, users, permissions, and workflows.
  • Monitoring is becoming embedded rather than standalone. The decline in standalone AI Safety Monitoring share in 2026 does not mean monitoring is weakening; it means monitoring is being absorbed into control planes, guardrails, and agent-security platforms.
  • The clearest future diligence rule is to ask whether an AI safety company owns a repeated enterprise workflow. Evaluation loops, gateways, identity, authorization, audit trails, runtime controls, and monitoring systems are more defensible than one-off assessments or narrow policy features.
Sources used for this page: Every deal was verified against a public source that directly reported the financing or gave enough detail to confirm the round. The source base includes direct company announcements, press releases, investor announcements, PR Newswire and Business Wire releases, tier-1 tech and business outlets such as TechCrunch and Axios, cybersecurity and startup trade media such as SecurityWeek and GeekWire, and regional publications used for smaller non-US rounds. Representative source examples include company announcements from Braintrust, Lakera, Geordie, Gray Swan, NewCore, and Fiddler AI; press-wire announcements from Business Wire and PR Newswire; and specialist or regional coverage from Tech.eu, Calcalist, Entrackr, VentureBeat, and SecurityWeek. The full deal tracker preserves the explicit URL for every included round.
Chart showing how prompt injection defense platform technology has evolved over time

This chart, featured in our AI safety market deck, shows how prompt injection defense platform technology has evolved over time

OUR METHODOLOGY TO BUILD THIS TRACKER

We built this AI safety funding tracker by reviewing publicly disclosed equity rounds raised by pure-play AI safety companies between January 2024 and July 2026. A company counts as pure-play when more than 80% of its activity is dedicated to reducing harms and failure modes from AI systems by measuring, mitigating, governing, securing, evaluating, monitoring, or controlling AI-model behavior and AI-specific risk.

We applied four filters to build the tracker. First, we only included equity rounds, so grants, debt, structured financings, token sales, acquisitions, and business-combination transactions are excluded. Second, we only counted rounds of $300K or more. Third, we only kept pure-play AI safety companies, which means we excluded generic MLOps, generic cybersecurity, general compliance, generic content moderation, and frontier model labs unless the funded product was specifically designed for AI-model behavior safety or AI-specific threat reduction. Fourth, every entry had to be confirmed by a direct company announcement, a press release, a tier-1 media report, a specialized industry source, or a relevant regional publication.

We also excluded undisclosed-amount rounds because including them would distort dollar-based metrics such as total capital, average round size, median round size, category share, geography share, and concentration ratios. The resulting tracker is a public-disclosure view of the AI safety market, not a paid private-market database. Stealth rounds, unannounced financings, undisclosed extensions, and database-only rounds may therefore be missing, but every included deal has a disclosed amount and a source-backed financing event.

Who is the author of this content?

NEW MARKET PITCH TEAM

We track new markets so founders and investors can move faster

We build living “market pitch” documents for emerging markets: from AI to synthetic biology and new proteins. Instead of digging through outdated PDFs, random blog posts, and hallucinated LLM answers, our clients get a clean, visual, always-updated view of what’s really happening. We map the key players, deals, regulations, metrics and signals that matter so you can decide faster whether a market is worth your time. Want to know more? Check out our about page.

How we created this content 🔎📝

At New Market Pitch, we kept seeing the same problem: when you look at a new market, the data is either missing, paywalled, or buried in 300-page reports that feel like they were written in the 80s. On the other side, LLMs and random blog posts give you confident answers with no sources, and sometimes they just make things up. That’s not good enough when you’re about to invest real money or launch a company.

So we decided to fix the experience. For each market we cover, we build a structured database and update it on a regular basis. We track funding rounds, fund memos, M&A moves, partnerships, new products, policy changes, and the real activity of startups and incumbents. Then we turn all of that into a clear “market pitch” that shows where the opportunities are and how people actually win in that space.

Every key data point is checked, sourced, and put back into context by our team. That’s how we can give you both speed and reliability: fast coverage of new markets, without the usual guesswork.

Back to blog