Business

Who funds this and at what price

Maps every confirmed AI-security funding round and acquisition since 2024, who's writing the checks, and what 2026 investors actually reward.

evidence: medium15 minupd 2026-08-29fundingventure-capitalm-and-aeconomicsmarket-map

Offensive security has out-raised defensive-code security in this cycle, the exit path is exclusively strategic acquisition with zero IPOs, and investors are pricing founder pedigree and named enterprise logos well above product maturity or revenue scale. No European fund has yet led a dedicated AI-security round at the size US specialists are writing. That's the whole picture in one paragraph — the rest of this page is the evidence.

#The master funding table, 2024–2026

Figures are headline round amounts; "undisclosed" means the round happened but the amount was never published. Every M&A dollar figure on this page is press-reported and not independently confirmed at the primary-source level — see the note under the M&A table.

#Offensive / autonomous pentesting — see Offensive AI security companies for product detail on each

Company Date Stage Amount Valuation Lead(s)
XBOW Jun 2025 Series B $75M undisclosed Altimeter Capital
XBOW Mar 18, 2026 Series C $120M (confirmed) $1B+ (confirmed) DFJ Growth, Northzone
XBOW May 6, 2026 Strategic $35M (confirmed) Accenture, DNX, Liberty Global, NVentures, Samsung, SentinelOne
Horizon3.ai Series D ~$650M
Horizon3.ai Aug 3, 2026 Series E $250M (confirmed) $2B+ (confirmed) NightDragon, NEA
RunSybil Mar 18, 2026 Series A $40M (confirmed) undisclosed Khosla Ventures
Terra Security Sep 2025 [date not independently reconfirmed] Series A $30M undisclosed Felicis
Dreadnode Feb 25, 2025 Series A $14M undisclosed Decibel, incl. In-Q-Tel

The confirmed 2026 rounds alone ($120M + $35M) sum to $155M; a widely repeated "$237–255M total" figure could not be independently verified and should not be repeated without a source.

#Defensive code / AppSec — see AI code security companies

Company Date Stage Amount Lead(s)
Endor Labs 2023 Series A $70M DFJ Growth / Lightspeed
Endor Labs 2025 Series B $93M same, repeat backers
Socket May 2026 Series C $60M (total $124.6M across 7 rounds) Thrive Capital
Semgrep 2025 Series D $100M Menlo Ventures
Aikido Security (Belgium) cumulative $85M total, confirmed unicorn status DST Global

Aikido's unicorn status is confirmed on its own site: "the fastest European cybersecurity company to reach unicorn status" (aikido.dev) — proof European founders can raise growth-stage money, just not yet from a European-led round at that size.

#SOC agents / agentic security operations — the most crowded sub-category; see AI SOC and detection companies

Company Amount Lead(s)
Exaforce Series B, $125M undisclosed
Dropzone AI undisclosed Leidos Holdings (corporate)
Prophet Security undisclosed Amex Ventures, Citi Ventures
Andesite undisclosed General Catalyst, In-Q-Tel, Red Cell Partners

At least nine well-funded SOC-agent entrants (Dropzone, Prophet, Radiant, Exaforce, Twine, Culminate, Conifers.ai, Andesite, Simbian) compete for the same tier-1-triage-replacement thesis — the single most crowded corner of the whole map.

#AI-security platforms (agent governance / model security)

Company Date Amount Lead(s)
Zenity Aug 3, 2026 $125M Series C (total $180M) Norwest Venture Partners
Noma Security Jul 31, 2025 $100M Series B Evolution Equity Partners
WitnessAI Jan 13, 2026 $58M (total $85M+) Sound Ventures
HiddenLayer Sep 2023 $50M Series A M12, Moore Strategic Ventures
Gray Swan AI May 28, 2026 $40M Series A (confirmed) Wing VC, Madrona
Irregular Sep 17, 2025 $80M (reported), $450M valuation (reported) — [unverified], see The AI cyber lab category Sequoia, Redpoint (reported)
Unverified

Irregular's round is repeated across trade press with a real URL but does not appear on Irregular's own newsroom — a direct check found no funding announcement, dollar figure, or investor name on the company's site. Cite it as press-reported, not company-confirmed.

Key numbers

HiddenLayer, one of the earliest "AI/ML security" platforms (2022 seed), has raised no confirmed round above its $50M 2023 Series A — total disclosed funding sits near $56M, small next to Noma ($100M B), Zenity ($180M total), and Irregular's reported $450M valuation. Being first does not mean staying best-funded.

#The pattern: offensive out-raised defensive, and what investors are actually buying

Offensive/autonomous-pentesting companies (XBOW, Horizon3.ai, RunSybil) collectively raised more in confirmed headline rounds than defensive-code companies this window — Horizon3's single $250M Series E alone exceeds the entire defensive-code table combined. The reason isn't subtle: offensive tools produce a legible, demoable output (a found vulnerability) that investors and buyers evaluate quickly, while defensive-code tools have to prove a negative over a much longer sales cycle. Horizon3's own Series E framing — explicitly "AI vs. AI" — is the clearest articulation of the thesis investors are pricing: both attackers and defenders will run autonomous agents, and the winners will be platforms built agent-native from day one.

The gap between the segment's fundraising and its revenue is real and mostly undisclosed. Confirmed absolute revenue figures are rare: Horizon3.ai discloses "120% YoY ARR growth" but no absolute ARR number; Pentera's often-cited "~$100M ARR" does not appear anywhere on its own site, which states only "the trust of over 1,000 CISOs globally" — a materially different, unconfirmed claim. TrendAI's $1B+ cumulative AWS Marketplace figure is one of the only hard, primary-sourced revenue numbers in the category. The rest is priced almost entirely on round size, valuation, and founder pedigree.

So what

No AI-security-native company has IPO'd in this window; every confirmed exit is a strategic acquisition. Growth-stage private valuations (XBOW $1B+, Irregular reportedly $450M, Horizon3 $2B+) sit well above what strategics have actually paid for comparable-stage companies — either investors expect materially larger future exits than the 2024–2025 acquisition cohort achieved, or a valuation bubble is building between what VCs will pay and what buyers historically have. Model both scenarios, not just the optimistic one.

#Active investors

US cyber specialists:

  • Ten Eleven Ventures — cyber-only mandate, appears disproportionately often relative to fund size (HiddenLayer's 2023 Series A).
  • Evolution Equity Partners — led Noma Security's $100M Series B, one of the most consistently active dedicated-cyber funds this window.
  • Ballistic Ventures — 2022-vintage, built explicitly around "AI-native security" as a core thesis; participated in Noma's Series B.
  • Glilot Capital Partners — Israeli early-stage cyber specialist; Noma's team, like Terra's and Zenity's, is Israeli.
  • Forgepoint Capital — long-standing cyber fund broadening into AI-security; participated in WitnessAI's round.
  • NightDragon — Dave DeWalt's operator-VC, co-lead on Horizon3's $250M Series E, increasingly the highest-profile lead on the largest late-stage rounds, with DeWalt personally taking board seats.
  • YL Ventures, Team8, Cyberstarts, SYN Ventures — general market presence; not independently confirmed as leads on a 2024–2026 round in this pass.

Generalists writing security-specific checks:

  • Khosla Ventures — led RunSybil's $40M round on a founder bet (Ari Herbert-Voss, OpenAI's first security hire), not a category thesis.
  • DFJ Growth — co-led XBOW's $120M Series C and both Endor Labs rounds; a dependable late-stage AI-security lead.
  • Menlo Ventures — led Semgrep's $100M Series D, participated in RunSybil's round; one of few funds on both the offensive and defensive sides.
  • Felicis Ventures — led Terra Security's $30M Series A; an early believer in agentic pentesting specifically.
  • Norwest Venture Partners — led Zenity's $125M Series C.
  • Sequoia Capital, Redpoint Ventures — reported co-leads on Irregular's round; Sequoia also repeats in XBOW's and Semgrep's syndicates. Visible pattern: late-seed-to-growth checks into companies whose customers are model labs themselves.

Corporate and strategic:

  • Anthropic's Anthology Fund — a confirmed participant in RunSybil's round, the clearest example here of a frontier lab funding third-party AI-security tooling rather than only competing with it. See What the frontier labs do themselves.
  • Qualcomm Ventures — in both Horizon3's Series E and WitnessAI's strategic round, suggesting an on-device AI-security bet.
  • In-Q-Tel (IQT) — named investor in Dreadnode and Andesite, its standard role funding dual-use security tooling for the US intelligence community.
  • SoftBank Vision Fund 2, Hitachi Ventures, LG Technology Ventures, Intel Capital — new or returning investors in Zenity's Series C, a notably internationalized syndicate.
  • CrowdStrike Falcon Fund, Cisco Investments — no confirmed AI-security-specific minority check from either; notable given how active both are as acquirers instead (see the M&A table). Strategics increasingly prefer to buy outright once a category leader emerges rather than take an early board seat.

#European and German capital

The live-verified picture is thinner than the US side, and it matters for what it doesn't show.

  • Northzone co-led XBOW's $120M Series C (March 2026) — a European fund co-leading a US-based round, not backing a European startup directly. The clearest European-VC data point here, and it cuts against the founder: European capital is already flowing toward US category leaders.
  • Aikido Security (Ghent) reached unicorn status on $85M from DST Global, PSG, Singular Ventures, Connect Ventures, and Notion Capital — proof European AI-security founders can reach growth-stage valuations, though Aikido is defensive-code AppSec, not frontier-cyber-eval, and its lead (DST Global) isn't a European specialist.
  • Earlybird, Cherry Ventures, HV Capital, Point Nine, Speedinvest, Lakestar, Project A, Atlantic Labs, Balderton Capital — generalist European early-stage funds, none confirmed as a dated 2024–2026 AI-security-specific lead in this research. [unverified in this niche]
  • La Famiglia merged into General Catalyst in 2023; General Catalyst appears as an investor logo on Andesite's site — the clearest indirect European-lineage-fund-into-AI-security data point found.

Non-dilutive and public money:

  • Cyberagentur — confirmed €109 million 2026 research budget across four programme areas incl. AI/ML "Key Technologies." Funds 10–15-year-horizon defense-relevant research, closer to DARPA than a startup accelerator (cyberagentur.de).
  • SPRIND — runs open "challenges" with public deadlines; no dedicated cybersecurity/AI-security track was visible at research time, though "Next Frontier AI" funds European AI teams more broadly. Check sizes undisclosed. [unverified]
  • EIC Accelerator — typically €0.5–2.5M grant plus up to €15M equity via the EIC Fund. [not re-verified live]
  • High-Tech Gründerfonds (HTGF) — typical first check €0.6–3M. [not re-verified live]
  • Deep Tech & Climate Fonds (DTCF) — targets first checks roughly €0.5–5M. [not re-verified live]
  • NATO Innovation Fund — reported as a roughly €1B multi-sovereign fund, typically seed–Series A, €1–15M checks, into dual-use deep-tech. [unverified — recommend a direct fetch before citing in a deck]
So what

Money flows into European AI-security founders from the same global generalist and growth funds active in the US (Sequoia, Northzone, Sofina, Alkeon) once the company already has US enterprise traction — not from a European-led seed or Series A. European public instruments (Cyberagentur, SPRIND, EIC, HTGF, DTCF, NATO IF) function as pre-seed derisking capital and government-relevant validation, not as the growth-stage check itself. A Berlin founder should plan the growth round as a US-syndicate event from the start.

#The M&A table and what it says about exit paths

Every dollar figure below is press-reported. None was independently confirmed against a primary-source disclosure (an acquirer's own press release rarely states the price) — mark all of them [unverified] in any external material; see Verification ledger for the full correction methodology.

Acquirer Target Announced Price (press-reported) Notes
Check Point Lakera Sep 2025 ~$300M [unverified] Became Check Point's Global Center of Excellence for AI Security
Cisco Robust Intelligence ~late 2024/early 2025 ~$400M [unverified] Became the operational core of Cisco Foundation AI
Palo Alto Networks Protect AI completed Jul 2025 ~$500M [unverified] AI/ML model-scanning platform
Palo Alto Networks CyberArk Jul 2025, completed Feb 2026 ~$25B [unverified] Identity security; by far the largest deal in the space
Palo Alto Networks Chronosphere Nov 2025, completed Jan 2026 ~$3.35B [unverified] Observability platform
CrowdStrike Flow Security Nov 2024 ~$200M [unverified] Israeli cloud data security
CrowdStrike Adaptive Shield Nov 2024 ~$300M [unverified] Israeli SaaS security posture management
CrowdStrike SGNL Jan 2026 ~$750M [unverified] Identity security
CrowdStrike Seraphic Security Jan 2026 ~$420M [unverified] Israeli browser-runtime security
F5 CalypsoAI closed Sep 29, 2025 ~$180M [unverified] Became "F5 AI Guardrails" / "F5 AI Red Team"
SentinelOne Prompt Security Aug 5, 2025 ~$250M [unverified] Israeli gen-AI security (acquisition confirmed via SentinelOne's own press archive)
Tenable Vulcan Cyber Jan 2025 ~$150M [unverified] Exposure/vulnerability management
Tenable Apex May 2025 ~$105M+ [unverified] AI security, Sam Altman-backed pre-acquisition
Snyk Invariant Labs Jun 2025 undisclosed AI-agent security research; confirmed via Invariant's own site

What this says about exit paths:

  1. Strategic acquisition, not IPO, is the only exit path so far. Every confirmed exit is an acquisition by an already-public platform vendor.
  2. The buyer set is narrow and repeats. Palo Alto, CrowdStrike, and SentinelOne account for most of the deal count and value, each running a "buy the point solution, fold into the platform" playbook — Palo Alto ran Protect AI → CyberArk → Chronosphere within six months; CrowdStrike ran five deals across 2024–2026; SentinelOne ran two AI-specific deals six weeks apart.
  3. The biggest dollar outcomes went to already-scaled adjacent categories, not born-AI-native startups. CyberArk (identity) and Chronosphere (observability) were already large before AI became their marketing frame; born-AI-native deals (Lakera, Protect AI, Prompt Security, CalypsoAI) cluster in the $100–500M range by press reports — evidence for adjacency-plus-AI-framing, not pure-play AI-native positioning.
  4. Israeli startups are disproportionately represented among the acquired — Flow Security, Adaptive Shield, Prompt Security, Seraphic Security, plus still-private Israeli companies raising large rounds (Terra, Noma, Zenity) — consistent with Israel's cyber-founder density and investors (Glilot, YL Ventures, Team8, Cyberstarts) building for a fast US strategic exit.

#What actually raises in 2026

Two data points from live 2026 reporting describe the dominant narrative: seed rounds are "reaching sizes that priced Series B a couple of years ago," and "logo quality dominates ARR magnitude at this stage" — a startup with modest revenue backed by two Fortune 500 CISOs raises faster than one with higher revenue from mid-market customers. A paid CISO design-partner pilot with a signed ROI memo is the defining 2026 seed artifact, not a product demo.

What investors want: AI-on-AI conflict framed as structural, not cyclical, is the dominant thesis (Horizon3's own Series E pitch is explicitly this). Frontier-lab-adjacent founders and frontier-lab customers act as signal — RunSybil (founded by OpenAI's first security hire), Irregular (customers include the labs themselves), and XBOW (founder built GitHub Copilot) are all funded largely on pedigree. A real incident converting board-level anxiety into budget matters most: the OpenAI/Hugging Face breach is repeatedly cited in 2026 trade press as the trigger that moved "rogue AI agents causing mayhem" from a research-paper topic onto board agendas.

What investors are tired of (synthesized from the funding-table pattern itself, since a dedicated sourced quote could not be located for every point — flagged accordingly): "thin wrapper" risk — a company whose entire moat is a prompt template over a frontier-lab API with no proprietary data, model, or distribution advantage, a widely discussed 2025–2026 concern across AI broadly. Frontier labs eating the category from above — Gray Swan's own homepage lists Google DeepMind, OpenAI, and Anthropic as customers while all three build internal red-teaming capability; the open question is whether a vendor like Irregular stays durably independent or gets internalized once proven valuable (see What the frontier labs do themselves). Distribution, not detection, as the real bottleneck — the insistence on named CISO pilots over technical depth is evidence investors price almost entirely on go-to-market proof (see Go to market). Round-inflation, with "seed" becoming a misnomer — trade press covering the 2026 seed surge flags uncertainty about how many reported "seed" rounds are genuine first-money seeds versus repackaged larger rounds. And HiddenLayer as the standing cautionary data point — see the number callout above.

What seed traction looks like: security company vs. AI company.

Baseline security seed AI-security premium seed, 2026
Round size / valuation $3–5M at $15–25M post $6–10M at $30–50M post (mega-seed outliers $34–60M)
Customers expected 2–4 named, logo-quality design partners Same, but frontier-lab or Fortune 500 logos specifically weighted higher
Revenue Pilot-stage, $15–40k pilots; conversion rate matters more than ARR magnitude Same bar, but founder pedigree (ex-frontier-lab) substitutes heavily for traction
Team Security-research credentials sufficient Frontier-lab alumni status is itself treated as a fundable signal

A generic AI product can often raise on a strong demo and a compelling narrative. A security product — AI or not — needs a named buyer who tested it against a real, credible adversary; the "signed ROI memo" bar is specific to security's slower, higher-trust sales cycle described in Who buys, and what they pay, and doesn't relax because the product is AI-native. See Unit economics and the compute bill and The first 90 days.

#What this means for us

  • The frontier-lab-eval-vendor path (Irregular's route) requires capital most European founders cannot access at seed — Sequoia/Redpoint-scale checks aren't showing up in Berlin yet. Plan the seed round as a security-specific European or transatlantic syndicate, not a copy of the US cap table.
  • Don't lead with technical depth alone — 2026 investors are explicitly pricing named enterprise or institutional logos above product maturity. The first paid design partner matters more than the next feature.
  • Non-dilutive German/EU capital (Cyberagentur's €109M budget, EIC Accelerator, HTGF, DTCF) is real and underused as pre-seed derisking — pursue it in parallel with, not instead of, venture conversations. See Germany: §202c and the Berlin question and EU regulation as a demand engine for the institutional context these instruments sit inside.
  • Model the exit as a strategic acquisition by Cisco, Palo Alto, Check Point, CrowdStrike, or SentinelOne, not an IPO — the only exit path this category has produced so far, with zero exceptions.
  • Watch the valuation gap: growth-stage private valuations here (Irregular reportedly $450M, XBOW $1B+) sit well above what strategics have actually paid for comparable-stage companies. Don't assume current private markups translate into an equivalent acquisition price.
  • Talent and funding constraints compound: see Talent: the actual constraint for why the hybrid security-plus-post-training hire is the harder bottleneck than capital itself.