Alice Raises $140 Million As AI Security Business Approaches $100 Million ARR And Grows 500%+

Alice (formerly known as ActiveFence) has raised $140 million in a funding round led by Apax Digital as the AI trust, safety and security company approaches $100 million in annual recurring revenue and expands its work with major frontier model developers. Samsung, SentinelOne, Maj Invest, MoreTech and Phoenix Insurance participated in the round alongside existing investors Resolute Ventures, Grove Ventures, CRV, Highland Europe, Vintage Investments, Norwest, NFX and Claltech. The financing brings Alice’s total funding to $280 million. Apax Digital will also join Alice’s board.

Alice focuses on identifying and preventing adversarial behavior across AI systems. And the company has spent nearly a decade studying how malicious actors exploit major digital platforms and has built a proprietary dataset of real-world attacks that it now applies to AI security.

Demand has accelerated as AI security becomes a larger requirement for model developers and enterprises.

Alice is approaching $100 million in ARR, while its AI business has grown more than 500% over the past two years.

The company operates one of the world’s largest AI security research labs, with more than 150 researchers focused on understanding how AI systems can be manipulated, misbehave or fail.

Alice currently works with eight of the 10 leading AI model labs and protects more than 3 billion people online.

Its work spans the lifecycle of an AI system.

Before models are released, Alice works with frontier labs including Anthropic, Google, and Cohere to simulate malicious prompts and agentic tasks.

Those tests identify unpredictable model behavior and strengthen systems against risks including jailbreaks and prompt injection.

Once models enter production, Alice helps enterprises add organization-specific protections on top of the safeguards already built into the underlying model.

Customers can define their own policies, simulate attacks to uncover compliance issues, data leakage, and unintended behavior, and monitor model inputs and outputs in real time.

A major component of Alice’s technology is Rabbit Hole, which the company describes as the world’s largest dataset of real-world adversarial and harmful content.

The dataset was developed from years of tracking fraud, extremism, coordinated manipulation, and other malicious behavior across the open web.

Alice uses those patterns to identify attacks against AI systems that resemble techniques already observed elsewhere online.

The company’s broader technology is also used across platforms including Google, Meta, TikTok and Amazon.

Alice sees an increasingly large opportunity as enterprises give AI agents access to more internal data, software tools, and the ability to take autonomous actions.

That shift can increase the consequences when an AI system behaves outside its intended scope.

The company argues that defenses need to evolve continuously because attack techniques are changing faster than static safeguards can address them.

Apax Digital sees the emergence of AI agents as creating a new security category similar to the expansion of cybersecurity that accompanied the transition to cloud computing.

Alice’s approach is designed around a feedback loop in which attacks observed in real-world environments inform new model tests; those tests improve guardrails, and production model behavior feeds back into both systems.

The company believes the effectiveness of that system increases as Alice observes more attacks and adds more customers.

Alice plans to use the financing to advance its AI platform across model testing, defense and monitoring.

The company will also expand the team supporting Rabbit Hole so the dataset can continue incorporating newly emerging attack techniques.

Additional capital will support expansion of Alice’s go-to-market organization serving foundation model developers and enterprises deploying AI.

Alice was founded in 2018 and is headquartered in New York and Tel Aviv.

Its positioning reflects a growing concern across the AI industry that more capable and autonomous systems will create a larger attack surface requiring specialized testing, monitoring and security infrastructure.

KEY QUOTES:

“There are infinite ways to break an AI, and you can’t defend against something you’ve never seen. We spent nearly a decade learning exactly how people abuse technology at the scale of billions, first on the world’s largest platforms and now on the models those same people are probing. We are very quickly democratizing capabilities before we’ve democratized the defenses. This round is about closing that gap.”

Noam Schwartz, CEO And Co-Founder Of Alice

“Just as the cloud platform shift created a new category of security, the AI platform shift is opening a rapidly growing attack surface that will only widen as enterprises roll out agents. As adversaries increasingly use AI, defenders can turn to Alice for model testing and guardrails built on the largest proprietary data asset of adversarial techniques.”

Patrick Kane, Partner At Apax Digital

“The world’s most sophisticated technology companies choose Alice because its defenses learn: attacks observed in the wild seed the tests, the tests tune the guardrails, and model behavior in production feeds back into both. The loop gets stronger with every observed attack and every new customer.”

Eric Levine, Vice President At Apax Digital