Key Takeaways

  • Apax Digital led the round, which values Alice at between $700 million and $800 million.
  • Alice is approaching $100 million in annual recurring revenue and has raised a total of $280 million since its founding.
  • The funding will support the company's AI security platform, Rabbit Hole dataset, research team, and commercial expansion.

Alice has raised $140 million as demand accelerates for technology that tests and protects AI models, applications, and increasingly autonomous agents. Apax Digital led the funding round, joined by Samsung, SentinelOne, Maj Invest, MoreTech, Phoenix Insurance, Norwest, CRV, Vintage, Grove and Highland Europe.

The investment brings total funding since founding to $280 million and establishes a valuation between $700 million and $800 million. The company is also approaching $100 million in annual recurring revenue, an important commercial marker in a market where many AI security products remain closer to experimentation than large-scale deployment.

Securing an AI agent requires different strategies than protecting conventional software. Traditional security focuses heavily on vulnerabilities, unauthorized access, malicious code, and compromised credentials. An agent may introduce another problem by operating with legitimate access to data and tools, yet still misunderstanding instructions, disclosing sensitive information, or taking actions beyond its assigned role.

Alice addresses this gap by utilizing its extensive background in threat detection. Formerly known as ActiveFence, the organization spent years identifying fraud, extremism, coordinated manipulation, cyberattacks, and other harmful behavior across online platforms. The company began working with AI labs including Cohere in 2022, before ChatGPT pushed generative AI into mainstream business use.

That history now feeds Rabbit Hole, a dataset of real-world adversarial and harmful content. The platform uses those attack patterns to test how models respond to malicious prompts, jailbreak attempts, prompt injection, manipulation, and agentic tasks designed to trigger dangerous or unpredictable behavior. Rather than relying solely on synthetic test cases, the system draws from techniques already used by fraudsters and other malicious actors.

The approach fits a broader shift in AI risk management. The NIST AI Risk Management Framework encourages organizations to map, measure, and manage AI risks across the technology lifecycle. The OWASP GenAI Security Project has similarly highlighted application-layer threats such as prompt injection and sensitive information disclosure. Meanwhile, MITRE ATLAS provides a knowledge base for understanding adversarial tactics and techniques affecting AI systems.

The technology functions at both the model-development and deployment stages. During development, more than 150 researchers test systems for unsafe behavior in collaboration with AI labs including Anthropic, Google and Nvidia. Once a model enters production, customers can define safety policies, simulate attacks, monitor inputs and outputs in real time, and apply guardrails based on their own data, compliance, and operational requirements.

An acceptable response in a consumer chatbot may be unacceptable in a banking, healthcare, or internal enterprise workflow. Organizations need controls reflecting what an agent can access, which actions it can perform, and when human approval is appropriate, as generic model safeguards often miss these business-specific boundaries.

The company reports its technology protects more than three billion users across platforms including Google, Meta, TikTok and Amazon, and is used by eight of the world’s 10 leading AI foundation-model labs. The CEO noted the systems are hosted by Amazon and Nvidia, among others. These deployments indicate a growing role across the AI stack, from foundation-model evaluation to production monitoring.

As organizations give AI agents access to email, databases, software tools, and business processes, the potential consequences of errant behavior become tangible. Open models also make advanced capabilities available to legitimate developers and malicious groups alike, supporting phishing, fraud, hoax campaigns, and data theft at greater speed.

The new capital will fund expansion of the AI platform, add resources to Rabbit Hole, track emerging attack techniques, and increase sales and marketing. The broader goal is turning this extensive archive of hostile online behavior into repeatable enterprise controls. For investors in the round, the bet is clear: AI assurance is expected to become a durable layer of the infrastructure surrounding models and agents, rather than a feature added after deployment.