Product1 distinct publisher3 min readPublished
The round doubles the company's lifetime funding and sells frontier labs their adversarial testing off the shelf. Bloomberg and the Israeli press named an investor the release did not.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The pre-ship half of this business is where the structural consequence sits. Alice's researchers work a model over before it ships, simulating malicious prompts and agentic tasks and hunting for jailbreaks, prompt injection and behaviour the lab did not intend [9]. The company names Anthropic, Google and Cohere among the labs it works with, and its chief executive declined to tell Bloomberg which specific models, citing confidentiality [10].
The product being bought is an archive. Alice calls it Rabbit Hole and describes it as the largest body of real-world adversarial and harmful content anywhere, assembled by tracking fraud, extremism, coordinated manipulation and cyberattacks across the open web since 2018 [12]. Noam Schwartz's own framing is that there are infinite ways to break a model and you cannot defend against something you have never seen [13]. Take that seriously from the buyer's side and the coverage of any pre-ship evaluation is bounded by what the collection happens to hold. In-house red teams miss different things at different companies. A shared supplier misses the same things everywhere it is installed.
The pricing is soft in a way the round's size hides. Against revenue approaching $100mn a year, growing more than 500% on the AI side in two years [19], the reported valuations put the business somewhere above 7x sales at the low end and above 10x at the chief executive's own figure [2]. Half of every dollar Alice has raised arrived in this one round [1], and the headcount tells the same story: more than 150 researchers inside a company of about 400, most of them in Israel [20].
The investor list is where the disclosure thins out. The release names MoreTech and Phoenix Financial as the new participants, alongside existing backers including Resolute Ventures, Grove Ventures, CRV and Norwest [3]. SentinelOne, a listed cybersecurity company, now holds a position in a firm whose post-launch business is selling enterprises policy enforcement on top of lab guardrails, simulated attacks against their own deployments, and live monitoring of inputs and outputs [11]. That is a security budget line, sold to security buyers, with a public security vendor on the cap table. It reached the market through reporters rather than through either company.
Schwartz is not selling catastrophe. He attributes the recent episodes to human error and inadequate guardrails rather than machine autonomy, and told Bloomberg he does not expect to see models running around hacking people anytime soon, while arguing the industry must take the problem seriously [18]. Cybersecurity experts have made a compatible argument, blaming developers whose sandboxes were loose enough to let test models out [16]. The pressure that actually moves budgets is procedural: fifteen US states demanded records of one incident, and OpenAI rewrote its safety rules afterwards [17]. Demands for records are answered with documentation and a vendor name, which is the market Alice sells into. The archive itself was built to moderate social platforms when the company was ActiveFence, founded in 2018 [22], repointed at generative models in 2022 starting with Cohere [23], and renamed in January [24].
Ranked by verification strength, evidence, and original report placement.
Alice, formerly ActiveFence, announced a $140mn round on Tuesday; Apax Digital Funds led it and will take a board seat.
The announcement names MoreTech and Phoenix Financial as new participants, with existing backers including Resolute Ventures, Grove Ventures, CRV, Highland Europe, Norwest, NFX and Claltech also joining.
Bloomberg and the Israeli press reported two investors the company's release leaves out: Samsung Electronics and the listed cybersecurity company SentinelOne, which now holds a stake in a firm selling into the same buyers.
Before a model ships, Alice researchers try to break it, simulating malicious prompts and agentic tasks and probing for jailbreaks, prompt injection and behaviour the lab did not intend.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One publisher relaying company and press figures
The cluster has a single source, which is transparent about provenance: round mechanics and the syndicate are documented, and the valuation is presented as three conflicting third-party reports rather than a fact. But the load-bearing commercial and technical claims - ARR approaching $100mn, 500% growth, eight of ten labs, three billion people protected, the 'largest adversarial corpus anywhere' - are company assertions with no audit, benchmark or customer confirmation. The article itself notes that the International AI Safety Report 2026 and METR establish the problem while assessing neither Alice nor its commercial claims.
Named lab customers, self-reported scale
Adoption is more than announcement-stage: three frontier labs are named in the release as customers, generative AI work dates to 2022, roughly 400 staff including 150-plus researchers are deployed, and revenue is described as approaching $100mn. The wider figures - eight of ten leading labs, three billion people protected across Google, Meta, TikTok and Amazon - are company-stated with no customer confirmation, and no contract, seat or usage detail is given, which keeps this below the level of measured deployment.
Valuation and moat claims run ahead of verified numbers
Positive but moderate. Overstatement sits with the subjects rather than the coverage: the chief executive's near-$1bn valuation exceeds the $700mn-$800mn reported by Calcalist and Globes by roughly $300mn with no company figure disclosed, and the 'largest body of adversarial content anywhere' superlative is unverifiable. Offsetting that, the same chief executive explicitly declines the apocalypse framing, calling the incidents human error and inadequate guardrails, and the article separates market evidence from company evidence, so the gap is narrower than a typical funding-round narrative.
Seller-sourced numbers with strategic investor overlap
Nearly every quantitative and threat claim originates with a party that profits from it. The valuation high end comes from the chief executive, the market thesis comes from the two Apax Digital partners who just invested, the threat framing comes from the vendor selling the defence - a conflict the article names directly - and the release omits the participation of SentinelOne, a listed security company that now holds a stake in a firm selling into the same buyers, plus Samsung Electronics. No valuation was disclosed officially, and lab customers' identities are partly withheld on confidentiality grounds.
Detailed but unreplicated single-source account
The account is internally consistent, specific about who said what, and attributes competing figures to named reporters at Bloomberg, Calcalist and Globes, which raises confidence in the reported facts of the round. But nothing here is independently replicated inside the cluster: one publisher, no primary filings, no customer or lab confirmation, and the most consequential figures are contested or self-reported.
invest
Alice's $140M round prices a decade of abuse data at seven to eight times revenue2 distinct publishers
build
First-turn evals test the safest part of your product, a 90,000-exchange audit finds1 distinct publisher
build
The best grade for controlling in-house AI agents is a C+, and buyers can now cite it2 distinct publishers
product
Washington's secret AI test is coming for open weights, and release dates go with it2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026