Skip to content

Invest1 publisher3 min readPublished

Cyera's $1 billion Oasis deal puts a price on one of the AI risks in Anthropic's leaked S-1

Anthropic's leaked S-1 warns AI could resist shutdown or game tests, and only agent-control startups have found acquirers, Cyera paying $1 billion for Oasis. Startups testing for hidden capabilities and deception are still raising money, often against work the labs do themselves.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Cyera's $1 billion Oasis deal puts a price on one of the AI risks in Anthropic's leaked S-1
Photo: yahoo.com

What happened

  • The leaked filing runs to about 80 pages of risk factors, covering losses, compute costs and customer concentration, according to Reuters as cited by CB Insights.
  • Cisco bought Astrix, Fortinet bought Virtue AI and F5 bought CalypsoAI earlier this year, all in the agent-control layer.
  • Noma Security, which manages agent identities and access, grew its team 154% in a year to 150 people and is in its funding window.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • precedent Four control-layer purchases by security vendors in one year make a trade sale the likely exit for WitnessAI, Zenity, Straiker and the other control startups CB Insights lists.
  • constraint Interpretability startups such as Goodfire and Tilde Research have to price their work against labs that, according to CB Insights, already give it away free.
  • exposure Anthropic has told would-be shareholders its models could refuse to stop or manipulate people, so an incident of that kind would land on a risk the company itself put in writing.

CB Insights, working from the leaked S-1 that Reuters reported, sorts the four behaviours into four markets and names 16 startups across them: five in agent control, four in testing, five in interpretability and two in manipulation [1][2][1]. All the acquirers are in the first group. Of the four deals CB Insights lists this year, every one is in agent control, and only Cyera's has a price attached [4]. Cisco, Fortinet and F5 bought before the S-1 leaked [5].

I think the buyers chose control because a company deploying agents can buy it without the lab's help. The startups limit what an agent can access and do when something goes wrong, and they leave the model alone [3]. E2B runs agent code in isolated environments for customers including Manus, Perplexity and Groq [5]. On its own growth figure, Noma had about 59 employees a year ago [2]. It is hiring at that pace in what CB Insights calls "among the more crowded areas in AI security" [6].

Irregular's reported valuation is 1.5 times what Cyera paid for Oasis [3]. Irregular tests advanced models for unexpected cyber capabilities [11]. CB Insights calls that category "much earlier than AI security or testing," and much of the work still happens inside the major labs [12]. The labs would be the natural customers. An investor at that price is betting that someone other than a lab pays for the test, or that a lab pays for an outside check it could run itself.

Manipulation has the shortest list. CB Insights found two startups, Alice and Apollo Research, and Apollo's tools cover broader safety risks than manipulation alone [14]. Much of the independent work sits with nonprofits such as Common Sense Media and the Independent AI Evaluation Foundation, launched last week [15]. CB Insights wrote that the shortage "could mean an opening or simply that nobody wants the product yet" [17].

Three outcomes are open. Testing could follow control into acquirers' hands. CB Insights wrote that "Agent security and testing are the safest bets, as one already has buyers and M&A, while the other is becoming a market" [16]. The labs could keep capability and deception testing in-house, and the independent firms in those lists would stay small [12][15]. Or liability could produce a customer. Anthropic lists liability as a risk if its AI goes wrong, and Armilla AI already sells AI liability insurance [18].

I think the leak adds a disclosure and no new buyer. The money went to the control layer because a deploying company can buy it alone [3][4], and a risk factor in Anthropic's filing changes neither that nor the labs' habit of doing the rest of the work themselves [12]. The case against this view is insurance. If underwriters such as Armilla start requiring outside tests before they cover a deployment, testing gets a paying customer the labs cannot replace [18].

What to watch

  • Irregular closing its round at the reported $1.5 billion, a price above the only disclosed control-layer deal.
  • A first priced acquisition of a testing startup such as Patronus AI, Mindgard, Gray Swan or Raindrop.
  • Whether the S-1 Anthropic files publicly keeps the shutdown, evaluation-gaming and manipulation risk factors from the leaked version.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories