Product1 publisher3 min readPublished
HelmGuard lets customers set the risk level above which a human checks its risk decisions
The London GRC startup has raised $7.3m in seed funding for agents that assess third-party risk and show a citation and a confidence score for every conclusion. The part that audits other companies' AI agents is still being built.
The Product Desk · Product desk

What happened
- HelmGuard, a London governance, risk and compliance startup, said on 9 September that it had raised $7.3m in seed funding co-led by Infinity Ventures and Frontline.
- HelmGuard says it assessed 1,250 counterparties for one US insurer in less than a week, then moved that customer off its previous platform in under 10 days.
- Part of the round pays for an agent assurance layer that will evaluate how AI agents behave while they run, and for a Verified Risk Network for exchanging current risk claims.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision Anyone renewing Vanta, Drata or Secureframe now has a second option on the table, and the choice is about who holds the judgement: your team working a checklist, or a vendor's agent producing a conclusion your team signs.
- exposure The risk threshold is a configuration field, and whoever fills it in decides which assessments leave the building without a human name attached. That person answers for them when an auditor pulls a sample.
- constraint A buyer shopping specifically for AI agent governance is buying a working third-party risk product plus a build plan, because the layer that watches agents at runtime is what the seed money funds.
- precedent If regulated buyers start accepting an agent-assessed claim as the unit of assurance, vendors get asked for live answers instead of a certificate issued months ago, and answering becomes a system to run.
Somebody has to put a number in the box. HelmGuard's customers can require a human check only above a risk level they set [11]. Jack Miller, the chief technology officer, told Tech Funding News that no competitor offers that [11]. Every assessment carries a confidence score, every conclusion links to a specific source, and a human reviews the result depending on how critical the decision is [10]. Below the line the customer drew, the agent's conclusion is the conclusion.
"Most compliance platforms were built to document a process, not to reach a conclusion," John Daley, the chief executive, said in the funding announcement [6]. He named the competition in his interview with Tech Funding News: Vanta, Drata and Secureframe create checklists for people to follow, he said, and HelmGuard's agents work through the checklists themselves [8]. "We have this phrase internally: decisions over documents," Daley told the outlet [9]. He spent eight years as an executive at Palantir, according to HelmGuard [3].
What runs today pulls risk, security and compliance data out of company documents and directly from source systems [4]. Specialised agents then handle third-party risk management, control gap assessments and checks on other AI agents [4]. The layer that evaluates how agents behave while they are running is what part of the seed money pays for [17]. Daley said the funding "lets us bring that capability to far more teams and extend it to governing the AI agents being deployed on other workflows" [7].
HelmGuard's case is speed. It says it assessed 1,250 counterparties for one US insurer in less than a week, and that its engineers moved that customer off its previous platform in under 10 days [13]. Across seven days, 1,250 assessments average about 179 a day [21]. HelmGuard did not name the insurer. A global telehealth and telecommunications customer cut first response times on customer assurance from days to minutes, the company said [14].
Callosum, a London AI scale-up, hired HelmGuard to design and run its security and compliance programme [15]. "We now have the capability of a mature security organisation and can compete at massive scale," Danyal Akarca, the company's co-founder and chief executive, said in the announcement [16].
The Verified Risk Network, also funded by the round, is meant to let companies exchange verified, current claims about risk instead of documents [18]. "An AI vendor's risk profile changes with every model update and every new tool its agents can call," Miller said in the announcement [19]. He said the network "makes the unit of assurance a claim assessed directly by an agent, rather than a document, and enables agent-to-agent exchange on a continuous basis" [20]. HelmGuard says its users sit in the US, Canada, the UK, Hong Kong and South Africa [12].
Ask what share of assessment volume falls under the threshold, because that share is where the vendor's model is the reviewer of record. Ask whether your auditor accepts the citation and reasoning trace HelmGuard shows as the answer to how a conclusion was reached [5]. A checklist tool leaves the judgement with your staff and bills you for the paperwork. An agent that reaches conclusions moves part of that judgement into a vendor's model, and the report still goes out under your company's name [5].
What to watch
- Whether the agent assurance layer ships with named customers running it against live agents, or stays a funded line item.
- Whether Vanta, Drata or Secureframe ship agents that draw conclusions of their own instead of generating checklists.
- Whether any auditor or regulator accepts a reasoning trace as evidence that a control was assessed.