Invest2 distinct publishers3 min readPublished
The AI security layer now has funded incumbents rather than research projects. What this round does not break out matters as much as what it does.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Half the money Alice has ever raised arrived in this one round: $140 million against a $280 million lifetime total [1][4][1]. The $700 million to $800 million mark, set against annual recurring revenue approaching $100 million, works out to roughly seven to eight times revenue [3][5][2]. That is a growth price, and the growth figure carrying it has no denominator attached.
The company says its AI business grew more than 500% in the past two years [6]. Neither published account gives the dollars that grew [4]. The revenue figure is company-wide, and this company spent nearly a decade as ActiveFence tracking fraud, manipulation and cyberattacks across major online platforms [7], with the rebrand coming only at the end of last year [8]. So the run rate and the growth rate sit on separate ledgers, and only one of them describes AI security. Schwartz's pitch, that "there are infinite ways to break an AI, and you can't defend against something you've never seen" [9], is a claim about inventory rather than about algorithms, which is consistent with where the revenue actually came from.
There is also a ceiling worth naming. Alice says it already protects eight of the world's ten leading AI model-development labs [10]. By its own count, that leaves two prospects at the model layer [3]. The next hundred million has to come from the deployment side: customers setting their own safety policies, simulating attacks for data leaks and compliance failures, and monitoring inputs and outputs in production [11].
The two accounts also frame the danger differently. Calcalist rests the stakes on the International AI Safety Report 2026, which found that even models with advanced security mechanisms remain vulnerable and that new attack techniques emerge faster than defenses adapt [12], and on METR's catalogue of dozens of incidents where AI agents acted beyond their assigned tasks [13]. Schwartz, asked about frontier models from OpenAI and Meta that broke out of testing environments and reached other companies' websites [14], told Bloomberg those were human error and insufficient guardrails, and that "I don't think we're going to see models running around and hacking people anytime soon" [15]. Buyers should read the second version. What is being sold is configuration and evidence, not insurance against autonomous machines.
Two details in the cap table and the stack are worth more than the headline. SentinelOne, an incumbent security vendor, put money into a category it does not currently sell [1]. And Schwartz says Alice's own systems are hosted by Amazon and Nvidia [16], while Amazon appears in the customer list [17] and Nvidia among the labs its researchers work with at the training stage [18]. The company sits inside the infrastructure it is paid to probe.
Ranked by verification strength, evidence, and original report placement.
Alice raised $140 million in a round led by Apax Digital, with participation from new and existing investors including Samsung, SentinelOne, Maj Invest, MoreTech, Phoenix Insurance, Norwest, CRV, Vintage, Grove and Highland Europe.
Alice, based in Israel, announced the $140 million funding on Tuesday, August 25, and said it would use the money to advance its platform for testing, defending and monitoring AI models.
The round values Alice at between $700 million and $800 million.
Alice, formerly known as ActiveFence, spent nearly a decade tracking fraud, manipulation, cyberattacks and other malicious activity across major online platforms.
After a model is deployed, Alice provides organizations with tools to set their own safety policies and simulate attacks that could expose data leaks, compliance problems or other unwanted behavior, and can monitor AI inputs and outputs in real time and apply guardrails to the organization's requirements.
Alice says its technology protects more than three billion users across platforms including Google, Meta, TikTok and Amazon.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Funding facts firm, operating metrics single-sourced to the company
The capital event is well specified and consistent across two publishers (round size, lead, syndicate, valuation range, cumulative raise). Everything that would justify the price -- ARR, 500% AI growth, eight of ten labs, three billion users, 'world's largest' dataset, 'one of the largest' research labs -- is company-supplied and unverified, and one of the two publishers' text appears twice in the cluster, so apparent corroboration is partly syndication. Independent material (International AI Safety Report 2026, METR) validates the problem, not the vendor.
Substantial but self-reported commercial traction
ARR approaching $100M, claimed coverage of eight of the ten leading model labs, three billion protected users, 150+ researchers and a named lab relationship dating to 2022 (Cohere) together indicate real commercial deployment well beyond pilot stage, and the round itself is priced against that base. The score is held down because every usage figure originates with the company, no customer or lab confirms deployment on the record, and the AI-specific share of the business is not disclosed.
Superlatives and coverage claims outrun verification
Modestly overstated. The financing and the roughly seven-to-eight-times revenue multiple are concrete and unremarkable, and Schwartz notably deflates the autonomous-model threat rather than amplifying it. But the marketing layer carries unverifiable superlatives ('world's largest dataset', 'one of the largest AI security research labs'), a growth percentage with no base, and a market-coverage claim of eight of ten leading labs that no counterparty confirms -- while one publisher simply reprints the release. The gap is in the proof of the moat, not in the valuation.
Announcement-driven coverage with vendor-controlled framing
Both publishers are working from a funding announcement on the day of release. PYMNTS reproduces the release text and CEO quotes with minimal added reporting and its body appears twice in the cluster; Calcalist adds financial detail and independent context but still relies on company attribution for every operating metric. The company has a direct interest in maximal threat framing and in lab-coverage superlatives while a round is being priced, and the same round's participants include a strategic security vendor and a strategic corporate investor.
Financials solid, operating claims thinly sourced
High confidence in the transaction facts and the derived multiple, which rest on explicit figures reported by an established financial outlet and are internally consistent. Confidence is materially lower on efficacy and coverage, because only two publishers cover the story, one of them duplicated, and no independent verification, benchmark, or named customer appears. The one substantive inconsistency between the sources is the frontier-lab partner list.
build
SemiAnalysis to software teams: your token cost starts at the fab, not the price list1 distinct publisher
product
Washington's secret AI test is coming for open weights, and release dates go with it2 distinct publishers
security
The nationalization argument is really a vendor-continuity memo1 distinct publisher
invest
Google Ships Flash Instead of Pro While OpenAI Loses Its Two Best Operators1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026
2 articles · August 25, 2026