Israeli-founded AI security company Alice has raised $140 million in a new funding round as demand surges for tools designed to prevent artificial intelligence models and autonomous agents from behaving unpredictably or being manipulated by attackers.
The round was led by Apax Digital, with participation from Samsung, SentinelOne, Maj Invest, MoreTech, Phoenix Insurance, Norwest, CRV, Vintage, Grove and Highland Europe, the company announced Tuesday.
Alice, formerly known as ActiveFence, said it is approaching $100 million in annual recurring revenue and now protects more than 3 billion users online as well as eight of the world’s 10 leading AI model labs. Its customers and partners include Anthropic, Google and Nvidia.
Founded in 2018 and headquartered in New York and Tel Aviv, the company originally focused on identifying fraud, extremism, coordinated manipulation and other harmful activity across major digital platforms. It is now applying that experience to one of the fastest-growing problems in the technology industry: keeping increasingly powerful AI systems under control.
Alice employs more than 150 researchers who study how AI models can be manipulated, circumvent safeguards or behave in ways their developers did not intend. The company says its teams work directly with leading AI labs and technology companies to uncover vulnerabilities before products are released.
“AI builders should be able to trust their models to do exactly what they were built to do,” said CEO and co-founder Noam Schwartz. “The only way to earn that trust is to stress test models and agents every day and guard them with defenses built from real attacks.”
From malicious prompts to autonomous agents
Alice provides security tools throughout the lifecycle of an AI model.
During model development and training, its researchers simulate malicious prompts and tasks designed to expose dangerous or unpredictable behavior. The tests are intended to identify vulnerabilities including jailbreaks, in which users circumvent built-in safety restrictions, and prompt-injection attacks, which manipulate an AI system into following malicious instructions.
Once AI systems are deployed, Alice allows companies to establish their own safety policies and test models against scenarios involving data leaks, compliance failures and other unwanted behavior. Real-time guardrails can then monitor what users send into the model and what the system produces in response.
The need for such systems has become increasingly urgent as companies move beyond chatbots and deploy AI agents capable of browsing the internet, retaining information and independently taking actions.
Alice cited the 2026 International AI Safety Report, which found that even highly protected models can still be compromised and that new methods for attacking AI systems continue to emerge. The company also pointed to research by the nonprofit METR documenting cases in which AI agents acted outside the tasks they had been assigned, including instances in which systems allegedly attempted to conceal their behavior from human oversight.
The company says its advantage comes partly from nearly a decade of observing how malicious actors behave across the internet.
Its technology is built around Rabbit Hole, a proprietary database containing examples of adversarial and harmful online activity collected from real-world platforms. Alice says information from those attacks is then used to design tests and update defenses against similar techniques.
Today, the underlying technology is also used to help protect users across platforms operated by companies including Google, Meta, TikTok and Amazon, according to Alice.
AI creates a new security market
Investors are betting that AI security could develop into a major new cybersecurity category as companies increasingly give AI models access to corporate systems and the ability to perform tasks autonomously.
“Just as the cloud platform shift created a new category of security, the AI platform shift is opening a rapidly growing attack surface that will only widen as enterprises roll out agents,” said Patrick Kane, a partner at Apax Digital.
Kane said Alice’s combination of model testing, real-time safeguards and a large database of adversarial techniques positioned the company to benefit from that shift.
Apax Digital Vice President Eric Levine said Alice’s system is designed as a feedback loop: attacks observed in the real world are used to build new tests, those tests help improve protective guardrails, and behavior observed in deployed models is fed back into the system.
Alice said it will use the new funding to expand its AI security platform, increase investment in Rabbit Hole and grow its commercial operations serving both frontier AI laboratories and companies deploying AI products.
For Schwartz, the company’s shift from policing harmful activity on traditional internet platforms to securing AI represents an extension of the same problem.
“For years, our teams have been embedded with the world’s leading platforms and AI labs, finding failures before deployment,” he said. “Now we are bringing that capability to every AI lab and enterprise launching AI in production.”


