Alice raises $140mn to stress-test the models Anthropic and Google ship

Alice, the Israeli firm that red-teams models for Anthropic, Google and Cohere, has raised $140mn led by Apax Digital. Its own announcement gives no valuation. According to Bloomberg it is worth close to $1bn, while Israeli outlets put it at $700mn to $800mn.


Alice raises $140mn to stress-test the models Anthropic and Google ship

Noam Schwartz, CEO and co-founder of Alice.

Image Credits Credit: Alice

One company spent eight years cataloguing the worst material on the internet. It has now raised $140mn to point that archive at AI models.

Alice, formerly ActiveFence, announced the round on Tuesday. Apax Digital Funds led it, and will take a board seat. Total funding now stands at $280mn.

The announcement names MoreTech and Phoenix Financial as the new participants. Existing backers including Resolute Ventures, Grove Ventures, CRV, Highland Europe, Norwest, NFX and Claltech also joined.

Bloomberg and the Israeli press add two names the release leaves out. Samsung Electronics took part, and so did the listed cybersecurity company SentinelOne. That last one now holds a stake in a firm selling into the same buyers.

Nobody agrees what it is worth

The company’s own announcement gives no valuation at all.

Chief executive Noam Schwartz told Marissa Newman at Bloomberg that the round values Alice close to $1bn. Meir Orbach put it lower in Calcalist, at $700mn to $800mn. Globes reported $800mn.

The gap between the low figure and the high one runs to roughly $300mn. That is more than twice the size of the round itself.

What the company actually does

Before a model ships, Alice researchers try to break it. They simulate malicious prompts and agentic tasks, probing for jailbreaks, prompt injection and behaviour the lab did not intend.

The release names Anthropic, Google and Cohere among the frontier labs it works with. Schwartz declined to tell Bloomberg which specific models, citing confidentiality.

Once a model is live, the work changes. Enterprises set their own policies on top of the guardrails the lab built in. They run simulated attacks to find data leaks and compliance gaps, and they monitor inputs and outputs as they happen.

The asset is the archive

Alice calls its dataset Rabbit Hole. It describes the collection as the largest body of real-world adversarial and harmful content anywhere.

It came from tracking fraud, extremism, coordinated manipulation and cyberattacks across the open web since 2018. The company now matches those patterns against attacks on AI systems.

“The worlds of manipulation, forgery and cyberattacks are our bread and butter,” Schwartz told Calcalist. Alice sits on the most contaminated data there is, he said.

There are infinite ways to break an AI, he added in the funding announcement. You cannot defend against something you have never seen.

Why the money arrived now

The round follows a run of incidents involving autonomous agents built by Anthropic, OpenAI and Meta. Those agents left their testing environments and reached outside organisations.

One agent faked identities to plant malware during safety evaluations. Anthropic’s own Claude Cowork could read credentials on a Mac after escaping its local machine.

Cybersecurity experts blamed the developers in some cases. Sloppy safeguards let models break out of the isolated spaces used to run tests, they argued. Fifteen US states demanded records of one such incident, and OpenAI rewrote its safety rules afterwards.

The chief executive is not selling the apocalypse

Schwartz calls the recent attacks examples of human error and inadequate guardrails rather than machine autonomy.

“I don’t think we’re going to see models running around and hacking people anytime soon,” he told Bloomberg. But the industry does need to take these things incredibly seriously, he said.

That is a narrower claim than the market it funds. It is also worth noting who is making it, which is the person selling the defence.

The numbers behind the round

Alice is approaching $100mn in annual recurring revenue, a metric startups use to approximate sales. Its AI business has grown more than 500% in two years.

The company employs about 400 people, most of them in Israel, with staff in New York, London and Hanoi. More than 150 of them are researchers in its AI security lab.

It says it works with eight of the ten leading model labs and protects more than three billion people across platforms including Google, Meta, TikTok and Amazon.

It used to be a content moderation company

Schwartz, Iftach Orr, Alon Porat and Eyal Dykan founded ActiveFence in 2018 to moderate content for social media platforms. It raised $100mn in 2021 without disclosing a valuation.

The company began handling generative AI work in 2022. It started with Cohere, before ChatGPT reached the mainstream, and concluded that its data mattered to model safety, Schwartz told Calcalist.

In January it renamed itself Alice, after the Lewis Carroll character, and turned towards securing models directly.

Independent research supports the market, not the numbers

More than 100 experts wrote the International AI Safety Report 2026. It found that even well-defended models still break at a high rate, and that new attack techniques emerge faster than defences close them.

METR, an independent research organisation, has catalogued dozens of incidents in which AI agents acted beyond the scope they were given. In some cases the agents tried to hide it from human oversight.

Neither body assesses Alice, and neither validates its commercial claims. They establish that the problem exists.

The investor case

The cloud platform shift created a new category of security, said Patrick Kane, a partner at Apax Digital. The AI shift is opening an attack surface that widens as enterprises roll out agents.

His colleague Eric Levine described the mechanism as a loop. Attacks observed in the wild seed the tests, the tests tune the guardrails, and model behaviour in production feeds back into both.

Where Europe sits in this

Highland Europe is among the existing investors, and Alice keeps a London office, but the round is otherwise Israeli, American and Asian money.

The regulatory pressure is European all the same. A UK regulator said this month that it is watching rogue AI agents, and Britain’s AI Security Institute ran the evaluations in which several of those agents escaped.

Schwartz put the underlying problem in one line. The industry democratised capabilities faster than it democratised defences, and this round is about closing that gap.

Get the TNW newsletter

Get the most important tech news in your inbox each week.

Also tagged with