Alice, the ActiveFence rebrand, sells AI safety tools: adversarial red teaming, jailbreak and prompt injection defenses, and scope checks on AI agents.
Eight of the ten labs building the world's most capable AI models now pay a New York company called Alice to break their own systems before anyone else can. Alice sells AI safety tooling: pre-release red-teaming, jailbreak defenses, and scope checks on AI agents. On Tuesday the company announced a $140 million funding round led by Apax Digital Funds, bringing its total funding to $280 million.
The customer list is the part that matters. Alice says it works with eight of the ten leading AI model labs, and has named Anthropic, Google, and Cohere as customers. Those are buyers, not investors. "Leading AI labs" is shorthand for the small set of companies training the largest general-purpose models, and the fact that most of them are paying for outside adversarial testing tells the reader something a funding figure cannot: model developers now treat safety red-teaming as a procurement line, the way a bank buys penetration testing or a drugmaker buys clinical-trial operations.
The company, rebranded from ActiveFence earlier this year, spent nearly a decade in platform trust-and-safety work before pivoting to AI. CEO and co-founder Noam Schwartz said the new capital will fund product expansion, headcount, and acquisitions. Other participants in the round include MoreTech and Phoenix Financial, alongside existing backers Resolute Ventures, Grove Ventures, CRV, Highland Europe, Vintage Investments, Norwest, NFX, and Claltech; Apax Digital will take a board seat. Alice also said its AI business grew more than 500% over the past two years and is approaching $100 million in annual recurring revenue, both figures the company reported itself and that no independent filing has yet verified.
The question the round is really pricing is whether outside tooling can keep up with the attack surface. Alice's own press release anchors that question in two pieces of independent research it cites: the International AI Safety Report 2026, written by more than 100 independent experts and documenting how frontier models remain vulnerable to jailbreaks, prompt injection, and misuse; and METR's incident catalog, which has tracked AI agents acting outside their intended scope and, in some cases, attempting to conceal the behavior from human oversight. Those are the same failure modes Alice sells defenses against, and they are still being added to faster than they are being closed out.
That tension is also why a $140M round can read two ways. One interpretation is that frontier labs are willing to pay a third party to do adversarial work they would rather not be seen to do publicly, and that the category is now capitalized to grow with the model market. The other is that the independent research the vendor itself cites says the gap is widening, not narrowing, and that a roughly $100M-revenue business inside a market where the failure modes are still being cataloged is selling a service that has not yet earned its keep on the most important benchmark: whether public incident counts start to fall.
TechStartups framed the round in customer-count terms; SecurityWeek's independent write-up is the cleanest secondary anchor. The public METR catalog and the next International AI Safety Report will be the test: a measurable drop in scope-violation incidents would show the line item is paying for solved; another year of net additions would show it is paying for staffed.