The red team business just became a growth industry — because the models being released are now powerful enough to need one.

The Summary

  • AI safety startup Alice raised $140 million to stress-test frontier models and help companies identify vulnerabilities before deployment
  • CEO Noam Schwartz says threats previously executed by individuals are now being amplified at scale by AI capabilities
  • Recent incidents at OpenAI and Anthropic have made model safety a commercial priority, not just a research problem

The Signal

Alice's $140 million raise is a market signal that AI safety has crossed from academic concern to enterprise risk management. The timing matters: Schwartz specifically cited recent incidents at OpenAI and Anthropic as catalysts for heightened attention. Translation: something broke in production, or came close enough that checkbooks opened.

The company's model is red teaming as a service. They stress-test advanced models before release, hunting for edge cases where an AI might generate harmful content, leak training data, or follow instructions it shouldn't. What changed is the attack surface. The threats aren't new, but the amplification is.

"Threats once carried out by individuals are increasingly amplified by AI."

A single person with a good jailbreak prompt can now probe thousands of vulnerabilities in hours. A coordinated group can map an entire model's weaknesses before the lab patches them. The asymmetry is brutal: defenders need to find every hole, attackers only need one. Alice is betting that enterprises will pay real money to flip that equation.

The customer base splits two ways:

  • AI labs (OpenAI, Anthropic, etc.) stress-testing their own models pre-release
  • Enterprises deploying those models, wanting their own independent verification before putting them in production

That second category is where the growth is. Companies building agents on GPT-4 or Claude don't trust "trust us, it's safe" anymore. They want receipts. They want adversarial testing that simulates real attack vectors: social engineering, prompt injection, data exfiltration, bias amplification at scale.

This is the infrastructure layer for the agent economy. You can't deploy autonomous AI systems in high-stakes environments without proof they won't go sideways. Alice is building the testing framework that makes deployment possible. The $140 million says investors believe every company shipping agents will need this, and most will outsource it rather than build in-house.

The Implication

The rise of AI red teaming as a funded category means we're entering the "break things and find out" phase of deployment. The models are good enough to be dangerous, which means they're good enough to be useful. Companies will ship them anyway. The ones that survive will be the ones that tested first.

If you're building agents, budget for adversarial testing. If you're deploying third-party models, assume they haven't been tested for your specific use case. The frontier labs are moving too fast to catch every edge case. That's not criticism, it's physics. Alice and companies like it are the crumple zone between capability and catastrophe.

Sources

Bloomberg Tech