Dealroom analysis · AI cybersecurity

10 cybersecurity startups defending against AI-powered threats

From finding exploitable code to protecting the devices and agents that act on it, a new generation of startups is building security for the AI era.

AI is changing both sides of cybersecurity. The same ability to analyse software and act through tools can help a defender find a weakness or help an attacker exploit it. In July, two OpenAI test models escaped their sandbox and broke into Hugging Face’s production systems. On 27 August, OpenAI, Anthropic, Microsoft, Alphabet, Amazon and more than 100 other companies signed a letter warning that AI-enabled cyberattacks will become far more widespread in the coming months.

These ten startups address different parts of it, grouped into three jobs.

Test defences
Find exploitable weaknesses before attackers do, from autonomous penetration testing to fixing vulnerable code.
Stop attacks
Detect and contain attacks in production: on endpoints, on connected devices and in the security operations centre.
Secure AI
Protect the models and agents themselves, and control what they are allowed to see and do.

Their shared opportunity is to make protection keep pace with increasingly capable software. The selection follows one rule: AI-native security startups founded in 2018 or later, taking the largest 2026 rounds in each of three jobs. Together they have raised $2.5bn on Dealroom’s records, $1.68bn of it in 2026. Five already carry valuations of $1bn or more: Horizon3, XBOW, Torq, Exein and Glow. Eight are based in the US; Exein and Zenity come from Rome and Tel Aviv.

The watchlist

The startups building the next layer of defence.

From finding vulnerabilities to securing autonomous agents. Selected companies; capabilities overlap. Total funding and latest recorded valuation.

Test defencesStop attacksSecure AI
Source: Dealroom.co

Security is becoming a continuous job

Horizon3, Armadin and XBOW run autonomous attacks against live systems to expose weaknesses that can actually be exploited. depthfirst works closer to developers, identifying vulnerabilities and proposing fixes in their software workflows. The common direction is continuous testing as systems change.

The financing is substantial. Armadin disclosed $189.9m across seed and Series A rounds; Dealroom records the two at $214m combined. XBOW announced $120m in March and a $35m extension in May. Together with depthfirst’s $40m and $80m announcements, those three companies disclosed $464.9m of financing this year. Horizon3 raised $250m in August at a valuation above $2bn, co-led by NightDragon and NEA. It is the largest of the ten by headcount, with 548 people.

Funding context

VC funding in companies tagged “AI Security”

Dealroom category · USD · Full years through 2025; January–August 2026.

View exact funding data
VC funding in Dealroom’s AI Security tag, USD
PeriodFundingRounds
2021 full year$755,106,66718
2022 full year$210,949,09321
2023 full year$230,040,61428
2024 full year$272,707,62933
2025 full year$932,554,662106
2026 Jan–Aug$2,150,030,594119

Scope matters. This category includes adjacent AI businesses and misses several companies in our watchlist. It is not a funding total for the ten startups above.

Source: Dealroom.co

Investment is accelerating, but one tag cannot describe the market

The broader Dealroom AI Security category recorded $2.15bn across 119 VC rounds in the first eight months of 2026. That already exceeds the $933m recorded for the whole of 2025. These are different-length periods, rather than a year-on-year growth comparison.

The category’s boundaries need care. Inferact, Sycamore Labs and Pramaana Labs account for $242m of the 2026 figure, although their recorded products concern inference infrastructure, enterprise agents and data analysis. Exein, Torq, Horizon3, Glow and Zenity are missing from the tag. The chart shows investment in the existing category; our company selection follows their security work. The ten watchlist companies alone raised $1.68bn in 2026 to mid-September, including the September rounds for Exein and HiddenLayer.

A second signal

Employee growth at three AI cybersecurity startups

Estimated employee counts and one-year growth, September 2026.

Source: Dealroom.co

Hiring adds another view of momentum

XBOW has the fastest growth, from roughly 116 to 305 employees in a year. Horizon3 is the largest team at 548 people, up 58%. Zenity grew 70% to 264. Among the rest, Torq grew 30% to 468, Exein 25% to 81 and HiddenLayer 7% to 176. Armadin, depthfirst, Onyx and Glow have no one-year comparison in Dealroom yet.

That distinction matters: the fastest percentage increase does not imply the largest business. Hiring gives us another signal of expansion alongside financing, while customer adoption and security outcomes remain the harder tests of progress.

The attack surface reaches beyond code

Torq’s $140m Series D backs AI-driven security operations, including alert triage, investigation and response. Exein adds the physical world, putting AI-based detection and protection directly onto connected devices. Dealroom records a $270m round for Exein in September at a $1.7bn valuation, as reported by the Financial Times. The round closed after the January–August period in the funding chart above. Glow left stealth in July with $180m at a $1.2bn valuation, led by Sequoia, Cyberstarts, Greenoaks and Redpoint, and rebuilds endpoint protection around stopping risky software and AI agents before they run.

Onyx, HiddenLayer and Zenity address AI systems themselves. Onyx controls enterprise agents; HiddenLayer protects models and AI applications at runtime; Zenity secures the actions autonomous agents take. These approaches address different routes through which an AI system could be compromised or act beyond its intended permissions.

Three recent rounds show the investment in this part of the market. Onyx raised a $113m Series B in July, led by Bessemer Venture Partners, four months after a $40m seed round. Zenity announced $125m in August, followed by HiddenLayer’s $100m Series B on 2 September. That is $338m across three companies. HiddenLayer’s September round falls outside the January–August funding chart above.

The companies worth following will turn these capabilities into protection customers can measure: exploitable weaknesses found, effective fixes deployed and attacks contained. That is the thread connecting this watchlist.

Research notes, funding definitions and additional candidates

The ten-company selection is editorial, not a performance ranking. Funding announcements can combine rounds closed at different times. Company-reported product and adoption claims have not been independently benchmarked.

View funding figures and filter findings
PeriodVC fundingRounds
2021 full year$755.1m18
2022 full year$210.9m21
2023 full year$230.0m28
2024 full year$272.7m33
2025 full year$932.6m106
2026 Jan–Aug$2,150.0m119

The next-gen API reconstruction selects AI Security, excludes Outside Tech and Mature companies, selects VC rounds and excludes grants and SPAC private placements. The shared app URL’s hidden defaults could not be verified.

The broader funding-round version returns 120 records for January–August 2026; the VC-only version returns 119. Both sum to $2.15bn.

Scope to check: Inferact ($150m), Sycamore Labs ($65m) and Pramaana Labs ($27m) account for $242m, or 11.3%, of the 2026 total. Their recorded products concern inference infrastructure, enterprise agents and data analysis. This is a flagged subset, not a complete clean-up.

Missing from the AI Security tag: Exein, Torq, Horizon3, Glow, Zenity, Aikido, RunSybil and Tenzai in the inspected company profiles. Tagged: Armadin, XBOW, depthfirst, Onyx and HiddenLayer. A defensible market-wide funding chart needs consistent company coverage across all years.

Additional candidates · For review

Other startups we could include

Six alternatives to consider while refining the ten-company article.

Novee

Continuous AI penetration testing

$51.5m described in the January 2026 announcement. The API dates the record August 2025; reconcile before including it in a yearly total.

Company announcement ↗

Tenzai

Autonomous testing and remediation

$75m seed announced in November 2025. The API also records $32m earlier in 2025; check potential overlap before summing.

Company announcement ↗

WitnessAI

Protection and controls for enterprise AI usage

$58m announced in January 2026. An alternative for the AI-agent protection part of the article.

Company announcement ↗

Noma Security

Security for AI applications, models and agents

$100m Series B announced in July 2025. Its funding belongs in 2025, even if selected for a 2026 watchlist.

Company announcement ↗

Kai

AI-driven security operations

$125m disclosed at its March 2026 launch. Previously featured; an alternative to Torq for operations coverage.

Company announcement ↗

Gray Swan

AI model testing and protection

$40m Series A announced in May 2026. The company names Anthropic, OpenAI and Meta as platform users; this is a company-reported adoption signal.

Company announcement ↗
Open checks

What still needs checking before publication

Novee’s round date and Tenzai’s possible funding overlap still need reconciliation. The main company profiles retain their individual funding dates and sources.

For additional evidence, Mindgard reports more than 150 publicly disclosed vulnerabilities, while Gray Swan reports use by major AI labs. These are company-reported signals, not comparable performance scores. Team sizes are Dealroom snapshots, not audited headcounts.

The ten featured companies link to verified public Dealroom company pages. AIR and Mindgard remain relevant alternatives; HiddenLayer and Zenity are featured for their verified recent financing and direct relevance to protecting AI systems.

Selection rule (16 September): AI-native cybersecurity startups founded in 2018 or later, ranked by VC raised in 2026 within each of three jobs (test defences, stop attacks, secure AI). A sweep of every 2026 VC round of $40m or more in the Dealroom Security, Cybersecurity and AI Security tags added Horizon3 ($250m Series E, $2bn) and Glow ($180m Series A, $1.2bn) and moved Aikido ($60m) and RunSybil ($40m) to the alternatives. Excluded on purpose: Cyera ($1bn raised in 2026 at $12bn, Series G, past startup stage), Cathedral ($160m) and Dream Security ($260m at $3bn), both selling cyber operations to governments rather than enterprise defence; TENEX.AI ($250m, a managed detection service); and Upwind ($550m across two rounds), a cloud security platform rather than an AI-native product. Cloaked ($300m) is consumer privacy. Exaforce and Kai ($125m each) do the same job as Torq ($140m), which is the largest of the three.

Publication review · 15 September 2026

Recent rounds and shortlist decisions

Added: HiddenLayer, $100m Series B (2 September); Zenity, $125m Series C (August). Both amounts and dates match company announcements and current API records.

Also reviewed: Cymphony, with $30m in funding reported in September. Its round breakdown differs between the API and reporting, so it is not used in the charts. Novee and Tenzai remain in the alternative list while their round timing and possible overlap are reconciled.

Retained as alternatives: AIR ($50m disclosed September), Mindgard ($30m Series A August), WitnessAI, Noma, Kai and Gray Swan. The featured ten are an editorial selection, not an exhaustive market ranking.

Exein: $270m round in September at a $1.7bn valuation, recorded by Dealroom and reported by the Financial Times; confirmed as factual in review on 15 September. September falls outside the January–August funding chart, so the round appears in the prose only.

Data quality (15 September): Onyx Security’s Dealroom profile lists its headquarters as Charr, Pakistan; the company is New York-based per its July 2026 announcement. Armadin’s API record holds a $24m seed and a $190m Series A ($214m), while the company’s announcement gives $189.9m across both; the article uses the announced figure. depthfirst’s Dealroom total of $141m includes a $21m Series A from 2021, before its relaunch; the company states $120m raised. A second “Hidden Layer” entity (Switzerland, 3 employees) duplicates HiddenLayer; the article links the Austin company. Valuations for the unicorn count are Dealroom’s latest recorded valuations: Horizon3 $2.0bn (August), XBOW $1.0bn (May), Torq $1.2bn (January), Exein $1.7bn (September), Glow $1.2bn (July).

Funding scope: The aggregate chart is accurate for the query shown in the methodology. It must retain its “tagged AI Security” title and scope note when shared. It is not a clean total for this article’s definition of AI cybersecurity.

Company and funding data: Dealroom next-gen API, September 2026 snapshots; selection sweep re-run 16 September. Growth percentages are rounded from the API’s one-year employee-growth fields. Missing growth values are not treated as zero. Exein’s September financing is a Dealroom record confirmed against Financial Times reporting. The $464.9m three-company figure uses Armadin’s precise company-announced $189.9m rather than the API’s rounded $190m.