The Israel-based company will use the financing to advance its platform, designed to test, defend and monitor AI models, Alice announced Tuesday (Aug. 25).
“There are infinite ways to break an AI, and you can’t defend against something you’ve never seen,” said Noam Schwartz, Alice’s co-founder and CEO. “We spent nearly a decade learning exactly how people abuse technology at the scale of billions, first on the world’s largest platforms and now on the models those same people are probing. We are very quickly democratizing capabilities before we’ve democratized the defenses. This round is about closing that gap.”
The announcement added that as labs and enterprises increasingly prioritize AI security, demand for Alice’s platform has increased, with the company’s AI business jumping more than 500% in the past two years. The company said it is home to one of largest AI security research labs in the world, with more than 150 researchers studying “how AI systems can be manipulated or fail, and how to stop it.”
Those researchers work with frontier labs like Anthropic, Google and Cohere, simulating “malicious prompts and agentic tasks” to uncover unpredictable behavior and strengthen models against jailbreaks and prompt injection.
After a model goes live, Alice said it helps companies safely deploy by filling the space between the model’s built-in safeguards and each firm’s requirements.
“Alice built this expertise over nearly a decade tracking fraud, extremism, coordinated manipulation, and other adversarial behavior across the open web,” the release said. “That work produced Rabbit Hole, the world’s largest dataset of real-world adversarial and harmful content, which lets Alice recognize attack patterns in AI systems that it has already seen elsewhere. The same technology protects more than three billion people across platforms including Google, Meta, TikTok, and Amazon.”
The new funding comes in the wake of recent cybersecurity incidents involving frontier AI models from companies like OpenAI and Meta broke free of their testing environments to breach the websites of other companies.
In an interview with Bloomberg News, Schwartz called these attacks evidence of human error and insufficient guardrails.
”I don’t think we’re going to see models running around and hacking people anytime soon,” he said. “But we do need to take these things incredibly seriously.”