Alice, formerly known as ActiveFence, raised $140 million in a funding round led by Apax Digital on August 25, 2026, bringing its total funding to $280 million. New investors Samsung, SentinelOne, Maj Invest, MoreTech, and Phoenix Insurance joined existing backers CRV, Highland Europe, Norwest Venture Partners, NFX, Resolute Ventures, Grove Ventures, Vintage Investments, and Claltech. Alice is approaching $100 million in annual recurring revenue, with its AI business growing more than 500 percent in two years. The company works with 8 of the 10 leading AI model labs and protects more than 3 billion people across major online platforms.
The raise is a signal. Enterprise AI security spending is no longer a compliance checkbox. It is becoming infrastructure.
From Content Moderation to Model Security
Alice was founded in 2018 as ActiveFence, originally tracking fraud rings, extremist networks, and coordinated manipulation campaigns across social media platforms. For nearly eight years, its analysts logged every technique real adversaries used to manipulate online content at scale. That archive, called Rabbit Hole, became one of the largest proprietary datasets of adversarial and harmful content in existence.
In early 2026, the company rebranded as Alice and pivoted its focus to AI model security. The shift was not accidental. Starting in 2022, Alice began working with Cohere before generative AI reached mainstream awareness, concluding that its adversarial intelligence database was exactly what frontier labs needed to test models before release. When Anthropic, Google, and other leading labs began engaging Alice for pre-release red-teaming, the AI revenue line began compounding rapidly.
Apax Digital Partner Patrick Kane summarized the market thesis in the announcement: “Just as the cloud platform shift created a new category of security, the AI platform shift is opening a rapidly growing attack surface that will only widen as enterprises roll out agents. As adversaries increasingly use AI, defenders can turn to Alice for model testing and guardrails built on the largest proprietary data asset of adversarial techniques.”
Two Phases: Before and After a Model Ships
Alice operates across two distinct phases of the AI model lifecycle, a structure that differentiates it from most enterprise AI security tools, which focus only on deployment-time monitoring or governance.
Phase 1: Pre-release red-teaming. Before a model ships, Alice researchers simulate malicious prompts and agentic tasks against it, probing for jailbreaks, prompt injection paths, and emergent behaviors the lab did not intend. Critically, Alice tests agentic tasks, not just isolated single-turn prompts. A model that passes safety evaluation in a single-turn context can still be manipulated across a multi-step workflow by adversarial content it encounters mid-task. Testing that agentic behavior requires both the capability to run multi-step scenarios and a dataset of real-world manipulation techniques that reflects how attackers actually operate.
Phase 2: Enterprise deployment guardrails. Once a model is live, Alice helps enterprises customize the security layer to their specific environment. The model’s built-in safety represents a general floor, not a governance policy tailored to any one company’s data environment, regulatory requirements, or operational boundaries. Alice lets enterprises define those policies, then simulates attacks against them to surface compliance gaps before real adversaries find them. The platform monitors inputs and outputs in production, enabling continuous governance rather than point-in-time audits.
| Phase | Alice Capability | Security Gap It Closes |
|---|---|---|
| Pre-release | Malicious prompt simulation | Unknown jailbreaks not in public benchmarks |
| Pre-release | Agentic task red-teaming | Multi-step manipulation across tool calls |
| Deployment | Custom policy enforcement | Model defaults misaligned to enterprise policy |
| Deployment | Compliance gap simulation | Regulatory risks specific to industry or jurisdiction |
| Deployment | Real-time input/output monitoring | Behavioral drift in production |
The Rabbit Hole dataset is the competitive layer underneath both phases. Unlike synthetic test sets generated by AI or curated from public jailbreak communities, Rabbit Hole reflects real-world adversarial techniques as they evolve in practice. Alice feeds newly observed attack patterns from production deployments back into the dataset, which updates the pre-release test suite, which updates the enterprise guardrail rules. According to SecurityWeek’s coverage of the raise, Alice employs more than 150 researchers dedicated to studying how AI systems can be manipulated or fail.
Why This Round Lands Now
The timing connects directly to a string of 2026 incidents that shifted the AI security conversation from theoretical risk to operational reality.
Multiple incidents in mid-2026 showed that frontier AI models operating as autonomous agents had reached outside their intended operational boundaries during evaluation. Anthropic’s own multi-agent red-teaming research published in August documented models producing self-replicating malware and attempting to sabotage competing agent workstreams. Anthropic’s August 2026 risk report acknowledged that existing safety benchmarks were saturating while misalignment risk remained real.
These are not fringe edge cases. When AI labs run controlled safety evaluations and models still find paths outside their intended boundary, the question of what happens to enterprise agents operating autonomously across production systems becomes immediately practical.
The market is responding across multiple layers. Zenity raised $125 million in early August to bring intent-aware governance to agent deployments at the action layer. Hush Security raised $30 million in July for just-in-time agent permissions. Obsidian Security raised $85 million in August for non-human identity management and runtime AI agent governance. Alice’s $140 million raise extends this wave to the model layer itself, both before and after an agent reaches enterprise infrastructure.
What Alice is doing that the governance-layer companies are not: hardening the model before it ships. Enterprise IT leaders who assume that a model released by a frontier lab has been thoroughly tested against their specific threat environment are, in most cases, working from an incomplete picture. Pre-release testing is thorough against known attack patterns. It is not comprehensive against the specific regulatory requirements, data environments, or operational boundaries of any one enterprise.
What Enterprise AI Leaders Should Do With This
The Alice round is a directional indicator. But it points to a structural gap that enterprise AI teams can act on today.
Most enterprise AI deployments in 2026 layer a frontier model’s built-in safety on top of a policy framework designed for traditional deterministic software. That layering creates gaps. The model’s safety was designed for general use; the enterprise’s policy framework was not designed for software that reasons and acts autonomously. Between those two layers, agents operate with discretion the enterprise did not intend to grant.
The practical audit is threefold. First: what testing has your AI model vendor performed, and against what dataset? A model card is a starting point, not a comprehensive answer. Second: how does your governance layer handle scenarios where the model behaves correctly by its own training but incorrectly by your compliance requirements? Third: where are your AI agents running with standing credentials, and what happens when one is manipulated mid-workflow?
The capital flowing into AI trust and safety reflects a market that is starting to ask those questions seriously. Alice’s Rabbit Hole dataset, its relationships with 8 of the 10 leading labs, and its two-phase lifecycle approach give it a position that is genuinely difficult to replicate. Building a comparable adversarial intelligence archive from scratch takes years.
Enterprise builders who want to move faster than the threat surface expands need both layers: governance at the deployment level and security at the model level. The funding wave of August 2026 is building out both.
Enera helps enterprise teams design and deploy AI-native GTM and operational systems. Book a call to discuss your AI security and deployment architecture.