Alice Raises $140 Million to Test AI Systems for Weaknesses Before Criminals Find Them

A company that tries to break AI models on purpose, so real attackers cannot, has secured fresh funding to expand that work to more businesses.

ThreatVectr Newsdesk· 4 min read
A sleek modern server room bathed in cold blue light, rows of densely packed rack hardware receding into the distance, subtle green status LEDs dotting the fram
Share

Key points

  • Alice, an AI security company, raised $140 million in a funding round announced Tuesday, 13 May 2025.
  • The raise brings Alice's total funding to $280 million since the company was founded.
  • Apax Digital Funds led the round, with ten other investors participating.
  • Alice employs more than 150 specialists whose job is to find ways to trick, manipulate, or destabilize AI systems before bad actors do.
  • The company's threat database, called Rabbit Hole, was built over nearly a decade by tracking online fraud and manipulation campaigns.

Most software gets tested before it ships. AI models, though, can be broken in ways that ordinary software cannot: feed them the right carefully worded sentence and they may ignore their own rules, reveal private information, or do things their makers never intended. Alice, an AI security company with offices in New York and Tel Aviv, exists to find those weaknesses first.

On Tuesday the company announced it had raised $140 million, pushing its total funding to $280 million. The round was led by Apax Digital Funds, with participation from MoreTech, Phoenix Financial, Resolute Ventures, Grove Ventures, CRV, Highland Europe, Vintage Investments, Norwest, NFX, and Claltech.

What does Alice actually do?

Before an AI product goes public, Alice's team fires hostile inputs at it. These include prompt injection attacks, where a cleverly worded instruction tricks the model into ignoring its safety rules, and jailbreak attempts, where users phrase requests in ways designed to get the model to produce content it should refuse.

Think of it as hiring a locksmith to try every possible way to break into your house before you move in. If they find a weakness, you fix the lock. If they do not, you have more reason to trust it.

Once an AI system is live and serving real users, Alice offers continuous red-teaming (ongoing, structured attempts to find fresh weaknesses) and real-time guardrails that flag unusual activity as it happens. Organisations can set their own rules and run simulated attacks against their own systems.

Underpinning all of this is a proprietary database the company calls Rabbit Hole. Built over roughly a decade by studying digital fraud, extremist content, and manipulation campaigns at scale, it gives Alice's platform a reference library of harmful content patterns to detect and block.

Should businesses using AI care about this?

Yes, and soon. AI is moving faster than the defences around it.

"There are infinite ways to break an AI, and you can't defend against something you've never seen," said Noam Schwartz, Alice's chief executive and co-founder. "We are very quickly democratising capabilities before we've democratised the defences. This round is about closing that gap."

Alice was previously known as ActiveFence before rebranding. The new funding will go toward expanding the platform, hiring more researchers, and reaching more enterprise customers.

Detail Figure
New funding raised $140 million
Total funding to date $280 million
Lead investor Apax Digital Funds
Research specialists employed 150+
Years building Rabbit Hole database ~10

For ordinary people, the practical upshot is straightforward. Every AI tool a business uses to handle customer queries, process documents, or make decisions is a potential target. Companies that skip security testing are trusting that no one will ever ask their AI the wrong question in the wrong way. Some will be wrong about that.

Common questions

Does this affect me if I just use AI tools at work?

Indirectly, yes. If the AI product your employer uses has not been tested for these weaknesses, a criminal could potentially manipulate it into leaking data or behaving dangerously. Asking your IT team whether your company's AI tools undergo security testing is a reasonable question.

What is a jailbreak in plain terms?

A jailbreak is when someone crafts a clever message that convinces an AI to ignore its own rules, for example getting a content-filtering chatbot to produce harmful output by disguising the request as a fictional story or roleplay scenario.

© 2026 Threat Vectr