# $280 Million Later, the Company That Tracked Extremists Online Is Now Hardening Your AI Models


The rebrand is telling. ActiveFence spent years crawling the internet's worst corners — jihadist forums, coordinated inauthentic behavior networks, child safety violation pipelines — building what the company calls Rabbit Hole: a proprietary archive of nearly a decade's worth of how people systematically abuse digital platforms at scale. Now the company has a new name, Alice, a fresh $140 million in funding, and a thesis that the same abuse playbooks being run against social media giants are about to be run against your enterprise AI deployment.


They're probably right.


## The Problem That $280 Million Is Trying to Solve


The pitch is deceptively simple: AI models ship before anyone fully understands how they break. Companies spend months on capability benchmarks and alignment evals, then push to production, and within weeks security researchers — or actual adversaries — find prompt injection vectors, jailbreaks, and indirect manipulation paths that nobody anticipated.


Alice's model is to embed with AI developers *before* release, running adversarial simulations against foundational models to expose erratic behaviors. Mock malicious inputs, complex agentic task chains, adversarial context injection. Then, when models go live, continuous red-teaming and what Alice calls dynamic runtime guardrails — letting organizations configure custom behavioral policies, monitor traffic in real time, and simulate breach scenarios against their specific deployments.


The funding round was led by Apax Digital Funds, with a roster of VCs that reads like a who's who of enterprise and deep tech: MoreTech, Phoenix Financial, Resolute Ventures, Grove Ventures, CRV, Highland Europe, Vintage Investments, Norwest, NFX, Claltech. This is not seed money chasing an unproven concept. At $280 million total raised, someone has done serious diligence and decided AI model security is a genuine market, not a feature.


## Rabbit Hole Is the Actual Competitive Moat


Most AI security companies are trying to build threat libraries the hard way — scraping forums, running red-team exercises, cataloging known attack patterns. Alice has something different, and it's worth understanding why.


When ActiveFence was protecting major social platforms from coordinated manipulation, it was sitting at the firehose. Billions of interactions. Every known and novel technique that nation-state actors, criminal networks, and fringe ideological movements ran to subvert platform safety systems — the company catalogued it. That database is now being applied to a different target: generative AI.


The implication is that Alice can show a model things it has never seen before — not hypothetical attack strings dreamed up in a lab, but documented real-world manipulation techniques refined by actual threat actors over years of adversarial iteration. That's a fundamentally different training signal than what most red-teaming shops can offer.


CEO Noam Schwartz put it bluntly: "There are infinite ways to break an AI, and you can't defend against something you've never seen." That quote sounds like marketing copy, but it's operationally accurate. The attack surface for a sufficiently capable language model is essentially unbounded. The model that generates your sales pitch can also be walked into generating something it was never supposed to. The question is whether you find those paths before your adversaries do.


## The Democratization Gap Is Real and Getting Worse


Here's what Alice and most of the industry press releases won't say directly: the barrier to conducting sophisticated prompt injection and jailbreak attacks has collapsed. What required a researcher with genuine ML knowledge two years ago can now be executed by someone with access to community forums and a few hours of trial and error.


Meanwhile, enterprise AI deployments are accelerating. Every major vendor is pushing agentic workflows, AI assistants with real system access, and automated decision pipelines. The attack surface is expanding faster than the defense ecosystem is maturing.


This isn't a hypothetical risk. We've already seen indirect prompt injection demonstrated against major AI assistants, jailbreak techniques get packaged into accessible toolkits, and agentic systems get manipulated into taking unintended actions by poisoned data in their context windows. The next evolution isn't more sophisticated attacks — it's more widespread ones.


That's the market Alice is selling into. And judging by the check sizes, enterprise buyers are getting the message.


## Who Needs to Pay Attention


If you're a CISO at an organization that has deployed — or is evaluating — AI systems with access to internal data, customer interactions, or automated workflows, Alice's funding round is worth reading as a signal, not a press release.


Runtime guardrails for AI systems aren't a nice-to-have. They're the functional equivalent of a WAF for an era when your application logic is a language model that can be socially engineered. The enterprises that will get burned in the next 24 months are the ones treating LLM security as a model selection problem rather than an ongoing operational one.


The company's 150-person research division — collaborating directly with major model developers — also points at a structural gap that most organizations can't fill internally. You don't have 150 people dedicated to breaking AI systems. Alice does.


---


## HackWire Analysis


The ActiveFence-to-Alice rebrand is more strategically significant than most coverage is treating it. ActiveFence built its reputation — and its Rabbit Hole dataset — doing unglamorous, high-stakes content moderation work for platforms that would rather not talk publicly about the scale of abuse they're managing. That work was operationally invisible but technically demanding: identifying manipulation campaigns before they metastasize, tracking how adversarial actors iterate their techniques, building classifiers that stay ahead of evasion.


That's exactly the capability set you need for AI model security. The threat actors probing LLMs today are running the same fundamental playbook as the ones who ran coordinated influence operations against social platforms — probe for weaknesses, iterate at scale, share successful techniques across communities. Alice recognized early that its archive of real-world adversarial behavior was a transferable asset, not just a trust-and-safety product.


Compare this to the other major AI security raises this year — Mindgard's $30M, Xpander's $7.5M — and Alice's $140M signals something different: institutional capital is betting that AI model security becomes a permanent enterprise budget line, not a consulting engagement. The Apax Digital Fund involvement in particular suggests this is being positioned as infrastructure-layer spending, not a discretionary tool.


What the coverage is missing: the agentic AI threat vector. Most AI security discussion still centers on chatbot jailbreaks. The real frontier is agentic systems — AI that takes actions, calls APIs, reads files, executes code. Indirect prompt injection in an agentic context doesn't just produce bad text; it can exfiltrate data, manipulate workflows, and chain into infrastructure access. Alice's work stress-testing "complex agentic tasks" suggests they see this too. Defenders should be reading that as the threat model to prepare for in the next 18 months, not chatbot jailbreaks from 2023.


The practical takeaway for security teams: budget for AI runtime monitoring the same way you budget for endpoint detection. The question isn't whether your deployed models will face adversarial inputs. It's whether you'll know when it happens.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)