# The AI Red-Teamers: Mindgard's $30M Bet That Enterprise Security Teams Can't Audit Their Own Models


When an automated security scanner found a zero-day code execution flaw inside Cursor IDE — the AI-powered coding tool that hundreds of thousands of developers have switched to — it landed with a particular irony. The tool helping developers write code faster had a vulnerability that could let attackers execute arbitrary code on their machines. The scanner that found it wasn't a human researcher burning midnight oil. It was Mindgard's platform, doing in minutes what a traditional pentest would take weeks to replicate.


That's the pitch Mindgard is now scaling with a $30 million Series A, led by Album VC and joined by Karma Ventures alongside earlier backers including .406 Ventures, Atlantic Bridge, IQ Capital, and Lakestar. Total raised: roughly $42 million. The company, spun out of Lancaster University in 2022 and operating between London and Boston, has built what it describes as an automated AI security and red-teaming platform — one that doesn't just probe for traditional CVEs but maps what its team calls the "psycho-technical attack surface" inside AI agents, models, and applications.


## What That Actually Means


Traditional vulnerability scanners look for misconfigurations, unpatched dependencies, exposed credentials. AI systems introduce a different threat class entirely. You can't run a CVSS scan against a large language model and call it secure. The attack surface includes prompt injection, jailbreaks that strip safety guardrails, adversarial inputs that cause model hallucination at scale, data poisoning through fine-tuning pipelines, and model extraction attacks that let adversaries steal proprietary systems by querying them into submission.


Mindgard's platform tries to automate the offensive side of that equation — continuously probing AI deployments the way a sophisticated red team would, then surfacing runtime protections to stop the attacks it identifies. According to the company, the system has uncovered more than 150 vulnerabilities across major AI products. Alongside the Cursor zero-day, the platform has flagged security defects in Google Antigravity and ChatGPT. Those aren't obscure research targets — they're production systems that enterprises are integrating into workflows right now.


## Why the Money Is Moving Now


Mindgard's raise lands in the middle of an unmistakable investment wave. Corma pulled in $60 million for defensive AI security. Oligo raised $60 million for runtime security. Zenity closed a $125 million Series C. Obsidian Security hit a $1.1 billion valuation at $85 million raised. The thesis driving all of it: organizations are deploying AI systems faster than they can reason about the risk, and the security tooling built for traditional software simply doesn't translate.


That's not a PR talking point — it's a structural problem. Most enterprise security teams don't have researchers who specialize in adversarial machine learning. Red-teaming an AI agent requires understanding how the model processes context, where system prompts can be overridden, how retrieval-augmented generation pipelines can be poisoned, and what happens when a multi-agent workflow trusts outputs from a compromised upstream model. The skill gap is real, and it's not closing quickly. The VC thesis is that companies will pay for automated expertise they can't hire.


Mindgard CEO James Brear framed it plainly: "We don't just automate attacks. We operationalize expertise, turning the knowledge of leading AI security researchers and offensive security practitioners into the capabilities every enterprise needs to secure their AI." That language — operationalizing expertise — is doing real work. It acknowledges that the product is essentially a compressed and deployable version of what a specialist red team does, available to organizations that can't staff one.


## Who's Actually Exposed


The company's target sectors tell their own story: financial services, healthcare, pharmaceutical, gaming, digital services, semiconductors. These aren't random. They're industries either already under heavy regulatory scrutiny, handling data that makes them attractive targets, or deploying AI at scale in ways that have direct operational consequences when things go wrong.


Financial services firms integrating LLMs into customer service, document processing, and fraud detection workflows have created novel attack surfaces almost overnight. A prompt injection attack against a customer-facing AI assistant that has read access to account data isn't a theoretical concern — it's a category of risk that didn't exist three years ago. Healthcare and pharma raise the stakes further: AI systems touching clinical decision support or drug discovery pipelines aren't just business risks if they're manipulated; they're patient safety risks.


Gaming is the interesting outlier on that list. Online gaming platforms are already high-value targets for credential theft and fraud. As AI-driven systems handle matchmaking, content moderation, and in-game economies, they become additional attack vectors — and ones that often receive less rigorous security review than the core platform.


## The Unflattering Truth About AI Deployment Today


Most enterprises deploying AI systems are doing so without adequate security assessment. The pressure to ship is intense. The competitive narrative around AI adoption rewards speed. Security reviews slow things down, and AI-specific security expertise is genuinely hard to find. The result is that a meaningful chunk of production AI deployments have never been red-teamed at all.


Mindgard's fresh funding will go toward scaling product, engineering, sales, and marketing — standard Series A usage. The more interesting question is whether the automated approach holds as AI systems grow more complex. Multi-agent architectures, where individual LLMs hand off tasks to one another and may trust each other's outputs by default, create attack paths that are harder to enumerate. A red-teaming tool that excels against single-model deployments may need significant evolution to keep pace with the agentic systems being deployed now.


---


## HackWire Analysis


The AI security funding wave is real, but it's worth being clear about what problem is actually being solved — and what isn't.


Mindgard's 150+ vulnerability finds across production AI systems is the most credible signal in this announcement. That's not a benchmark score or a research paper finding; it's evidence that live deployments being used by enterprises right now have security problems that weren't caught before shipping. The Cursor IDE zero-day is the headline detail because it's concrete and specific — an AI-native developer tool with a code execution flaw is the kind of thing that should have been caught before GA release, and wasn't.


The broader pattern here connects to a failure mode we've seen repeatedly in software security: categories of risk that don't fit existing tooling get systematically underassessed until something goes wrong publicly. Web application firewalls didn't exist until SQL injection and XSS became epidemic. Cloud security posture management didn't take off until S3 bucket leaks became a weekly occurrence. AI security tooling is following the same arc, but with less time. The window between "AI widely deployed in production" and "AI-specific attacks causing real damage at scale" is almost certainly shorter than the window we had with web apps in 2005.


The sector targeting — especially healthcare and pharmaceutical — should be read as a warning. These are industries where AI adoption is moving fast under competitive pressure, regulatory frameworks for AI security are still forming, and the consequences of a compromised AI system aren't just financial. A pharmaceutical company whose AI-assisted drug discovery pipeline is quietly poisoned by a data poisoning attack may not discover the problem until it's very expensive to unwind.


Defenders who want to get ahead of this should be asking three questions: What AI systems are in production in our environment and what data do they have access to? Have any of those systems been red-teamed by someone with AI-specific expertise? And for agentic workflows specifically — what happens if one agent in our pipeline is fed adversarial inputs by a compromised upstream source?


Most security teams can't answer all three right now. That's the market Mindgard is walking into.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)