LONDON, 15 AUG 2026 — Mindgard closed a US$30 million Series A on 12 August. What it sells is a way to find the AI systems a company did not know it had, attack them on purpose, then watch them at runtime.
That product description is the news. A category has formed around the premise that a deployed AI system is an attack surface requiring its own tooling, and investors are funding it as a separate line item rather than as a feature of existing security products.
The round
Karma Ventures joined, alongside existing backers .406 Ventures, Atlantic Bridge, IQ Capital and Lakestar. The company is headquartered in Boston and London and grew out of more than a decade of AI security research at Lancaster University in the United Kingdom.
The platform covers shadow AI discovery, AI red teaming and runtime protection, and the money is going into product, engineering, sales and marketing.
Read the product list, not the round
Each of those functions addresses a problem that was barely on the radar eighteen months ago. The first is the most telling.
Shadow AI discovery exists because organisations have lost track of their own AI usage. Staff wire a model into a workflow, a team ships an assistant, a vendor quietly adds a feature, and none of it passes through procurement. A security team cannot protect what it cannot enumerate. That discovery is now a sellable product confirms how widespread the problem has become.
AI red teaming is penetration testing for model behaviour rather than for infrastructure. The target is not a port; it is whether the system can be induced to do something it should not, which is a different discipline requiring different people.
Runtime protection exists because the first two steps are insufficient. Pre-deployment testing only shows how a model behaved on your test set; it does not bind its behaviour in production against an unbounded and adversarial input space.
The pattern around the raise
The individual raise matters less than the pattern it sits in.
Between 15 July and 4 August, twelve cybersecurity companies announced qualifying funding deals totalling roughly US$1.09 billion. Seven of the twelve directly protect AI agents, AI-enabled applications or non-human identities.
That seven-out-of-twelve figure is the significant one. More than half of recent security funding is going to a category that barely existed as a procurement line two years ago, and the composition of that spending — agents, AI applications, non-human identities — shows where the market believes risk has moved.
Non-human identity is the quiet one in that list. When agents act on their own credentials, calling tools and other services without a person in the loop, the population of things holding permissions in an enterprise grows quickly and is not managed by anything built for staff joiners and leavers.
What the market has decided, and what it has not
Capital allocation is a claim about the future, and this one claims that AI security is a distinct discipline with its own tooling rather than a feature the incumbent platforms will eventually absorb.
That claim is contestable. The history of security markets is littered with categories that looked distinct, funded a generation of startups, and were then acquired into platforms: endpoint, email, cloud posture, identity governance. If AI security follows the same arc, today's specialists are building acquisition targets rather than durable businesses, which is a perfectly good outcome for their investors and a worse one for a customer choosing a long-term supplier.
This category might prove different if AI red teaming requires expertise that does not transfer well — the kind that comes from a research group rather than a product roadmap. Mindgard's provenance in a decade of university research is an argument for exactly that, and it is the most interesting thing on its balance sheet.
The uncomfortable question about testing
The entire category faces a fundamental limitation, and it is not a knock on any single company.
Red teaming a model gives you a result about the prompts you tried. Unlike a port scan, which enumerates a finite space, the input space of a language model is unbounded and an adversary is actively searching it. A clean red-team report is evidence of effort and a weak claim about safety.
This is why runtime protection sits in the product list. It is also why a buyer should ask what the runtime component actually blocks, not just how many attack categories the testing covers. The second number is easier to market and tells you less.
What this means for buyers here
Two practical notes for organisations in this region, and the first costs nothing.
Before buying a discovery tool, try it yourself. Most organisations here have not attempted to enumerate their own AI usage, and the exercise often finds enough to change the internal conversation: assistants wired into customer data, models called from scripts nobody owns, vendor features enabled by default. If the list is short, you do not need a platform. If it is long, you now have a specification instead of a sales call.
Second, be careful about where the testing expertise sits. Regional deployments frequently run in Bahasa Indonesia, Malay, Thai, Vietnamese or Chinese, and a red-teaming methodology validated in English does not automatically transfer. Model safety behaviour is known to vary across languages, and a vendor that cannot describe how it tests in the languages you actually deploy in is selling you assurance about a different system.
What we could not establish
Mindgard's revenue, customer count, or growth, none of which were disclosed. Nor the valuation the round was raised at, which is the figure that would say most about how the market prices this category.
Mindgard did not disclose several other details, including what its runtime protection enforces and at what layer, how its red teaming is evaluated for coverage, whether any of it has been independently assessed, and whether the company operates in this region. Nor is it clear how the twelve-deal funding tally was scoped; without published criteria, the US$1.09 billion figure is best read as indicative.
What to watch
The clearest test is an acquisition. If an incumbent platform buys one of these companies, that settles whether AI security is a category or a feature, and it settles it by transaction rather than argument.
Watch also for a published red-teaming methodology that others can run. Shared, reproducible evaluation is what turned penetration testing from a craft into a profession, and this field does not have it yet.
The third thing to track is non-human identity governance. If agents holding their own credentials become the dominant risk, the tooling that manages them will not stay a bullet point on somebody else's platform.