Alice Raises $140 million to Expand AI Model Defenses and Enterprise
The company, previously known as ActiveFence, has raised a total of $280 million from investors. Alice Raises $140 million to Expand AI Model Defenses and.
By Dillip Chowdary • Aug 25, 2026 • Source: SecurityWeek
What happened
Alice, the AI trust and safety company formerly known as ActiveFence, has raised $140 million in a new funding round, bringing its total capital raised to $280 million. The raise signals continued investor appetite for infrastructure that sits between AI models and the real-world harm those models can enable or amplify.
This piece examines the mechanics of the round, the strategic timing, the stated uses of the capital, where Alice sits relative to its competitors, and the questions that remain unanswered for builders evaluating whether its guardrail infrastructure belongs in their stack. It is aimed at engineers, security architects, and product leads who are currently deploying or evaluating large language model systems in enterprise environments.
Alice raised $140 million, which doubles the company's total funding to $280 million. The company is the renamed version of ActiveFence, a trust and safety firm that originally built detection and policy enforcement tooling for platforms contending with user-generated content. The rebrand to Alice reflects a repositioning toward AI-native defense rather than purely reactive content moderation. The round was reported by SecurityWeek, though the lead investor or investors have not been named in the available source material, and neither has the round's designation — whether Series C, D, or another label — been confirmed publicly.
How it works
The $140 million figure is notable on its own because it matches the total raised in all prior rounds combined, based on the $280 million cumulative figure. That doubling pattern suggests either a significant valuation step-up or a compression of previous rounds into a tighter timeline. Neither a valuation figure nor a post-money cap table breakdown has been disclosed, which limits what can be said with confidence about investor returns expectations or dilution at the current stage.

Enterprise demand for AI guardrail infrastructure has accelerated sharply as regulated industries — financial services, healthcare, legal — move from AI pilots into production deployments. Those environments carry legal and compliance exposure that generic model outputs cannot absorb without some form of interception layer. Alice's timing aligns with that transition from experimentation to accountability, where procurement decisions are moving from developer tools budgets into security and GRC budgets.
Why it matters
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
The rebranding from ActiveFence also matters for context. ActiveFence built its reputation on detecting policy violations at platform scale, which gave it a large dataset of adversarial behavior patterns. Alice's pitch appears to be that this adversarial pattern library, built from human content moderation at scale, translates into more robust AI model defenses than competitors starting from scratch with synthetic red-team data. Whether that translation holds up empirically is something buyers should validate independently, but it is the evident foundation for why this raise is happening now rather than earlier.
The stated use of funds covers expansion of AI model defenses and enterprise guardrails. That phrasing encompasses two distinct product surfaces: defenses that wrap or probe the model itself, and guardrails that govern model outputs within a specific enterprise deployment context. The first category typically includes red-teaming tools, prompt injection detection, and jailbreak monitoring. The second includes output filtering, role-based access controls over model capabilities, and audit logging for compliance purposes.
Builders evaluating Alice should clarify which of these two surfaces the capital is primarily funding, since the engineering and integration implications differ substantially. Model-level defenses often require access to model internals or at minimum to the inference pipeline, which constrains which deployment architectures they can support. Guardrail layers, by contrast, tend to sit at the API boundary and are generally more deployment-agnostic. Confirming which surface Alice prioritizes will determine whether it fits a given team's threat model.
Who is affected
Alice enters this phase of growth against a field that includes both venture-backed startups and features shipping inside the major model providers themselves. OpenAI, Anthropic, and Google DeepMind each ship some form of built-in safety layer, and each has published alignment and red-team research that informs those layers. Third-party guardrail vendors have to make a credible case that they provide meaningfully better or more customizable coverage than what the model provider includes by default.
Other named competitors in this category include Lakera, Protect AI, and Robust Intelligence, all of which have raised capital targeting similar enterprise use cases. Alice's differentiation, based on the ActiveFence heritage, is depth of adversarial pattern data from real-world content moderation rather than synthetic datasets. The question for buyers is whether that historical pattern data is continuously updated to reflect AI-specific attack surfaces, which evolve on a different cadence from traditional content policy violations.
What to watch next
The source material does not name the investors, the round designation, or a valuation. For a $140 million raise, the absence of named investors is unusual and worth noting. Institutional lead investors typically expect recognition in funding announcements, so the omission may indicate a strategic or undisclosed investor, a press embargo on specific participants, or simply that the full announcement has not been published at the time of this reporting.
For builders specifically, the critical unresolved question is integration path. Alice's enterprise guardrail positioning implies some form of SDK, API gateway, or proxy layer, but no specific integration documentation or platform compatibility list is available from this announcement. A team evaluating Alice should request a technical architecture overview covering latency overhead, data residency handling, and whether the system requires the model provider to be in the loop or can operate independently at the application layer.
Developer Action Items
- ☐ Map where Alice Raises million Expand sits in your stack (SDK, API key, billing, data-processing addendum).
- ☐ Hold the $140 million figure to the primary report; do not brief a number that is not on the record.
- ☐ Hold non-urgent migrations until the integration or use-of-proceeds roadmap is public — day-one coverage is not a ship signal.
- ☐ If you are mid-contract or mid-POC, ask the vendor what changes for existing customers this quarter.
- ☐ Write the single decision this forces: stay, dual-source, or exit.
Advertisement