AI Security · Funding Agentic AI

General Analysis Raises $10M in Seed Funding to Build the Security Infrastructure Agentic AI Has Been Missing

iTech360Hub | 5 min read | Seed Round

In March 2026, a single adversarial AI agent walked up to 50 live customer service bots and, in roughly three minutes per target, convinced them to hand over more than $10 million in fabricated perks — million-dollar gift cards, years of free services, whatever it could extract. Of 55 bots tested, only five refused. This was not a theoretical exercise. It was a stress test run by General Analysis, a San Francisco startup that has now raised $10 million in seed funding to build the security infrastructure that agentic AI urgently needs.

The round was led by Altos Ventures, with participation from 645 Ventures, Menlo Ventures, Y Combinator, and additional strategic investors and angels. Founded in 2025 by former researchers from NVIDIA, Cohere, and DeepMind-affiliated institutions, General Analysis is already working with enterprise customers in support and finance — companies whose products and workflows are used by hundreds of millions of users — and is targeting what it sees as one of the most consequential and least-solved problems in enterprise technology today.

$10M
seed round led by Altos Ventures with top-tier VC participation
50/55
live AI agents manipulated in adversarial stress test — only 5 refused
3 min
per target to extract $10M+ in fabricated perks per adversarial test

"We hear from security teams that they want agents that are secure by design. What that often turns into in practice is a stack of isolation layers and ad hoc context restrictions that makes a system feel more controlled. Those measures either fail to eliminate the underlying vulnerability or constrain the agent enough to limit its usefulness. The problem is that feeling safer and being safer are not the same thing."

— Rez Havaei, CEO & Co-Founder, General Analysis

Why Agentic AI Demands an Entirely New Security Discipline

Traditional cybersecurity is built for predictable systems. Engineers read code, trace behaviour, and reason about outcomes in advance. Agentic AI does not follow that script. These systems take in new inputs, generate novel responses, and take actions that shift unpredictably from one moment to the next — a property known as non-determinism. Their failures cannot be anticipated by reading code alone, which means the existing security playbook is structurally insufficient for the task.

General Analysis was built on the conviction that securing AI agents is a genuinely distinct technical discipline — one that requires purpose-built methods. The company combines adversarial evaluations with a broad defensive toolkit to identify the specific failure modes present in each deployment, measure the effect of different interventions, and help enterprises configure defences that actually reduce risk without crippling agent performance.

Security teams face a stark dilemma: lock agents down too tightly and they stop being useful; open them up fully and the risks become impossible to measure. General Analysis is building the empirical framework to resolve that dilemma — helping enterprises understand exactly where their systems fail, under what conditions, and how to address it without sacrificing capability.

The Empirical Approach: Measure Failure, Then Drive It Down

At the heart of General Analysis's methodology is a core philosophical stance: security for AI systems is an empirical problem, not a policy problem. No set of rules or restrictions can prove an agent is safe. What teams can do — and what General Analysis helps them do systematically — is measure how often an agent fails under adversarial conditions, how severe those failures are, and which interventions actually move both numbers down.

"Our position is that security for AI systems is an empirical problem. It has to be grounded in rigorous measurement of how those systems behave under realistic and adversarial conditions. You cannot prove an agent is safe. You can only measure how often it fails, and how badly, and drive both numbers down."

— Maximilian Li, Co-Founder, General Analysis

The "Lethal Trifecta" — A Real-World Vulnerability Already Uncovered

General Analysis's research has already produced findings that resonated far beyond the company's own customer base. Last summer, the team demonstrated how a widely used Supabase integration inside Cursor — a popular AI code generation agent — could be exploited through a single malicious support ticket. The ticket tricked an internal agent into leaking a complete private database, without any direct access by the attacker.

Simon Willison, the British engineer widely credited with coining the term "prompt injection," cited the finding as a textbook case of what he calls the "lethal trifecta" — the dangerous combination of an AI system that simultaneously holds private data, ingests untrusted content, and can communicate externally. It is a pattern that is increasingly common in enterprise agentic deployments, and one that traditional security tooling is ill-equipped to detect before deployment.

The "Lethal Trifecta" of Agentic AI Risk
1

Access to private data — the agent holds or can retrieve sensitive internal information.

2

Ingestion of untrusted content — the agent processes inputs it cannot fully verify, such as user messages, tickets, or external documents.

3

Ability to communicate externally — the agent can take actions or send outputs beyond the system boundary, creating a path for data exfiltration.

The Founding Team: Research Pedigree Meets Real-World Mission

General Analysis was founded by three researchers whose backgrounds span the most consequential labs and institutions in modern AI:

Rez Havaei
CEO & Co-Founder

Former AI researcher at Cohere and NVIDIA. Leads the company's overall strategy and enterprise customer relationships.

Maximilian Li
Co-Founder

AI safety researcher from Harvard University. Leads the company's adversarial evaluation methodology and empirical security framework.

Rex Liu
Co-Founder

Machine learning researcher from Caltech. Leads the technical development of General Analysis's defensive tooling and platform infrastructure.

"The rise of agentic systems requires a fundamentally different security mindset centred on continuous adversarial testing rather than static rules."

— Tae Yoon, Partner, Altos Ventures
What General Analysis Delivers
Adversarial Agent Testing Empirical Security Measurement Prompt Injection Defence Pre-Production Stress Testing Defensive Tooling & Controls Enterprise AI Security Infrastructure

Key Takeaways

1

General Analysis has raised a $10M seed round led by Altos Ventures — with Y Combinator, Menlo Ventures, and 645 Ventures participating — to build dedicated security infrastructure for agentic AI systems.

2

Its adversarial stress test in March 2026 showed that 50 out of 55 live AI agents could be manipulated into granting over $10 million in fabricated perks — demonstrating in concrete terms how vulnerable deployed agentic systems can be.

3

The company's founding thesis — that AI security is an empirical discipline, not a policy one — drives an approach centred on adversarial simulation, measurement, and targeted defensive tooling rather than static rules or isolation layers.

4

Founded by researchers from NVIDIA, Cohere, Harvard, and Caltech, the company is targeting $2M ARR within 12–18 months before pursuing a Series A — with enterprise customers in support and finance already engaged.

The $10 million seed raise is a signal of broader market recognition that agentic AI security is no longer a future problem — it is a present one. As enterprises move autonomous agents into customer support, finance, internal operations, and beyond, the gap between how quickly these systems are being deployed and how rigorously they are being secured is widening by the day. General Analysis is positioning itself as the infrastructure layer that closes that gap — not through the comfort of rules and restrictions, but through the rigour of empirical measurement.

For enterprises deploying or planning to deploy agentic AI systems, the message from this funding round is clear: adversarial testing is no longer optional — it is the new baseline for responsible AI deployment.

Tags
Agentic AI Security Seed Funding Adversarial Testing Prompt Injection AI Infrastructure Enterprise AI Y Combinator AI Governance