Alex Vainer
Life in the AI era: Israel and beyond

Israel Is Building AI’s Safety Layer

Machine Checkpoint — an autonomous delivery robot halted at a blue-and-white barrier in Israeli-modernist concrete and glass. Why: the only bright frame in the set, so it stands out against a feed of dark tech imagery, and it does the Israel nod through architecture and palette instead of symbols.

On May 28, Anthropic published a 244-page technical report on its newest model and included a number no company has a commercial reason to print. Point a red team at Claude Opus 4.8 while it is driving a web browser, across 129 test environments, and the attacker took control of it 31.5 percent of the time.

With the company’s own safeguards switched on, that fell to 0.5 percent. Read the two figures together and you have the founding document of an industry. The defenses work. The hole underneath them does not close.

So the protection is being built outside the model, as a separate layer with its own vendors and its own money. Between July 23 and August 25, six Israeli companies doing precisely that work disclosed roughly $718 million in funding. Six companies whose entire product is watching what an AI agent is about to do and deciding whether to let it.

The flaw is the architecture, not the bug

The attack is called prompt injection, and the plain version is this: you hide instructions inside something the model is going to read anyway. A web page, an email, a calendar invite, a comment in a code file. The model reads it and cannot tell it was content rather than a command.

That confusion is structural. Speaking at Infosecurity Europe on June 4, Ariel Fogel, a researcher at Israel’s Pillar Security and a co-lead on OWASP’s agentic security work, explained why it resists a fix: models process everything as a single token sequence, with no reliable way to enforce a privilege boundary between the system prompt, the user’s question, and whatever the agent went off and fetched. Nothing in the stream is marked trustworthy. Britain’s National Cyber Security Centre said the same in December 2025: prompt injection may never be fully mitigated the way SQL injection eventually was, because the model is an inherently confusable deputy. OWASP now maps the attack to six of the ten categories in its Top 10 for agentic applications.

For a chatbot, a successful injection produced a bad answer. For an agent, it produces a chain of real actions.

I run agents in production, and that shift is easy to feel from the inside. An agent that drafts a reply is a writing tool. An agent with a refund button is a different animal, and the question stops being whether the output reads well and becomes whether anything upstream could have talked it into pressing.

Thirty-three days, six companies, $718 million

On July 23, Calcalist reported that three Israeli cyber startups had left stealth inside eight days with a combined $340 million. Glow disclosed $180 million at a $1.2 billion valuation for endpoint security built for AI-native devices. Neo, staffed with alumni of SentinelOne, Wiz and Palo Alto Networks, took $100 million to inventory and govern the agents and machine identities companies have quietly amassed. Oak raised a $60 million seed for identity management in AI environments, under a founder whose three previous security companies were bought by Mellanox, Palo Alto and Tenable. Some of that money closed months earlier and surfaced at once, which itself says something about how crowded the calendar had become.

Six days later Onyx Security raised $113 million led by Bessemer at roughly a $640 million valuation, four months after leaving stealth. Its co-founders are Maxim Bar Kogan, a former Unit 8200 cyber intelligence officer, and Gil Elbaz, a former Nvidia AI architect. The product watches each step of an agent’s reasoning and interrupts it, approving, redirecting or blocking an action before it lands. Onyx says it covers more than 1.1 million agents, and in June Anthropic announced an integration with it.

On August 3, Zenity closed a $125 million Series C led by Norwest, with SoftBank Vision Fund 2 and Intel Capital joining, taking it to about $185 million. Its research team sits in Tel Aviv, and its pitch is deterministic: judge the intent behind an agent’s next action across Microsoft Copilot, ChatGPT Enterprise and Gemini, then block it before execution.

Then on August 25, Alice raised $140 million led by Apax Digital at a valuation reported around $800 million. Founded in 2018 as ActiveFence and renamed in January, it has about 400 employees, most in Israel, and recurring revenue approaching $100 million. It attacks models during training, firing simulated jailbreaks at them before release. Alice says it works with eight of the world’s ten leading model-development labs, Anthropic, Google, Nvidia and Cohere among them.

That is the detail to sit with. The labs building the most capable systems on earth have decided that hardening them is a specialist trade, and they have largely hired the same specialists.

Why it ended up here

The clearest measure comes from a landscape map kept by Lior Drihem at Prompt Security, an interested party in its own right, bought by SentinelOne last year. As of August 21 it counted 398 companies building security for agentic AI across 25 countries. The United States has 213 of them, 54 percent. Israel has 90, or 23 percent. Between them the two countries hold 76 percent of the companies and 94 percent of the disclosed funding.

The acquisition prices show what is actually being bought. Cato Networks paid an estimated $300 to $350 million for Aim Security in September 2025, when Aim had about 30 employees and had raised $28 million, and its founders, Matan Getz and Adir Gruss, had worked on AI and cyber together in Unit 8200. Palo Alto’s roughly $700 million purchase of Protect AI came when the company was reported to be doing about $5 million a year.

These are not revenue multiples. They are prices for small groups of people who already think in adversaries. The skill that carried Israel through the cyber decade was never a particular product. It was the reflex of assuming every input is hostile until proven otherwise, held by people trained to attack before they were ever paid to defend. Prompt injection is that instinct applied to a new medium, at a moment when the industry needed it and did not have it.

What the money could be wrong about

Plenty. Most of this category is thin. Calcalist noted during the 2025 wave that nearly none of the targets cleared $10 million in annual revenue, and about 30 percent of the 398 mapped vendors are repositioned incumbents rather than AI-native startups, which is what a feature looks like shortly before it stops being a company. Check Point, Palo Alto and Cisco have each absorbed three of these firms already, and acquisitions in the category went from 4 in 2024 to 12 in 2025 to 19 so far in 2026. A spike like that can mean validation or a scramble to sell before the window shuts.

Against that, some of these businesses now have revenue rather than promise. Alice is near $100 million recurring. Zenity says its revenue tripled year over year, twice. Onyx says it quadrupled in four months.

The deeper risk is the happiest one. If the labs ever solve this inside the model, the layer built around it compresses fast. Nobody serious expects that soon, which is exactly why the money moved.

Israel did not win the model race and is not going to. It has no frontier lab, and the compute gap is not closing. What it found instead is the position it was always shaped for. The labs build the intelligence. Israel is getting paid to not trust it.

About the Author
Alex Vainer is an AI expert based in Brooklyn, NY. He works hands-on with the most advanced AI systems in the world, and writes about what they actually make possible. His subject is the frontier where artificial intelligence collides with ordinary life, in Israel, in Jewish life, and everywhere else: what is genuinely new, what is only hype, and what it means for the rest of us.
Related Topics
Related Posts
Sign in or Register
Please use the following structure: example@domain.com
Or Continue with
By registering you agree to the terms and conditions
Register to continue
Or Continue with
Log in to continue
Sign in or Register
Or Continue with
check your email
Check your email
We sent an email to you at .
It has a link that will sign you in.