Skip to content

Gray Swan AI

Carnegie Mellon-linked startup building automated red-teaming and runtime guardrails that frontier AI labs use to stress-test their models before release.

Visit Website ↗ + Add to Compare Claim This Company
77/100Meaningful Innovator

Overview

Gray Swan AI builds tools for finding and closing security gaps in large language models and AI agents before attackers do. Its core products are Shade, an automated red-teaming agent that runs adversarial tests against models throughout pre-deployment and CI/CD, and Arena, a continuous public competition that draws more than 15,000 researchers and security professionals to attack AI systems and surface novel jailbreaks and exploits. The company also offers Cygnal, a runtime protection layer.

The company was spun out of Carnegie Mellon University by Matt Fredrikson (CEO) and Zico Kolter (chief scientist), both machine-learning security researchers, and is based in Pittsburgh. Its key differentiator is treating adversarial testing as a continuously-updated, crowd-sourced discipline rather than a one-time audit: new attack techniques found in Arena feed directly into Shade’s test suite. That approach has earned it citations in system cards from Anthropic, OpenAI, and Meta — a notable form of independent validation, since frontier labs do not credit external red-teamers lightly.

In mid-2026 the company closed a $40 million Series A co-led by Wing Venture Capital and Madrona, with Snowflake Ventures, Samsung Next, and Hudson River Trading also participating, to expand lab partnerships and go-to-market operations.

Innovation Matrix Assessment

Innovation Velocity 8/10

Launched its Arena crowd-testing competition and Shade red-teaming agent within roughly two years of founding, and has already cited integration feedback loops between the two products.

Operational Value 7/10

Gives security and AI teams a continuous adversarial-testing pipeline instead of a point-in-time pentest, directly reducing the risk of shipping exploitable models.

Market Momentum 8/10

Raised a $40M Series A from tier-one investors (Wing VC, Madrona, Snowflake Ventures) and is cited in system cards from Anthropic, OpenAI, and Meta — real adoption signals, not just vendor claims.

Category Disruption 7/10

Its crowd-sourced, 15,000-researcher Arena model is a genuinely different operating model from traditional red-teaming firms, though automated adversarial testing itself is an increasingly contested category.

Real-World Efficacy 7/10

Being named in frontier-lab system cards is independently verifiable third-party evidence of real-world use, which is rare for a company this young.

Enduring Relevance 9/10

As enterprises deploy more autonomous AI agents, continuous adversarial testing of model behavior will only become more central to security programs.

Why CISOs Should Care

Gives security teams a way to continuously probe AI agents and models for exploitable behavior before and after deployment, rather than relying on a single pre-launch audit.

What Makes It Different

Combines a large, continuously-running public red-teaming competition with an automated agent that feeds newly discovered attack patterns directly into its testing pipeline.

The Matrix Verdict

77/100 — MEANINGFUL INNOVATOR

Gray Swan AI lands as a Meaningful Innovator: strong, independently corroborated adoption by frontier AI labs and a genuinely novel crowd-testing model, tempered by the fact that AI red-teaming is still a nascent and fast-consolidating category.

Editorial Note: Claims vs. Verified Findings

Frontier-lab system card citations and the funding round are independently reported; specific efficacy numbers (e.g., vulnerabilities found per test cycle) come only from company materials and were not included in scoring.

Sources