Gray Swan AI
Carnegie Mellon-linked startup building automated red-teaming and runtime guardrails that frontier AI labs use to stress-test their models before release.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Gray Swan AI builds tools for finding and closing security gaps in large language models and AI agents before attackers do. Its core products are Shade, an automated red-teaming agent that runs adversarial tests against models throughout pre-deployment and CI/CD, and Arena, a continuous public competition that draws more than 15,000 researchers and security professionals to attack AI systems and surface novel jailbreaks and exploits. The company also offers Cygnal, a runtime protection layer.
The company was spun out of Carnegie Mellon University by Matt Fredrikson (CEO) and Zico Kolter (chief scientist), both machine-learning security researchers, and is based in Pittsburgh. Its key differentiator is treating adversarial testing as a continuously-updated, crowd-sourced discipline rather than a one-time audit: new attack techniques found in Arena feed directly into Shade’s test suite. That approach has earned it citations in system cards from Anthropic, OpenAI, and Meta — a notable form of independent validation, since frontier labs do not credit external red-teamers lightly.
In mid-2026 the company closed a $40 million Series A co-led by Wing Venture Capital and Madrona, with Snowflake Ventures, Samsung Next, and Hudson River Trading also participating, to expand lab partnerships and go-to-market operations.
Innovation Matrix Assessment
Launched its Arena crowd-testing competition and Shade red-teaming agent within roughly two years of founding, and has already cited integration feedback loops between the two products.
Gives security and AI teams a continuous adversarial-testing pipeline instead of a point-in-time pentest, directly reducing the risk of shipping exploitable models.
Raised a $40M Series A from tier-one investors (Wing VC, Madrona, Snowflake Ventures) and is cited in system cards from Anthropic, OpenAI, and Meta — real adoption signals, not just vendor claims.
Its crowd-sourced, 15,000-researcher Arena model is a genuinely different operating model from traditional red-teaming firms, though automated adversarial testing itself is an increasingly contested category.
Being named in frontier-lab system cards is independently verifiable third-party evidence of real-world use, which is rare for a company this young.
As enterprises deploy more autonomous AI agents, continuous adversarial testing of model behavior will only become more central to security programs.
Why CISOs Should Care
Gives security teams a way to continuously probe AI agents and models for exploitable behavior before and after deployment, rather than relying on a single pre-launch audit.
What Makes It Different
Combines a large, continuously-running public red-teaming competition with an automated agent that feeds newly discovered attack patterns directly into its testing pipeline.
The Matrix Verdict
77/100 — MEANINGFUL INNOVATOR
Gray Swan AI lands as a Meaningful Innovator: strong, independently corroborated adoption by frontier AI labs and a genuinely novel crowd-testing model, tempered by the fact that AI red-teaming is still a nascent and fast-consolidating category.
Editorial Note: Claims vs. Verified Findings
Frontier-lab system card citations and the funding round are independently reported; specific efficacy numbers (e.g., vulnerabilities found per test cycle) come only from company materials and were not included in scoring.
Sources
Alternatives to Gray Swan AI
Adaptive Security
AI-driven platform that simulates deepfake, voice, and multichannel social-engineering attacks to train and test organizations against next-generation phishing.
Quilr
Early-stage agentic AI security startup building a 'Service-as-Software' platform to guard against human-related breaches and secure AI agent…
Zenity
Governance and security platform for AI agents and low-code/no-code development, securing agent identity, permissions and behavior across the…
Tenzai
An agentic AI penetration testing startup building autonomous 'AI hackers' to find and validate exploitable vulnerabilities at a…
Reco
Reco secures the "agentic ecosystem" — mapping what AI agents can access across SaaS and enterprise apps, detecting…
Charm Security
Agentic AI workforce that investigates and intervenes on scams and fraud in real time, reading manipulation and intent…