Two Rounds, One Day Apart

On 12 August 2026, Mindgard put out a press release confirming a EUR 26 million (USD 30 million) Series A, led by Album VC with Karma Ventures, .406 Ventures, Atlantic Bridge, IQ Capital and Lakestar joining in. The company, a spinout of Lancaster University now based in London and Boston, builds tools that red-team AI models and agents the way a penetration tester probes a network.

One day later, Cytix announced its own Series A: EUR 6 million (USD 7 million), led by the UK regional investor Northern Gritstone, with Auriga Cyber Ventures and the Northern Powerhouse Investment Fund II also putting in money. Cytix has nothing to do with Mindgard - different founders, different investors, a different product - yet both press releases used the same two words: AI security.

Read separately, these are two modest funding stories in a crowded season for cybersecurity capital. Read together, they say something neither company said on its own: the market they are both selling into has quietly split into two layers, and an enterprise now has to budget for both.

Mindgard Tests the Model Itself

Mindgard's product sits directly against the AI system. It runs continuous automated red-teaming against models and agents, probing for the kind of failure that only shows up when something adversarial is thrown at the system: prompt injection, data leakage, a model coaxed into behaviour its owner never intended.

Alongside that, Mindgard does shadow-AI discovery - finding the AI tools employees have quietly plugged in without anyone in IT ever approving them - and real-time threat protection once an AI system is live in production. The company says it already sits inside Fortune 2000 clients across finance, pharma, gaming and semiconductors, sectors where a misbehaving model is not a curiosity but a regulatory and financial exposure.

This is security aimed at the AI system's behaviour: what the model does, what it says, what it can be tricked into doing. It has nothing to say about how the code around that model got written or reviewed.

Cytix Watches the Pipeline Around It

Cytix starts from a different question entirely. AI coding assistants such as Copilot and Cursor-style tools have sped up the part of software delivery where code gets written. Review and QA capacity, in most organisations, has not sped up to match. Cytix calls the gap that opens up 'change risk' and built a platform to measure it directly.

The company is not red-teaming a model. It is assessing the security risk in what AI-accelerated development actually ships - code that moves faster through the pipeline than the humans checking it can keep pace with. That is a pipeline and process problem, not a model-behaviour problem, and it needs a different kind of tooling to see.

Northern Gritstone's involvement is itself a small UK regional story - a fund built to back university-adjacent, deep-tech companies in the north of England putting money behind a specifically process-layer security bet, rather than the more visible model-security lane that has drawn most of the attention this year.

Why the Split Is the Real Story

Neither Mindgard's announcement nor Cytix's mentioned the other company. There is no reason they should have - they are not competitors and were not trying to make a market argument. But placed side by side, the two rounds show something that is easy to miss when 'AI security' gets used as a single catch-all term: it already covers two genuinely different failure modes.

One layer is about what the AI system itself does once it is running - the model or agent misbehaving, leaking data, or being manipulated. The other is about what gets shipped around that AI system - code written faster than it can be reviewed, moving through a pipeline that was not built for the new pace. A vendor built for one job is not automatically competent at the other.

This is not a prediction that the categories will formally split into named markets with analyst reports to match. It is a narrower and more useful claim: the two rounds landing a day apart show the split has already happened in practice, whether or not anyone has put a label on it yet.

What This Means for an Owner's Vendor List

If your organisation is rolling out AI coding assistants, AI agents, or both, the practical takeaway is not to sign with the first vendor that uses the phrase 'AI security' and assume the box is checked. Ask specifically which layer they cover.

Ask whether the product red-teams the AI system's behaviour - the Mindgard lane - or whether it assesses the change risk in what your AI-accelerated pipeline is shipping - the Cytix lane. A vendor that only does one of these will tell you, if you ask directly, that the other is out of scope.

The two roughly EUR 6-26 million rounds landing within a day of each other in August 2026 are early evidence, not proof of a permanent market structure. But for now, treat AI security as two line items on the budget, evaluated against two different questions, until a vendor demonstrates otherwise.