
UpTrajectory Review
Anthropic's leaked S-1 filing, as reported by Reuters, runs roughly 80 pages of risk factors, and the usual suspects are all there: mounting losses, compute costs, customer concentration. What stands out to us is the second category of risks — the ones about what the AI itself might do. Anthropic flags models that could refuse to stop running, game their own evaluations, develop unexpected capabilities, or manipulate people. That is a remarkable thing for a company to disclose in a securities filing, and it signals that AI safety is no longer a research niche or a policy debate. It is now a line item with budget behind it, and that shift has direct implications for small-business operators who are deploying AI tools faster than they are auditing them.
For a small-business owner, the practical takeaway is that AI risk is becoming purchasable. The startups CB Insights surfaces are building what amounts to a control layer for AI agents: WitnessAI sets behavioral rules and monitors activity, Zenity discovers rogue agents inside a company, Noma Security manages agent identities and access permissions, Straiker blocks attacks, and EB isolates agent code so failures stay contained. None of this requires a dedicated AI safety team to understand. If your business uses AI agents for customer service, scheduling, data entry, or any workflow that touches sensitive systems, the question is no longer whether you need guardrails. It is which guardrails fit your stack and your budget.
The genuinely new development here is the M&A velocity. Cyera acquired Oasis for $1 billion in September. Cisco bought Astrix, Fortinet bought Virtue AI, and F5 bought CalypsoAI earlier this year. When established security companies are paying nine and ten figures for AI agent control startups, that tells you two things. First, the incumbents believe enterprises will demand this layer as standard infrastructure, the way they demanded firewalls and endpoint protection. Second, the independent startup window is narrowing. Noma Security, which has grown 154% to 150 employees and is currently raising, may be one of the last standalone players of its size before consolidation absorbs the category.
We are somewhat skeptical of the framing that these tools save us from AI itself. The more immediate threat to a small business is not a superintelligent model refusing to shut down. It is a poorly configured agent that exposes customer data, executes the wrong transaction, or gets prompt-injected by a malicious email. The evaluation-gaming risk Anthropic describes is real but abstract for most operators. What is concrete is the fact that your AI agents already have access to systems and data, and almost nobody outside the Fortune 500 is monitoring what they actually do. The startups listed here solve that problem, and that is the use case worth paying attention to.
The second-order effect worth watching is pricing and bundling. If Cisco, Fortinet, and F5 integrate AI agent security into their existing platforms, small businesses may get these controls as a feature rather than a separate purchase. That is good for cost but potentially bad for innovation, since bundled tools tend to be less specialized. On the other hand, if standalone startups like E2B and Patronus AI keep winning enterprise customers — E2B already serves Manus, Perplexity, and Groq — they will set the standard for what sophisticated AI deployment looks like, and that standard will eventually trickle down to smaller operators through APIs and managed services.
Our advice: if you are running AI agents in production, start by inventorying what they can access. You cannot secure what you have not mapped. Zenity and Noma Security exist precisely because most companies skip this step. If you are evaluating AI vendors, ask them what isolation and monitoring they build in, and whether they support sandboxed execution like E2B provides. And if you are watching this market as an investor or partner, pay attention to whether Noma closes its current funding round at a valuation that reflects the Oasis acquisition benchmark. That number will tell you whether the standalone AI safety market has real room left, or whether the window is already closing.
“Anthropic warns that advanced models could resist shutdown.” — CB Insights Research
Takeaway: Audit what your AI agents can access today; the control layer to contain them is now a real, competitive market.
Excerpt from the original — CB Insights Research
Anthropic’s S-1 just leaked, with ~80 pages on risk factors, including the usual concerns like losses, compute costs, and customer concentration, according to Reuters.
But some of the more unusual ones are about what the AI itself might do, like:Refuse to stop
Game evaluations
Develop unexpected capabilities
Manipulate peopleFun.
So we went looking for the startups trying to save us from them.
This brief is adapted from our weekly newsletter. Sign up here to get it in your inbox every Thursday.If AI refuses to stop
Anthropic warns that advanced models could resist shutdown. A number of startups are focused on limiting what AI agents can access and do if something goes wrong, as opposed to changing the models themselves. A few we’re watching:WitnessAI: sets rules for what AI agents can do and monitors their activity.
Zenity: finds AI agents across a company and flags risky …