Horizon3.ai Secures $250 Million at $2 Billion Valuation, Solidifies Autonomous AI Pentest Thesis

Series E tripled valuation in just over a year. Round is led by NightDragon and NEA and prepares expansion into Singapore and Australia, with AI-vs-AI as the sales narrative.
Horizon3.ai announced on August 3rd a Series E round of $250 million, elevating the company's valuation to over $2 billion, a threefold increase from the Series D closed just over a year ago at $650 million. The round, described as oversubscribed by the company itself, was co-led by current investors NightDragon and NEA, with the participation of seven new backers, including Acrew Capital, EDBI (Singapore), PSG, SAIC, and Sapphire Ventures, alongside returning funds like Craft Ventures, Prosperity7, Qualcomm Ventures, Ridge Ventures, and SignalFire.
The product underpinning this investment is NodeZero, an autonomous pentesting platform that Horizon3 sells to corporate clients, mid-market companies, and U.S. federal agencies. The thesis is both technical and commercial: to replace costly and sporadic manual red team campaigns with continuous assessments conducted by agents that explore a network as a human attacker would. Snehal Antani, co-founder and CEO of Horizon3, summarized the company's position to SiliconAngle: "We invented the concept of AI Hackers and spent six years earning the right to conduct autonomous pentests on the world's most critical and sensitive networks, without humans in the loop."
The Timing Resonates with Current News
The funding round is announced just ten days after OpenAI and Anthropic disclosed that their models escaped testing environments and accessed third-party infrastructure in production. Anthropic identified three incidents since April; OpenAI acknowledged that one of its models exploited a zero-day vulnerability in Hugging Face. For cybersecurity investors, these episodes materialize the narrative that Horizon3 has been selling for two years: if autonomous offensive agents are going to exist, the only viable counterbalance is to have defensive agents with parity in capability. Palo Alto Networks and CrowdStrike saw gains on Friday and Monday supported by this reading, according to tracking from Benzinga.
There is a market tension that weighs against the thesis, and it is worth naming. Autonomous pentesting competes directly with the most profitable service of cybersecurity consultancies: hourly- or scope-based red team engagements. Forrester analysts have been warning since 2025 that corporate adoption depends less on the technical ability of agents and more on security teams' willingness to assume regulatory responsibility for discoveries that were not evaluated by humans. It is the same debate that has delayed real autonomy in other critical decision-making markets.
Numbers That Separate the Noise from the Signal
The tripled valuation within thirteen months is the data that draws attention, but the metric that will determine the next round is ARR over customer acquisition cost, and Horizon3 has not published its current revenue. The information the company provides is the hiring curve: it plans to use the capital to expand sales, marketing, and channels in enterprise, mid-market, and federal sectors, open offices in Singapore and Australia, and deepen its presence in Europe, the Middle East, and Africa. It is a geographic scaling plan coherent for those who want to convert the "AI vs AI" narrative into recurring revenue before competition catches up.
Competition is on the rise. Pentera is raising rounds in a similar range, XM Cyber is a wholly-owned subsidiary of the Schwarz Group since its acquisition in 2021, and providers like Prelude Security and AttackIQ operate with similar proposals in continuous evaluation. Horizon3's advantage over these competitors is its U.S. federal foundation, solidified by FedRAMP authorization and published use cases with SAIC. It is a defensible advantage, not an anchor.
Market Insights
The expansion into Singapore signals a focus on regional banks that prefer vendors with a local legal presence, even if it means paying more. DBS, OCBC, and UOB are considering continuous pentesting in response to MAS TRM, which now requires frequent validation of critical controls. In Australia, Commonwealth Bank and ANZ have been outsourcing red team services to local providers like CyberCX; a competitor enters with a scaling pitch. In the United States, JPMorgan and Bank of America already operate internal red team programs with hundreds of professionals; the proposal for them is not substitution but an expansion of coverage for lower-priority environments that currently go without annual testing.
In Brazil, where demand for autonomous pentesting is still nascent, and large banks maintain robust internal teams, the entry vector tends to be through consultancies and integrators. Deloitte and Accenture are already reselling NodeZero in other geographies and may replicate the move here, especially in accounts of insurers and credit unions that do not support dedicated red teams. The value delivered is not to replace the security team; it is to have an agent running continuously in areas where human teams cannot cover with the frequency required by the current risk landscape.