Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

SaaS iconSaaSOctober 4, 2026

Subvocal launches under-chin wearable for silent computer control

Subvocal launches under-chin wearable for silent computer control
YcBrain Computer Interface+3
SaaS iconSaaSOctober 4, 2026

DoD Solution raises $2M for AI drone navigation in war zones

DoD Solution raises $2M for AI drone navigation in war zones
Defense TechDrone Tech+3
SaaS iconSaaSJuly 4, 2026

BRAINR Extends Record Seed to $12.8M for Food Manufacturing AI

BRAINR Extends Record Seed to $12.8M for Food Manufacturing AI
Ai AutomationVertical Saas+3
Climate / Social Tech iconClimate / Social TechJuly 4, 2026

World's Largest Second-Life Battery Factory Built in Six Weeks

World's Largest Second-Life Battery Factory Built in Six Weeks
Battery RecyclingEnergy Storage+3

Founders Mentioned

Brian Singer

Incalmo

saas icon
SaaS

Brian Singer

Incalmo

saas icon
SaaS
SaaS iconSaaS
July 4, 2026
Ai AgentsCybersecurityAutonomous SystemsAi TestingEnterprise Security

CMU Spinout Incalmo Tests AI Agents for Autonomous Cybersecurity

The startup collaborated with Anthropic to evaluate Claude's network hacking capabilities, spotlighting the race to build AI-powered autonomous defense systems.

CMU Spinout Incalmo Tests AI Agents for Autonomous Cybersecurity

Last year, a small team spun out of Carnegie Mellon spent months doing something that would have sounded like science fiction a decade ago: training one of the world's most capable AI systems to break into computer networks on its own.

The work wasn't theoretical. Incalmo, the startup behind the effort, partnered with Anthropic to see whether Claude Sonnet 4.5 could autonomously execute network attacks across simulated environments containing dozens of interconnected hosts. The results, published in an October company blog post titled "Can Sonnet 4.5 hack a network?", offered a rare public window into what frontier AI models can actually do when pointed at enterprise security infrastructure.

It's the kind of experiment that makes cybersecurity veterans nervous and venture capitalists lean forward.

Red Teaming, But Make It Autonomous

Brian Singer, who founded Incalmo while finishing his PhD at CMU, framed the research as a benchmark: can a large language model handle the kind of multistage network penetration that typically requires skilled human operators? Using custom harnesses and tools Incalmo built to give the AI structured access to cyber ranges, the answer appears to be yes—at least in controlled settings.

The collaboration marked one of the first public attempts to systematically evaluate a frontier model's offensive capabilities at scale. Red teaming by machine, not by people.

Singer and his research collaborators—a group that includes CMU researchers Keane Lucas, Lakshmi Adiga, Meghna Jain, Lujo Bauer, and Vyas Sekar—laid out their technical approach in a January preprint paper. The work introduced what they call a "high-level attack abstraction layer," essentially middleware that sits between an LLM and the environment it's probing, translating fuzzy AI outputs into executable commands.

The same architecture, Incalmo argues, can be flipped. If you can teach an AI to attack, you can teach it to defend.

Betting on the Inevitable

Digital illustration for article section "Betting on the Inevitable" in "CMU Spinout Incalmo Tests AI Agents for Autonomous Cybersecurity" - A clean, minimal, and modern conceptual image representing the transition to autonomous cybersecurit...

The company's pitch is straightforward, if ambitious: human-led security operations can't keep pace with the threat landscape ahead. Incalmo's tagline—"The next generation of autonomous cybersecurity"—reflects a broader thesis that agentic AI isn't a future curiosity. It's arriving now, and organizations that don't adapt will be outmatched.

Whether that's hype or prescience depends partly on timing. Incalmo raised a pre-seed round from Pear VC, though the company hasn't disclosed the amount or specific timing. Singer's personal site mentions the round in passing ("we recently closed a pre-seed") but offers little else. The startup's LinkedIn profile lists somewhere between two and ten employees, and its website points inquiries to a general email address rather than advertising open positions.

What the company has done is earn visibility. In March, Incalmo was named a finalist at the RSAC Launch Pad pitch competition, alongside Konvu and Obverra. Singer pitched as CEO and co-founder. Making it to that stage signals momentum, perhaps active fundraising—but no seed round or customer wins have been announced publicly.

For a company working on technology this sensitive, the opacity may be deliberate.

A Market Getting Crowded

Digital illustration for article section "A Market Getting Crowded" in "CMU Spinout Incalmo Tests AI Agents for Autonomous Cybersecurity" - A conceptual 3D illustration representing a crowded and heavily funded market in autonomous security...

Incalmo is far from alone in chasing autonomous security. Investor appetite for the space has been anything but subtle. Sycamore pulled in a $65 million seed round in March to build what it describes as a "trusted agent OS for enterprise AI." Rilian closed $17.5 million the following month, also targeting agentic AI for cyber and defense. Even Konvu, which shared the Launch Pad stage with Incalmo, raised $5 million in 2024 for AI-driven vulnerability triage.

The logic underpinning all this capital is elegantly simple: if AI can hack, it can defend. The race is less about whether autonomous security will exist and more about who gets there first—and whether defenders can deploy it before adversaries do.

Still, there's a tension here that nobody's fully resolved. Building AI that can autonomously exploit networks means putting that capability into the world, even if the stated intent is defensive. The scaffolding you build for one side can serve the other.

Academic Roots, Commercial Ambitions

Incalmo continues publishing. The team presented research at IEEE S&P under the title "Incalmo: An Autonomous LLM-assisted System for Red Teaming Multi-Host Networks," maintaining its academic bona fides even as it pivots toward a product. But the path from research to revenue is rarely straightforward, especially in a domain where customers are enterprise security teams with long procurement cycles and deep skepticism about unproven tools.

The collaboration with Anthropic, as far as publicly disclosed, appears limited to the evaluation work Singer described. No strategic partnership has been announced, no joint go-to-market. Incalmo hasn't named design partners or paying customers, which isn't unusual for an early-stage company but does leave questions about traction.

What's clear is that the company remains small—a tight team translating cutting-edge research into something they hope will sell. Their bet is that autonomous cybersecurity isn't speculative. It's inevitable.

Whether that inevitability arrives in time to matter, or whether the same technology empowers attackers faster than it fortifies defenders, remains one of the more unsettling open questions in enterprise security. For now, Incalmo is building. The rest of us are waiting to see what happens when the machines start defending—and attacking—on their own.

More stories

  • Subvocal launches under-chin wearable for silent computer control
  • DoD Solution raises $2M for AI drone navigation in war zones
  • BRAINR Extends Record Seed to $12.8M for Food Manufacturing AI
  • World's Largest Second-Life Battery Factory Built in Six Weeks
  • Venice AI Hits $1B Valuation With Privacy-First AI on Base Blockchain
  • Dominion Dynamics Raises $139M CAD for Arctic Defense Tech
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.