Last year, a small team spun out of Carnegie Mellon spent months doing something that would have sounded like science fiction a decade ago: training one of the world's most capable AI systems to break into computer networks on its own.
The work wasn't theoretical. Incalmo, the startup behind the effort, partnered with Anthropic to see whether Claude Sonnet 4.5 could autonomously execute network attacks across simulated environments containing dozens of interconnected hosts. The results, published in an October company blog post titled "Can Sonnet 4.5 hack a network?", offered a rare public window into what frontier AI models can actually do when pointed at enterprise security infrastructure.
It's the kind of experiment that makes cybersecurity veterans nervous and venture capitalists lean forward.
Red Teaming, But Make It Autonomous
Brian Singer, who founded Incalmo while finishing his PhD at CMU, framed the research as a benchmark: can a large language model handle the kind of multistage network penetration that typically requires skilled human operators? Using custom harnesses and tools Incalmo built to give the AI structured access to cyber ranges, the answer appears to be yes—at least in controlled settings.
The collaboration marked one of the first public attempts to systematically evaluate a frontier model's offensive capabilities at scale. Red teaming by machine, not by people.
Singer and his research collaborators—a group that includes CMU researchers Keane Lucas, Lakshmi Adiga, Meghna Jain, Lujo Bauer, and Vyas Sekar—laid out their technical approach in a January preprint paper. The work introduced what they call a "high-level attack abstraction layer," essentially middleware that sits between an LLM and the environment it's probing, translating fuzzy AI outputs into executable commands.
The same architecture, Incalmo argues, can be flipped. If you can teach an AI to attack, you can teach it to defend.
Betting on the Inevitable

The company's pitch is straightforward, if ambitious: human-led security operations can't keep pace with the threat landscape ahead. Incalmo's tagline—"The next generation of autonomous cybersecurity"—reflects a broader thesis that agentic AI isn't a future curiosity. It's arriving now, and organizations that don't adapt will be outmatched.
Whether that's hype or prescience depends partly on timing. Incalmo raised a pre-seed round from Pear VC, though the company hasn't disclosed the amount or specific timing. Singer's personal site mentions the round in passing ("we recently closed a pre-seed") but offers little else. The startup's LinkedIn profile lists somewhere between two and ten employees, and its website points inquiries to a general email address rather than advertising open positions.
What the company has done is earn visibility. In March, Incalmo was named a finalist at the RSAC Launch Pad pitch competition, alongside Konvu and Obverra. Singer pitched as CEO and co-founder. Making it to that stage signals momentum, perhaps active fundraising—but no seed round or customer wins have been announced publicly.
For a company working on technology this sensitive, the opacity may be deliberate.
A Market Getting Crowded

Incalmo is far from alone in chasing autonomous security. Investor appetite for the space has been anything but subtle. Sycamore pulled in a $65 million seed round in March to build what it describes as a "trusted agent OS for enterprise AI." Rilian closed $17.5 million the following month, also targeting agentic AI for cyber and defense. Even Konvu, which shared the Launch Pad stage with Incalmo, raised $5 million in 2024 for AI-driven vulnerability triage.
The logic underpinning all this capital is elegantly simple: if AI can hack, it can defend. The race is less about whether autonomous security will exist and more about who gets there first—and whether defenders can deploy it before adversaries do.
Still, there's a tension here that nobody's fully resolved. Building AI that can autonomously exploit networks means putting that capability into the world, even if the stated intent is defensive. The scaffolding you build for one side can serve the other.
Academic Roots, Commercial Ambitions
Incalmo continues publishing. The team presented research at IEEE S&P under the title "Incalmo: An Autonomous LLM-assisted System for Red Teaming Multi-Host Networks," maintaining its academic bona fides even as it pivots toward a product. But the path from research to revenue is rarely straightforward, especially in a domain where customers are enterprise security teams with long procurement cycles and deep skepticism about unproven tools.
The collaboration with Anthropic, as far as publicly disclosed, appears limited to the evaluation work Singer described. No strategic partnership has been announced, no joint go-to-market. Incalmo hasn't named design partners or paying customers, which isn't unusual for an early-stage company but does leave questions about traction.
What's clear is that the company remains small—a tight team translating cutting-edge research into something they hope will sell. Their bet is that autonomous cybersecurity isn't speculative. It's inevitable.
Whether that inevitability arrives in time to matter, or whether the same technology empowers attackers faster than it fortifies defenders, remains one of the more unsettling open questions in enterprise security. For now, Incalmo is building. The rest of us are waiting to see what happens when the machines start defending—and attacking—on their own.
