Menlo Ventures - Security for AI: The New Wave of Startups Racing to Secure the AI Stack - February 2024 logo

Menlo Ventures - Security for AI: The New Wave of Startups Racing to Secure the AI Stack - February 2024

Free

A startup market map for securing the AI stack

FreeFree tier
Type
Open Source
Company
Menlo Ventures

About Menlo Ventures - Security for AI: The New Wave of Startups Racing to Secure the AI Stack - February 2024

A comprehensive market perspective from Menlo Ventures analyzing the emerging startup landscape for AI security. Published in February 2024, the article outlines the new threat vectors introduced by generative AI—such as prompt injections, model theft, and supply chain attacks—and categorizes the defensive technologies into governance, observability, and security. It highlights specific startups like Cranium, Credo, and Mithril Security, and argues that enterprise adoption of AI depends on solving these security challenges. The piece serves as both a threat analysis and an investment thesis for early-stage companies building AI security solutions.

Key Features

Categorizes AI security into governance, observability, and security
Analyzes threat vectors: prompt injections, model theft, insecure output handling, supply chain attacks
Highlights specific startups: Cranium, Credo, Mithril Security
Provides enterprise adoption context and investment thesis
References OWASP top 10 for LLM applications and real-world attacks like the OpenAI DoS

Pros & Cons

Pros
  • Comprehensive overview of AI security challenges and categories
  • Names specific startups and their focus areas
  • Grounded in real-world attack examples (OpenAI DoS, Mithril Security poisoning)
  • Clear structure dividing governance, observability, and security
  • Written by experienced venture capitalists with deep industry context
Cons
  • Not a practical tool or framework—just a market analysis report
  • Lacks detailed technical implementation guidance
  • Primarily from an investor's perspective, not a practitioner's
  • Does not provide evaluation criteria or benchmarks for comparing tools

Best For

Understanding the AI security startup landscape for investmentEvaluating enterprise risks of deploying generative AI modelsIdentifying governance and observability tools for AI adoptionStaying informed on emerging threats like prompt injections and model poisoning

FAQ

What are the main categories of AI security discussed?
The article divides emerging AI security technologies into three categories: governance, observability, and security. Governance helps organizations catalog AI services and tools; observability monitors AI behavior; security includes firewalls and guardrails.
What are the key threats to generative AI models?
Key threats include prompt injections (direct and indirect), model theft via compromised credentials or supply chain attacks, insecure output handling, sensitive information disclosure, insecure plugin design, and model poisoning (e.g., embedding backdoors in open-source models).
Which specific startups are highlighted in the report?
The article mentions Cranium (governance), Credo (governance), and Mithril Security (security) as examples of startups in the AI security space.
What is the investment thesis of Menlo Ventures regarding AI security?
Menlo believes the complexity and scale of AI security challenges create a massive opportunity for new startups. They invest in early-stage companies building solutions for governance, observability, and security, with near-term focus on threats that expose models to outside actors.