In short
HelmGuard AI, an “agentic GRC and security” platform, announces a $7.3M seed round to expand its team, product, and U.S. presence. The founders argue frontier AI should be used defensively for continuous security/compliance monitoring, not just checklists or chatbot add-ons.
Guests
John Daley (ex-Palantir; 8 years focused on internal security/compliance/data protection; embedded with government and financial services customers; began using frontier AI models from 2023). Jack Miller (AI researcher/engineer; undergrad during early “scaling” era; wants defensive use of frontier models; studied cyber “capture the flag” training trends).
Key claims
Agents can “ride the wave” of improving models; use evals for consistency and reduce cost-to-serve; legacy tools fail because they lack agent context and enterprise data models; security incidents show incentive gaps.
Notable examples
Colossum as a partner—HelmGuard’s Atlas graph database plus AI agents continually verify third parties, customer requirements, and investment decisions with human oversight.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOAnnouncement of Funding
0:46 to 2:29
Jack and John announce their recent $7.3 million seed funding and its implications.
“and we really want to bring the power of the Frontier AI models to help ordinary organizations use and leverage Frontier AI capabilities to run their internal security and compliance operations in a new type of way.”
Understanding HelmGuard's Mission
2:30 to 4:05
Exploration of HelmGuard's purpose and the problem it aims to solve using AI.
“actually as an undergrad, back when the original scaling papers came out and you were just seeing this kind of ever-improving scaling, originally from OpenAI.”
Jack's Perspective on AI Scaling
4:06 to 6:04
Jack discusses the evolution of AI scaling and its impact on cybersecurity.
“especially, you know, around 23, 24, a lot of the advice was going, you know, if you really care about this sort of stuff, go and join the Frontier Labs.”
Leveraging AI for Defensive Security
6:05 to 7:40
John and Jack explain how HelmGuard uses AI for defensive cybersecurity.
“And so we use a wide variety of models, the right task, sorry, a model for the right task.”
Client Case Study: Colossum
7:41 to 10:43
Discussion on how HelmGuard collaborates with Colossum to enhance their security operations.
“are they doing what they're meant to be doing to a population sample?”
Market Strategy and Growth Plans
10:44 to 13:50
Details on HelmGuard’s future plans for product development and market expansion after the funding.
“Because if you think about the range of things Jack just mentioned there, covering internal risk and compliance work, a third-party risk management, and then increasingly also agent governance and assurance work.”
The Importance of Agent Architecture
14:00 to 15:08
Learn about the foundational belief in architecting platforms for agent interaction.
“And that replacement is really interesting.”
Insights from AI Incidents
15:09 to 17:59
Explore the implications of recent AI incidents on industry practices.
“data lot of building, which we work on very early in our engagements with customers.”
Incentives in AI Security
18:00 to 19:46
Understand the current incentive structures affecting AI security and compliance.
“So in a post hoc analysis, they use AI models to basically go through the logs, look at the traces, determine what's happened.”
Shifting Perspectives on Security Challenges
19:47 to 21:03
Discover how recent events have reshaped views on enterprise security challenges.
“And the question is, if you're a 10-person IT team, how are you going to deal with that?”
Show all 11 chapters
Operationalizing AI in Security
21:04 to 22:56
Learn how organizations can effectively integrate AI into their security operations.
“but I think have been hard for our customers to necessarily understand.”
Transcript
Automatic transcript. May contain errors.0:00Jack Miller:Hello and welcome back to the Scaling Europe show. Today we've got two amazing founders on the show, John and Jack, founders of Helmgard. Welcome, how are you both doing today?
0:07John Daley:Great, really a pleasure to be here. Yeah, it's great to be here.
0:11Jack Miller:The pleasure is all mine. It's a very exciting time for you guys. Does one of you want to kick off? What is the news that you're sharing and why is it so exciting?
0:20John Daley:Yeah, sure, I can start off. So we're announcing today that we've raised$7.3 million in a seed round from a great group of UK and US-based investors. And we're going to be using this to grow our team, expand our product offering and expand our presence in the U.S. market as well. Amazing. Very exciting times.
0:39Jack Miller:Can you tell people maybe this is the first time coming across Helmgard? What is it that you've built?
0:45John Daley:Sure. So we are an agentic GRC and security platform. and we really want to bring the power of the Frontier AI models to help ordinary organizations use and leverage Frontier AI capabilities to run their internal security and compliance operations in a new type of way. Amazing. And where did this come from?
1:10Jack Miller:Why is this a problem that you two set out to solve? Yeah, sure.
1:15John Daley:I can provide a little bit of context there And then I'd love Jack to share more about the technical angle that he has been leaning on. So I worked at Palantir for eight years, worked across a wide variety of roles and functions there, but spent all the time both on internal security compliance data protection type work. And was also embedded with a number of our customers in both government and financial services working on these types of problems. and from 2023 onwards as I began to use the frontier AI models in my work, it just became obvious that, one, you were going to have to totally rethink how this work was done as the offensive capabilities of third actors began to use the AI in novel ways, but also it was going to totally change what was possible and what was economical to deliver on his workflows.
2:06John Daley:And then I met Jack, who is an AI researcher and engineer by background. And I think he made my vision even more ambitious because he said, you're not thinking deeply enough around how much the agents are going to be able to do. Yeah, Jack.
2:23Jack Miller:Yeah, absolutely. I mean, I think similar story to John. I was kind of in the AI world, actually as an undergrad, back when the original scaling papers came out and you were just seeing this kind of ever-improving scaling, originally from OpenAI. Obviously, Google did some work as well in establishing the scaling laws. And what you could see is that pre-training was really working, you know, every model release, it was unclear what the new emergent behavior would be, but it was clear that there would be some improvement. And so you could see that scaling, you know, occurring in the early 2020s.
3:03Jack Miller:And so it was pretty obvious that, you know, a model like kind of GPT-4, GPT-4.5 would eventually be reached. And that would be incredibly helpful for loads of different tasks. But then what you saw after that, of course, was the introduction of reinforcement learning. And it really was at that point in time that things became foreseeable that we would reach the kind of situation we're in today, where models are trained on these cyber tasks to go and capture the flag. It's a very easily reinforced reward to get really, really good at offensive cybersecurity. And we've seen that come in, you know, with the Mythos class of models.
3:50Jack Miller:And so, you know, the timelines were unclear, but the eventual state, I think, was foreseeable. And what I really wanted to do was start a company that is leveraging the frontier for defensive capabilities. And I think what you see is, especially, you know, around 23, 24, a lot of the advice was going, you know, if you really care about this sort of stuff, go and join the Frontier Labs. I think what we've seen is that the Frontier Labs have a significant incentive to race, to get the best model out that they can against both themselves and against China, of course. And that actually relatively few people are thinking about how to use the Frontier for genuinely defensive capabilities.
4:36Jack Miller:And I thought that that's where my time would best be spent um there was a moment where i thought i'd do a phd um but like you know if i did a phd i'd still have another couple of years and i think by that time maybe we would have agi and like it could do my thesis in the last two months so i was like yeah maybe maybe i can
4:59John Daley:yeah i mean we're talking the day after um gpu6 astra came out and i think the agi conversation is so funny because if you drop someone from 2024 in front of gp they're like oh this is of course agi but i think because it's like this incremental but a very rapid improvement we're sort of inert to the fact that like these capabilities are just amazing and i think um you know we really enjoy talking with prospects and customers and helping them understand how much you can actually do i'd say and and what that means to get deployed in your enterprise and how do you react to a new
5:32Jack Miller:model you know like the new model that just came out what happens for you in the business is this like oh my god like we have to test everything which we build everything how do you react and building the defensive capability said well yeah what happens for you when a new model like this
5:46John Daley:gets dropped yeah i think there's a philosophical position then a technical angle on that so maybe i'll speak to the first i let jack speak to the second i think we've built the company uh on the thesis that at the application layer, you can just ride the wave of improving model capability over time. And so we use a wide variety of models, the right task, sorry, a model for the right task. And we do a lot for our customers in terms of optimizing cost and performance. And we think that's just going to increase. And ultimately, we're one of the beneficiaries of the hundreds of billions of dollars being spent at the frontier plus the amount the enormous amount of open source innovation coming now at the same time you need to make sure that as new models come out um they're performing consistently with uh with expectation and you're running evals and so i'll check
6:41Jack Miller:and talk about how we think about that yeah absolutely and i'd i'd kind of put new model releases on kind of two dimensions one is like improvements to frontier intelligence so for example you know astra i haven't uh looked specifically the benchmark to see if it does in fact beat fable 5.1 i guess they're probably pretty similar um but one is like improvements to the frontier and there are some bits of our platform where that that helps you know particularly long running um tasks but it helps a lot obviously with internal stuff you know software engineering um we've got kind of a fleet of virtual machines that we use now for development where we just like basically parallelize everything um and have this this long verification loop and new models are incredibly useful there.
7:23Jack Miller:But then the second dimension is cost to serve. And you see every year this kind of 10x marginal decrease for the same level of intelligence. And so that helps us immensely in the cybersecurity domain, because the point of our platform is to move from a world where you sample, you just take a small sliver of an organization and work out in this part, are they doing what they're meant to be doing to a population sample? We want to look at everything all the time to determine whether it's secure and meeting kind of the requirements either from the regulator or from customers. And so I look at both.
8:01Jack Miller:And it tends to be when like you get an improvement in the frontier, we tend to take something away from our scaffold. So, you know, as the models get more intelligent, they need less and less guidance. And then if you get a radically cheaper model, then we tend to expand the set of things that we look at. Or we provide something for free that we otherwise wouldn't have provided for free before. So that's what tends to change. That's really interesting. I feel like we're getting more into the meat of what you're really building and how you're serving customers. Could you give an example? Because I know that you're working closer.
8:36Jack Miller:Could you talk about a bit like the type of customers and clients that you're serving and what it is that they're really looking for. Yeah, sure.
8:46John Daley:Jack, do you want to talk about that Colossum?
8:47Jack Miller:Yeah, absolutely. I mean, I think Colossum are a great example of one of our partners. And so with them, we're helping to kind of accelerate their security program. So to define everything that they're doing as a business that's security relevant on our platform. And they're basically orchestrating AI agents to be continually checking and verifying the activities of the organization. They're in a really interesting position because they are selling to governments, they're selling to critical organizations across Europe and the US, of course. But then they also have a series of quite complex, quite important third parties that they rely upon, namely data centers, chip providers.
9:33Jack Miller:So really, they have a very complex landscape, both in terms of their third parties, their internal operations, and really stringent customer requirements. And so what we do for them is essentially build out, as we do for our other customers, a second brain for their security department, where we've encoded in our what we call Atlas, a graph database, all of the relevant assets, third parties, customers that they have. And then we basically orchestrate AI agents on top of that to automate the day-to-day work that needs to be done, whether that's verifying a new third party that they need to work with, whether it's checking on a particular requirement for a customer, whether it's making a decision as to where to invest in the future.
10:20Jack Miller:That stuff all gets automated with human oversight and advisory work on top. So that's been really exciting. And obviously, they are actually an inference provider to us as well. So it's kind of dog-footing their own product where their inferences is improving our product. And I hope our product is improving their offering as well.
10:43John Daley:Yeah, and I think that's a good way to talk about the work we're doing with other larger enterprises in services, in healthcare, in government and in industrial technology. Because if you think about the range of things Jack just mentioned there, covering internal risk and compliance work, a third-party risk management, and then increasingly also agent governance and assurance work. There are point tools that look at sort of parts of those individually. I think there's not really anyone bringing to bear agent capabilities to have those all managed and observable in a single platform, right? So if you are thinking about the risks and compliance implications of a particular party, well, we intelligently and dynamically link that to your internal requirements, the controls that you've implemented, how those are implemented, and that is all being updated on an ongoing basis.
11:34John Daley:And so when you as a user come into our platform, you're benefiting from the massive amounts of work the agents have done on your behalf on an ongoing basis. And it's bringing you much closer to that point of decision making and action, which is really what the value add as a person using our platform is. It's like what are you actually – what decisions are you taking that change the way your enterprise operates to be more aligned with the security and compliance posture that you want? Or are you continuing, in fact, in the same way with more conviction on the basis of the work the agents have done?
12:11John Daley:I think that's really quite different from a legacy tools in this space that in the failure mode devolving to just checklists divorced from operational decision making.
12:27Jack Miller:And now you've raised this 7.3 million round. is this going to be on back further building out the product adding new capabilities or is this going to be about all right we've got something that works we've got something that we know can scale it's just about go to market and expansion yeah so i think there's a bit of both um we we
12:44John Daley:got to about a million dollar run rate with a three-person team in nine months from launching the platform which you know it was only possible because we leverage ai for everything across the business from software dev to to go to market to of running our daily internal stand-ups right um but with the ambition we have we know we need to bring on more um people although not the size of company that we would have had to build say two even two three years ago to get to the same outcomes so basically three three parties uh of this round uh people um so we're now 10 people uh we brought on a bunch of great engineers and the foundation of a great go-to-market team products.
13:24John Daley:There's a ton of customer demand we have to extend the capabilities we currently have. And then we have big emissions, particularly on the agentic assurance and governance side, which we can talk more about to build out over the next six to 12 months. And then, yeah, go to market. So to date, it's just been Jack and I, time to pay them to encounter lead sales. But now we're actually beginning to put a real go to market motion in place. And, you know, we think we're going into a big replacement cycle in the next few years where there's going to be tens of billions of dollars of enterprise spend changing over and we need to be in as many of those conversations as we possibly can.
14:02Jack Miller:And that replacement is really interesting. Why do you think that's going to happen? Why are the incumbents not well prepped for this new world?
14:11John Daley:Yeah. So I think Jack mentioned earlier our graph database atlas. And I think it really comes down to, have you architected your platform assuming it is agents doing most of the work, right? And I think like really foundationally, you need to have that assumption that we are building for a little bit. It is agents talking to other agents and people to both collect data, do assessment, and then take action. And that's been our foundational belief since we began building the platform, you know, 18 months ago. And I think the legacy of platforms who bolted on AI chatbots. There's a veneer of AI capability, but they're really not providing the agents that context and that capability in the background to do as much as effectively and as accurately as what we built.
15:04John Daley:And then there are other AI native platforms out there, but I think they haven't necessarily internalized some of the costs around that kind of data lot of building, which we work on very early in our engagements with customers. And this is informed both by Jax Research and also my time at Palantir, where we were very early to see that that data model of your enterprise is actually like the key differentiating thing in many ways. And so we internalize that. And when agents are carrying their tasks, they have that ability to understand like an analyst or a person would, right? Why am I doing this, right?
15:40John Daley:Well, it's because I'm in this part of the org. This is the type of concern we have. Here's the data I'm looking at, right? And I think that's a core thesis we have.
15:48Jack Miller:And this has become a particularly hot topic, I think, at the moment in the last few months, given some of the incidents that we've seen at OpenAI Ananthropic. You must live and breathe incidents like this. You must be really into the weeds and have a sort of an insider view of what's going on and what's happening. Can you share your views, I guess, on incidents like this, maybe a specific one, and what it means for the broader industry? Yeah. I think anybody that reads the report on the OpenAI incident, I don't think you can read that report and not update your views on the world. It's just such an insane thing to have happened.
16:27Jack Miller:And there's obviously the report and then WeShed internally was mandated listening for everybody at the company, the three Dwarkesh episodes about this. And so, obviously the Ryan Greenblatt one was not after the report, but covered the same topics. So that was mandated listening for everybody, even the salespeople, they've got to have a listen to it. And I think what it shows is a couple of things. I think number one, it shows that we do not have a good handle on what these models can do. It is remarkable to me, that they were able to do the sorts of things they were doing with this secret message board, with the coordination.
17:09Jack Miller:It is just incredible that that occurred. I mean, using the models day to day, they still make quite silly mistakes. And then seeing that this occurred internally is actually just a remarkable fact about the world that you have this kind of spikiness and capabilities that's hard to wrap your head around. I think the second thing is, I think the cybersecurity side is really interesting because in some sense, the cybersecurity capabilities are pretty good. They're pretty remarkable that they were able to do this, but I think it's actually more of a reflection on the incentives that exist in the industry today.
17:43Jack Miller:And those incentives are towards getting the best model out that you can and not necessarily observing what's going on within within your organization. So, you know, if you read the report, you can see that actually they use AI models to discover what has happened, right? So in a post hoc analysis, they use AI models to basically go through the logs, look at the traces, determine what's happened. Now, they could have easily been doing that during the time, right? If you had a monitor looking at the way that these models were doing the evaluation, you could have seen that this was occurring, And so that tells me that it's not necessarily a technology problem.
18:25Jack Miller:It is a technology problem in some sense, but it's also an incentive problem. And so one of the big pushes that we have at HelmGuard is to change the incentive landscape for security and compliance in general. to move to a world where if you are verifying something about a company, you don't expect that to be a sample. You expect that to be on the population level. You expect everything to be monitored because it's so cheap to do so. And some of our work with Colossum actually is bringing down the cost of this sort of agent monitoring by like orders of magnitude. And so to me, really, it's an incentive problem.
19:07Jack Miller:And we've kind of built Helmgard to change the incentives in this security and compliance industry to move towards a world where companies need to constantly monitor what's going on internally and that that will be the de facto standard moving into the future. And I think, you know, I think that really is a... It is that incentive piece, which is remarkable to me, that you can spend this much on compute. You can be running this eval and nobody is checking what's going on. that to me is the central fact that we should be focusing on um and that we need to change the way in which the industry works from a security and compliance perspective because look this is going to be happening in open ai obviously they trained a persistent model it's pretty clear that like there are some pretty like specific circumstances there but i think what you're going to see in like a year's time these sorts of incidents i wouldn't be surprised occurring in the enterprise especially with the use of open source models, especially with continual learning becoming more and more of a thing, I don't think it's unlikely that we'll see a case of this outside of the labs in the next year.
Read the full transcript
20:22Jack Miller:And the question is, if you're a 10-person IT team, how are you going to deal with that? It just seems like a very difficult problem to solve. And I think that goes back to our thesis of bringing these frontier capabilities to the everyday enterprise right because i think they will be struggling with the same governance concerns labs do um in a year two years time i mean it's crazy i mean it's absolutely absurd what happened how did it change how did did it change your both of your perceptions about the business that you're building or the scale of the problem that you're facing?
21:02John Daley:I think it made concrete some things that we've held for a while, but I think have been hard for our customers to necessarily understand. And that's a lot of what we're doing in our sales process. But I think there is that like, if you look at the traditional set of security and GSC work, one thing we're already doing there and I'm doing for the better part of a year now is saying things that were not sort of impossible, impossible, what were not economical to do, are now economical because agents can execute that work at expert level at very minimal cost. And so that changes where you should be spending time and effort as an organization, the types of decisions that you can form with that work.
21:42John Daley:That's the kind of internal risk and security and the third party prongs of our platform. On the agent assurance and governance side, it's sort of the same idea, but different that you can only do this work if you're operating in like AI native terms, right? You can't be keeping up with what agents are doing in your enterprise if you're not operating in an agentic way, right, on those terms at that speed with that same type of dynamic reasoning and assessment capability. And so that is like concretely what it means to be bringing these capabilities to bear in a defensive way. And I think if we do that correctly, it's actually quite an optimistic sort because unlike threat actors who are operating from the other side, you should be able to know everything that's going on within your organization and have that defensive edge, right?
22:32John Daley:But it is dependent upon actually bringing to bear and effectively deploying systems like ours, we hope, and others that can help you do that. You know, what agents are running, what are they doing on a dynamic basis because they're acting dynamically? Is it consistent with what we're expecting and looking at the reasoning and the traces and the tool calls? And so both in a static configuration and at runtime. time and that's really how we're extending our platform and that's a big set of product investments
23:03Jack Miller:that we're making uh with this round yeah i mean it's so interesting that people have just been so focused on kind of like value and yeah you know just trying to get as much deployed and loads of people have been given these budgets to spend on ai tools and they're like laser focused on trying to see something happen and value that they're skipping all this vital infrastructure in the middle to actually make sure that the thing is safe and secure uh well look very grateful to to what you're both out of time. Massive congratulations to what you both have done so far and the round that you've raised.
23:32Jack Miller:It's going to be really exciting to see the next stage of your journey and keep me informed as things grow. Of course. I can't wait to be doing this at the Series A. I look forward to it. Thank you so much, Sam.
From the publisher
HelmGuard just raised a $7.3m Seed round led by Infinity Ventures and Frontline. Its AI agents handle a company's security and compliance work automatically, checking everything all the time instead of relying on manual paperwork and periodic reviews.
John Daley and Jack Miller are HelmGuard's co-founders, John as CEO and Jack as CTO. It took them just nine months to hit a million dollars in run rate with a three-person team.
The Scaling Europe show is presented by Deel. Check them out here: https://get.deel.com/ruynb7o4lfjk
Sponsors:
SurrealDB: https://surrealdb.com/
Airwallex: https://www.airwallex.com/uk
Lovable: https://lovable.dev/
Parloa: https://www.parloa.com/
Conveo: https://conveo.ai/
NatWest: https://www.natwest.com/
WWT: https://www.wwt.com/
Timestamps:
0:00 - Introduction
0:20 - HelmGuard's $7.3m seed round
0:45 - What HelmGuard's platform does
1:15 - John's eight years at Palantir
2:24 - Jack's background in AI research
5:48 - How HelmGuard reacts to new model releases
8:45 - HelmGuard's work with Callosum
12:27 - HelmGuard's plans for the new funding
14:12 - Why legacy security platforms can't keep up
15:54 - What the OpenAI incident means for AI oversight
20:57 - How the OpenAI incident changed HelmGuard's thinking
