Aslan raises $20.8M to run AI agents as undercover spies

Share
Aslan raises $20.8M to run AI agents as undercover spies

Two agent stories worth your attention tonight: a startup is selling the FBI autonomous undercover personas, and Anthropic is handing enterprises back the keys to their own data after 30-day retention spooked its biggest customers.


Aslan came out of stealth with $20.8 million to build AI agents that work like undercover spies in online forums. Khosla Ventures and XYZ Venture Capital led the round, with 2048 Ventures, BoxGroup, Liquid2 and Alumni Ventures also participating, and CEO Chase Reid told Axios the agents — each overseen by a human — do the work of FBI analysts and undercover operatives inside Telegram channels and dark web forums. "It's not just passively collecting," Reid said. "Our agents are capable of actively engaging and doing cyber effects within these online ecosystems." In one case he described, agents ran autonomously for 21 days and two of them reached a tiny Telegram channel where six people were coordinating a smuggling operation, pulling out who the coordinators were and when the border crossing would happen.

The FBI and Homeland Security Investigations have already worked with Aslan on investigations, according to Reid, and the company says it uncovered a coordinated Chinese recruitment effort aimed at U.S. defense professionals. That last detail is the one to sit with: this is not a chatbot summarizing open-source chatter, it is a persistent synthetic identity that can hold a relationship with a target for weeks. The sector has neighbors — Massive Blue's Overwatch platform has sold AI personas to local law enforcement, and the FBI has more than 100 approved AI use cases with an $88 million computing contract behind them — but Aslan is the first to wrap it in a national-security funding story at this size. The open question isn't capability, it's standing: nobody has settled who is legally responsible when an agent makes a promise during an investigation, and defense attorneys are lining up to test exactly that.


Anthropic reversed course on enterprise data retention. The company introduced Enterprise Frontier Safeguards, which stores customer activity data in cloud infrastructure the customer controls — on AWS, Google Cloud or Azure — rather than on Anthropic's own systems, while keeping the cross-account monitoring it says it needs to catch misuse. Eligible customers get zero data retention on Fable 5 and Fable 5.1 in the meantime, with EFS rolling out in phases starting this fall.

The retreat is the interesting part. Anthropic introduced 30-day retention with Fable 5 specifically because it wanted visibility into abuse — it cites attempted misuse ranging from fraud to autonomous agents engaging in destructive behavior, sometimes using stolen enterprise credentials that are hard to spot without watching traffic over time. It built EFS with more than 100 customers across financial services, healthcare, law and the public sector, including the CISOs of every U.S. global systemically important bank through the Analysis and Resilience Center for Systemic Risk. The compromise it landed on keeps the monitoring but moves the storage and the human review into the customer's own cloud account, with customer-managed encryption keys and fully automated review each opt-in. Anthropic says it isn't charging for it — customers pay their own cloud bills. It's a capitulation dressed as a product launch, and it tells you where the leverage sits in enterprise AI: the buyer's compliance team, not the lab's safety team.


CrowdStrike declared breakout time effectively dead at Fal.Con, and its answer is to let two AI models fight each other. The company launched SafeMind, a harness built on Nvidia's Nemotron open model that pairs Red Tempest — an offensive model trained on Falcon telemetry and 15 years of incident-response data — with Blue Solano, a defensive model that patches what Red Tempest finds. Red Tempest probes a digital twin of a customer's environment built from Falcon sensor data; Blue Solano remediates, and the loop repeats until nothing is left. CEO George Kurtz has spent years narrating breakout time falling from two minutes to 72 seconds to 30 seconds; this year the message was that the number is now just runtime. Nvidia's Jensen Huang shared the stage as both partner and customer, saying SafeMind has replicated Nvidia's own IT environment.

The framing that stuck came from theCUBE's Dave Vellante: the old pyramid of pain put nation-states at the top, and now agents sit there and the pyramid is flat — the adversary is a prompt. That is a genuine change in the defender's problem, and CrowdStrike is selling the obvious response, which is to meet machine-speed offense with machine-speed defense. Skepticism is warranted on two counts. Both models come from the same vendor's telemetry, so "Red Tempest found it and Blue Solano fixed it" is closer to a self-grading exam than an independent audit, and the loop only sees attack paths that Falcon's data can represent. We covered the open-source version of this idea this morning — OpenAEV v3 turns red-teaming autonomous and aims it at AI agents — and the pattern is clear: autonomous offense is arriving faster than anyone's ability to score it.

Would you trust an AI persona to go undercover in a criminal network on your behalf, and who should answer for its choices? Tell us in the comments.

Sources: Axios via Yahoo Tech · Techmeme · Crypto Briefing · Anthropic · CNBC · CSO Online · SiliconANGLE · CrowdStrike