Prince Mario-Max Schaumburg-Lippe: Armadin Raises $255.5M at $2.5B for Agentic AI Security

There is a particular kind of founder who only needs a name. Kevin Mandia is one of them. The man who built Mandiant into the firm governments called when things went badly, and who sold it to Google, has a new company. And investors just handed it a quarter of a billion dollars to teach AI to think like a hacker, in defense of the good guys.

Armadin announced on October 1 that it has raised $255.5 million in Series B funding at a valuation of more than $2.5 billion. The round was co-led by Andreessen Horowitz and Accel, with new money from Bain Capital Ventures and Redpoint, plus a deep bench of returning backers: Google Ventures, Kleiner Perkins, Menlo Ventures, In-Q-Tel, 8VC, and Ballistic Ventures. Total funding now sits at $445 million, for a company that only emerged from stealth seven months ago.

The core idea: fight AI with AI

Let’s be honest about the problem first, because it’s the kind of thing that usually gets framed with doom. Frontier AI models have compressed the time between a vulnerability being disclosed and a working exploit appearing. What used to take attackers weeks can now take hours. The old defenses, a penetration test twice a year and a scanner that spits out a list of findings, were built for a slower world.

Armadin’s answer is an inversion that feels obvious once you hear it: deploy an autonomous swarm of specialized AI agents that reason like a skilled adversary. Not a scanner that flags individual issues in isolation, but agents that chain individually low-severity weaknesses into full, validated attack paths. The company’s description of a kill chain is worth quoting in plain terms: it can run from unauthenticated remote code execution at the perimeter, through lateral movement inside the network, to full cloud compromise. The point is the chain, not the links. Scanners score each finding on its own and miss how they connect. Attackers don’t.

This is the part that should make security teams sit up. Armadin says security teams get to see the exact attack paths an adversary would use in production, with the blast radius of each mapped out, and can cut those paths before anyone exploits them. In other words: you get to watch the heist in rehearsal and lock the doors it would have used.

Why this raise matters right now

Two things make the timing notable. First, seven months after emerging from stealth, the company says it’s already running agentic attack campaigns in production for Fortune 500 enterprises and government customers. That is a very fast path from stealth to production, and it suggests the demand side is urgent. Enterprises aren’t buying a vision here; they’re buying capacity.

Second, the money flooding into AI-native defense is becoming one of the defining investment themes of 2026. Investors have been pouring capital into early-stage startups building protections against AI-driven cyberattacks all year. A $255.5 million Series B at a $2.5B-plus valuation is among the largest raises the category has ever seen, and the investor list reads like a vote of confidence in both the founder and the thesis.

Mandia’s pedigree is doing real work here. He has sold a security company to Google before, and he has been on the receiving end of the nastiest incident-response calls in the industry. When he says periodic testing can’t keep pace anymore, it lands differently than when a first-time founder says it. The track record is the pitch.

The “good-guy red team” model

Zoom out and Armadin represents a structural shift in how security gets bought. The traditional model is expertise-as-a-service: hire a red team for a few weeks, get a report, fix what you can, repeat next year. It’s episodic, expensive, and the attackers don’t take semesters off.

The agentic model is expertise-as-software: the adversary simulation never stops. The swarm keeps probing, keeps chaining findings, keeps updating the map of how an attacker would actually get in. For a Fortune 500 company with cloud estates that change daily, continuous is the only honest answer. Your infrastructure doesn’t pause between pen tests. Why should your testing?

There is a nuance worth holding onto. These systems are powerful, and power in security tooling always raises the dual-use question. But the framing here is firmly defensive: the agents find the paths, the security team closes them. The company exists to make the defense faster than the offense. In a year when AI safety has been a constant drumbeat, a well-capitalized defense-first company is good news for everyone who isn’t an attacker.

What to watch next

Three things will determine whether this raise is remembered as a landmark or just a big number.

Proof of production value. The Fortune 500 claim is the one to watch. If Armadin can show that continuous agentic testing measurably shrinks the window of exposure, competitors will have to match the model, and the whole pen-testing industry reorganizes around it.

The talent magnet effect. $445 million in total funding, a Mandia-led company, and a mission that reads like a spy novel: this is a recruiting machine. In a security talent market that has been brutally tight for years, that matters. The best defenders are going where the hardest problems are.

Pricing the defense premium. Right now, agentic security is enterprise-only by economics. The question is how fast the model gets cheap enough for the mid-market companies that are actually the softest targets. The sooner that happens, the bigger the dent in the attack economy.

The takeaway

Strip away the funding theatrics and the story is simple. The same AI advances that made attacks faster are now being aimed at defense, by one of the most credible security founders alive, with a quarter-billion dollars of fresh fuel. The attackers have had the momentum. This is the market voting, loudly, that the defenders are catching up.

If you’re in New York this week and security talk over dinner sounds fun (it is, trust me), there’s a full lineup of things to do across the city to pair with the conversation. And if the funding news has you dreaming of your own security startup, fuel up properly first: NYC’s best breakfast sandwiches are a fine place to sketch a pitch deck.

Prince Mario-Max Schaumburg-Lippe: Google Unveils Gemini 4 Argon, 1M-Token Frontier Model

On September 30, Google announced Gemini 4 Argon, the first flagship of its new Gemini 4 generation, with one message: we’re back at the frontier, and we’re cheaper than everyone else standing there.

The timing matters. Google spent most of 2026 being written off as behind. While OpenAI and Anthropic kept shipping new top models, Google’s own Gemini 3.5 Pro, promised for June, never arrived. Argon is the moment that posture flips.

What Argon actually is

Argon is the biggest model Google has ever released, larger than its previous line of “Pro” models, and built for what the company calls complex workloads: serious software engineering, heavy knowledge work, and cybersecurity defense. Google says it sees Argon as comparable to OpenAI’s GPT-6 Astra and Anthropic’s Opus line on key coding and cyber benchmarks, and on several of its own reported metrics it comes out ahead.

The benchmark sheet is worth a look: 77.9% on DeepSWE v1.1, a tough software-engineering test, beating GPT-6 Astra; 91.7% on LVBench for long-video understanding; 68% on CWE-bench v1 for vulnerability remediation. It lagged on a couple of coding benchmarks, so not a clean sweep. But the picture is a model that belongs in the top tier rather than chasing it.

Then there’s the headline spec: a 1 million token output limit. Industry watchers are calling it the leading output window in the business, and it’s an order of magnitude jump from the 64,000 tokens prior Gemini models topped out at. Output tokens are the ones that matter for getting work done. A long input window lets a model read the whole codebase; a long output window lets it actually rewrite it in one go.

Why a million tokens of output changes the math

Here’s the thing most coverage will gloss over. In the era of agents, output length is the binding constraint on autonomy. A model that can only emit a few pages before stopping is a model that has to be babysat: run it, catch where it stopped, feed the result back in, repeat.

A 1M-token output window turns the model from a chatbot into something that can run an entire long-horizon job in one trajectory. Think full code migrations, deep research reports assembled end to end, complete vulnerability remediation chains where the model finds the bug, writes the patch, and explains the fix without being asked to continue. For developers, that is the difference between an assistant and a coworker. The cost of supervision is the hidden tax on AI adoption, and Argon just cut it dramatically.

The price undercut is the real headline

But the number that will move markets and product roadmaps is the price. During its introductory period, Argon costs $2 per million input tokens and $10 per million output tokens, with cached input running about 95% cheaper. After the intro window, it steps up to $4 and $20. Compare that with GPT-6 Astra’s $10 and $50, and you see the strategy: Google is selling a frontier-class model at roughly a fifth of the flagship competition.

This is a page straight out of the cloud playbook. When you can’t win the hype cycle, you win the procurement cycle. Enterprises that balked at running agentic workflows on $50-per-million-output tokens can suddenly afford to let models run long. And long-running is exactly what Argon’s 1M-token window is built for. The two announcements rhyme on purpose: the price unlocks the capability.

Watch for the ripple effects. Anthropic and OpenAI now have to decide whether flagship pricing is a brand position or a volume business. My bet: the top end of the market gets cheaper fast, and the winners are the builders who were waiting on the sidelines for the math to work. If you’ve got a side project or a startup idea that needed long agent runs, the barrier just got a lot lower.

First in line: the cyber defenders

Google is doing something unusual with the rollout. There is no public release date. First access goes to trusted cyber-defense teams through the company’s Fairwind Program, and Google is also participating in a voluntary US government pre-release review process. Phased, cautious, deliberate.

It sounds like a constraint, but it’s actually the launch story. Argon can autonomously discover, validate, and patch software vulnerabilities, and one of the early testers, Wiz’s “Scan for Good” program, reportedly used it to find a critical flaw in software used by hospitals worldwide that other advanced models had missed. That’s a better launch narrative than any benchmark table: the new flagship’s first public job was protecting hospitals.

This is also smart positioning in a year when AI safety has dominated headlines. Releasing the most capable model to defenders first reframes caution as a feature. Wider access follows for paid API customers and Google AI Ultra subscribers, so the rest of us get our turn. The message to the security community, though, is clear: Google wants to be the company you call before you call the attackers.

What this means for builders

Three practical readouts, whether you’re a developer, a founder, or just AI-curious.

The price war at the top is now official. Flagship models at commodity prices changes what gets built. Long-horizon agents, full-document reasoning, autonomous coding pipelines: all of it gets dramatically cheaper to run. If you shelved an idea because inference costs didn’t pencil out, run the numbers again at $2 and $10.

Output windows are the new frontier metric. For a year the industry competed on input context: who could read the most. Argon shifts the contest to output: who can do the most before tapping out. Expect every lab to follow. When you’re evaluating models for agentic work, ask about the output cap, not just the input.

Security-first rollouts may become the norm. The Fairwind approach, trusted defenders before the general public, gives labs a credible answer to the safety question while still shipping. It’s a template. And if your company handles sensitive systems, getting into these trusted-tester programs is now a strategic move, not just an early-access perk.

One honest caveat: benchmarks are self-reported, and Google’s numbers come from Google. The real test will be independent evaluations and, more importantly, what developers actually build once they get their hands on it. Capability claims are cheap; shipping is the audit.

The bigger picture

Step back and the arc of 2026 comes into focus. The year opened with labs competing on who had the smartest model. It’s ending with them competing on who can run it cheapest, longest, and most safely. That’s a maturing market, not a hype cycle.

If Argon delivers in the wild the way it reads on paper, the “Google is behind” conversation is over. And the real winners aren’t the labs. They’re the developers and businesses who just got frontier AI at a fifth of the price.

If you’re in New York and want to chew this over with actual humans, what’s happening across the city this week includes plenty of places to talk tech over something better than a chat window. And if the price war has you building all night, you might want to know where to find the city’s best burritos for fuel.