Gray Swan AI
15,000 red-teamers paid in prize money; revenue from the software their attacks train. The widest inferred spread in the atlas, on the thinnest evidence.
Latest (Sep 2026): Hired Rob Jenks (ex-Tanium SVP) as Chief Strategy Officer on 2026-01-08. Announced a $40M Series A on 2026-05-28 co-led by Wing VC and Madrona (with Obvious, Snowflake Ventures, Hudson River Trading, Samsung Next, Magarac), bringing total raised to ~$50M; Forbes put the valuation at $200M and said frontier labs are the majority of current revenue across ~20 customers. Its work is cited in frontier system cards (Anthropic, OpenAI, Meta), and in June 2026 the founders said the automated Shade system now beats human red-teamers on fixed-time tasks.
Gray Swan runs three products off one asset. Arena is a crowd of roughly 15,000 red-teamers who attack models in timed, prize-funded challenges. Shade is automated red-teaming. Cygnal is runtime guardrails. The crowd generates attack data; the software is what enterprises buy (Forbes Australia; RL List).
That separation is the company. Forbes states it directly: enterprise revenue comes from Shade and Cygnal, not from Arena — Arena's output trains the products. The crowd is compensated in challenge prizes; the value accrues to a software line.
The money
$40M Series A at roughly $200M post-money, May 2026, co-led by Wing VC and Madrona with Snowflake Ventures, Hudson River Trading and Samsung Next (Gray Swan). Total raised is approximately $45M+; the atlas register carries no earlier priced round.
Revenue: not disclosed, anywhere, at any point. Neither is customer count beyond "20+ enterprise customers", nor gross margin, nor the cost of the crowd. Every economic claim on this page is an inference.
Customers
Verified: Anthropic, OpenAI, Meta, the UK AI Security Institute. Claimed but not independently confirmed: Google DeepMind, xAI, Amazon, Snowflake, ByteDance, ElevenLabs, Intercom, Deloitte (Forbes Australia; RL List).
The distribution asset is not the customer list, it is the citation list: Gray Swan's work appears in 11 frontier model system cards, including GPT-5. A system card mention is a durable, public, third-party endorsement that a competitor cannot buy. It is the closest thing to a moat on the buyer side of Adversarial evals and red-team crowds.
Note the shape of that customer base against One customer is a binary event. A handful of frontier labs plus 20-odd enterprises is a short list, and nobody has published what share the largest one represents. Appen was worth $4.3B with 80% of revenue in five clients before Google left.
What the crowd is paid
This is the documented half of the business.
The UK AISI challenge run with OpenAI, Anthropic and Google DeepMind carried a total prize pool of $171,800: $86,000 on the leaderboard, $45,000 distributed by volume, $25,800 in first-break bounties at $300 each, $10,000 for over-refusal, $5,000 for new users, with a $100 minimum payout threshold. Gray Swan challenge pools generally range $40,000–$300,000+ (MBG Security).
At the individual level: a profiled top red-teamer earned $10,000 across 1,000+ challenges in roughly a year.
Set that against the alternative on offer. Lab-run bounties pay OpenAI up to $100k (standard awards $200–$20,000), Anthropic max $15,000, Google's AI VRP from $30,000 — with median payouts of $500–$5,000 across programmes (Wraith). Arena competes for the same people, and the people can go direct. That is the Getting cut out risk, and it is unquantified.
The take rate, and why it is a guess
The atlas estimates Gray Swan's effective take on its crowd's output at >90% [UNVERIFIED]. That number is built from two separately sourced facts — prize pools in the tens to low hundreds of thousands, and enterprise revenue attributed to Shade and Cygnal rather than Arena — with nothing connecting them. Gray Swan has never disclosed revenue or cost of crowd. The estimate is a structural argument about where value lands, not a measurement, and it should not be typed into a model. Compare Expert networks, where the ~70–80% take is observed from both sides of the trade, or Prolific, which publishes a 42.8% platform fee on its own pricing page. See What a rake can actually be and GMV is not revenue.
The one comparable that states its mechanism openly is Synack: buyers purchase flat credits and "researchers are compensated internally by Synack". The platform absorbs the variance and keeps the difference. Gray Swan's structure looks like that with a leaderboard bolted on and a software business attached to the exhaust.
What to watch
Whether Shade cannibalises Arena. Automated red-teaming trained on crowd output is, eventually, a substitute for crowd output. That is either the correct strategy — convert transient human labour into a renewing asset, the same move Distyl AI is attempting in Forward-deployed engineering — or the moment the crowd realises what it is building. Both readings are live; see What better models do to each layer.
Whether the crowd stays. $10,000 a year for a top performer, on a platform marked at $200M, is the arithmetic that gets posted to a forum. The prize mechanic works because status is part of the compensation; status is fragile.
Whether revenue arrives. The Information published "Revenue Lags at AI Evaluation Startups" on 14 April 2025 — the atlas has the headline and dateline, not the article. Haize Labs reached a ~$100M valuation seven months after founding on a General Catalyst seed (PitchBook) and has generated no coverage since. Irregular raised $80M at $450M post from Sequoia and Redpoint (TechCrunch). None of these companies has published a revenue figure; the vertical has no observed cash valuation in its history — Lakera's sale to Check Point and Robust Intelligence's to Cisco were both undisclosed. See What the public market pays for labour.
Founding date, headquarters, headcount, revenue, gross margin, customer concentration, cost of crowd, and the Arena/Shade/Cygnal revenue split. The single source for the crowd-versus-software separation is one Forbes piece. For a company whose valuation rests entirely on that separation being true, the record is close to empty.
The specialist wedge
The bet is that one domain buys cheaper experts and faster belief, and that both advantages expire the moment you have a reference customer. What would have to be true, what the evidence supports, and the trade-off that decides which niche.
Gray Swan, in full
The crowd is not the product — it is the training set for the product. 15,000 people produced 130,000 breaks for $490K, and the Arena terms hand Gray Swan an irrevocable worldwide licence to all of it at under four dollars a unit.
Offensive supply
Every researcher count in this market is inflated about thirtyfold, the median earning bug bounty hunter makes $1,620 a year, and twenty hours at $85 beats that — so the recruit is the 97% the platforms never monetised, not the top hundred.
The labs as buyers
Two buyers hold the money, and both have said in writing that their cyber evaluation stock is exhausted — one paused a frontier training run over it, the other published the sentence that is the whole sales pitch.
The security read
Build, still — but on worse terms than the first reading. The six firms are named, one of them already sells this exact product to at least two labs, the first contract values in the market's history are now public from UK transparency data, and the elite labour tier costs three times what the earlier estimate assumed.
The one shape that survives
AddressSanitizer separates a real memory-corruption bug from a hallucinated one with zero false positives. For logic bugs Anthropic says it loses that ability entirely — and hires professional human contractors instead. That sentence is the whole business: expert validation of logic vulnerabilities, plus the held-out evaluation content that falls out of it.
Commercial buyers
The weakest section in the dossier, said plainly: no job posting, contract or methodology section anywhere names a paid external annotator at a security vendor. What is evidenced is a segment that needs a scoreboard and is losing the only neutral one.
Defensive security
The widest benchmark gap found anywhere — frontier models at 23–34% on malware analysis — with a small reachable pool and the hardest data-sourcing problem in the set. Superseded: the deep dossier found the incumbent this page said did not exist.
Paying the crowd
Gray Swan buys perpetual worldwide rights to an attack trajectory for about $3.77; Mercor pays $70–95 an hour and up for the same skill. Tournament and payroll are different products, and the buyer of a dataset wants the expensive one.
The bounty platforms
HackerOne has publicly foreclosed selling its corpus and Bugcrowd built an RL product that routes around its own researchers — the two incumbents with the best human attack data both looked at paying humans for licensable trajectories and declined.
The capital register
Every company the sweep found, with what it raised, what it was marked at, what it earns and whether that revenue is gross or net. Plus the exits, the failures and the absence of a public bear case.
Adversarial evals and red-team crowds
Labs pay five and six figures per model to be attacked; the attackers are paid in prize money. The widest spread and the scarcest supply in the sweep.
Evidence register
Not a bibliography — a graded list of the claims the atlas leans on, what each one holds up, where it came from and how much weight it will take.
Irregular
The company you have filed as Pattern Labs. Same firm, new name: 35 people in Tel Aviv running cyber evals for four frontier labs, at $450M.
Sizing the cyber pot
$25M–$120M a year, most likely $40M–$80M, for externally-sourced frontier-lab cyber evaluation content in 2026 — derived two independent ways that bracket each other, with every step of the working shown and every figure an inference.
Vals AI
$40M at $400M for building the benchmark layer in professions the labs were not yet buying for. The existence proof that a specialist can manufacture a budget rather than wait for one.
How this was built
Eight research passes, about 54,000 words of notes, a writing pass and a verification pass — built with a search budget that ran out partway through, which shaped what is here and what is missing.
Offensive security
The strongest demand evidence of any niche in this atlas — named in system cards, with lab reqs carrying pay bands — which is exactly why two funded specialists already own the network and the benchmark.
Centaur Labs
The clinical incumbent: $31M raised to crowdsource medical annotation through a diagnosis game. It sells labelled artefacts, which leaves physician reasoning unsold.