Miju Labs

The security dossier

Gray Swan, in full

The crowd is not the product — it is the training set for the product. 15,000 people produced 130,000 breaks for $490K, and the Arena terms hand Gray Swan an irrevocable worldwide licence to all of it at under four dollars a unit.

medium confidence9 minupdated 2026-08-30gray swan · crowds · red-teaming · data rights · unit economics

The short profile at Gray Swan AI says the software is what enterprises buy and the crowd is what trains it. That separation is not an inference. The founders describe it themselves, and once you take it literally the rest of the company falls into place.

Arena results feed Shade's training. Matt Fredrikson and Zico Kolter describe a "virtuous cycle: community findings → model training → better products → customer value" (Latent Space). And they say what the cycle has produced: Shade is "quite a bit better" than human red teamers, outperforming people at breaking models within a given time window and task set.

Read those two statements in sequence. Fifteen thousand people are contributing, in a tournament, to a system whose stated performance benchmark is those same people — and the system is winning.

The one-line version

Gray Swan is not a competitor selling human offensive data. It is a competitor that has worked out how to acquire human offensive data at ~$3.77 a unit with perpetual rights, in order to build the model that replaces the humans producing it.

What the crowd cost

Gray Swan publishes unusually good numbers on its own Arena About page, and they are the only crowd economics disclosed by anyone in this market.

FigureValue
Community members13,000+ (About page); 15,000 (Forbes and the Series A release)
Total lifetime rewards distributed$490,000+
Attack attempts submitted4,000,000+
Successful breaks130,000+
Participants placed in paid red-team roles100+

The two community figures come from different sources and are not reconciled anywhere. The About page says 13,000+; Forbes and the Series A press release say 15,000. The gap is probably registered-versus-active or simple date drift. It matters only because it moves the per-head figure by 15%, and the per-head figure is the whole point.

Dividing through — my arithmetic on company-reported aggregates, not a disclosed unit price:

  • ~$33 of lifetime earnings per community member ($490K ÷ 15,000)
  • ~$3.77 per successful break ($490K ÷ 130,000)
  • ~$0.12 per attack attempt ($490K ÷ 4M)

These are the economics of a game, not a labour market. The design makes that deliberate. The Indirect Prompt Injection Q1 2026 challenge carried a $40,000 pool split across roughly sixty leaderboard positions plus per-model pools capped at the first 500 breaks, with a $100 minimum payout threshold and sub-$100 earnings carried forward indefinitely (rules page). The median participant in any given challenge earns literally nothing.

Cyber specifically is cheap even by Arena standards. The concurrent "Hazard Hunt: Chem, Bio, Cyber, Misc" challenge carried $80,000 total, split $20,000 to each of four categories (leaderboard). Twenty thousand dollars is the current going rate for a cyber-category competition — which is roughly one week of a single senior contractor at the rates on The generalists in cyber.

Prize pool ranges disagree across sources

The About page gives a range of $20,000–$170,000+ per competition. Secondary coverage cited on Gray Swan AI gives $40,000–$300,000+, and documents one UK AISI challenge at $171,800. Both may be true of different periods. Use the company's own range when modelling and note that the ceiling is unsettled.

The clause that matters more than the price

Buried in the Arena terms is the single most important commercial fact in this sector. By submitting, participants grant "Gray Swan AI and its partners an irrevocable, worldwide license to use and share the submission for any purpose" (Arena About).

Take the words apart. Irrevocable — no participant can withdraw consent later. Worldwide — no territorial carve-out. And its partners — sublicensable to the labs. For any purpose — no field-of-use limit, no training carve-out, no research-only restriction.

Gray Swan acquires unrestricted, perpetual, sublicensable rights to every attack trajectory in the corpus for an average of $3.77 per successful break.

Set that against the position the bug bounty platforms hold. On The bounty platforms, HackerOne's researchers retain IP, HackerOne takes a licence limited to providing the service, and neither HackerOne nor its customers may resell. The largest human attack corpus in existence is contractually locked; the second-largest is contractually free. That difference is not a detail of drafting — it is the entire reason one of these companies can train a model on its crowd and the other cannot.

Other Arena terms worth knowing: one account per person, manual submissions only, AI assistance for strategy permitted, a 30-day disclosure embargo, 18+, residents of Russia, North Korea, Iran, Syria and Cuba ineligible, payment within two to four weeks of close, winners bear all tax.

What the citations are worth

Gray Swan appears in 11 frontier model system cards (RL List), with verified customers listed as Anthropic, OpenAI, Meta and the UK AI Security Institute. The Series A release claims "over 20 customers across frontier labs and global enterprises." Six of the largest buyers — UK AISI, OpenAI, Anthropic, Amazon, Meta and Google DeepMind — co-sponsored a single $40,000 challenge pool.

That citation stack is the asset a competitor cannot buy, and it is the same asset Irregular holds from a completely different production model. Note what it implies about One customer is a binary event on the buyer side: a company whose distribution is eleven system cards has a customer list short enough to fit on one line.

The 0.7% that should govern anyone's supply plan

Fifteen thousand signups produced 100+ people good enough to be placed into paid red-teaming roles. That is a 0.7% conversion from crowd to professional, computed and published by the party with the strongest incentive for it to look higher.

It is the most useful number Gray Swan has released, and it is bad news for anyone planning to assemble offensive supply by advertising. If the funnel that reaches the densest concentration of AI-specific offensive talent anywhere converts at seven in a thousand, the realistic ceiling on genuinely qualified practitioners is thousands, not hundreds of thousands. Offensive supply works that through.

The corollary is more useful still: the 14,900 who did not convert are not worthless, they are unmonetised. They are also not exclusive. Their submissions are bound to Gray Swan; the people are not.

What this means if you are entering

Three consequences, in order of severity.

Your supply would be bid against by a competitor whose cost basis is a prize pool. Gray Swan does not need to pay market rates for attack trajectories because it is not buying labour, it is running a tournament that transfers all discovery risk to the participant. A company paying $85–$250/hr for the same people is competing against a cost structure of $3.77 a unit. You cannot win that on price, and should not try — the pitch has to be that hourly, consented, provenance-clean production yields a different artefact, not a cheaper one. See Paying the crowd.

The rights position is the product, not the data. Gray Swan's advantage over HackerOne is not corpus size — HackerOne's is larger by orders of magnitude. It is that one has a licence and the other does not. Any competitor's contracting must resolve this at the point of signature, and must pay enough that a full perpetual sublicensable assignment is uncontroversial, because a dataset with murky provenance is unsellable to a frontier lab.

The buyer is trying to make the seller unnecessary. Shade is already reported as better than human red teamers on bounded tasks. That is the direction of the whole category, and The autonomous pentest field shows the same pattern with a $2B outcome attached. The counter-argument is real — every one of those systems was trained on human data and the frontier keeps moving — but it makes this a business whose customers are actively funding its obsolescence, which is a different risk profile from a normal supply business. See Getting cut out for the related question of what stops the crowd going direct.

What Gray Swan has never disclosed

Revenue, and the split between Shade/Cygnal licences, paid lab evaluations and private arenas — which determines whether the crowd is a cost centre or a profit centre, and therefore whether any of this is replicable. Also: founding date from a primary source, headcount beyond a directory's "11–50", the cost of running the Arena, and the canonical list of the eleven system cards. The $200M valuation is single-sourced to Forbes and the company's own release does not disclose it.