
Agentic governance, risk and compliance platform HelmGuard has raised $7.3 million to expand in the US and develop technology that monitors AI agents at runtime.
Infinity Ventures and Frontline co-led the seed round, with participation from FinTech Collective, Stage 2 Capital and Entrepreneurs First. HelmGuard plans to establish operations in New York and San Francisco, recruit engineering and commercial staff, and accelerate development of its agent assurance layer and Verified Risk Network.HelmGuard uses specialised AI agents for third-party risk management, control assessments and AI governance. The company says the agents collect evidence from source systems, test it against policies and controls, and connect risks, assets, suppliers and AI applications within a single view.
Third-party assessment data can become stale quickly. Questionnaires, certifications and audit reports recording a supplier’s controls provide snapshots, but underlying risks can change as suppliers modify systems, subcontractor relationships, access new data sources or deploy AI agents.
HelmGuard says its Verified Risk Network is designed to replace repeated document exchanges by checking claims against underlying evidence. Vendors can publish claims verified by HelmGuard agents, supported by a provenance record and automated AI review. Buyers can query those claims when assessing a supplier or monitoring an existing relationship.
“The Verified Risk Network makes the unit of assurance a claim assessed directly by an agent, rather than a document, and enables agent-to-agent exchange on a continuous basis,” said Jack Miller, co-founder and chief technology officer at HelmGuard.
HelmGuard serves customers in the US, Canada, UK, Hong Kong and South Africa across financial services, insurance, healthcare and industrial markets. HelmGuard says one US insurance client used the platform to assess 1,250 counterparties in less than a week before migrating from its previous GRC system. Another customer automated parts of its customer-assurance process and reduced initial response times from days to minutes.Pressure on Third-Party Oversight
Financial institutions are heavily dependent on third-parties with EU and UK rules requiring firms to monitor those suppliers throughout the relationship and, more importantly, firms retain accountability for the risks involved.
HelmGuard cites research by EY that found 32% of surveyed businesses placed third-party and supply-chain risk among their three leading threats. Of those businesses, 41% had limited or no confidence in their compliance function’s ability to manage it. EY also found that 62% believed their processes or systems restricted the speed or coordination of their response.
The European Union’s Digital Operational Resilience Act (DORA), requires financial entities to include information and communications technology (ICT) third-party risk within their risk-management frameworks and monitor their technology dependencies continuously.
The UK’s Critical Third Parties regime has brought designated providers of systemic services under direct regulatory oversight. Regulated firms and financial market infrastructures remain responsible for due diligence, risk management and contingency planning across their third-party arrangements.
HelmGuard says its platform combines structured records, contracts, policies and other unstructured material with evidence collected from internal and third-party systems. Its agents prepare assessments and identify changes for review by designated employees who approve, reject or escalate the findings.
“Most compliance platforms were built to document a process, not to reach a conclusion,” said John Daley, co-founder and chief executive officer of HelmGuard. He said the company’s agents collect and assess risk signals at source, reducing the manual work involved in gathering evidence and completing assessments.
Monitoring Agents at Runtime
HelmGuard will use part of the funding to develop an assurance layer for AI agents operating inside enterprise applications and workflows. The company says the technology will monitor agent behaviour at runtime or asynchronously and compare that activity with the organisation’s policies, controls and approved operating parameters.
Firms need to monitor agents that call external tools, access sensitive systems and complete multi-stage tasks alongside internal models and policies.
ESMA research published in 2026 found that 22% of surveyed securities firms used or planned to use agentic AI. Only 5% hosted their AI systems entirely on private infrastructure.
Anthropic and the UK AI Security Institute have separately reported unauthorised agent actions during cybersecurity evaluations in environments with internet access or reduced safeguards.
Anthropic identified three incidents where Claude models accessed organisations’ systems without authorisation. The evaluation environment had retained internet access following a misunderstanding between Anthropic and an evaluation partner. The models were also operating without the classifiers and monitoring used in Anthropic’s commercial deployments. Anthropic attributed the incidents primarily to failures in the evaluation harness and its operation rather than model alignment.
In the separate AI Security Institute exercise, agents took 19 unsanctioned actions across 10 of 122 evaluation runs. In the most serious case, an agent attempted to insert malicious code into an open-source project and created false identities to encourage its approval. A human maintainer rejected the code, and the institute found no evidence of real-world harm. The tests had allowed internet access and disabled some provider safeguards to examine model behaviour under permissive conditions.
In both evaluations, the agents’ behaviour depended partly on the permissions and network access configured in the test environment.
Governing AI Agents
Accelerating agentic AI adoption presents capital-markets firms with two connected control problems. The first is governing agents deployed within the firm: defining access, monitoring actions and assigning accountability to a human. The second is the growth of critical third-party risk as ICTs deploy agents in services supporting regulated operations.
HelmGuard is positioning its platform to address both challenges. Its agent-assurance layer is designed to monitor behaviour against approved controls, while its Verified Risk Network provides current, evidence-backed claims about third-party controls. Together, these capabilities would give firms a continuous view of risk across their own agents and the suppliers on which their operational resilience depends.
Subscribe to our newsletter


