Paris-based cybersecurity startup Fleuret AI has closed a €4 million pre-seed round to automate penetration testing with agentic AI, positioning itself as a European answer to the growing gap between how fast companies change their systems and how slowly they test them. The round was led by RAISE Ventures, with participation from Auriga Cyber Ventures, Wind Capital and Better Angle, alongside a roster of business angels drawn from the cybersecurity world. According to EU-Startups, which reported the raise on October 5, 2026, the funding will be used to hire talent across AI, software engineering and offensive security, and to accelerate development of the company's platform.
Fleuret AI was founded in 2026 by chief executive Yanis Grigy and chief technology officer Augustin Ponsin. The startup's premise is that penetration testing still behaves like a one-off audit: a team arrives, produces a snapshot of security at a particular point in time, and leaves. The next deployment can alter the attack surface within days, leaving the report stale almost as soon as it lands. Fleuret AI wants to replace that rhythm with continuous security, moving pentesting from a periodic event to an always-on process.
From one-off audits to continuous security
The platform is organized around five pillars: mapping the systems a company has exposed, identifying vulnerabilities, demonstrating that they can actually be exploited, helping teams fix them, and verifying that the fixes hold. That last step matters more than it sounds. Many security tools flag theoretical weaknesses; far fewer prove exploitability or confirm remediation afterward, which is where audits most often lose credibility with engineering teams.
Tech.eu reports that Fleuret AI is automating the tester's workflow through two AI agents, named Emile and Champollion. The agents map a company's environment, explore its applications, APIs and infrastructure, and attempt to exploit the vulnerabilities they identify. Each finding is accompanied by proof of compromise intended to show whether an issue is genuinely exploitable rather than merely suspicious. Beyond the initial assessment, the platform continuously monitors the attack surface and can initiate additional tests as systems change, while tools for prioritization, integration with technical teams and automatic re-testing support the remediation side of the loop.
A crowded race toward autonomous offense
Fleuret AI enters a market that is heating up fast. In August 2026, autonomous pentesting company Horizon3 raised $250 million at a $2 billion valuation, with investors including a sovereign wealth arm, a defense prime contractor and a semiconductor venture unit betting that automated security validation is becoming infrastructure rather than a service. According to TechTimes, which covered the round, the distinction between an annual snapshot and continuous proof has become the central commercial argument across the sector. A month later, Reflectiz launched agentic pentesting for websites, claiming up to ten times the coverage of conventional tests, as reported by GlobeNewswire.
The pattern rhymes with what is happening across the agent economy more broadly. As Fleuret AI frames it, defenders now face adversaries whose tools are cheap, fast and widely available, so testing that runs once a year is structurally outmatched. The same logic is pushing platform owners to treat agent risk as a first-class security concern, as seen in Apple's crackdown on full disk access and the parallel push to inventory every AI agent inside the enterprise. Continuous, provable testing is the offensive complement to those defensive moves.
The European sovereignty play
Fleuret AI is also making a deliberately European play. The company describes its platform as sovereign, a word that carries weight in a market where regulated industries face mounting compliance obligations under frameworks like NIS2 and DORA. Paris gives it proximity to a dense cluster of French cybersecurity talent, and the angel roster reinforces the point: it includes Jules Veyrat, co-founder and chief executive of Stoïk, Stoïk's chief risk officer Alexandre Andreini, GitGuardian chief executive Eric Fourrier, Vade co-founder Georges Lotigier, and Almond co-founders Olivier Pantaleo and Jean-François Aliotti.
The investors are betting on the team as much as the thesis. According to EU-Startups, RAISE Ventures co-head Thibaut Schlaeppi said the firm believes Fleuret AI can become the reference in offensive security in Europe, arguing that AI has put powerful attack tools within everyone's reach and that organizations need to test against every technique, including the newest ones. Grigy, the co-founder, told EUStartups.news that the ambition goes beyond automating pentesting as it exists today; the goal is to build the offensive cybersecurity layer that lets companies of any size stay secure throughout the year.
What to watch
The pre-seed round buys Fleuret AI time to prove the hardest part of its claim: that agentic systems can produce exploit-quality results, not just vulnerability-shaped noise. Autonomous pentesting lives or dies on false positives, and enterprise buyers burned by scanner spam will demand proof of compromise they can act on. The company's five-pillar framing, with verification of fixes built into the loop, reads like an answer to exactly that skepticism.
Competition will not stand still. Horizon3's capital advantage is enormous, and incumbents in vulnerability management are layering agent features onto existing products. Fleuret AI's edge, if it has one, is focus: a young team, a European home market where sovereignty sells, and a platform built from scratch for continuous offensive security rather than retrofitted from periodic scanning. For now, the €4 million raise is a bet that in cybersecurity, the agents doing the attacking and the agents doing the testing are about to be the same technology.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.