HelmGuard raises $7.3M to make AI agents inspect compliance evidence
Former Palantir executive John Daley and AI researcher Jack Miller will use the seed round to expand in New York and San Francisco.
By RuntimeWire Staff · Published
Primary source: Tech.eu
Why it matters
HelmGuard is betting that regulated companies will buy live, source-linked assurance as AI agents make periodic reviews less useful. The round funds its US push and the harder task of proving automated assessments can satisfy auditors.

John Daley and Jack Miller have raised a $7.3 million seed round for HelmGuard, giving the London startup fresh capital to sell its AI-driven risk and compliance software in the US and develop a system for continuously assessing other AI agents.
The financing, reported September 9th by Tech.eu, was co-led by Infinity Ventures and Frontline Ventures. FinTech Collective, Stage 2 Capital and Entrepreneurs First also participated.
Daley spent eight years at Palantir before starting HelmGuard, where he worked with large organizations confronting security, compliance, data protection and operational risks. He came away with a straightforward diagnosis: risk teams were spending much of their time collecting and normalizing information held in separate systems, leaving less time for analysis and decisions.
Miller approached the same problem from AI research and governance. He studied mathematics and computer science at the Australian National University, worked with research groups including ANU and ETH Zurich, and joined an AI governance fellowship in Cambridge before co-founding HelmGuard. Miller describes HelmGuard's work as helping healthcare and financial institutions assess third-party cybersecurity risks and verify that the relevant protections remain in place.
A risk system that reads the source
HelmGuard is building a shared data layer that connects documents, controls, risks and information from underlying company systems. Specialized agents use that layer to collect evidence, evaluate vendors, identify control gaps and prepare material for internal reviews, auditors and regulators.
Daley's pitch is that most governance, risk and compliance software was built to record a process after people had done the work. HelmGuard wants its software to participate in the assessment itself.
"Our agents go to the source to collect and assess risk signals directly," Daley told Tech.eu.
That distinction matters in third-party risk management, where organizations routinely ask suppliers to complete questionnaires and provide policies or certifications. Those documents can describe a vendor at a particular point in time, while the vendor's systems, subcontractors and security posture continue to change.
HelmGuard says its agents produce citations and reasoning traces, with human review built into the workflow. Those features carry the product's credibility. A regulated buyer cannot simply accept an AI model's conclusion that a control is working; the buyer needs to trace the conclusion back to evidence and show how the assessment was reached.
The product is aimed at financial services, insurance, healthcare and industrial companies, sectors where vendor failures and compliance gaps can trigger operational and regulatory consequences. HelmGuard has publicly described support for work involving frameworks such as SOC 2, ISO 27001 and GDPR, although its product performance claims remain company-reported.
The founders are moving toward runtime assurance
The seed round also backs a broader product bet. HelmGuard is developing an Agent Assurance layer intended to evaluate AI-agent behavior while agents are operating. A related Verified Risk Network would allow organizations to exchange individual, continuously assessed risk claims rather than passing static documents between compliance teams.
An agent's risk profile can change when its model, permissions, connected tools or operating environment changes. A review completed before one of those changes may no longer describe what the agent can do. HelmGuard's planned system would make the assessed claim, rather than the annual certificate or questionnaire, the unit passed between organizations.
That product direction expands HelmGuard beyond established GRC workflows and into the emerging problem of governing autonomous software. It also raises the technical and commercial bar. HelmGuard will have to show that its agents can evaluate evidence consistently, resist manipulated inputs and generate records that risk teams, auditors and regulators are prepared to use.
Daley has been outlining this approach since at least April 21st, 2025, when he published HelmGuard's founding thesis. He argued that security, compliance, legal and operational risk were being managed in separate tools even when a single incident could affect all four areas. HelmGuard's proposed answer is a connected risk system that can follow those relationships across an organization.
Miller has focused on the technical implementation. In a 2025 presentation at Palantir's developer conference, he described HelmGuard as structuring policies, standards, architecture information and compliance documentation into a knowledge base that agents can query and act upon. The demonstration centered on processing third-party security questionnaires, an immediate use case that can provide a route into larger enterprise accounts.
The investor lineup points west
The financing will support engineering and commercial hiring, along with operations in New York and San Francisco alongside HelmGuard's London headquarters. The investor mix closely matches that plan.
Frontline Ventures explicitly backs early-stage European software companies seeking to make the US their largest market. Infinity Ventures focuses on B2B fintech and commerce infrastructure, giving HelmGuard a partner familiar with selling into highly regulated financial institutions. Stage 2 Capital specializes in go-to-market support for early-stage B2B software and AI companies.
The $7.3 million seed is not HelmGuard's first outside financing. Atlas AI VB Fund records a pre-seed investment dated May 11th, 2025, and identifies Entrepreneurs First as HelmGuard's venture builder. The size of that earlier investment is not listed, so the seed amount should not be read as HelmGuard's total capital raised.
HelmGuard's UK operating entity was incorporated on October 18th, 2024. Less than two years later, Daley and Miller are trying to turn a familiar enterprise complaint - compliance work that is repetitive, fragmented and stale by completion - into a platform spanning vendor assessments and AI-agent oversight.
The next phase depends on distribution as much as model capability. Large regulated companies buy risk software slowly, demand integrations with existing systems and expect evidence that automated assessments can survive scrutiny. The seed round gives HelmGuard room to pursue those buyers on both sides of the Atlantic while building the runtime assurance product behind its larger thesis.