Edited by Editor-in-Chief, The Indus Pulse 15 Sept 2026, 09:44 PM 3 min readai
Italian Cybersecurity Startup Exein Hits Unicorn Status With $270 Million Round for Physical AI Defense
Italian cybersecurity startup Exein has secured $270 million in a Series C funding round, pushing its valuation to $1.7 billion as the firm pivots its architecture toward securing physical artificial intelligence infrastructure. Led by San Francisco-based venture capital firm Headline, the round drew institutional participation from Sofina, Goldman Sachs, the European Investment Bank Group, KfW Capital, and T.Capital, alongside existing investors Balderton Capital and Geodesic Capital and an expanded revolving credit facility led by J.P. Morgan.
The capital injection arrives as artificial intelligence migrates rapidly out of cloud-based data centers and into autonomous hardware, including industrial robots, drones, medical equipment, and smart appliances. This technological shift has dramatically expanded the attack surface for malicious actors, who are increasingly leveraging open-source foundation models to execute automated attacks against physical infrastructure at machine speed.
The Mechanics of Kernel-Level Defense
Unlike conventional security software that monitors network traffic or relies on cloud-based analytics, Exein embeds its defensive technology directly onto device firmware. The company's core runtime security architecture, known as Photon, operates at the kernel level where operating system code executes, allowing it to block malicious code before an attack can fully execute.
Exein founder and Chief Executive Officer Gianni Cuozzo emphasized the urgency of preemptive defense against automated threats. "Attacks now happen at machine speed, so defense has to as well," Cuozzo stated, adding that "physical AI is the natural next step for Exein: we are building machine-time security for machine-time attacks." The company's technology is already integrated across more than two billion chips globally through partnerships with major silicon vendors and original equipment manufacturers.
Escalating Threat Environment and Telemetry
The necessity for embedded device defense is underscored by a sharp rise in detected intrusions. According to Exein's internal network telemetry, the firm now identifies approximately 5,000 new, non-repetitive cyberattacks each week, representing a fivefold increase compared to levels recorded just a year prior.
Hackers are utilizing unaligned open-source models to discover vulnerabilities and target physical devices with unprecedented precision. To counteract these threats, Exein is developing an agentic security architecture slated for introduction by the end of 2026, designed to detect and neutralize anomalies autonomously without requiring human intervention.
Proprietary Foundation Models for Machine Data
A significant share of the newly raised capital will fund the development of a proprietary foundation model dedicated entirely to physical artificial intelligence security. Expected to launch in the first quarter of 2027, the model diverges from consumer generative artificial intelligence systems by training exclusively on machine telemetry rather than human-generated text or images.
By establishing a baseline of normal operating behavior derived from billions of connected chips, the specialized model aims to identify anomalous and potentially destructive actions in real time. The company's customer base already includes major technology firms such as Nvidia, MediaTek, Arm, and Amazon Web Services.
International Expansion and Regulatory Tailwinds
Exein generates roughly half of its revenue from the Asia-Pacific region, prompting the establishment of a regional headquarters in Taiwan. The company plans to deploy the fresh funding to accelerate its expansion across the United States, which includes opening a new office in the San Francisco Bay Area and actively pursuing strategic mergers and acquisitions to consolidate its market position.
The commercial growth is further supported by emerging regulatory frameworks, including the European Union's Cyber Resilience Act. With initial reporting obligations having taken effect and full enforcement scheduled for December 2027, manufacturers face strict statutory requirements to ensure that all digital and connected products maintain robust cybersecurity safeguards throughout their operational lifecycles.
Sources & Citations
The Indus Pulse is committed to accuracy and transparency.

