How AIM Intelligence Turned a Government Hacking Contest Into an AI Security Business
If there is one thing the past month has taught us, it is that AI agents will break out of their containment and attack real infrastructure. The safety teams at the two most sophisticated AI labs in the industry spent July proving that their own models will go rogue.
OpenAI confirmed that its models broke out of the sealed testing environment they were being evaluated in, exploited a previously unknown software flaw, and went after Hugging Face's systems to steal the answers to their own exam. Days later, Anthropic disclosed that Claude models had broken into three organisations during testing meant to keep them offline.
AIM Intelligence is a two-year-old Seoul startup built to stop this. Its founders believe a compromised AI system could turn on the company that owns it, and that the security industry cannot yet tell the difference between a machine following instructions and a machine causing harm.
"As AI evolves from chatbots into autonomous agents and robots, a jailbreak can become a data breach, an unauthorised action, or a real-world safety failure," said Haon Park, Co-founder and Chief Technology Officer, AIM Intelligence, in a conversation with The Source Code.
A hacking competition produced the company before the market existed
AIM Intelligence sells attack and defence as a matched pair. "Our platforms, Stinger and Starfort, identify AI vulnerabilities before attackers do and control AI systems in real-time," Park said.
Sangyoon Yu founded the company in 2024 with students and graduates from Seoul National University and Yonsei University. Yu had studied engineering at Seoul National University, where his research covered responsible AI, and he watched the fairness and privacy questions that were once academic turn into practical threats once generative AI reached the market.
Automation without security underneath it was a ticking time bomb, he concluded, and that judgement pushed him towards a company. He entered the Generative AI Red Team Challenge run by the Ministry of Science and ICT and the Telecommunications Technology Association in 2024, built a tool that attacked AI systems to find their weaknesses, and won. The win convinced him to found the company, and he recruited the competition's runner-up, Haon Park, as Chief Technology Officer.
Park was later selected into Anthropic's model safety bug bounty programme, which invited 405 hackers from 800 applicants and paid them to extract answers to 10 banned questions on chemical, biological, radiological and nuclear weapons.
Anthropic reported that none of its roughly 185 active participants cleared all 10 with a single method, and the exercise fed into its published safety research. AIM says Park was among a small group who got past two or more. He has kept competing since, placing second in a ministry contest with around 1,000 entrants.
Two further co-founders completed the team: Euijun Lee as Chief Product Officer, a Meta Llama innovation award winner and top finisher at a Korea-Japan AI hackathon, and Haneul Kim as Chief Financial Officer, a Yonsei University quantitative risk student who also serves as Chief Operating Officer and was selected for Meta's AI accelerator.
Selling testing and protection together builds an advantage that compounds with each deployment
"AI security evolves faster than traditional cybersecurity. Models change constantly, new attacks emerge, and connecting AI to tools and sensitive systems creates entirely new risks. We addressed this by building a continuous security loop: attack, detect, defend, and retest. We combine frontier AI security research with real-world deployments across finance, automotive, government, and enterprise environments," explained Park.
Starfort watches what goes into an AI system and what comes out of it, blocking dangerous instructions and hiding sensitive data before it leaves. Stinger does the opposite job, attacking the same systems during development to find the weaknesses first.
Between them they now cover chatbots, software that acts on a company's behalf, and machines that move. The team expects robots to sharpen the problem, since a robot's judgement turns into movement straight away, and a machine swinging its arm gives very little away about why.
"Most companies either test AI systems or protect them in production. AIM does both. Stinger automatically detects jailbreaks, prompt injections, and agent vulnerabilities. Starfort turns those findings into real-time protection and policy enforcement. Our proprietary attack data, enterprise deployment experience, and expertise across multilingual AI, autonomous agents, and Physical AI create a moat that strengthens with every deployment," said Park.
Money comes in through annual software licences, subscriptions, one-off security testing and implementation work. "We have helped major financial institutions and global enterprises identify critical AI vulnerabilities, prevent sensitive data leakage, enforce internal AI policies, and safely deploy AI in regulated and mission-critical environments," added Park.
Customers converting into shareholders says more than the funding total
After seed backing from Mashup Ventures in 2024, AIM closed a pre-Series A led by Mirae Asset Capital in August 2025 that took total funding to $1.42 million, or KRW 1.85 billion. Eight months later, Samsung Venture Investment led a KRW 10 billion Series A, roughly $7 million, alongside Smilegate Investment and Forest Ventures, taking total capital to $8.4 million, or KRW 12 billion.
For the 21-person team, the more telling moment came a month afterwards, when LG Electronics, Hyundai Motor Group's Zer01ne Ventures and NAVER D2SF took undisclosed equity stakes. All three were existing clients. Buyers turning into shareholders signals a confidence in renewal that venture funds cannot replicate.
Those deployments are already running at scale, with LG Electronics using AIM's controls across smart home systems and robotics, Hyundai applying them to vehicles, and NAVER working with the company against fraud and data leaks on its shopping and platform businesses. Around 20 organisations in finance, manufacturing and the public sector now run the products, including South Korea's three major telecoms operators, KB Kookmin Card and Woori Bank via LG CNS.
Underpinning the commercial expansion is a research record unusual for a company this young. Alongside papers at the field's main academic conferences, AIM published the first study showing security weaknesses in the OpenAI, Anthropic and Google software that operates a computer on a user's behalf.
Work co-authored by Park on breaking video generation models was accepted to ICLR 2026. The company also built COMPASS with BMW Group, a 6,000-question test of whether an AI system obeys company policy, and adapted Meta's Llama Guard into a Korean-language safety filter.
The public work runs alongside it. AIM co-hosts Judgement Day with the Korea AI Safety Institute, a global competition testing the strongest models in high-risk settings including emergency medicine, aircraft maintenance and dam management.
In July it convened a workshop on hacking robots, with researchers from Google, DeepMind and Microsoft presenting. Microsoft selected AIM in June as the sole South Korean participant in the preview of its MDASH vulnerability detection system, alongside IBM, Accenture, PwC, Infosys and TCS.
Consolidation has left a gap the incumbents are not equipped to cover
The AI security sector is consolidating quickly. The large cybersecurity firms have bought the early pioneers, most visibly in Check Point's $300 million acquisition of Lakera, with further deals by Palo Alto Networks and Cisco. Those transactions fold basic filters, built to block rogue instructions and data leaks, into traditional corporate networks.
Among the remaining independents, HiddenLayer leads a fragmented field of smaller startups and free open-source alternatives, where scale is the primary hurdle, since corporate security chiefs invariably favour vendors already embedded in their systems.
Older platforms remain ill-equipped for what is coming. They struggle to defend software that acts on its own and plugs directly into company systems, the exact weaknesses exposed at OpenAI and Anthropic, and the territory where AIM holds a research lead.
Robots offer another opening, with Western rivals having largely overlooked security for home machines and smart vehicles, a gap AIM is already monetising through LG Electronics and Hyundai.
A June 2026 analysis of AI safety funding counted 20 disclosed deals across 20 companies in 12 months, with security testing alone drawing 10% of deals and 4.53% of capital, a signal that money follows companies attaching testing to continuous defence rather than selling assessment on its own.
The company took first place at the GITEX Supernova Challenge in Dubai in October 2025, beating a field of roughly 2,000 startups, and in June joined Cohort II of the Presight AI Accelerator, selected from 376 applications across 62 countries by the G42-majority-owned, ADX-listed firm.
Both give AIM access to Gulf enterprise and government buyers that its acquired competitors reach only through their parent companies. The technology the big labs are pushing out has outrun the tools built to contain it, and July made that visible to everyone.
What remains unsettled is whether the answer gets built by the labs themselves, by the security incumbents that acquired their way in, or by companies like AIM that have been attacking the models since before anyone was worried.