NEWS

OpenAI Acquires AI Security Startup Promptfoo to Safeguard Enterprise Agents

AI security testing and enterprise software development representing OpenAI Promptfoo acquisition

OpenAI has agreed to acquire Promptfoo, an AI security startup that helps enterprises identify and fix vulnerabilities in artificial intelligence systems before they reach production. The deal, announced on Sunday, marks OpenAI’s latest move to position its enterprise platform as the default infrastructure for companies deploying autonomous AI agents.

Financial terms of the acquisition were not disclosed. PitchBook data shows Promptfoo carried a post-money valuation of approximately $119 million following an $18.4 million Series A round led by Insight Partners with participation from Andreessen Horowitz in mid-2025.

Promptfoo Built the Testing Tools Fortune 500 Companies Already Use

Founded in 2024 by Ian Webster and Michael D’Angelo, Promptfoo developed an open-source command-line tool and library that allows developers to red-team large language models, testing them for prompt injections, jailbreaks, data leakage, and unsafe tool execution. The platform has attracted more than 100,000 developers and is used by over 25 percent of Fortune 500 companies, according to the company.

“As AI agents become more connected to real data and systems, securing and validating them is more challenging and important than ever,” Webster said in a statement.

Integration Into OpenAI Frontier

Once the acquisition is finalized, Promptfoo’s technology will be integrated directly into OpenAI Frontier, the company’s platform for building and deploying enterprise AI agents. The integration will add automated safeguards including real-time testing for prompt injections, tools to detect accidental data exposure or tool misuse, and enhanced reporting for regulatory compliance.

“Enterprises need systematic ways to test agent behavior, detect risks before deployment, and maintain clear governance,” OpenAI said in its announcement. The Promptfoo project will continue as an open-source effort, and its team will join OpenAI.

Why AI Agent Security Matters Now

The acquisition comes at a time when the AI industry is rapidly shifting from chatbots to autonomous agents that can browse the web, write and execute code, manage databases, and interact with enterprise software without human oversight. That expanded capability introduces new attack surfaces that traditional cybersecurity tools were not designed to handle.

Promptfoo’s tooling addresses risks specific to this new category of software, including prompt injection attacks where malicious instructions are hidden in data the agent processes, unsafe tool execution where agents take actions beyond their intended scope, and data leakage where sensitive information is exposed through agent responses. These are problems that grow more urgent as companies move from experimenting with AI to deploying agents in production environments where they handle real customer data and business operations.

The Broader Race to Secure Enterprise AI

OpenAI is not the only major AI company investing in security infrastructure. The deal follows a broader trend of frontier labs working to prove their technology is safe enough for mission-critical enterprise deployments. For startups building products on top of large language models, the acquisition signals that AI security testing is becoming a standard requirement rather than an afterthought. Companies developing AI agent platforms and tools will face increasing pressure from enterprise customers to demonstrate that their systems have been rigorously tested before deployment.

The Promptfoo acquisition also highlights the growing value of open-source developer tools as acquisition targets. By building a widely adopted testing framework used by Fortune 500 companies, Promptfoo created both a product and a distribution channel that OpenAI can now leverage across its enterprise customer base.

Read More From the NEWS desk