The future of business, today.
RSSNewslettersAdvertise
Business Future Today

Embedded cybersecurity

Exein’s New Unicorn Status Signals a Security Race for Physical AI

Exein’s $270 million round and $1.7 billion valuation put embedded security for robots, vehicles and industrial devices at the center of the physical AI buildout.

Exein: left to right, Gerardo Gagliardo, CFO & Co-Founder; Gianni Cuozzo, CEO & Founder; Giovanni Alberto Falcione, CTO & Co-Founder

Italian cybersecurity startup Exein has raised $270 million at a $1.7 billion valuation, becoming a new European unicorn. The round, led by Headline, is a bet that the rapid spread of AI-powered machines will make security at the device level—not just the network level—a core operating requirement.

Exein began with internet-of-things security, but is now positioning itself as a security layer for “physical AI”: connected products that sense, decide and act in the real world. That includes robots, drones, autonomous vehicles, industrial equipment, sensors and smart appliances running models at the edge.

What changed

The company’s central proposition is that devices should be able to defend themselves even when they are outside a trusted network. Its latest product, Photon, is designed as a runtime security tool that seeks to prevent attacks at a device’s kernel level.

That is a meaningful shift from a conventional enterprise-security model centered on perimeter controls, cloud monitoring and endpoint agents. Many embedded systems have constrained hardware, long product lifecycles and intermittent connectivity. They also cannot always accommodate the software footprint or operational model used for employee laptops and servers.

Exein says it has secured more than 2 billion connected devices across aerospace, industrial automation, automotive manufacturing, energy, healthcare and semiconductors. Those company claims are not independently verified in the report, but they illustrate why its strategy depends on working upstream with original equipment manufacturers and silicon vendors. Security built into a device’s software and hardware supply chain is harder to retrofit later—and potentially harder for customers to replace.

Why it matters for operators

Physical AI expands the consequences of a cyber incident. A compromised chatbot may expose data or produce poor output; a compromised industrial controller, medical device, vehicle or robotic system can interrupt operations and create safety risks. As more inference moves onto devices, organizations need a threat model that covers firmware, operating systems, runtime behavior and update mechanisms alongside cloud-based AI systems.

For product leaders, the immediate lesson is to make embedded security an engineering and procurement concern early in the design process. Questions to ask include: who owns vulnerability response after deployment, how are devices authenticated and updated, what telemetry is available, and what controls still work if connectivity is limited or a network is already compromised?

The regulatory direction adds urgency. The European Union’s Cyber Resilience Act has begun its reporting obligations and is due to come fully into force in December 2027. It requires manufacturers of digital products to address cybersecurity risks. That creates a potentially durable demand driver for suppliers that can help OEMs document, monitor and remediate security issues across deployed products.

Capital for scale—and consolidation

Exein plans to use the funding for acquisitions, product expansion and hiring in the U.S. and Asia-Pacific. The company says Asia-Pacific already accounts for half of revenue and that it is growing 400% year on year. The new valuation is more than double the level reported after its December 2025 equity-and-debt financing.

The funding also reflects investor interest in a security category where distribution matters as much as detection technology. Winning OEM and chip-vendor partnerships can provide access to device fleets at manufacturing time, but sales cycles, certification requirements and support obligations can be demanding.

What to watch next

Exein says it is training a foundational model for physical-AI security on machine data and telemetry, with a planned first-quarter 2027 release. The key test will be whether that model produces actionable detection or prevention in diverse, resource-constrained environments—not simply better analysis after an event.

Buyers should also watch for evidence of deployment depth: named design wins, integrations with silicon and device platforms, response performance at runtime, and the company’s ability to turn regulatory compliance into a repeatable product motion. The physical AI wave may widen the attack surface, but the enduring opportunity will go to security vendors that fit reliably into how devices are designed, shipped and maintained.

Sources

STAY AHEAD

The future of business, in your inbox.

Useful signals on the companies, technologies and shifts changing business.

One useful briefing. Unsubscribe any time.