MasterNodeAI
news

Exein raises $270M at $1.7B to secure physical AI devices

Italian startup Exein raised $270M at $1.7B valuation to secure physical AI devices. EU Cyber Resilience Act and edge AI adoption drive demand for runtime security.

news

Exein raises $270M at $1.7B to secure physical AI devices

What Happened

On September 15, 2026, TechCrunch reported that Italian cybersecurity startup Exein closed a $270 million funding round led by Headline at a $1.7 billion valuation. The round was significantly oversubscribed, according to the company.

Exein, founded in 2018 and headquartered in Rome, provides runtime security for connected and AI-powered physical devices. Its core product, Photon, operates at the kernel level of devices to prevent attacks in real time, working directly with OEMs and silicon vendors rather than through network-layer defenses. CEO Gianni Cuozzo told TechCrunch that the company's thesis is simple: "every device should be able to defend itself, regardless if they are connected to a secure network or not."

The company claims to have secured more than 2 billion connected devices across sectors including aerospace, industrial automation, automotive manufacturing, energy, healthcare, and semiconductors. Exein reports 400% year-over-year growth, with Asia Pacific driving half of its revenue.

The valuation jump is notable: Exein's worth has increased thirty-fold since its Series B approximately two years ago and more than doubled since it secured equity and debt financing in December 2025. The company plans to use the new capital for M&A activity to round out its product portfolio and to accelerate hiring for U.S. and APAC expansion.

Exein is also developing a foundational model for physical AI security, trained on machine data and telemetrics, with a target release in Q1 2027.

Why It Matters

This raise sits at the intersection of three accelerating trends: edge AI deployment, device-level cyber threats, and regulatory enforcement.

First, physical AI is moving from concept to deployment. Robots, drones, autonomous vehicles, and industrial sensors running models on-device are entering production environments where a cyberattack can cause physical harm — not just data loss. Exein's Cuozzo reports an increase in "machine-speed attacks" facilitated by open-source models running without guardrails, making it cheaper and faster for attackers to target physical devices.

Second, the EU Cyber Resilience Act's reporting obligations kicked in the week of September 15, 2026. Full enforcement arrives in December 2027, requiring manufacturers to ensure all digital products are safe from cyber threats. This creates a hard compliance deadline for any company shipping connected devices into the EU market.

Third, the funding environment for physical AI infrastructure is heating up. In August 2026, a16z raised $1.1 billion for its Machine Age Fund targeting the physical layer of AI. Hadrian secured a $7.5 billion valuation in June 2026 for its physical AI manufacturing capabilities. Exein's raise confirms that investors are now funding the security layer of this stack — not just the hardware or the models.

For operators, the implication is clear: device-level security is becoming a design requirement, not a post-deployment add-on. Companies that treat embedded security as an afterthought will face both regulatory penalties and market rejection.

Who Is Affected

OEMs and silicon vendors building AI-powered physical products are the most directly affected. They must now embed runtime security into devices at the kernel and silicon level, working with vendors like Exein during the design phase rather than after deployment.

Enterprise buyers deploying edge AI in regulated industries — healthcare, energy, automotive, aerospace — need to audit their device fleets for compliance with the EU Cyber Resilience Act and similar emerging regulations. Devices without runtime-level protection are becoming a measurable liability.

Cybersecurity startups in the IoT and edge AI space should expect increased competition and consolidation. Exein's explicit M&A strategy, backed by $270 million in fresh capital, signals that smaller security vendors may become acquisition targets.

Strategic Implications

For AI startup founders

If you're building physical AI products — robots, drones, autonomous vehicles, smart industrial equipment — budget for embedded security at the design stage. The EU Cyber Resilience Act creates a compliance deadline of December 2027, and investors are actively funding the security layer that enables this transition. Ignoring this requirement now will create expensive retrofitting costs later.

For developers and operators building with AI APIs

Edge AI deployments running models on physical devices need runtime protection at the kernel level. Evaluate whether your device stack includes security solutions like Exein's Photon or comparable runtime defenses. This is especially critical if you're shipping into EU markets where regulatory enforcement is imminent.

For non-technical business owners evaluating AI tools

If you operate connected devices or AI-powered hardware in regulated industries, ask your vendors about their embedded security posture and their EU Cyber Resilience Act compliance roadmap. Devices without runtime-level protection are becoming a liability — both regulatory and reputational.

What to Watch Next

Monitor Exein's M&A activity over the next two quarters — acquisitions will signal which adjacent security capabilities the company sees as gaps. Also watch for the Q1 2027 release of Exein's foundational model for physical AI security, which could establish a new category standard. Finally, track EU Cyber Resilience Act enforcement actions in early 2027, as these will create the demand signal that validates or challenges the physical AI security thesis.

Frequently Asked Questions

Q: What is physical AI security and why is it different from traditional cybersecurity?

A: Physical AI security protects AI-powered devices — robots, drones, autonomous vehicles, industrial sensors — at the device level, typically at the kernel or silicon layer. Unlike traditional network-based cybersecurity, it ensures each device can defend itself even when not connected to a secure network. This matters because physical AI devices can cause real-world harm if compromised, not just data breaches.

Q: How does the EU Cyber Resilience Act affect companies building AI-powered devices?

A: The EU Cyber Resilience Act requires manufacturers to ensure all digital products are safe from cyber threats. Reporting obligations began in September 2026, with full enforcement by December 2027. Companies shipping connected or AI-powered devices into the EU market must demonstrate that their products have adequate built-in security measures — making solutions like Exein's runtime security increasingly necessary for compliance.