Curious about today's AI digest?ai-tldr.dev

Daily Digest

Pomegra Startups

Cytix Raises €6M to Police AI-Generated Code Risk

UK cybersecurity startup Cytix raises €6M Series A led by Northern Gritstone to help enterprises detect security risks introduced by rapid AI-driven software changes.

FundingCybersecurityNOTABLE4 min read
Cytix Raises €6M to Police AI-Generated Code Risk

Manchester cybersecurity startup Cytix has secured €6 million in Series A funding to scale a platform that monitors security risk from AI-accelerated software development, with NCC Group and KPMG among its early distribution partners.

  • Cytix's €6M Series A was led by Northern Gritstone, with co-investment from Auriga Cyber Ventures and NPIF II - PXN Equity Finance.
  • The platform sits between a company's software development pipeline and its security and compliance functions, logging every AI-generated code change.
  • Cytix distributes through managed service partnerships with NCC Group and KPMG, targeting regulated industries where software change governance is a compliance obligation.

Lead

Cytix, a Manchester-based cybersecurity company founded in 2020, announced on August 12, 2026 a €6 million Series A round led by Northern Gritstone, the university-backed venture firm that backs science and technology companies across northern England. Existing backers Auriga Cyber Ventures and NPIF II - PXN Equity Finance, managed by PXN Ventures as part of the Northern Powerhouse Investment Fund II, also participated. Valuation terms were not disclosed.

The capital will go toward scaling Cytix's newly released change risk platform - software that monitors, validates, and logs every code change flowing through an enterprise's development pipeline, including output from AI coding assistants and agentic workflows.

What Problem Is Cytix Solving?

The premise is straightforward: AI-assisted development has made it possible to ship code far faster than the security models built to govern it. Where a team might have reviewed a few hundred pull requests per sprint, automated pipelines and AI pair-programmers can now generate thousands of changes in the same window. Traditional application security tools were not designed for that velocity.

Cytix positions its platform as a security decision layer - continuous monitoring that tells security and compliance teams whether a given change warrants attention, what risk it introduces, and what action is required. For companies operating under financial services or critical infrastructure regulations, the platform also produces evidence logs that can be shown to regulators to demonstrate how risks were handled. That audit trail function is central to the product's pitch in regulated markets.

How Does This Fit the Broader AI Security Market?

AI-generated code risk has moved quickly from theoretical concern to boardroom topic. The volume of code produced by tools like GitHub Copilot and similar assistants has expanded the attack surface for enterprises, and security teams have struggled to keep pace. Established categories - static analysis, software composition analysis, penetration testing - catch many issues, but tend to operate as point-in-time checks rather than continuous governance. Cytix is betting that the gap between those checks and the speed of AI-assisted delivery is large enough to support a new product category.

The company's channel strategy reinforces that thesis. Partnering with NCC Group for continuous testing and KPMG for professional services distribution is an efficient route into regulated enterprise accounts. Both firms serve clients for whom change governance is already a compliance requirement, not an optional layer.

Northern Gritstone's involvement adds further context. The fund focuses on deep-tech and science-based companies spun out of or adjacent to the universities of Manchester, Leeds, and Sheffield. Cybersecurity, particularly around infrastructure and software supply chains, fits that thesis, and the investment continues a pattern of backing companies that address structural weaknesses in enterprise security rather than endpoint or perimeter plays.

What Does This Round Signal About the Market?

The implied trajectory is consolidation of a nascent category. Cytix is not the only company watching AI-generated code volume and arguing that enterprises need a dedicated governance layer. A €6 million Series A, however, is a modest bet relative to the scale of the problem it targets - enough to prove the commercial model and build distribution, not enough to dominate. The next funding milestone will say more about whether the category is real or whether the problem collapses back into existing tools from larger vendors.

The Northern Powerhouse Investment Fund II co-investment is also notable for reflecting continued public-private appetite for building a competitive technology cluster in the North of England, with cybersecurity as one of the priority sectors.

Outlook

Cytix enters the second half of 2026 with a platform in general release, two established channel partners, and enough capital to test its enterprise sales motion. The core question is whether change risk management earns its own budget line at large organizations or gets absorbed by existing security tooling vendors moving upmarket. If AI-assisted development continues at its current pace, demand for governance tooling will only grow. Whether Cytix can own that market before incumbents move is the bet Northern Gritstone just made.

More Startup News