Cytix, a Manchester cybersecurity startup, has raised a £5m Series A round to help companies keep control of the security risk created when AI coding assistants change software faster than humans can review it. The round was led by the investment firm Northern Gritstone, which put in £3m, with returning backers Auriga Cyber Ventures and the British Business Bank-linked NPIF II. It is a small raise by AI-industry standards, but the problem it targets is squarely the one facing any business now letting AI write and change its code: the pace of change has outrun the ability to govern it. The product's effectiveness is Cytix's own claim; the demand behind it is real.
This piece reflects reporting as of August 2026. Funding figures and company claims are as reported by the company and the trade press, and may change.
What Cytix does, in plain terms
Cytix sells software that plugs into a company's software development process, the pipeline through which code is written, changed and shipped. Rather than producing another list of vulnerabilities, its "change risk" platform watches each change a business makes to its software, including changes generated by AI coding assistants and automated workflows, and tries to judge which of those changes actually carry meaningful risk. The pitch, in the company's framing, is that security teams are drowning in alerts about what could be wrong, but lack a clear read on which specific changes are genuinely dangerous. Cytix says it also keeps an evidence log of how each risky change was handled, which matters for regulated firms that have to prove they governed a change.
The founders make the case bluntly. Cytix chief executive Ben Armstrong said that with AI-assisted development, "change now happens at machine speed", while few security leaders have a real grip on it. That is the nub of the story: the tooling that lets a small team ship far more code, far faster, also produces far more changes for someone to check.

Why this is more than one funding round
Funding announcements are easy to over-read, and a £5m Series A is modest. What makes this one worth noting is the problem it implicitly confirms. Over the past two years, AI coding assistants have gone from novelty to normal in many development teams. That raises output, but it also means more code is being written and altered by systems that do not fully understand a company's security context, and more of it is being merged with less human scrutiny. A startup raising money specifically to govern that flow, and being backed to do it, is a market signal that the risk is being taken seriously by people who spend for a living.
It also fits a pattern AIToolBible has tracked before: the security questions around AI-written code are not hypothetical. Researchers have shown AI coding tools can introduce subtle, exploitable mistakes, and the faster code ships, the less time anyone has to catch them. Cytix is betting that "which changes are risky" becomes a distinct product category from "which vulnerabilities exist". Whether its platform delivers on that is unproven from the outside, and the claims here are the company's own.
Who is behind the money
The round was led by Northern Gritstone, an investor focused on deep-tech companies in the North of England, which contributed £3m of the total. Auriga Cyber Ventures and NPIF II, managed by PXN Ventures through the British Business Bank's Northern Powerhouse Investment Fund II, also took part as returning investors. Cytix was founded in 2022 by Ben Armstrong, Thomas Ballin and Matt Milan, and had previously raised a smaller round. Northern Gritstone chief executive Duncan Johnson framed the deal around "the explosion of AI-assisted software development" and the race to keep it secure.
For UK readers, the geography matters a little. This is a Manchester deep-tech story, backed partly by public money through the British Business Bank, and sold in part through two established names, NCC Group and KPMG, as channel partners. It is a reminder that the AI build-out is not only a story about a handful of US labs; there is a supporting layer of UK companies trying to make the resulting mess governable.

The honest caveats
Two things are worth holding in mind. First, the figures. BusinessCloud reports the round as £5m; UKTN puts it at $7m, which it converts to £5.1m. These describe the same Series A, and the round size is as reported by the company, not independently audited. Second, the product. Everything about how well the platform actually distinguishes risky changes from harmless ones comes from Cytix and its backers. The demand is easy to believe; the performance is not yet something an outsider can verify. This is a company with a plausible thesis and fresh money, not a solved problem.
FAQ
What problem is Cytix trying to solve?
The security risk created when software changes faster than people can review it, especially when AI coding assistants and automated workflows are generating those changes. Cytix aims to flag which changes carry real risk, not just list vulnerabilities.
How much did it raise, and from whom?
A £5m Series A (reported by UKTN as $7m / £5.1m), led by Northern Gritstone with £3m, alongside returning investors Auriga Cyber Ventures and the British Business Bank-linked NPIF II.
Is this a UK company?
Yes. Cytix is based in Manchester, was founded in 2022, and part of the funding comes via the British Business Bank's Northern Powerhouse Investment Fund II. It sells directly and through NCC Group and KPMG.
Does the platform actually work?
That is the company's claim, not an independently verified result. The market demand is clear, but the platform's effectiveness at spotting genuinely risky changes is unproven from the outside.
The takeaway
The interesting thing here is not the size of the cheque but what it is for. As AI coding assistants become ordinary, the volume and speed of software change is rising faster than most teams can govern, and investors are now funding companies whose entire pitch is to close that gap. Cytix may or may not be the one that cracks it. Either way, the raise is a useful marker that "who is watching the code the AI just wrote?" has become a real, fundable question, with a UK company among those trying to answer it.