The graph says Lasso Security, Knostic, Ema compete with us but were never flagged, and ranks UiPath as our top buyer prospect. 14 of 20 prospects and 8 of 10 rivals keep their spot when the 70 unverified edges are added.
All the seeds are security-eval vendors, so the buyer list means “wired into the red-team world,” not “ready to buy.” The method cannot see us either: AoC ranks #93 of 162 because it has only 2 verified edges. Check the edges column before acting on a thin nomination. And note who is missing: no bank ranks near the cluster yet — bank security deals are rarely public, so read that as unmapped, not uninterested.
We flagged 14 companies as competitors by hand. This panel asks the graph two questions. Which buyers sit closest to that red-team cluster? Those are prospects. And which unflagged companies does the graph treat as one of the pack? Those are rivals we may have missed.
The idea: give the graph a few examples and ask for more like them. Each company gets a position computed from the verified edges alone, placed so that companies with similar connections sit near each other. Each of the 14 rivals then ranks every candidate by distance, and we merge the lists with two standard rank-combining rules. Where both rules agree (17 of the top 20), we call it consensus and color it on the map. One warning from the data itself: the rivals do not form one tight cluster — their average spacing is 1.36× the market's, wider than 90% of random same-sized groups. That is why each rival votes separately instead of being averaged into a single query point, which would land in empty space. The “edges” column shows how much verified wiring backs each nomination; a rank built on 2 edges is a lead, not a verdict.
for the curious
Vertex nomination via adjacency spectral embedding (Fishkind, Lyzinski, Pao, Chen & Priebe, Vertex nomination schemes for membership prediction, Ann. Appl. Stat. 2015). ASE of the binarized undirected company graph, verified edges only (464 unique pairs from 468 verified records; diagonal augmentation; Zhu–Ghodsi elbow picked d=4; svd_seed=0). The graph is disconnected — 13 companies have no verified edge, embed at exactly the origin, and are excluded from the candidate pool as artifacts. Per-seed Euclidean distance ranks are fused by Borda count and by reciprocal-rank fusion (Cormack, Clarke & Büttcher, SIGIR 2009; k=60), ties broken lexicographically. Tightness null: 1000 random seed-sized subsets of embedded companies. Sensitivity: the pipeline re-run on all 531 unique pairs including unverified edges, same candidate pool; a row “survives” if it stays in its table.
Sequoia Capital tops the shortlist — 100% of its log-weighted grant dollars already go to AoC-shaped work, its checks span $8.85k–$250k, and the door is open (rolling).
Only 25 of 62 funders have grants tracked in this graph — the other 37 are scored on declared focus areas with zero recency (37 funders sit at recency 0). 15 of 130 money edges lack both amount and year; 38 of 62 funders publish no check size. Every imputation is flagged in the table (12 of the top 12 rows carry flags).
Agents of Chaos will soon ask for first money — roughly $100k–$1M in grants. The funding map holds 62 funders. Which door do we knock on first? This panel is a plain scoring rubric, not a graph model: four factors, every weight visible.
Each funder gets four scores between 0 and 1. Mission: the share of its grant dollars that go to agent-security or evals work (log-dollars, so one $30M mega-grant counts as attention, not a thousand small grants). Check fit: how much of our $100k–$1M ask its published check sizes cover. Openness: rolling or open-deadline programs score 1, invite-only 0.4, closed 0. Recency: recent grant dollars count far more than old ones (half-life about 1.4 years). The composite multiplies openness against a mission-heavy blend of the rest, so a perfect-fit funder you cannot apply to scores zero — by design.
for the curious
Deterministic scoring, no fitted model. Mission: Σ rel(g)·log1p($) / Σ log1p($) over each funder's grant edges, rel = 1.0 if the grantee's domainTags hit {agent-security, evals}, 0.5 for {technical-alignment}, else 0 — the half-weight marks alignment work as adjacent to, not identical with, AoC's red-teaming lane. Funders with no tracked grants (37 of 62) fall back to the mean tag-weight of their own declared domainTags, flagged. Undisclosed amounts → the funder's median disclosed grant, else the global median ($2.12989M); missing years → median year; missing check sizes (38 of 62) → the 25th percentile of disclosed minima and maxima ($8.85k–$250k), all flagged. Check fit is the log-scale overlap with [$100k, $1M]. Openness: rolling = 1, rounds with a deadline past the newest apply.lastVerified in the data = 1, rounds without a stated window = 0.7, invite-only = 0.4, closed = 0. Recency: Σ $·exp(−λ·(2026−year)) with λ=0.5 and 2026 = max year in the data (never wall clock), rescaled by log1p to [0,1]; re-ranking at λ=1.0 gives Spearman ρ=1.000, so the decay choice barely moves the list. Composite = openness × (0.5·mission + 0.25·check + 0.25·recency). The quadrant dots carry ±0.018 seeded jitter so funders with identical scores stay visible as separate dots.
9 of the 41 open doors on the funding map close on a date, every one inside the next 87 days — the best-fit dated door is ARIA — Safeguarded AI (fit 0.42, closes Jul 27), and 3 of the 9 dates are a single Aug 8 multi-agent application.
24 of the 41 open doors have no tracked money edges, so fit cannot be computed; the 5 dated ones stay in the table unscored, and the other 19 (mostly VCs and new programs) appear only on the minimap. 4 more funders hold a single investment no other funder shares, which the truncated embedding cannot see — also unscored. For the best-fit dated door (ARIA — Safeguarded AI), the fit rests on one undisclosed grant (EleutherAI). Led-round investment amounts are round totals, not the fund's own check.
Agents of Chaos needs first money, and funders' doors do not stay open. At the July 5, 2026 snapshot, 41 of the map's 62 funders will take an application — 32 on rolling intake, 9 with hard dates, every one of those dates inside the next 87 days. Which doors do we walk through, and in what order?
Most of this panel is a plain join, not a statistical model: for every funder whose door is open at the snapshot, the deadline, program, and check size are read straight off the graph's application metadata. The one computed column is fit. We factor the funder-by-grantee money matrix the way a recommender factors users-by-items: an SVD gives every funder and every grantee a position in the same 8-dimensional taste space, where two funders sit close when their dollars flow to the same kinds of grantees. We average the positions of the 26 grantees already doing AoC-shaped work — agent security, evals, multi-agent — into one profile, and score each open funder by the cosine between its position and that profile. Cosine keeps the direction of a funder's taste and throws away its size, so a small fund concentrated on our lane outranks a giant that touches it incidentally.
for the curious
Open door: apply.mode = rolling, or rounds with deadline ≥ meta.generatedAt (2026-07-05); one rolling program (ONR's Long Range BAA) publishes a hard close and is treated as dated. Fit: truncated SVD (numpy.linalg.svd) of the 62×69 funder-by-grantee matrix, cell = log10(dollars+1) summed over grant and investment edges; the 23 of 130 edges with undisclosed amounts enter at the minimum disclosed grant ($15,000). Rank d=8 is the smallest holding ≥90% of squared Frobenius energy; Spearman ρ of fit against d=6 and d=10 is 0.88 and 0.95. Positions U√Σ (funders) and V√Σ (grantees) share one deterministic sign convention (fix_signs on U, the same flips applied to V); profile = unweighted mean of the seed positions; fit = cosine. SFF's regrants (payer: Jaan Tallinn) stay on the SFF row — the s-process taste is what you apply to — and no payer duplicates them as direct edges, so no dollar is counted twice. Funders with no money edges, or whose only edges are invisible to the top 8 components, are shown unscored rather than imputed.
The wiring and the rubric agree on just 1 of 10 top funders: read as a recommender, the giving graph makes Coefficient Giving the #1 structural fit for an AoC-shaped org, while the rubric's favorites — mostly VCs with one or two tracked deals — sit in another room of the graph.
Structure can only speak about the 25 of 62 funders with at least one tracked money edge — the other 37 have no row in the matrix and are unranked, not low-ranked. Scores scale with expected log-dollars, so prolific funders (Coefficient Giving holds 50 of the 130 tracked edges) sit high partly because they fund a lot of everything. Rubric shares hit 100% for single-deal funders by construction — 10 of the rubric's top 10 rest on ≤2 tracked deals, flagged in the table.
The shortlist panel scores funders on published attributes — focus areas, check sizes, open doors. This panel throws the attributes away and asks the wiring itself: which funders already put money on orgs shaped like Agents of Chaos? And where the two answers disagree, which one should we believe?
This is the streaming-service trick applied to grantmaking: a recommender never reads a movie's synopsis, it factorizes the who-watched-what matrix and suggests films from viewers with similar taste. We factorize the who-funds-whom matrix (weighted by log dollars) so every funder and grantee gets coordinates in a 2-dimensional taste space — sitting close means funding the same kinds of orgs. Agents of Chaos is not in the funding graph yet, so we place a virtual AoC at the average position of the 26 grantees already working its lane (agent-security, evals, multi-agent), and score every funder by the dot product with that virtual position — the model's guess at how much money each funder would put on an org shaped like ours. The guess checks out: rank funders for each seed grantee and its actual funders land at median rank 3 of 25 (chance would be 13); hide the seed from the virtual position first and the median is still 5.
for the curious
Truncated SVD of the funder-by-grantee matrix (log10(USD+1); grants + investments; 25 funders with ≥1 tracked money edge × 69 funded grantees), positions U√S and V√S — the adjacency spectral embedding of a bipartite random dot product graph (Sussman et al., 2012), signs fixed. d=2 by the largest scree gap within 2–8 (the global elbow sits after the first singular value, one dimension short of usable); at d=3 the ranking broadly holds (Spearman ρ=0.86), while by d=4 the VC block gains spectral mass and 2 VCs enter the structural top 5 — the low-d story treats them as a separate room. 23 of 130 money edges lack amounts — imputed at the funder's median disclosed grant, else the global median ($2.1M); led VC rounds carry round totals rather than the fund's own check, which log-weighting compresses. SFF regrants are attributed to the distributor once (asserted: the payer holds no duplicate direct edge). Rubric = the share of each funder's log-dollars landing on lane-tagged grantees, ties broken by lane log-dollars; Spearman between structure and rubric is ρ=-0.18. Validation is reconstruction plus leave-one-out placement: per-seed hit-rate of actual funders in the top 5 is 66% (LOO 55%).
Hide a fifth of the graph's 111 tracked grants and a 1-dimensional embedding finds them again with AUC 0.76 — turned on the 2,718 absent pairs, it calls Survival & Flourishing Fund → Stanford University the field's most overdue check.
“Missing” means missing from this graph — a predicted check may exist in reality but be untracked by our sources. 28 of 41 grant-side funders have no tracked grants, so the model can never nominate them. The top list leans on one funder (2 distinct funders in 15 rows): at d=1 the model knows activity and breadth, not thematic fit — the “why plausible” column is annotation from declared domain tags, not model output. Investment predictions failed validation (AUC ≈ 0.5) and are deliberately absent.
The funding map records 111 grants that did happen. For anyone planning a raise — Agents of Chaos included — the sharper question is which checks haven't happened yet but fit the pattern of the ones that did. This panel scores every absent funder→grantee pair and ships only what survives validation.
This is the recommender-system trick — people who bought X also bought Y — run on money instead of movies. Fill a funder × grantee grid with log-dollars, factor it with an SVD the way a recommender compresses user × movie ratings, and a large predicted value in an empty cell is a grant the pattern says is missing. The honest part is the test: hide a fifth of the real grants, refit, and ask the model to pick them out from decoy pairs — AUC 0.76 means the real hidden grant outranks a decoy about three times out of four. Validation also chose d=1: 111 grants earn the model exactly one axis — how much a funder deploys × how widely a grantee is funded — and every richer model scored worse. The VC investment layer validates at coin-flip (AUC 0.54 at best), so we refuse to predict it. A 200-node graph gives coarse recommendations; read the list as prioritized homework, not prophecy.
for the curious
Random-dot-product-graph link prediction: truncated SVD of the 41×69 funder × grantee matrix, entries log10($+1), scores X@Yᵀ (Athreya et al., JMLR 2018 for RDPG/ASE; Koren–Bell–Volinsky 2009 for the matrix-completion reading). Undisclosed amounts (13/111 grants, 10/19 rounds) get the median disclosed amount of their edge type; re-scoring with the minimum disclosed instead reorders candidates with Spearman ρ=0.87 and keeps 15/15 of the top list. SFF's regranted checks (payer: Jaan Tallinn) count once, under the program that decided them. The grant and investment layers share no funders and only Apollo Research as a grantee, so each layer embeds separately — jointly, the philanthropy block zeroes out the VC block. d is chosen from {1…12} by 5-fold edge holdout (numpy default_rng(0)): hide a fold, re-embed, score hidden edges against equal-count random absent pairs. d=1 maximizes mean AUC (0.764; folds 0.71–0.90). Against harder decoys — absent pairs of the 13 funders with tracked grants — AUC falls to 0.60: much of the easy signal is knowing who writes checks at all. SVD signs fixed via _shared.fix_signs with coordinated flips on both factors; scores shown relative to the strongest predicted gap.
8 of the 62 tracked checkbooks already fund a flagged rival — $98.65M of it verified — but 3 of the 8 hold only exited positions (Insight Partners, Andreessen Horowitz, Index Ventures), and 13 clean funders back agent-security or evals work without touching a rival.
Coverage is the caveat: 10 of 14 rivals are not funding-graph nodes, so their backers are known only as the 42 name strings on their company cards — no amounts, dates, or verification. Across all 14 cards, just 6 of 62 distinct investor names match a tracked funder; the remaining 2 of the 8 rival backers (AI Grant, Juniper Ventures) surface through funding-graph money edges instead. The clean list is therefore only as clean as the map: General Catalyst (Haize Labs) and Madrona (Gray Swan) back rivals too, they just are not tracked funder nodes here. Absence from every table means untracked, not unconflicted.
Agents of Chaos competes with 14 companies flagged as direct rivals on the companies graph. Before we pitch anyone, we want the money sorted into three piles: checkbooks already behind a rival (likely conflicted for our equity — but with proven appetite for exactly our category), checkbooks funding agent-security and evals work with no rival exposure (the clean targets), and rivals whose money we cannot see at all (intel gaps). Both facts about a rival-backer matter, conflict and appetite, so the table shows both and lets you weigh them.
There is no model here — this is a database join dressed up as a graph walk, and the value is in the curation, not the math. We take the 14 rival-flagged companies and look them up in the funding graph two ways: by identity (four rivals are funding-graph nodes with money edges pointing at them) and by name (every investor listed on a rival's company card, matched against the 62 tracked funder nodes). Any funder with a hit lands in the conflict table; funders whose tracked money touches agent-security or evals grantees but never a rival land in the clean table. It is the same move as checking a benchmark for train–test contamination: mechanically trivial, but you want the overlap list before you trust the split. One wrinkle the tables keep visible: five rivals have already exited to acquirers, so those backers' conflicts died with the deal while their taste for the category did not.
for the curious
Deterministic two-key join, no fitted model. Key 1: identity — a funding-graph grantee whose networksId (or id) equals a competitor-flagged companies-graph id, plus all grant/investment edges into it (4 edges, 4 rivals). Key 2: canonical name equality (casefold, strip one trailing parenthetical) between the companies-graph investors[] strings and the funder node names; entries marked '(acquirer)' are treated as exits, not positions. No fuzzy matching — misses land in the intel-gap table rather than being guessed, and a prefix-containment assert guards near-miss names. Dollar conventions: led-round funding edges carry the round total (Sequoia's $80M into Irregular is the Series B it co-led with Redpoint, not its own check); undisclosed amounts stay null and are never imputed. Appetite = at least one money edge into a grantee whose domainTags include agent-security or evals; SFF's qualifying grants are all regrantOf Jaan Tallinn and are counted once, under the SFF vehicle, flagged. 'Safety-native' on a rival-backer means at least 3 non-rival portfolio companies carrying safety tags (agent-security, evals, interpretability, technical-alignment).
Anthropic, OpenAI, and Google DeepMind sit three hops from AoC — and since the 2026-07 edge audit, all 24 best routes open rival-free through AIUC.
AoC's seat is still mostly rivalry — 4 of its 5 edges are competitor ties. But the fifth, an unverified business tie to AIUC, stopped being a dead end in the 2026-07 edge audit: AIUC's certification ties (ElevenLabs, Intercom's Fin, UiPath) give AoC a rival-free corridor reaching 150 companies. That corridor hangs on a single unverified edge; every other route still starts through a rival.
The map shows who is adjacent to whom; this panel turns that into asks. For eight company targets — the top prospects, the major labs, and one VC — plus the top five funders, we compute the three cheapest intro routes each, then count who keeps showing up in the middle. The recurring middlemen are the relationships worth investing in.
The route-finder works like a maps app asked for alternates: the best path, then the next-best that differs somewhere, never revisiting a stop. Each hop has a price. A business tie costs 1, a shared investor 2, a rival 10 — so a route through one competitor wins only if it saves ten partner hops. Three routes per target means two backups when a relationship goes cold. On the funding side, routes start from the 3 grantees nearest AoC (Gray Swan AI, Apollo Research, Haize Labs), and every hop counts the same. One structural fact: every person in the funding graph has exactly one edge, so no route passes through a person — a chain can only end at one. That is why the person routes end with a name and a role.
for the curious
Yen (1971) k-shortest loopless paths, k=3, via networkx shortest_simple_paths (Dijkstra subroutine on the weighted company graph; unweighted BFS hops on the funding graph). Edge weights business=1, shared-investor=2, competitor=10 are design choices, not measurements — reweighting reorders routes but cannot create reachability. For the 7 company pairs with two edge types we keep the cheaper. Targets were curated at bake time from the competitor-nominations and funder-shortlist panels plus the four majors; all 8 company targets sit inside AoC's 183-node component (0 unreachable), while 2 of 5 shortlist funders (Sequoia Capital, Insight Partners) have no funding-graph path from any AoC-linked grantee. Funding caveats: 85/199 edges lack a year, and affiliation edges carry roles but no dollars.
On the mapped wiring, the best single new tie is Accel — that one edge cuts AoC's distance to the mapped market by 15.4%. It is nearly a tie: Index Ventures sits 0.057 points behind, and the whole top-10 spans 7.34 — so pick the one you can actually reach.
All of this depends on the current edge inventory: four of AoC's 5 edges are competitor ties (the fifth, AIUC, is an unverified partner tie), so “distance to market” is measured mostly through the rivalry layer. Unverified edges count as wire, and the 6 companies outside the connected core are not scored.
Agents of Chaos touches this map through five edges — four rival ties and one unverified partner tie (AIUC). Suppose we could add exactly one new relationship — a design partner, an investor, a platform integration. Which one would pull us closest to the whole market at once, not just to one company?
Treat the graph as an electrical circuit: every edge is a resistor, and the effective resistance between two companies measures how hard it is to travel between them through all routes at once. Many short parallel paths mean low resistance. We score AoC's position as the sum of its resistances to all 182 other companies in the connected core. Then, for each of the 177 companies we have no tie to, we ask: add that one edge — what is the exact new score? (An algebraic shortcut answers this exactly for every candidate at once.) The winners are not the market's hubs but its thin-wired investors: a fund touching the map by only one to three public edges is so far away, resistance-wise, that one direct tie beats another route into the dense core — though thin here often means a quiet portfolio, not a small one. Even the worst candidate cuts 4.5%; the best cuts 15.4%. The comparison column scores the same edge by how much it shrinks resistance between all pairs of companies. Since the 2026-07 edge audit thickened the wiring around our own cluster, the two objectives largely agree: the global winner (Index Ventures, −16.9% global) ranks #2 of 177 for AoC as well.
for the curious
Resistance distance per Klein & Randić (1993); global objective is the Kirchhoff index Kf = n·tr(L⁺). L⁺ computed once via dense numpy.linalg.pinv (hermitian) on the 183-node largest connected component of the all-edges company graph (unweighted, unverified edges included). Adding edge (a,u) updates L by +(e_a−e_u)(e_a−e_u)ᵀ; the pseudoinverse follows by Sherman–Morrison, exact because e_a−e_u is orthogonal to the Laplacian null space (cf. Ranjan, Zhang & Boley 2014). Exhaustive over all 177 non-neighbors; the top-3 deltas verified against brute-force pinv recomputation to 1e-8. The 6 companies outside the core are unreachable (infinite resistance) and excluded.
21 vendor→buyer pairs probably exist but aren't on the map — starting with Robust Intelligence (Cisco) × Notion — and the same model ranks all 70 unverified edges into a verification queue.
The vendor × bank cell of the base-rate table is exactly 0.000: the map holds no verified security-vendor–bank edge, so the model cannot recommend what it has never seen — bank pairs rank last and survive here only on co-investor evidence. Only 3 pairs have two or more shared investors, and investor names are unresolved strings, so aliases quietly undercount overlap.
The map only shows edges someone wrote down. Two questions follow. Which customer relationships are probably out there but unmapped? And of the edges we drew without confirming, which should we verify first? Both matter commercially: a rival vendor's unmapped buyer is, by symmetry, our prospect.
The model is a table of base rates. Group the 188 companies by vertical and measure how densely each pair of verticals is wired, using verified edges only. Every company pair then inherits its verticals' rate as its expected chance of a link — no pair-level nuance, but honest about what is typical. A missing edge with a high expected chance is a hole where the market usually has a wire. Since the rate is the same for every pair in a cell, we break ties with pair-level evidence: shared investors, weighted so that an investor with few bets counts more than one with hundreds. The table keeps only pairs where that second signal fires. The same base rates, applied to the edges we drew without confirming, put the audit queue in order: verify the most-expected edges first, because that is where the graph most expects a wire and where a wrong one distorts everything downstream.
for the curious
Supervised SBM: graspologic 3.4.4 SBMEstimator(directed=False, loops=False) fit on the verified-only binarized adjacency with y = the 8 vertical labels (Holland, Laskey & Leinhardt, Social Networks 1983). The MLE is the closed-form per-block-pair edge density — deterministic, seedless, and connectivity-agnostic, so the graph's 7 components and isolates need no LCC restriction. Candidates: all non-edges (no edge of any type, verified or not) between a competitor-flagged vendor and the buyer verticals {banks, health, enterprise, infra}, ranked by p_mat_. Cross-checks on the verified shared-investor subgraph restricted to 2-hop pairs: adamic_adar_index (Adamic & Adar, Social Networks 2003) and cn_soundarajan_hopcroft (WWW 2012) with community = vertical — for cross-block pairs the S–H community bonus can never fire, so it reduces to a common-neighbor count and always agrees with AA (asserted); both are reported as one signal. Investor overlap counts matching name strings, not resolved entities.
Funders on this map hunt in packs: two funders from the same pack are 7.3× more likely to co-fund the same grantee than two funders from different packs — and the pack nearest AoC's multi-agent lane (cooperative-AI bloc: NSF, Cooperative AI Foundation, Macroscopic Ventures) has 2 doors open.
Thin where it matters: only 25 of 62 funders have tracked money edges, 4 of those co-fund with nobody, and 3 of the 6 packs rest on a single shared bet (one syndicated round, not a repeated pattern — flagged in the table). The entry-pack boundary is the least stable cut: under Jaccard weighting the cooperative-AI bloc merges into the EA grant core (the two blocs already seek each other out at 1.9× expected), so read it as the multi-agent-flavored wing of one big philanthropy pack — its open doors are real either way.
Raising a first grant is not 62 independent doors. Funders share deal flow, referees, and joint calls, so landing one of them moves its pack-mates' priors about you. This panel finds the packs in the funding map and measures how much being inside one matters — then names the pack, and the specific open doors, where Agents of Chaos should start.
Think of each funder as a label and each grantee as a training example: labels that keep firing on the same examples are correlated, and that co-occurrence signal is the same raw material word embeddings are built from. We wire two funders together by how many grantees they both back, then run a community detector on that co-occurrence graph — the packs fall out the way clusters fall out of an embedding. To check the packs are real and not just an artifact of a few prolific funders, we compare each pack pair's observed co-funding against what a degree-matched random rewiring would produce; on a log scale, green cells mean the packs seek each other out beyond what their sheer activity predicts. The payoff number reads like a recommender's lift: 63% of same-pack funder pairs back at least one common grantee versus 9% of cross-pack pairs — 7.3× the co-funding odds.
for the curious
Bipartite funder→grantee multigraph (grants + investments) projected onto funders; edge weight = count of shared grantees, so the 13 of 111 grants with undisclosed amounts carry the same evidentiary weight as disclosed ones and no dollar is ever double-counted. SFF's grants are regrants of Jaan Tallinn's money; they are counted once, as SFF decisions (the s-process makes the pick), and the payer has no direct grant edges — asserted in code. Communities: graspologic's Leiden (Traag, Waltman & van Eck 2019), random_seed=1, trials=20, partition asserted identical across two runs. Robustness: re-clustering with Jaccard weights (shared over union) reproduces 4 of 6 packs exactly and merges the two philanthropy blocs into one. The ledger is DCSBM-style: observed block-pair weight over the configuration-model expectation DrDs/2m (Chung–Lu), shown as log10; tiny packs get huge diagonals because their degree-expected weight is near zero. The lift compares P(≥1 shared grantee) for same-pack vs cross-pack pairs among the 21 partitioned funders; it is descriptive, not predictive — the packs were learned from the same co-funding matrix, so it quantifies how concentrated co-funding is, not an out-of-sample forecast. Entry pack: among packs with ≥2 grant edges, the one whose grants most often land on grantees tagged agent-security, evals, or multi-agent (29% for the cooperative-AI bloc vs 24% for the EA-adjacent grant core; 3 of 3 members declare multi-agent as a focus). Door-open claims are judged against the snapshot date 2026-07-05, never wall clock.
12 named people hold the doors to $159.8M a year of verified field giving across 7 funders — and NSF's four program officers hold the only door in this table that is also a bridge between separate money territories.
The people layer covers 39 of 62 funders and misses the two biggest hubs: Coefficient Giving ($92.7M/yr and the graph's strongest bridge) and the Survival and Flourishing Fund have no staff mapped yet, so nobody holds those doors in this table — and two smaller dollars-plus-bridge doors, Long-Term Future Fund and Schmidt Sciences, are likewise unstaffed in the map. Gated dollars can only see the funders that publish an annual figure — 57 of 69 people show $0 for that reason, not because their door is small (Juniper Ventures and the Cooperative AI Foundation, the two strongest people-held bridges, are both in that bucket). And betweenness measures tracked edges, not influence.
Grant applications go to institutions, but doors are opened by people — the funding map carries 69 of them, each verified from a staff page to a current role at a funder. Which of them sit at the gates of the most money reachable by agent-safety work, and which hold doors that bridge funding territories that otherwise never touch on the map? Being on this who-to-get-to-know list is a compliment: the graph is saying your door matters.
Each person gets two scores, and neither is a black box. Gated dollars is simply the verified annual field budget of the funder whose staff page lists them — the size of the budget behind their door. Brokerage asks how often shortest paths through the money graph (funders wired to the grantees they fund) route through that person's funder. That is betweenness centrality, and it behaves like attention bottlenecks in a transformer: a few tokens end up on the route most heads pass through, and masking one cuts distant parts of the context off from each other — here, a high-brokerage door joins funding territories that otherwise never meet. The striking thing is how little the two scores overlap in this table — big budgets mostly sit behind doors that bridge nothing we can see, and the strongest people-held bridges publish no budget at all. Only one door here scores on both.
for the curious
Gated dollars = the funder's annualFieldGivingUSD (basis year varies by funder; null → $0, flagged — 57 of 69 people sit behind doors with no published figure). Brokerage: betweenness centrality (Freeman 1977), exact unweighted undirected shortest paths on the funder–grantee money graph (130 grant + investment edges, presence only — undisclosed amounts count as presence; SFF's regranted edges kept as topology, dollars never summed through them). We first computed betweenness for the person nodes themselves on the full tripartite person–funder–grantee graph, as one should: every one of the 69 people carries exactly one current affiliation edge, so each is a pendant and their betweenness is identically zero — a degree-one node lies on no shortest path (verified in-script, asserted on every rebake). The brokerage a person exercises is therefore the brokerage of the door they hold: the table reports their funder's betweenness as a percentile — the share of the other 61 funders strictly below (51 of 62 funders sit at zero, so any bridging at all clears the 80s). Colleagues at the same funder tie on both scores by construction; their roles differentiate them. Affiliations are current-only; deadline checks use the snapshot date 2026-07-05, never wall clock. No randomness anywhere.
Collapse the regrant chains and 90% of the $459.4M in tracked grants originates with just two sources — Coefficient Giving (85%) and Jaan Tallinn (5%); most other doors hand out money that started somewhere else.
Tracked is not the field: only 6 of 62 funders have dollar-stamped grants in this graph, and the biggest, Coefficient Giving, also runs the most public grants database — so the 90% measures concentration of what we can verify, with a visibility bias toward funders who publish. 13 of 111 grants carry no amount (floored in HITS, absent from the ledger); SFF's untagged $27.3M is pooled money we cannot split across its payers; the Macroscopic→CAIF seed is documented in node blurbs, not as a graph edge.
A pitch meeting goes differently depending on whether the desk across from you is where the money originates, a professional pass-through, or a line in an institution's budget. Distributors have open applications and fast cycles — you pitch them; sources set the agendas the distributors execute — you cultivate them; programs answer to calls and budget years. This panel classifies all 62 funders on the map and traces every tracked grant dollar as far upstream as the data allows.
Think of gradient flow in a deep network: the loss is computed in one place, and every layer in between just passes the signal along, reshaped. Funding has the same structure — SFF is the desk that hands you the check, but most of its tracked grants are tagged as Jaan Tallinn's money, so the signal you need to please originates one layer up. We follow each grant's regrant tags (and the one funder-seeding the data documents, Macroscopic's $15M into CAIF) upstream until the trail ends, then re-total the ledger by ultimate source. Separately, a weighted HITS pass — the algorithm behind early web search — scores funders by whether their money lands where other credible money also lands, and grantees by how much credible money converges on them. The classification reads off the move: pitch distributors, cultivate sources, watch the programs' calls.
for the curious
Attribution: each dollar-stamped grant (98 of 111; $459.4M) is credited to its regrantOf funder when tagged (15 dollar-stamped SFF edges → Jaan Tallinn; 16 tagged in all), else across the blurb-documented Macroscopic→CAIF seeding, else to the payer of record; dollars paid by distributors with no tag stay in explicit “pool — payers untagged” buckets rather than being credited as origins, and program budgets (government, corporate) count as their own origin. Weighted HITS (Kleinberg 1999), hand-rolled power iteration on the 13×56 funder→grantee matrix with W = log10(pair dollars + 1), undisclosed amounts floored at the smallest verified grant ($15k); all-ones init, 100 iterations, L2-normalized each step — deterministic, converging to the leading singular vectors of W. Classification: government/corporate → program; VC → distributor of LP capital; FMF's AI Safety Fund → distributor (it pools the frontier labs' money); the 23 philanthropies are hand-classified from blurbs and regrant structure, with every judgment call flagged in the table. Investments (19 edges, $385M of led-round totals) are excluded throughout — round totals are not the investor's own dollars.
A random walk started at AoC lands most often on Anthropic, OpenAI, Google DeepMind — and 7 of the top 25 reachable companies hang on a single mapped relationship.
Every step out of AoC goes through one of its 5 ties: 4 rival edges (weight 0.3) plus one inferred, unverified business tie to AIUC that alone carries 45% of each step out — a single hand-drawn edge with that much say over the ranking. 6 companies sit in components no walk from AoC can reach: zero score, grey on the map.
The map has 188 companies, but which ones can Agents of Chaos actually get to from where it sits? Sitting near someone on the map is not the same as reaching them: a warm path through two strong ties beats a cold one through five. This panel scores every company by how easily we reach it — and flags where that reach hangs on a single mapped relationship.
The score comes from a random walk — the same idea Google built its search rankings on. Drop a walker on the AoC node, let it follow relationships (business ties at weight 1.0, shared investors 0.7, rivalry 0.3), and every so often pull it home to restart. The share of time it spends at each company is that company's reach score. It counts every path at once, not just the shortest. The restart setting α is the walker's leash length, and the three columns compare leashes: at α=0.5 the walker stays near home (8 of its top 25 lie beyond two hops), while at α=0.95 it drifts toward the graph's biggest hubs — Anthropic (48 ties) and OpenAI (33) — and 16 of the top 25 sit three or more hops out. A row that only shines at high α is hub gravity, not closeness. The last two columns measure distance two ways: hops counts raw handshakes, and resistance treats the graph as an electrical circuit, where many parallel paths lower the resistance and one thin wire keeps it high. Close in hops but far in resistance — the flagged rows — means one mapped relationship is doing all the work.
for the curious
Personalized PageRank (Page et al. 1999; topic-sensitive form of Haveliwala 2002) by power iteration (networkx, tol=1e-10) on the weighted undirected company graph, personalization mass 1 on agents-of-chaos; parallel typed edges between a pair sum their weights. Main ranking α=0.85; the table excludes AoC itself and its 5 direct neighbors (4 rivals plus AIUC, its only edges), so rows start at hop 2. Hop distance: unweighted BFS. Resistance distance (Klein & Randić 1993), r(a,b)=L⁺aa+L⁺bb−2L⁺ab from the Moore–Penrose pseudoinverse of the weighted Laplacian of the 183-node largest component; the 6 companies outside it are unreachable (exactly zero PPR mass) and carry no resistance value. Bottleneck flag: resistance rank ≥ 25 places worse than hop rank (competition ranking over the component).
Mapped rival money is wide but shallow: 67 listed investors back our 14 rivals, yet only 2 (Lightspeed Venture Partners and Sequoia Capital) hold more than one — and the closest look-alike fund with no mapped rival position is Sapphire Ventures (similarity 0.51 to Sequoia Capital, 6 shared bets).
Investor lists cover 134 of 188 companies and are free-text strings: near-duplicates like Samsung vs Samsung Next count separately, Adversa AI lists no investors at all, and “portfolio” means portfolio-on-this-map, not the fund's real book — the twins only see the slice of each fund that happens to be mapped here.
Fourteen companies on this map are flagged as direct competitors. Their investor lists are public evidence of who has already paid for agent red-teaming, and the map records acquirers for 6 of the 14 — so this category demonstrably exits. Two lists fall out: the funds with proven appetite, and the funds that invest just like them but hold no rival position. The second list is a pitch list with no conflict the map can see.
Treat each investor as a checklist over the 188 mapped companies: a mark for every company it backs. Two investors are similar when their checklists overlap — the same math behind “customers who bought X also bought Y.” For each proven rival-backer we find its nearest neighbors among investors holding zero rival positions. High similarity means overlapping bets, so the twin plausibly shares the investment thesis without the conflicting position. Investors with a single mapped company are excluded (one shared deal is not a pattern), and funds with more than 25 mapped companies would be excluded for being similar to everyone — today that excludes no one (the largest mapped portfolio is 24).
for the curious
Bipartite investor×company incidence over the public map (134/188 companies list investors; 417 distinct investors after canonicalizing free-text names by case and trailing parenthetical, so “Andreessen Horowitz (a16z)” folds onto “Andreessen Horowitz”). Twins: cosine similarity of L2-normalized binary rows — item-based collaborative filtering per Sarwar et al. (WWW 2001). Anchors are the 18 rival-backers with ≥3 mapped companies; candidates need 2–25 mapped companies, zero rival overlap, and no name-string kinship with any rival-backer or acquirer (this removes “Lightspeed” vs “Lightspeed Venture Partners”, “NVentures (Nvidia)”, “Cisco Investments”). Investor names are labels, not graph nodes; ties break by shared-deal count, then portfolio size, then name.
The labs aside, the map's best-placed broker is LangChain (LangGraph / LangSmith) (constraint 0.09, 15 ties across 5 verticals) — and counting business ties alone, the seat passes to Microsoft (0.10).
AoC's own 5 edges are 4 competitor ties plus one unverified business tie (AIUC), so its seat in the full-map table (constraint 0.22, rank 58 of 142) mostly reflects rivalry. In the business-only map, AoC now reaches the main commercial web — its one path runs through AIUC — but a single business tie sits below the 3-tie floor, so AoC still earns no broker score. Note also that none of the top 25 full-map brokers are VCs — the mapped VCs sit at the map's edge, though that mostly reflects thin public portfolios, not few ties.
Who in this market can actually broker an introduction? Not the best-connected company — the one whose contacts don't already know each other. That company sits across the open gaps between clusters, and those gaps are where deal flow, hiring, and early market intelligence move first.
The score, called constraint, measures how much a company's contacts overlap: high when all its ties fold back into one tight clique, low when its contacts are strangers to each other and it alone connects them. Low constraint is what makes a broker. Effective size is the companion number — a tie count discounted for redundancy, so 12 contacts who all know each other count as far fewer than 12 independent ones. We rank the 183 companies in the map's main connected cluster from least constrained to most, keeping the 142 with at least 3 ties (41 smaller nodes are excluded — with one or two ties, the score says nothing). Then we re-run on business edges only — customer, partner, and platform relationships — because a bridge made of shared-investor edges may never convert to a warm intro. The second table is the honest broker list.
for the curious
Burt (1992), Structural Holes: constraint ci = Σj(pij + Σq piqpqj)²; effective size via the Borgatti (1997) simplification for binary graphs; networkx implementations of both. Full mixed run: giant component of the company graph (183 nodes, 528 edges; smaller components excluded — constraint is a local statistic, so this only drops their few eligible members). Business-only run: giant component of the business-edge subgraph (95 nodes, 147 edges, 37 nodes over the degree floor). The funding graph was checked and not shipped: it has zero triangles (a forest), so constraint reduces to exactly 1/degree for all 33 nodes over the floor — the statistic would restate degree and nothing else.
7 of 59 companies sit in the prospect quadrant — central in the money network, but with few mapped business deals (Vercel (AI SDK), Revolut, Ambience Healthcare, …). One caution: the market's “core” looks no more special than its edge counts alone would predict (p = 0.91), so read “core” as “well-connected,” nothing more.
7 of our 14 rivals land in the core mostly because the 27 security vendors all point competitor edges at each other. AoC itself is crust: rank 79 of 189 on 5 thin edges (4 rival ties + 1 unverified business tie), and with no shared-investor edges at all it cannot appear on the quadrant chart. Two of the 7 “prospects” are competitor-flagged.
Every market has an establishment and a crust. We ask three things. Which companies hold the middle of the agent ecosystem? Is that core a real structure, or just who happens to have the most edges? And the actionable one: who is central in the money network but peripheral in the business network — well-financed, with no deals on this map yet? Open ground or deals done quietly: either way, those are the companies to pitch.
Each company gets a score from 0 (crust) to 1 (core), fitted so that high scorers hold most of the map's edges in the classic establishment shape: core companies connect to everyone including each other, crust companies connect only to the core. We compute it three times — on all 531 ties, on business ties only, and on shared-investor ties only. Then a reality check: rewire the map at random 500 times, keeping each company's number of ties, and re-fit. The real map does not beat the rewired ones (p = 0.91), and the score tracks raw tie count almost exactly (correlation 0.86) — so the overall core is largely popularity in disguise. The useful signal is in the split: crossing the money score against the business score separates the establishment (high on both) from the prospects (financed, no mapped deals yet).
for the curious
Rombach et al., “Core-Periphery Structure in Networks (Revisited)”, SIAM Review 59(3), 2017 — continuous coreness via the cpnet implementation (label switching, α=0.5, β=0.8, best of 10 runs; the kernel maps ranks onto two blocks, crust ≤ 0.25 and core ≥ 0.75, so the quadrant guides at the axis midpoints split exactly core-block vs crust-block). Significance: Kojaku & Masuda's (q,s)-test (Scientific Reports 8:7351, 2018) with 500 Chung-Lu expected-degree null graphs; Rombach yields a single core-periphery pair, so significance is all-or-nothing across the 186 nodes — here: not significant. Determinism note: cpnet's inner loop is numba-jitted and uses numba's own RNG, which numpy seeding does not touch; we seed numpy, python, and numba (via a jitted np.random.seed) and verify by double-run. The method needs no connected graph: all 186 non-isolated companies across 5 components are scored, and small components land in the crust by construction.
The companies wired most like AoC are Magic.dev, Cognosys, Alibaba Qwen — 13 of 20 stay on the list when unverified edges are dropped.
AoC's only mapped edges are its 5 rival ties, so its position on this map reflects rivalry — add real investor and partner edges and the map sharpens.
What does the market look like if you ignore the hand-drawn category labels and let the connections speak? We give every company a position computed purely from who it connects to, then read off where Agents of Chaos sits — and who sits closest.
The technique works like a word embedding: companies with similar connection patterns land near each other, whether or not they share a category. (An automatic rule picked 4 coordinates per company here.) Distance on this map means playing a similar role in the market — so AoC's nearest non-rival neighbors, listed below, are a prospecting shortlist: the network treats them as companies in our position. A company's distance from the center also roughly tracks how much agent activity it has (correlation 0.20).
for the curious
Adjacency spectral embedding of the binarized undirected company graph (all 492 edges; diagonal augmentation; Zhu–Ghodsi elbow via graspologic, svd_seed=0), per Sussman et al. (JASA 2012) and the RDPG survey of Athreya et al. (JMLR 2018). Sensitivity: re-embedding on the 421 verified edges only; a neighbor “survives” if it stays in the top-20. Caveats: AoC's own edges are 5 competitor ties, so its position is defined by the rivalry layer; isolates embed near the origin; distances beyond the second elbow dimension are noise at this sparsity.
The map's biggest white space is AoC's own lane: zero of the 111 tracked grants touch an agent-security grantee — all $394.6M of tracked agent-security money is venture capital into startups, even though 16 grantmakers declare agent security as a focus.
Coverage limits what the wiring can say: 46 of 62 funders are missing from the map — 37 have no tracked money edge at all, and the other 9 are VCs whose checks sit in 6 investment islands (18 nodes, $395.1M) that share no grantee with the grant economy; island money appears in the matrix but not on the map. 8 of 16 placed funders have exactly one tracked check, so their positions are one-edge readings (flagged). 32 of 69 grantees carry no domain tags; their $105.6M sits in the matrix's untagged row rather than vanishing. VC cells credit full round sizes to the round's lead, and 23 undisclosed amounts enter at the $2.1M median floor.
The funding map's curated view sorts funders into four kinds and eight domains. This panel throws the labels away and asks what shape the money actually has: every funder and grantee is placed purely by who pays whom, weighted by dollars. The shape answers two business questions at once — which funders behave alike (whatever their label says), and where no tracked check lands at all.
Think of the t-SNE plots people make of embedding spaces — except this one is deterministic and linear, so distances are honest and rerunning it cannot rearrange the picture. Each funder's row of log-dollars across grantees is its portfolio vector; a matrix factorization compresses those vectors so that two funders land close when they fund the same orgs at similar scale, and each grantee lands amid its funders. The first coordinate mostly measures volume (r=0.70 with log dollars routed), so size lives in the dot area and the map shows the next two coordinates — the ones that encode taste. Three poles emerge: Coefficient Giving's institutional portfolio on the left, the SFF/Tallinn cluster on the right, and the NSF/Cooperative-AI campus pole on top. The funders far from their own kind's center are the findings — NSF, a federal science agency on paper, is wired like a philanthropy: its nearest neighbor on the map is the Cooperative AI Foundation.
for the curious
Adjacency spectral embedding of the weighted bipartite funder×grantee matrix (entries log10($+1); undisclosed amounts floored at the tracked median $2.1M, 23 of 130 edges): rank-3 truncated SVD, funders at U√S, grantees at V√S (Sussman et al., JASA 2012), joint sign-fixing for reproducibility. Symmetrizing first degenerates — bipartite spectra pair up ±σ and the top singular vectors load on one side each (verified) — so the rectangular route is required. The map plots dimensions 2–3; dimension 1 is volume and moves into dot area (r ∝ √$ through the node, clipped 2–9px; funders use tracked outbound dollars, grantees their verified fieldDollarsUSD). Giant component only (76 of 94 nodes with money edges); affiliation edges excluded — people would clutter a money map. SFF's regranted checks stay attributed to SFF; the payer (Jaan Tallinn) has no direct edges, so no dollar is counted twice. Off-center = distance to the leave-one-out centroid of the funder's own kind in map coordinates. The white-space matrix splits each check evenly across the grantee's domain tags so every dollar lands exactly once (CMU FOCAL's $3.5M halves between multi-agent and technical alignment); it covers all 130 money edges, islands included. Two identically-wired pairs — two funders splitting the same single grantee, and two grantees sharing the same single backer — are nudged apart by ±0.04 seeded jitter. The third axis rides a modest eigengap (σ₃=16.5 vs σ₄=14.1), so read vertical positions as suggestive, not exact.
Security vendors' documented commerce runs through frontier labs — 27 of their 54 mapped business edges — while security×banks and security×healthcare show zero mapped deals. And when an algorithm redraws the groups from the wiring alone, its best match to the shelves is weak — agreement peaks at 0.28 of 1, and its stable cut has 5 groups, not 8.
The clustering method has a known blind spot: groups holding fewer than about 22 internal edges cannot surface on their own, and verticals the size of frontier-lab (14 companies) or investor-vc (16) fall below that — so low agreement is partly the method's floor, not proof the taxonomy is wrong. And the empty security×banks and security×healthcare cells may be unmapped deals rather than absent ones — 70 of 538 edges are themselves unverified.
The map colors 189 companies by eight hand-assigned verticals. Two questions. Do those shelves describe how the market actually connects? And — the sales question — which buyer verticals actually transact with security vendors? We first score the shelves against the real edges, then let an algorithm redraw the groups from scratch and count the disagreements.
Part one keeps the labels: for each pair of verticals, count what share of the possible company pairs actually hold an edge. That gives an 8×8 grid of connection rates per edge type. The business grid is a hub-and-spoke around the frontier labs: labs' mapped deals with security vendors, banks, and enterprises run at about 7× the typical rate, while security→banks and security→healthcare are empty on the map. Part two deletes the labels: a clustering algorithm regroups the companies from the wiring alone, run 40 times from coarse to fine. If the taxonomy matched the wiring, some run would recover eight groups agreeing with the shelves. Agreement is scored from 0 (chance) to 1 (a perfect match). Part three lists the best-connected companies whose data-drawn group is dominated by a different vertical than their own.
for the curious
Supervised: graspologic 3.4.4 SBMEstimator with y fixed to the vertical labels (Holland, Laskey & Leinhardt 1983) — a supervised fit is per-block density estimation, so the graph's 4 components need no LCC restriction. Unsupervised: graspologic.partition.leiden (Traag, Waltman & van Eck 2019), random_seed=1 (the native PRNG rejects 0), γ ∈ logspace(−2, 1, 40), all 538 edges unweighted, ARI per Hubert & Arabie 1985. Below γ≈0.07 Leiden returns exactly the 4 connected components, so those cuts are trivial; the reported plateau is the longest constant-K run above the component count (K=5, γ≈0.07–0.20, agreement 0.04). K passes through 8 only at γ≈0.59, where agreement peaks at 0.28 — even at its best, the members mostly don't match. At the plateau, 115 of 189 partitioned companies sit in a community whose modal vertical is not their own; the table shows the top 15 by degree.
Partnership edges cut across the market structure that co-investment and rivalry respect (cross-wiring 4.6, vs ≤0.2 for the other two), the wiring only faintly matches our hand-drawn verticals (0.06 of 1) — and no company's role changes more between lenses than Gray Swan AI's.
The shared-investor lens leans on unverified investor lists (plain-text names, 17 of 178 edges inferred), so shifts involving it are softer evidence. Agents of Chaos itself has no shared-investor edges (its 5 ties: 4 rivals + 1 unverified partner), so it does not appear in the shift table, which needs at least one tie of every kind.
The company map draws three kinds of edges — business ties, shared investors, and competitor ties — and flattens them into one picture. But are “who you partner with,” “who shares your investors,” and “who you fight” really the same map? And which companies look most different depending on which of the three lenses you pick up?
We give every company one position on a shared two-coordinate map, then ask how each kind of tie uses those coordinates: does it connect companies that sit alike on a coordinate, or wire one coordinate to the other? The small 2×2 grids below summarize that, one per edge type; if the three lenses agreed, the grids would look alike. They don't. Investor and rivalry ties connect like to like, while business ties load on the cross cell (4.6) — partnerships cut across the very structure that co-investment and competition respect. Grouping companies by their shared positions matches our hand-labeled verticals at only 0.06 on a 0-to-1 scale, so the wiring faintly echoes the org chart at best. For the shift table, each of the 51 companies active in all three layers gets one comparable position per lens, and we rank by how far its three positions sit apart. A big shift (Gray Swan AI, Anthropic, Zenity lead) means the network sees a different company depending on the lens: partner-space says one thing, rivalry-space another.
for the curious
MASE (Arroyo et al., JMLR 2021) on the three binarized undirected layers over all 189 companies, d=2 fixed and svd_seed=0; at per-layer mean degrees of 1.7–2.0 the Zhu–Ghodsi elbow is unstable, so we do not trust automatic dimension selection here. Score matrices Rₖ = VᵀAₖV on the sign-fixed shared basis. ARI: KMeans(8, n_init=10, random_state=0) on V vs vertical labels. Shift table: OmnibusEmbed (Levin et al., arXiv 2017), d=2, svd_seed=0, restricted to the 51 nodes with degree ≥1 in all three layers; per-node shift = sum of pairwise distances between its three omnibus positions. Layers are disconnected with 31–89 isolates each — spectral embeddings tolerate that (graspologic warns), but isolate positions are meaningless, hence the degree filter.