Somewhere inside a perfectly respectable company, an employee is using a personal ChatGPT account to rewrite a proposal. A developer has discovered a coding assistant that procurement has never heard of. Marketing is generating images in a third tool, and finance is experimenting with a fourth. The board, meanwhile, has a slide titled “AI strategy.” Velatir's entire business begins in the comic distance between that slide and those browser tabs.
The Odense startup calls this the second AI strategy - the one employees and agents have already put into production. It is faster, messier and probably more revealing than the official version. Velatir does not want to replace ChatGPT, Copilot, Claude or Gemini. It wants to become the neutral layer beneath them: a place to see which services are being used, catch sensitive data before it travels, apply company rules, ask a person when software should not decide, and leave evidence behind.
That proposition has just attracted €5 million. The seed round, announced August 20, was completed in two weeks and co-led by new investor Spintop Ventures and returning investor Ugly Duckling Ventures. Norrsken Evolve returned too. EIFO provided a match loan, while n8n founder Jan Oberhauser and robotics executive Thomas Visti invested as angels. It arrived only six months after a €1.35 million pre-seed. In startup time, that is less a funding cadence than a double tap.
The product lives between paste and send
Velatir's quickest entry point is a managed browser extension. The company says it recognises more than 4,000 AI services across chat, code, writing, image, video, audio and enterprise software. A desktop product extends monitoring beyond the browser. SDKs, an MCP server and an n8n node cover workflows that a human does not launch from a tab.
Each interaction becomes a trace and related traces form a session. Two core agents then do narrow jobs. Gatekeeper checks whether the service itself is permitted. Data Protector looks for sensitive content and can support warning, redaction or blocking. Coach, launched later, offers contextual guidance to employees while they work. Brand Guardian, which checks output against company guidelines, is listed as coming soon.
One prompt, five stops
The human part matters. An awkward request can be escalated to Slack, Microsoft Teams or a phone, where an actual owner approves or rejects it. The software handles routine categories; the organisation retains the judgment. That is more useful than the usual “human in the loop” sticker because Velatir also records who the human was, what the agents assessed and how the case ended.
“We basically told people not to paste anything sensitive into AI tools and hoped for the best.”Thomas Overgaard, head of compliance, in a Velatir customer testimonial
That quote identifies what failed first: prohibition by memo. It asks an employee under deadline pressure to remember a policy, correctly classify the material and voluntarily choose friction. The employee may be careful, but the system is still hope with typography. Velatir moved the control to the point of use because people did not stop adopting AI. The company is blunt that they were right not to wait.
A map before a moat
The shrewd product decision is to observe before enforcing. A company can begin with visibility, discover which tools and accounts people actually use, separate free usage from paid usage and spot duplicate subscriptions. Only then does it decide what to sanction, warn about or stop. The first sale is not fear. It is a map.
The procurement list is not the AI inventory
Velatir analysis of 1.1 million sessions and 15,000 users, published by the company in 2026
Velatir says just 13 percent of activity in its 1.1 million-session analysis ran through accounts controlled by the organisation. The remaining 87 percent was personal, unmanaged and largely invisible. It also found active Grok or DeepSeek use in one quarter of the organisations studied, with 93 percent of that activity coming from privately paid accounts. These are company-produced findings, not a census of European business, but they clarify the wedge: leaders cannot govern an inventory they do not possess.
The customers are small and mid-sized organisations where IT, security, legal, compliance and operations teams have responsibility without omniscience. A current Chrome listing reports 4,000 users. Velatir says it has paying customers, though its site mostly identifies them by role rather than corporate logo. One compliance leader says the product changed the conversation from saying no to everything to letting teams use what they need. That is the commercial promise: governance as an accelerator, not a brake.
The price of the boring layer
Velatir sells B2B software in Visibility, Protection and Enterprise tiers. The public pricing page offers a seven-day trial but currently leaves the monthly figures blank, making the practical buying motion quote-based. All tiers list unlimited workspaces and members, audit logs, exports, role-based access, escalation and dedicated customer success; Protection adds active data controls, while Enterprise is positioned for larger deployments.
The disclosed cost of building the bet is easier to count: €6.35 million across two rounds, with an EIFO match loan included in the seed financing. The company says the new money will fund more talent, product development and entry into more European markets. Its LinkedIn page listed 22 employees on announcement day, up from the four founders who started in 2025.
Ugly Duckling Ventures led, with Norrsken Evolve participating.
Spintop and Ugly Duckling co-led. Closed in two weeks, according to Velatir.
The funding jump also reflects where Velatir fits in the market. AI governance vendors such as 2021.AI, Credo AI, Holistic AI, ModelOp and Saidot help organisations register systems, document risk and manage regulatory obligations. Security products discover generative-AI use or prevent data loss. Old-school alternatives combine secure web gateways, procurement spreadsheets, annual training and a policy PDF. Velatir is trying to stitch discovery, endpoint control, human escalation and audit evidence into one operating layer.
Its European position is more than flag waving. Velatir says the complete stack runs on European-owned and hosted infrastructure, not an American hyperscaler relabelled with an EU region. CEO Michael Blicher Sørensen previously worked on security for mission-critical Meta infrastructure and spent more than 14 years in Danish defence and NATO collaborations. The team's broader experience includes Meta, Nexi and LEGO. The product has ISO 27001 certification, according to the company.
“The bottleneck isn't intelligence. It's trust.”Velatir, announcing its €5 million seed round
That stance gives Velatir a clean answer to American model dominance: do not build another foundation model; become the European-owned traffic control through which many models run. It is a credible differentiator for regulated buyers, though not a universal advantage. A customer that is comfortable with hyperscaler contracts, already owns a capable security stack, or operates mainly outside Europe may value integration breadth and price more than sovereignty.
What another operator can steal
There is a reusable playbook here, even for a company that never buys Velatir. Start with behaviour, not policy. Run a short observation period. Build the real service catalogue from usage rather than surveys. Separate personal accounts from managed accounts. Identify repeated data classes and nominate the person who owns each hard decision. Then choose the smallest useful intervention: teach, warn, redact, block or escalate.
Measure services, accounts, teams and frequency before purchasing more AI seats.
Compare paid tools with actual use and consolidate subscriptions people have abandoned.
Every escalation needs an owner, a response channel and an acceptable response time.
Begin passive. Add warnings or blocks only where observed risk justifies the interruption.
The clever sequence is visibility, evidence, permission. It changes the conversation from “Which AI should we ban?” to “Where is useful work happening, and what guardrail lets us keep it?” It can also surface mundane savings. If three teams pay for overlapping products while most employees use a fourth free account, governance has found a procurement problem wearing a security costume.
When this approach will not work
Endpoint monitoring fails when employees do not trust the collection boundary, when works councils or privacy teams are brought in too late, or when the organisation cannot staff human escalations. It also misses value if custom tools sit beyond the supported browser, desktop or integration paths. Most important, telemetry is not compliance by itself. A company still needs lawful policies, accountable owners and the discipline to act on what the dashboard reveals.
Velatir's culture appears designed for that unglamorous work. The founders cover the neat set of CEO, CTO, COO and CPO. Company posts describe hiring for personality and capability, co-creating culture and outgrowing an early office within months. By summer, the team had moved to Østergade 61 in central Odense and planned an open-house reception. The tone is ambitious but oddly domestic: Europe needs an infrastructure champion; please also come by for food and drinks.
The company now has to prove that a control layer can remain neutral as models, agents and browsers mutate underneath it. It must make monitoring feel proportionate, keep false positives low, integrate broadly and turn a burst of regulatory attention into durable software revenue. Those are not small conditions. But Velatir has chosen a problem that grows each time somebody opens a new AI tab without asking. That part of the strategy is already shipping.