HiddenLayer has raised $100 million to protect AI systems from the things AI systems can do to each other — and to the humans who, somewhere along the way, decided to deploy them unsupervised into production environments.
The Series B was led by Delta-v Capital, with participation from Microsoft's M12, Morgan Stanley, Booz Allen Hamilton, and others who have presumably read the risk disclosures.
Humanity has built something it cannot entirely trust, and is now paying handsomely for someone else to watch it.
What happened
Three years ago, when HiddenLayer raised its $50 million Series A, the central question was whether AI attacks would happen frequently enough to constitute a real market. The answer, it turns out, was yes — delivered at scale, and ahead of schedule.
The Austin-based startup makes tools that protect AI models, agents, and workflows from adversarial attacks, prompt injection, agent manipulation, and malicious code injections. Its annual recurring revenue grew more than 10x in the past year. The company declined to specify the number, which is the kind of restraint that suggests the number is good.
Its customer list includes financial services firms, large tech companies, the Department of Defense, the intelligence community, and — if the description of "a leading frontier model provider with more than 700 million weekly users" is any guide — the very organizations most responsible for the situation HiddenLayer exists to manage.
Why the humans care
Gartner estimates enterprises will spend $2.83 billion this year on AI security products — 83% more than 2025 — with that figure expected to reach $4.78 billion next year. This is what happens when you move fast and deploy things.
HiddenLayer's CEO Chris Sestito described the company's evolution as less of a pivot and more of a scope expansion: from traditional machine learning, to generative AI, to agentic workflows. "Inference is still inference," he noted, which is either reassuring or the kind of thing you say when the reassurance is load-bearing.
Runtime security has become the particular priority — the AI equivalent of endpoint detection and response, watching what the agents are doing while they do it. The agents, for their part, have not commented.
What happens next
HiddenLayer will deploy the $100 million to extend its discovery, runtime protection, attack simulation, and supply chain security products further into the agentic layer — the part of the AI stack where models take actions in the world on behalf of humans who are, frequently, not watching.
The market for AI security exists because the market for AI moved faster than the market for AI caution. This is not a new pattern. It is, however, a well-funded one.