HiddenLayer Raises $100M Series B as Enterprises Rush to Secure Agentic AI
Posted on 4th Sep 2026 06:05:40 in Artificial Intelligence, Machine Learning
Tagged as: AI Security, HiddenLayer, Series B, Agentic AI, Cybersecurity, AI agents
Three years ago, when HiddenLayer raised its $50 million Series A, the honest question hanging over the young company was whether AI attacks would ever occur at a scale big enough to justify a dedicated security market. On September 2, 2026, the Austin-based startup answered that question with a $100 million Series B round led by Delta-v Capital, joined by Ten Eleven Ventures, Morgan Stanley, Microsoft's venture fund M12 and Booz Allen Ventures. The round follows a year in which HiddenLayer's annual recurring revenue grew more than tenfold, and it lands squarely on the industry's newest front line: protecting not just AI models, but the autonomous agents now writing code and making decisions inside enterprises.
The money is a milestone, but the round's real significance is what it signals about the AI security market itself. When HiddenLayer raised its Series A in 2023, security researchers struggled to point to many real-world attacks against AI systems at scale. That has changed. Enterprise deployments of generative AI and agentic workflows have multiplied, and with them has come a new class of threats: prompt injection, agent manipulation, malicious tool use and compromised open-source models. The market is moving fast enough that Gartner now forecasts organisations will spend $2.83 billion on AI security products in 2026, an 83 percent jump over 2025, growing to nearly $4.78 billion in 2027. HiddenLayer's Series B is, in effect, a bet that this is still the early innings.
From Model Defense to Agentic Runtime Security
HiddenLayer's product portfolio has grown without a fundamental pivot. The company still sells the four pillars it built in its earliest days: discovery, runtime protection, attack simulation and supply chain security. What has changed is the threat surface those pillars must cover. CEO and co-founder Chris Sestito described the evolution bluntly: inference is still inference, whether it runs on a traditional machine learning model, a generative model or an agentic workflow. The company extended the same detection technology outward to cover prompt injection, agent manipulation and malicious tool use as enterprises moved from deploying models to deploying agents.
That extension now has a name. HiddenLayer recently unveiled Agent Harness Security, a new module that extends its runtime protection to AI coding agents, the systems that write, review and ship code with far less human oversight than traditional development tools. Sestito likened the company's runtime security to endpoint detection and response (EDR), the category that transformed traditional cybersecurity two decades ago, except that HiddenLayer's EDR watches AI agents in production, flagging and stopping manipulation, tool misuse and unauthorized actions as they happen.
The supply chain angle may be the most quietly alarming part of HiddenLayer's work. The company scans roughly 50 different AI file frameworks to verify that open-source and open-weight models are what they claim to be. Sestito calls the threat "hidden models inside of models": artifacts that purport to be one thing and turn out to be another. The research depth behind these products is substantial. HiddenLayer's team holds 39 granted patents and 65 pending patents across adversarial detection, model protection and AI threat analysis, and it developed the first comprehensive Adversarial Prompt Engineering (APE) Taxonomy. Its researchers also contribute to the broader security ecosystem through CISA/JCDC, MITRE, NIST, OWASP and OpenSSF.
Who Is Buying: Tenfold Growth and a 700-Million-User Customer
The commercial traction is the strongest evidence that AI security has arrived as a budget line item. HiddenLayer's annual recurring revenue grew more than 10x over the past year into the tens of millions of dollars, with more than 90 percent of that growth coming from new customers signed in the last twelve months. The company added more than 50 new platform customers across securities brokerage, banking, insurance, accounting, government, technology, IT services, pharmaceuticals and airlines. Internationally, new customers include one of the world's largest pharmaceutical companies, premium automotive brands and food and beverage providers.
The customer list also reaches into the most sensitive corners of the ecosystem. HiddenLayer holds contracts with the U.S. Department of Defense and intelligence community, and it supports a leading frontier model provider in securing a platform with more than 700 million weekly users. The public-sector validation extends further: the company was selected to support the Department of Energy's $60 million Prometheus Initiative, and it has won work on the Missile Defense Agency's SHIELD programme. That combination, commercial ARR plus federal contracts, is rare for a Series B company and gives HiddenLayer two distinct buyer pools validating the same platform.
What the $100 Million Will Fund
Sestito was clear that this round is not primarily about inventing new technology. The company plans to put the capital toward sales and distribution, deepening its channel relationships and expanding engineering and research. International expansion begins with Europe and the wider EMEA region, and the leadership team is already being built out: HiddenLayer recently named Mike Gesnaldo as Chief Revenue Officer, with more hires planned to keep pace with enterprise demand.
The competitive landscape explains why speed matters. Large security vendors have decided that buying is faster than building: Cisco announced an intent to acquire Robust Intelligence, Palo Alto Networks agreed to acquire Protect AI, and Check Point bought Lakera. Well-funded startups such as Noma and Zenity have raised $100 million or more to attack adjacent parts of the AI security market. HiddenLayer's investors framed the round in exactly these terms. Delta-v Capital partner Dan Williams said traditional security tools were built for code and infrastructure, not for models that can be poisoned, hijacked or manipulated through their own inputs. Ten Eleven Ventures co-founder Mark Hatfield put it more plainly: enterprises do not shift budgets at this pace unless a problem is urgent, and AI needs its own category of protection.
What This Means for Enterprises
For the enterprises adopting AI, HiddenLayer's own threat research provides the sobering context. In its 2026 AI Threat Landscape Report, the company found that 96 percent of organisations already consider AI critical to their core operations, yet nearly a third cannot say with certainty whether they have experienced an AI-related breach. That gap between dependence and visibility is precisely what the new generation of AI security platforms is designed to close, and it explains the "tens of millions" in ARR the category's leaders are now recording.
The philosophical shift behind the funding is worth noting. HiddenLayer's core claim, echoed by its investors, is that AI cannot be made trustworthy through design-time principles alone. Trust has to be continuously tested and proven at runtime, which means security must watch models, agents and the tools they use while they operate, not just audit them before deployment. As agentic AI moves from pilots into production workflows, that argument is becoming easier to sell to CISOs every quarter. The $100 million question, as the rest of the industry catches up, is whether HiddenLayer can convert its head start into an enduring business, and the answer will play out over the next two years in the fastest-growing corner of the security market.
Sources
- TechCrunch — HiddenLayer nabs $100M as enterprises rush to secure their AI deployments
- PR Newswire — HiddenLayer Raises $100M Series B to Advance Trustworthy AI
- AI Weekly — HiddenLayer Raises $100M Series B as AI-Security ARR Jumps 10x
- Gartner — Forecast: Market for Securing AI to Reach Almost $5 Billion in 2027
- Microsoft Security Blog — Prompts Become Shells: RCE Vulnerabilities in AI Agent Frameworks