i
DATAIST
News · 2026-09-02

HiddenLayer raises $100M as AI security becomes a budget line

@neuronium_ai @neuronium_ai

HiddenLayer has raised $100 million in a Series B led by Delta-v Capital, twice the size of the $50 million Series A it closed three years ago. The Austin company sells tools that protect models, AI agents and AI workflows against attacks, vulnerabilities and injected malicious code. Chris Sestito says annual recurring revenue grew more than tenfold over the past year and now runs into "tens of millions" of dollars, with more than 90% of that growth coming from customers who signed in the past year.

Cover: HiddenLayer raises $100M as AI security becomes a budget line

HiddenLayer has raised $100 million in a Series B led by Delta-v Capital, twice the size of the $50 million Series A it closed three years ago. The Austin company sells tools that protect models, AI agents and AI workflows against attacks, vulnerabilities and injected malicious code. Chris Sestito says annual recurring revenue grew more than tenfold over the past year and now runs into "tens of millions" of dollars, with more than 90% of that growth coming from customers who signed in the past year.

The gap between the two rounds is the story. When HiddenLayer raised its Series A, the industry was still arguing about whether a market for AI security would exist at all, and real examples of large-scale attacks on AI systems were hard to find. Gartner now puts corporate spending on products that secure AI tools at $2.83 billion this year, 83% above last year, and expects it to reach nearly $4.78 billion next year. A category that had to justify its own existence three years ago has a forecast line.

What has actually changed on the attack side is less dramatic than the spending curve. Security vendors now build controls not only for AI agents but for the tools and extensions those agents call. Headlines about successfully exploited agents are still scarce. What persists is the risk that an agent behaves unpredictably inside a production environment — a risk buyers are paying to contain before it shows up in an incident report.

HiddenLayer's largest segments are financial institutions and large technology companies building AI products. It also holds contracts with the US Department of Defense and the intelligence community. One customer, the company says, is a "leading frontier model developer" with "more than 700 million weekly users." HiddenLayer did not name it; the obvious guesses are OpenAI and Anthropic, and that is a guess, not a disclosure.

The round drew Ten Eleven Ventures, Morgan Stanley, M12 — Microsoft's fund — Booz Allen Hamilton and other investors alongside Delta-v. Booz Allen on the cap table fits a company whose customer list runs through defense and intelligence. M12 is more interesting, for reasons that come up below.

The product line is broadly what it was at the Series A, extended to cover new attack scenarios: discovery of AI components, runtime protection, attack simulation, supply chain security, defense against prompt injection, countermeasures against manipulation of AI agents, and controls on malicious tool use. Sestito argues the underlying technology still applies across traditional machine learning models, generative AI and agentic workflows, so the company had to widen its scope rather than change direction.

Runtime protection is the piece Sestito says demand concentrated on. He compares it to EDR — endpoint detection and response — adapted for AI systems. The framing is deliberate: EDR is a category enterprises already budget for and already understand, which makes it the easiest analogy to sell against.

The sharpest concrete threat in the company's account is open models. HiddenLayer parses and scans roughly 50 different AI file formats to check whether a tool is what it claims to be, looking for models that advertise one function while doing something else, including hidden models embedded inside other models. That is a supply-chain problem with a physical artifact attached — a file that can be opened and inspected — which is why it is the part of the pitch that does not need a forecast to sound urgent.

The $100 million goes primarily to sales and distribution, with continued hiring in engineering and research, plus expansion into Europe, the Middle East and Africa.

Here is what I take from the numbers. Tenfold growth is reported against a base the company will not disclose, and "tens of millions" of ARR is a small business raising a round five to ten times its revenue. That is priced on the Gartner curve, not on the current book. The more interesting question is whether AI security is a product category or a platform feature. Sestito concedes that individual HiddenLayer capabilities may end up inside Microsoft, OpenAI and AWS, and argues those platforms will drift toward governance — component discovery, identity, access policy — rather than toward what HiddenLayer builds. That is a reasonable bet, and Microsoft's own fund just bought a position in it, which cuts both ways: validation, or a cheap option on a capability Microsoft may prefer to own.

The exit logic is already visible in the market around it. Cisco, Palo Alto Networks and Check Point tend to buy this kind of technology rather than build it, and Noma and Zenity have each raised more than $100 million in adjacent or overlapping segments. Notably absent from the announcement is any customer count, revenue figure or retention number — the things that would distinguish a durable business from an early lead. HiddenLayer's plan is to expand vertically with AI and then horizontally into the parts of cybersecurity that increasingly depend on it. That plan has a clock on it: the incumbents acquire when a category is proven, and proving the category is exactly what makes it acquirable.