Three years ago, when AI security firm HiddenLayer closed a $50 million Series A round, a legitimate question hung over the entire category: would AI-specific threats ever materialize at a scale large enough to support a real commercial market? At the time, concrete examples of attacks targeting AI systems in the wild were genuinely hard to come by, and the threat landscape felt more theoretical than urgent.
That uncertainty has since evaporated. Security vendors across the industry are now racing to build products capable of monitoring not just AI agents themselves, but the broader ecosystems around them - including the third-party tools, plugins, and integrations those agents rely on. Documented incidents of agents being exploited in production remain relatively rare in the headlines, but the operational risk of AI agents behaving unpredictably or being manipulated during deployment is now widely acknowledged as a genuine concern for enterprises. The commercial response has been swift: research firm Gartner projects that organizations will collectively spend $2.83 billion this year on AI security products alone, a figure representing 83% growth compared to 2025 levels. By next year, that number is expected to climb to nearly $4.78 billion.
From Niche Startup to Growth-Stage Company
HiddenLayer, which develops tools designed to protect AI models, agents, and automated workflows from adversarial attacks, software vulnerabilities, and malicious code injections, has been well-positioned to benefit from this accelerating demand. Co-founder and CEO Chris Sestito says the company's annual recurring revenue grew more than tenfold over the past twelve months. While he declined to share a precise figure, he confirmed ARR now sits in the "tens of millions" of dollars, with more than 90% of that growth attributable to customers who signed on within the past year.
The company's largest customer segments currently include financial services institutions and major technology firms actively building AI-powered products. HiddenLayer also holds contracts with the U.S. Department of Defense and elements of the intelligence community. Among its disclosed customer base is what the company describes as a "leading frontier model provider" with more than 700 million weekly users - a description that points toward organizations like OpenAI or Anthropic, though neither has been officially named.
A $100 Million Series B to Fuel Expansion
To capitalize on its current trajectory, HiddenLayer has now secured $100 million in a Series B funding round. The round was led by Delta-v Capital, with additional participation from Ten Eleven Ventures, Morgan Stanley, Microsoft's venture fund M12, Booz Allen Hamilton, and several other investors. The Austin, Texas-based startup plans to direct the capital primarily toward scaling its sales and distribution operations, while continuing to invest in engineering and research. International expansion into Europe and the broader EMEA region is also on the roadmap.
At its core, HiddenLayer is still selling a version of what it offered back in 2023 - a suite that spans model discovery, runtime protection, attack simulation, and supply chain security. However, Sestito explains that the company has had to meaningfully extend each of those product areas to address a new generation of threats, specifically prompt injection attacks, agent manipulation techniques, and the misuse of external tools connected to AI systems.
"Inference is still inference. So whether it's on a traditional machine learning model, whether it's GenAI, whether it's an agentic work stream, a lot of our technology still applied. So really, we haven't had to pivot, but we've had to grow our scope - from traditional modeling to GenAI to agentic."
Runtime Security and the Open Source Model Risk
Sestito has placed particular emphasis on runtime security as AI deployments become increasingly embedded in enterprise operations. He draws a direct analogy to traditional endpoint detection and response (EDR) solutions in conventional cybersecurity - tools that monitor systems in real time for signs of compromise or anomalous behavior - framing HiddenLayer's approach as the functional equivalent for AI infrastructure.
One emerging area the company has focused on involves the risks associated with open source AI models. Sestito described a threat vector that may not be immediately obvious to organizations adopting publicly available models: the possibility that a model is not what it claims to be. According to Sestito, HiddenLayer's platform parses and scans approximately 50 different AI file frameworks in order to verify the integrity and authenticity of models, particularly open-weight models sourced from public repositories.
"We're looking at things like models purporting to be one thing, but they're another - hidden models inside of models," he said, pointing to scenarios where a model file might contain embedded components designed to behave maliciously or covertly collect data without the knowledge of the organization deploying it.
A Competitive and Consolidating Market
Despite the strong growth figures, HiddenLayer is operating in a market that is attracting considerable attention from both established cybersecurity players and well-funded startups. Large vendors such as Cisco, Palo Alto Networks, and Check Point have historically preferred to acquire companies offering specialized capabilities rather than build them from scratch internally. Meanwhile, startups working in adjacent or overlapping areas of AI security - including Noma and Zenity - have each raised more than $100 million in funding, signaling that competition for this market is intensifying.
Sestito acknowledged that some of the capabilities HiddenLayer currently offers could, over time, be absorbed into the broader platforms built by companies like Microsoft, OpenAI, or Amazon Web Services. However, he expressed confidence that the direction of AI infrastructure development will trend toward governance-oriented features - things like discovery, identity management, and policy enforcement - rather than the more specialized, defense-focused tooling that HiddenLayer specializes in. In his view, that distinction provides the company with durable differentiation even as the larger platform players expand their security offerings.
The Road Ahead
Sestito described HiddenLayer's current strategic posture as a commitment to "scaling vertically alongside artificial intelligence," with an eventual ambition to expand horizontally into broader areas of cybersecurity that are becoming increasingly dependent on AI systems. It is an ambitious long-term vision, but one that first requires the company to demonstrate it can convert its current momentum and early-mover advantage into a durable, defensible business - before larger, better-resourced competitors close the gap.
With $100 million now in hand and annual recurring revenue growing at a rapid pace, HiddenLayer has the resources to press its advantage. Whether it can maintain that lead as the AI security market matures and consolidates will be one of the more consequential storylines to watch in enterprise technology over the next few years.



