HiddenLayer nabs $100M as enterprises rush to secure their AI deployments
AI security startup HiddenLayer has raised $100 million in a Series B funding round, reflecting surging enterprise demand for tools that protect AI models, agents and workflows from adversarial attacks and manipulation. The Austin-based company, whose core products cover discovery, runtime protection, attack simulation and supply chain security, has extended its offerings to tackle newer threats such as prompt injection, agent manipulation and malicious tool use as businesses increasingly deploy AI agents in production.
The round was led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, Microsoft's M12 and Booz Allen Hamilton, among others. CEO Chris Sestito said annual recurring revenue grew more than tenfold over the past year to "tens of millions" of dollars, driven largely by new customers, with financial services, large tech firms and US defence and intelligence agencies among its biggest clients. Gartner estimates spending on AI security tools will reach $2.83 billion this year, an 83% rise on 2025, climbing to nearly $4.78 billion in 2027; HiddenLayer says the new funding will be used mainly to expand sales and distribution while continuing engineering growth.
- HiddenLayer raises $100M Series B for AI security tools
- ARR grew over 10x in the past year
- Gartner predicts AI security spending will hit $2.83bn this year
New here? Start with this
HiddenLayer is a cybersecurity company that focuses specifically on protecting artificial intelligence systems, rather than traditional computer networks. As businesses increasingly build AI models and automated "agents" into their operations, they face new kinds of attacks, such as attempts to trick an AI into leaking data or behaving in unintended ways. HiddenLayer builds tools that spot these AI models, test them for weaknesses and guard them while they are running.
The company is based in Austin, Texas, and is led by chief executive Chris Sestito. Its customers include banks, large technology firms and US government defence and intelligence agencies, sectors where the reliability and safety of AI systems is considered especially important.
The wider context is a fast-growing market for AI security: as more companies deploy AI tools in everyday business processes, analysts expect spending on protecting those systems to rise sharply in the coming years. Investment in firms like HiddenLayer reflects how seriously both businesses and investors are treating the risks that come with widespread AI adoption.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Advocates of this surge in AI security investment argue that as organisations rush to deploy AI agents with real access to systems, data and decisions, the attack surface has grown faster than defensive tooling, making dedicated protection against prompt injection, model manipulation and supply chain compromise a genuine operational necessity rather than a fad. They point to the calibre of backers, including Microsoft's venture arm, Morgan Stanley and a defence contractor, as evidence that sophisticated, risk-aware institutions see these threats as material and are willing to pay accordingly. On this view, funding a company that has already proven tenfold revenue growth with blue-chip and government clients is simply capital following demonstrated, unmet demand for safeguarding critical infrastructure as AI becomes deeply embedded in finance, defence and enterprise workflows.
The case against
Sceptics would counter that eye-catching funding rounds and vendor-sourced market forecasts, such as Gartner's projections cited here, should be treated cautiously, since they are often produced or amplified by parties with a direct commercial interest in inflating perceived threat levels and market size. They might argue that some AI security spending risks becoming a form of security theatre, sold to boards anxious about a fast-moving technology they do not fully understand, without robust independent evidence that these tools meaningfully reduce real-world incidents. From this perspective, the more prudent path is for enterprises to invest in fundamentals, such as careful system design, access controls and human oversight of AI agents, rather than assuming a specialised product category can be relied upon to solve novel and still poorly understood risks.