HiddenLayer has raised $100 million in a Series B round as enterprises scramble to secure their AI deployments. The funding was led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, Microsoft’s M12, and Booz Allen Hamilton.
When HiddenLayer raised its $50 million Series A three years ago, the market questioned whether AI threats would materialise in sufficient numbers to create a real business. Kyle Wiggers, a former colleague, noted at the time that identifying actual attacks at scale was difficult. The situation has shifted quickly.
Security firms are now building products to monitor agents alongside the tools and add-ons they use. While headlines about exploited agents remain scarce, the risk of agents malfunctioning during production is genuine. Gartner estimates companies will spend $2.83 billion this year on products to secure AI tools, an 83% increase from 2025. Spending is expected to reach nearly $4.78 billion next year.
The growth
HiddenLayer protects AI models, agents and workflows from adversarial attacks, vulnerabilities and malicious code injections. Chris Sestito, the co-founder and CEO, told TechCrunch that annual recurring revenue grew more than 10x over the past year. He declined to give an exact figure but stated ARR is now in the “tens of millions” of dollars. Over 90% of that growth came from new customers signing in the last year.
Financial services and large tech companies building AI products are the largest verticals. The company also holds contracts with the Department of Defense and the intelligence community. One customer is a “leading frontier model provider” with “more than 700 million weekly users,” a description that fits OpenAI or Anthropic.
The startup sells broadly the same products it did in 2023. Sestito said the main change involved extending existing tools for discovery, runtime protection, attack simulation and supply chain security to address prompt injection, agent manipulation and malicious tool use.
“Inference is still inference,” Sestito said. “So whether it’s on a traditional machine learning model, whether it’s Gen AI, whether it’s an agentic work stream, a lot of our technology still applied. So really, we haven’t had to pivot, but we’ve had to grow our scope … from traditional modeling to Gen AI to agentic.”
Runtime security has become a priority as AI deployments spread across businesses. Sestito compared it to traditional endpoint detection and response (EDR) solutions, but specifically for AI.
The company’s new products reflect this shift. Sestito highlighted a new vulnerability where attackers exploit open-source models. HiddenLayer parses and scans about 50 different AI file frameworks to ensure that, particularly with open-source, open-weight models, the tool being used is the one believed to be it. They look for models purporting to be one thing but being another, including hidden models inside of models.
The $100 million will help build in that direction, with a focus on sales and distribution while expanding engineering and research. The company plans to expand into Europe and EMEA.
HiddenLayer may need to tap that war chest again. Large cybersecurity firms like Cisco, Palo Alto Networks and Check Point often prefer to buy rather than build this technology. Startups like Noma and Zenity have raised over $100 million each to cover adjacent or overlapping areas.
Sestito acknowledged that some parts of HiddenLayer’s AI security products could eventually be bundled into platforms built by Microsoft, OpenAI and AWS. He expects AI infrastructure will grow towards governance features such as discovery, identity and policy controls, rather than the tools his company builds.
For now, the goal is to “scale vertically alongside artificial intelligence,” and eventually expand horizontally into parts of cybersecurity that increasingly depend on AI. That is an ambitious goal, but the startup must first prove it can turn its head start into an enduring business before the rest of the industry catches up.




