When AI security startup HiddenLayer raised $50 million in Series A three years ago, one of the big questions in the space was whether the AI threats the startup was defending against would emerge in enough volume to form a real market. As my former colleague Kyle Wiggers pointed out at the time, examples of large-scale attacks against AI have been difficult to identify.
How quickly things changed! Security companies are now scrambling to develop products that can monitor not only agents but also the tools and add-ons they use. While there aren’t as many headlines about agents being exploited yet, the risk of agent disruption during operations is still real. And the market for tools to prevent this has exploded. Gartner estimates that businesses will spend $2.83 billion this year on products to secure AI tools, an 83% increase over 2025, and expects spending to reach nearly $4.78 billion next year.
HiddenLayer, which creates tools that protect AI models, agents, and workflows from adversarial attacks, vulnerabilities, and malicious code injection, has been able to capitalize on that shift. Co-founder and CEO Chris Sestito told TechCrunch that the company’s annual recurring revenue has grown more than 10x over the past year. He declined to give exact numbers, but said ARR is now in the “tens of millions” of dollars, with more than 90% of its growth coming from new customers signed up in the past year.
Financial services companies and big tech companies that develop AI products are now the company’s largest verticals, and it also has contracts with the Department of Defense and the intelligence community. One of its customers appears to be a “major frontier model provider” with “over 700 million weekly users,” which sounds like OpenAI or Anthropic to me.
To make the most of its momentum, the startup has now raised $100 million in a Series B funding round led by Delta-v Capital with participation from Ten eleven Ventures, Morgan Stanley, Microsoft’s M12, Booz Allen Hamilton, and others.
While the Austin-based startup is still largely selling business as usual in 2023, Sestito told TechCrunch that the biggest changes the company had to make were extending its existing products (detection, runtime protection, attack simulation, and supply chain security) to address rapid injections, agent manipulation, and the use of malicious tools.
“Inference is still inference. So a lot of our technology is still being applied, whether it’s traditional machine learning models, whether it’s GenAI, whether it’s the agent workstream. So we haven’t really had to pivot, but we’ve had to expand the scope… from traditional modeling to GenAI to agents,” he said.
Sestito emphasized that runtime security has become a particular priority as AI adoption becomes commonplace across the enterprise, likening it to traditional endpoint detection and response (EDR) solutions that are specifically focused on AI.
The company’s new products reflect that change, and Sestito highlighted new opportunities for attackers to exploit the open source model. “We parse and scan about 50 different AI file frameworks to make sure that the tools you’re using are what you believe they are and are what they are, especially in the case of open-source open weight models. We’re looking at things like models that purport to be one thing, but they’re something else. It’s a model hidden within a model,” he said.
The company says the new $100 million will help it expand in that direction, with a greater focus on sales and distribution while continuing to expand engineering and research. The company also plans to expand into Europe and EMEA.
However, HiddenLayer may end up tapping into its war chest even further. Large cybersecurity companies such as Cisco, Palo Alto Networks, and Check Point often prefer to acquire rather than build this type of technology, while startups such as Noma and Zenity have each raised more than $100 million to take on adjacent or overlapping areas of the field.
Sestito acknowledged that some of his company’s AI security products could eventually be bundled into platforms built by companies like Microsoft, OpenAI, and AWS. However, he expects AI infrastructure to grow toward governance capabilities such as discovery, identity, and policy controls, rather than the kinds of tools that companies build.
For now, he said HiddenLayer’s job is to “scale vertically in parallel with artificial intelligence” and eventually horizontally into parts of cybersecurity that increasingly rely on AI. It’s an ambitious goal, but startups first need to prove they can turn that head start into a lasting business before others in the industry catch up.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.
