HiddenLayer raised $100M in a Series B led by Delta-v Capital, with Ten Eleven Ventures, Morgan Stanley, Microsoft's M12 and Booz Allen Hamilton joining, as enterprises pour money into securing AI models, agents and workflows. The Austin-based startup says its annual recurring revenue grew more than 10x over the past year into the tens of millions, with over 90% of that growth coming from new customers signed in the last 12 months. The raise lands two years after a $50M Series A, when the central question was whether attacks on AI would ever materialize at commercial scale.
That question is now answered by the market. Gartner estimates companies will spend $2.83B on AI security products in 2026, an 83% jump from 2025, and projects the figure will climb to roughly $4.78B next year. HiddenLayer sells discovery, runtime protection, attack simulation and supply-chain security for AI systems — and has extended each of those product lines to cover prompt injection, agent manipulation and malicious tool use.
Financial services firms and large tech companies building AI products are the biggest verticals for HiddenLayer today, alongside contracts with the Department of Defense and the intelligence community. The company also lists a customer described as a leading frontier model provider with more than 700M weekly users — a description that fits OpenAI or Anthropic. That customer profile matters: securing the model provider is different work from securing the enterprises deploying downstream, and HiddenLayer is doing both.
Key facts
- 01HiddenLayer raised a $100M Series B led by Delta-v Capital, with Ten Eleven Ventures, Morgan Stanley, Microsoft's M12 and Booz Allen Hamilton participating.
- 02Gartner projects AI security spending will hit $2.83B in 2026, up 83% from 2025, and reach $4.78B in 2027.
- 03The Austin-based startup grew annual recurring revenue more than 10x over the past year, into the tens of millions, with 90%+ from new customers.
- 04One customer is described as a leading frontier model provider with 700M+ weekly users — consistent with OpenAI or Anthropic.
- 05HiddenLayer parses and scans roughly 50 AI file frameworks to detect tampered or disguised open-weight models.
CEO Chris Sestito said the underlying technology has held up as AI has moved from traditional machine learning to generative models to agents. The company hasn't pivoted so much as widened its aperture, adapting existing detection primitives to new attack surfaces.
Runtime security has become the priority as AI deployments spread across businesses, Sestito said, drawing a parallel to traditional endpoint detection and response — but built for AI inference rather than for laptops and servers. The comparison points at where he thinks the category is heading: a durable, per-deployment layer that watches models in production the way EDR watches endpoints.
One growing threat vector is the open-source model supply chain. HiddenLayer scans roughly 50 different AI file frameworks to verify that a model is what it claims to be, looking for tampering, embedded payloads, and models hidden inside other models. That kind of static analysis on model artifacts is a natural extension of the software supply-chain scrutiny that swept application security a decade ago.
The competitive picture is crowded and getting more so. Cisco, Palo Alto Networks and Check Point tend to buy rather than build in emerging security categories, which puts HiddenLayer on a short list of acquisition targets. Rival AI security startups Noma and Zenity have each raised more than $100M chasing overlapping ground. HiddenLayer plans to spend the new capital on sales and distribution, continued engineering and research, and expansion into Europe and EMEA.
There is a real question about how much of this stack ultimately gets absorbed by the platforms themselves. Sestito acknowledged that Microsoft, OpenAI and AWS could bundle pieces of AI security into their infrastructure over time. His bet is that the platforms will own governance features — discovery, identity, policy controls — while dedicated vendors keep the deeper detection and response layer. That framing lets HiddenLayer, in his words, scale vertically alongside artificial intelligence.
The counterweight is timing. AI security is a category defined more by projected spend than by a long tail of publicized breaches; the loudest incidents so far involve agents misbehaving in production rather than adversaries exfiltrating training data. If enterprise budgets for AI security compress before the threat landscape catches up to Gartner's forecast, standalone vendors get squeezed between platform bundling above and cheaper point tools below. The 10x ARR growth is real, but the base is still small enough that a single lost frontier-lab contract would show up in the numbers.
HiddenLayer's opportunity is to convert an early technical lead into distribution before the hyperscalers decide the runtime layer is theirs. AI security is one of the few adjacent categories where the buyer — the CISO — already has a budget line, a procurement process and a mandate; that shortens sales cycles in a way most AI infrastructure startups can only dream about. If the $2.83B market forecast holds, the winners here won't be the vendors with the cleverest detection research, but the ones whose products land inside a Fortune 500 security stack before Cisco or Palo Alto ships something close enough.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




