
Share
Three years after struggling to prove AI attacks were a real threat, HiddenLayer has 10x'd its ARR and landed a $100 million round, riding a market Gartner expects to nearly double by 2027.
The pitch has flipped. Three years ago, HiddenLayer's founders had to convince investors that attacks on AI systems would ever materialize at scale. Today, the company is closing a $100 million Series B on the strength of annual recurring revenue that grew more than 10x in the past year, now sitting in the "tens of millions" of dollars, according to co-founder and CEO Chris Sestito.
The round was led by Delta-v Capital, with Ten Eleven Ventures, Morgan Stanley, Microsoft's M12, and Booz Allen Hamilton also participating. It follows HiddenLayer's $50 million Series A in 2023, a raise that came with real skepticism about whether AI-specific threats justified a standalone security category. That skepticism has largely evaporated.
Gartner now estimates enterprises will spend $2.83 billion this year securing AI tools and deployments, an 83% jump from 2025, with spending projected to reach $4.78 billion in 2027. That trajectory maps closely onto HiddenLayer's own growth. Sestito says over 90% of the company's revenue expansion in the past year came from new customer logos rather than upsells, a signal that the buying pool for AI security is widening, not just deepening among existing accounts.
The shift is less about headline-grabbing breaches and more about operational risk creeping into production environments. There still aren't many public examples of AI agents being exploited by outside attackers. What's changed is the recognition that agents can go haywire on their own, misfiring in ways that expose companies to reputational, financial, or compliance damage. Microsoft flagged this dynamic directly in a May blog post on remote code execution vulnerabilities in AI agent frameworks, and it's a theme showing up across the security industry.
HiddenLayer's customer base reflects where the pressure is concentrated. Financial services and large tech companies building AI products make up its biggest verticals, and the company also holds contracts with the Department of Defense and intelligence community. One customer, described only as a "leading frontier model provider" serving more than 700 million weekly users, strongly resembles OpenAI or Anthropic, though Sestito declined to name names.
What's notable is how little HiddenLayer has had to reinvent its core technology to meet this demand. Sestito frames the company's evolution as an extension rather than a pivot: the same discovery, runtime protection, attack simulation, and supply chain security tools built for traditional machine learning now cover prompt injection, agent manipulation, and malicious tool use. "Inference is still inference," he said, whether it's a traditional ML model, generative AI, or an agentic workflow. The company likens its runtime security offering to endpoint detection and response, the EDR category that became a cybersecurity staple, but built specifically for AI systems.
One emerging attack surface Sestito highlighted is open source and open-weight models. HiddenLayer now parses and scans roughly 50 different AI file frameworks to verify that a model is what it claims to be, screening for "hidden models inside of models" that misrepresent their own identity or purpose. That's a fairly specific and technical threat vector, but it points to a broader trend: as enterprises pull more open-weight models into production, the provenance and integrity of those artifacts becomes a security question in its own right.

The $100 million will go primarily toward sales and distribution, with continued investment in engineering and research, and an expansion into Europe and EMEA. That allocation is telling. HiddenLayer isn't describing a product gap it needs to close so much as a go-to-market race it needs to win before the category consolidates.
That race looks increasingly crowded. Large cybersecurity vendors have shown a clear preference for acquiring AI security capability rather than building it internally. Cisco bought Robust Intelligence, Palo Alto Networks acquired Protect AI, and Check Point picked up Lakera, all within the AI security space. Meanwhile, well-funded startups working adjacent or overlapping territory, including Noma and Zenity, have each raised more than $100 million to pursue their own slices of the market.
Sestito is candid that some of what HiddenLayer sells could eventually get absorbed into the platforms built by hyperscalers like Microsoft, OpenAI, and AWS. His bet is that those platforms will gravitate toward governance functions, discovery, identity, and policy controls, rather than the deeper protection tooling HiddenLayer specializes in. That's a reasonable distinction, but it's also the kind of line that platform vendors have blurred before in adjacent security categories.
His stated strategy is to "scale vertically alongside artificial intelligence" first, then expand horizontally into cybersecurity functions that increasingly depend on AI themselves. It's an ambitious two-stage plan, and the acquisitions across the sector suggest the window to build an independent, durable platform before consolidation accelerates further is narrowing.
The math here is straightforward on the surface: a market growing 83% year over year, a company growing revenue 10x, and a fresh $100 million to fund distribution. That combination explains the investor interest, particularly with strategic backers like Morgan Stanley and Microsoft's M12 in the mix, both of which bring customer and partnership pipelines that matter more than capital alone at this stage.
The risk sits on the exit side. With Cisco, Palo Alto Networks, and Check Point all having already made their AI security acquisitions, the largest natural acquirers may have already filled their rosters, leaving HiddenLayer to prove it can either go public independently or find a buyer in a thinner field. New customer acquisition driving 90% of growth is a strong signal of market pull, but it also means retention and expansion economics remain largely untested at scale. Investors should watch whether ARR growth holds pace as the easy new-logo wins get harder to find, and whether HiddenLayer's EMEA push produces revenue or just headcount. The category's growth is not in question. Which companies capture it durably still is.
Tags
Original Sources
HiddenLayer nabs $100M as enterprises rush to secure their AI deployments | TechCrunch
↗ https://techcrunch.com/2026/09/02/hiddenlayer-nabs-100m-as-enterprises-rush-to-secure-their-ai-deployments
About the author
Marcus began tracking AI's market implications in 2016, noticing AI-related patent filings accelerating ahead of earnings upgrades before most of the sell-side had caught on. A former fixed-income quantitative analyst, he spent two decades building models that priced risk across emerging markets before pivoting to cover the economic impact of AI full-time. His writing translates opaque technical developments into clear risk/reward terms — and he's rarely diplomatic about the gap between AI valuations and underlying fundamentals. He believes most market participants still underestimate AI's long-run deflationary effect on knowledge work.
More from The Analyst →This Week's Edition
8 September 2026
41 articles
Related Articles
Related Articles
More Stories
© 2026 Cedar & Bloom. All rights reserved.