HiddenLayer, an Austin-based startup that builds tools to protect AI models, agents and workflows from adversarial attacks, vulnerabilities and malicious code injection, has closed a $100 million Series B round led by Delta-v Capital. Other participants include Ten Eleven Ventures, Morgan Stanley, Microsoft’s M12, Booz Allen Hamilton and additional investors.
The company says annual recurring revenue (ARR) grew more than tenfold over the past year and is now in the “tens of millions” of dollars, according to co-founder and CEO Chris Sestito. He declined to disclose an exact figure, but said over 90% of that growth came from new customers signed in the last 12 months.
Why demand is rising
As AI deployments proliferate, security vendors are expanding their focus beyond models to include agents, tools and add-ons that AI systems use. Although large-scale, headline-grabbing exploits of agents remain uncommon, the risk of agents behaving unexpectedly or tools being misused in production environments is real. Gartner estimates companies will spend $2.83 billion this year on products designed to secure AI tools—83% more than in 2025—and expects spending to approach $4.78 billion next year.
Product evolution rather than pivot
HiddenLayer’s core product areas remain discovery, runtime protection, attack simulation and supply chain security. Sestito told TechCrunch the company has extended these capabilities to cover newer threats such as prompt injection, agent manipulation and malicious tool use. "Inference is still inference," he said, meaning much of the firm’s technology applies across traditional ML models, generative AI and agentic workflows; the company enlarged its scope rather than changing direction.
Sestito emphasized that runtime security has become especially important as organizations deploy AI in production, likening the need to traditional endpoint detection and response (EDR) but tailored for AI systems.
Open-source models and hidden-risk vectors
The startup has also built detection capabilities aimed at open-source models: it parses and scans roughly 50 different AI file frameworks to verify that open-weight models and related assets are what they claim to be, and to detect issues like models hiding other models inside them. This addresses a growing attacker surface linked to open-source components.
Customers, market position and spending plans
HiddenLayer’s largest customer verticals are financial services and large technology companies building AI products. The company also holds contracts with the Department of Defense and the intelligence community. Sestito mentioned a customer described as a "leading frontier model provider" with "more than 700 million weekly users," suggesting relationships with major public providers.
The $100 million will be used primarily to scale sales and distribution, while continuing to invest in engineering and research. HiddenLayer also plans expansion into Europe and the broader EMEA region.
Competitive landscape and outlook
Large cybersecurity vendors such as Cisco, Palo Alto Networks and Check Point often prefer to acquire capabilities like these rather than build them internally. At the same time, startups including Noma and Zenity have raised more than $100 million each to pursue overlapping or adjacent parts of the AI-security market.
Sestito acknowledged that some AI-security features might eventually be absorbed into platforms from companies like Microsoft, OpenAI and AWS, but he expects AI infrastructure to evolve toward governance capabilities—discovery, identity and policy controls—rather than the specific protections HiddenLayer provides.
For now, HiddenLayer’s stated objective is to scale vertically alongside artificial intelligence deployments and later expand horizontally into cybersecurity areas increasingly dependent on AI. The challenge for the company will be turning its current lead and momentum into a durable business before competitors catch up.



