AI security firm HiddenLayer has closed a EUR 86 million Series B funding round, capitalizing on a fast-growing market as companies race to protect their AI systems. The Austin-based startup builds tools that shield AI models, agents, and workflows from adversarial attacks, vulnerabilities, and malicious code injections.
The timing marks a sharp reversal from three years ago, when HiddenLayer raised its EUR 43 million Series A. Back then, the central question was whether AI threats would ever materialize at a scale large enough to sustain a real market, since concrete examples of attacks against AI were hard to find.
That uncertainty has faded. Security vendors are now building products to monitor not only AI agents but also the tools and add-ons those agents rely on. Although exploited agents rarely make headlines, the risk of agents malfunctioning in production is real, and demand for tools to prevent it has surged. According to Gartner, companies will spend EUR 2 billion this year on products designed to secure AI tools, an 83% increase over 2025, with spending projected to reach nearly EUR 4 billion next year.
Rapid Revenue Growth and Major Customers
Co-founder and CEO Chris Sestito said HiddenLayer’s annual recurring revenue grew more than tenfold over the past year. He declined to share an exact figure but placed ARR in the “tens of millions” of dollars, adding that more than 90% of that growth came from new customers signing on in the past year.
Financial services and large tech companies building AI products are the company’s biggest verticals. HiddenLayer also holds contracts with the Department of Defense and the intelligence community. One customer is described as a “leading frontier model provider” with “more than 700 million weekly users.”
The new Series B round was led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, Microsoft’s M12, Booz Allen Hamilton, and others.
Expanding Scope to Agents and Open-Source Models
HiddenLayer still sells much of what it offered in 2023, but Sestito said the biggest shift has been extending its core products, which include discovery, runtime protection, attack simulation, and supply chain security, to address prompt injection, agent manipulation, and malicious tool use.
“Inference is still inference,” Sestito said, explaining that much of the company’s technology carries over across traditional machine learning models, generative AI, and agentic workflows. Rather than pivoting, he said, the firm has broadened its scope from traditional modeling to Gen AI to agentic systems.
Sestito emphasized that runtime security has become a top priority as AI deployments spread across businesses, comparing it to traditional endpoint detection and response (EDR) solutions built specifically for AI. He also flagged open-source models as a new target for attackers. The company parses and scans roughly 50 different AI file frameworks to verify that a tool, especially an open-source or open-weight model, is genuinely what it claims to be.
Source
Image: techcrunch.com