DTWdailytechwire
Tech Intelligence, Wired Daily
Startups

AI Security Startup HiddenLayer Closes $100M Round as Model Attack Surface Explodes

Three years after its Series A, the Austin firm now defends frontier models serving 700 million users and watches a nascent threat category mature into a $2.8 billion market.

AS
Arjun S. Mehta
AI Correspondent · Bengaluru
Sep 3, 2026
4 min read
AI Security Startup HiddenLayer Closes $100M Round as Model Attack Surface Explodes
AI Security Startup HiddenLayer Closes $100M Round as Model Attack Surface ExplodesCredit: HiddenLayer

From Skepticism to Scale

When HiddenLayer raised its Series A in 2023, the fundamental question wasn't whether AI models could be attacked. It was whether anyone would bother trying at scale. The threat landscape was theoretical, the exploit examples sparse, and the market opportunity speculative at best.

That hesitation has evaporated. The Austin-based security firm has now closed a $100 million Series B led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, Microsoft's M12, and Booz Allen Hamilton. The round reflects a broader recognition that as AI moves from prototype to production, the surface area for adversarial manipulation has grown exponentially.

According to Gartner, enterprises will spend $2.83 billion this year on AI-specific security tooling, an 83% increase over 2025, with projections climbing to $4.78 billion next year. That trajectory suggests organizations are no longer asking whether their models need protection; they're racing to deploy it before something breaks in public.

HiddenLayer's co-founder and CEO Chris Sestito says the company's annual recurring revenue grew more than tenfold over the past year, reaching the tens of millions of dollars. Over 90% of that growth came from new customer acquisition, concentrated in financial services, large technology firms building AI products, and defense and intelligence agencies. One client is described as a frontier model provider serving more than 700 million weekly users, a profile that points to OpenAI or Anthropic.

Runtime Defense for Agentic Workflows

The core product suite hasn't fundamentally changed since 2023: discovery, runtime protection, attack simulation, and supply chain security. What has changed is the scope of what those tools must defend against. Early iterations focused on adversarial perturbations and model extraction. Today, the threat model includes prompt injection, agent manipulation, and malicious tool invocation.

Sestito frames the evolution as an extension rather than a pivot. Inference mechanics remain consistent whether the target is a traditional machine learning model, a generative system, or an agentic workflow. The company's runtime security offering, he argues, mirrors endpoint detection and response in traditional IT environments but tailored to AI's unique execution patterns.

As agents gain autonomy and integrate with external APIs, databases, and internal tools, the risk isn't just that a model produces incorrect output. It's that a compromised agent could execute unintended actions: exfiltrate data, manipulate financial transactions, or alter production systems. Runtime monitoring aims to catch those deviations before they cascade.

Open-Weight Models as a New Supply Chain Risk

One emerging vector that HiddenLayer has prioritized is the integrity of open-source and open-weight models. The company now parses and scans approximately 50 AI file frameworks to verify that a downloaded model matches its claimed identity and hasn't been tampered with.

Sestito highlights a specific threat: models that masquerade as one architecture or capability but contain hidden payloads or nested models designed to trigger malicious behavior under specific conditions. This is analogous to supply chain attacks in traditional software, where a compromised dependency introduces vulnerabilities downstream.

The parallel to software composition analysis is deliberate. As organizations increasingly pull pre-trained models from repositories like Hugging Face or private registries, verifying provenance and detecting modifications becomes critical. A poisoned model can be subtle, altering outputs in ways that only surface under narrow input conditions or after deployment at scale.

Competitive Pressure and Platform Consolidation

The $100 million infusion is earmarked for sales expansion, engineering talent, and a push into Europe and the broader EMEA region. But the round also positions HiddenLayer to fend off a crowded and well-capitalized field. Startups like Noma and Zenity have each raised over $100 million to tackle overlapping segments of AI security, while incumbents like Cisco, Palo Alto Networks, and Check Point have the distribution muscle and customer lock-in to bundle similar capabilities into existing platforms.

Sestito acknowledges that some of HiddenLayer's feature set could eventually be absorbed into the infrastructure layers built by Microsoft, OpenAI, AWS, and Google Cloud. His bet is that those platforms will prioritize governance features like discovery, identity management, and policy enforcement, leaving room for specialized vendors to own the deeper technical controls around model behavior and adversarial defense.

That distinction may prove fragile. Hyperscalers have a history of commoditizing adjacent tooling once adoption reaches critical mass. For HiddenLayer, the window to establish defensible differentiation and lock in enterprise customers is narrow.

Scaling Vertically, Expanding Horizontally

Sestito's articulated strategy is to "scale vertically alongside artificial intelligence" and later expand horizontally into adjacent cybersecurity domains increasingly dependent on AI. That means deepening capabilities around model and agent security while positioning to address AI-driven threats in traditional IT environments: phishing detection, anomaly identification, incident response automation.

The logic is sound. If AI becomes the substrate for enterprise software, then securing AI becomes synonymous with securing the enterprise. But execution requires navigating a rapidly consolidating market, fending off well-resourced competitors, and proving that specialized AI security tools deliver enough value to resist bundling into broader platforms.

For now, HiddenLayer's momentum is undeniable. Revenue growth at 10x, a customer base spanning defense contractors and frontier labs, and a fresh $100 million warchest provide runway and credibility. Whether that translates into an enduring independent business or a lucrative acquisition target will depend on how quickly the rest of the industry catches up and whether enterprises continue to buy best-of-breed security tools or consolidate around platform vendors.

The AI security market has moved from theoretical to tactical. HiddenLayer's challenge is to stay ahead of both the attackers and the acquirers.

Read next
Startups

AfterQuery Hits $3.2 Billion Valuation Five Months After Series A

Arjun S. Mehta · 5 min
Startups

Chinese AI Lab Manus Charts Independent Path After Beijing Blocks Meta Acquisition

Wei Zhang · 4 min
Startups

Nexperia's China Units Face Operational Split as Court Order Freezes $318M in Assets

Wei Zhang · 5 min
Spot something wrong? Email corrections@dailytechwire.com. We log every correction publicly.