HiddenLayer Raises $100M Series B for Enterprise AI Security
Most companies are bolting AI agents onto their business before they can explain what those agents are allowed to do. HiddenLayer just raised $100M because that recklessness is becoming a very expensive market.
Most companies are bolting AI agents onto their business before they can explain what those agents are allowed to do. HiddenLayer just raised US$100 million because that recklessness is becoming a very expensive market.
The $100M bet is not really about cybersecurity
Austin-based HiddenLayer announced its US$100 million Series B on September 2, 2026, led by Delta-v Capital. Ten Eleven Ventures, Morgan Stanley, Microsoft’s M12 and Booz Allen Ventures participated. The company sells protection for AI models, agents and workflows: the stuff businesses are hurriedly plugging into customer service, software development, internal operations and decision-making. ([hiddenlayer.com](https://www.hiddenlayer.com/news/hiddenlayer-100m-series-b-ai-security)) ([techcrunch.com](https://techcrunch.com/2026/09/02/hiddenlayer-nabs-100m-as-enterprises-rush-to-secure-their-ai-deployments/))
This is not a cute little seed round for a founder with a slick demo and a decent LinkedIn following. It is a nine-figure cheque into a company whose job is to stop AI systems being manipulated, poisoned, hijacked or tricked into doing things their owners never intended.
That tells you where the real money is moving.
For the past couple of years, executives have treated AI security as an irritating appendix to the exciting bit: build the chatbot, launch the coding agent, announce the productivity gain, collect the applause. Security got invited in later to write a policy document nobody read.
That approach is stuffed.
HiddenLayer says its annual recurring revenue grew more than tenfold in the past year, with more than 50 new platform customers. Chief executive and co-founder Chris Sestito told TechCrunch that annual recurring revenue is now in the tens of millions of dollars, with more than 90% of that growth coming from customers signed during the past year. Those are company-reported figures, obviously, but the direction matters more than the precise spreadsheet cell: buyers are no longer treating AI security as theoretical. ([hiddenlayer.com](https://www.hiddenlayer.com/news/hiddenlayer-100m-series-b-ai-security))
AI agents have created a new kind of operational stupidity
Traditional software mostly does what it is coded to do. AI agents are being asked to interpret language, access tools, use company data and take actions across systems. That is enormously useful — and a completely different risk profile.
A dodgy email used to trick an employee. Now a malicious instruction can potentially trick an AI system with access to files, code repositories, customer records or business software. The problem is not simply that AI can make mistakes. Every human-run business makes mistakes. The problem is that an autonomous system can make mistakes at machine speed, across a much larger surface area, while everyone assumes somebody else checked it.
HiddenLayer is pushing into what it calls Agentic Runtime Security and Agent Harness Security — products aimed at observing agent behaviour in production and protecting autonomous coding agents while they write, review and ship code. Its wider platform covers discovery, supply-chain security, attack simulation and runtime protection. ([hiddenlayer.com](https://www.hiddenlayer.com/news/hiddenlayer-100m-series-b-ai-security))
The phrase “agent harness” sounds like something invented by a consultant who charges by the syllable. Ignore the jargon. The commercial point is dead simple: if you let AI take actions, you need controls while it is taking them — not a security review from six months ago sitting in a shared drive.
Gartner estimates companies will spend US$2.83 billion on products to secure AI tools in 2026, up 83% from 2025, and forecasts nearly US$4.78 billion next year. Forecasts are not facts, and Gartner has never missed a chance to put a large number in a slide deck. But HiddenLayer’s round is a far more useful signal: serious investors with exposure to financial services, government work and enterprise software are putting actual money behind the category. ([techcrunch.com](https://techcrunch.com/2026/09/02/hiddenlayer-nabs-100m-as-enterprises-rush-to-secure-their-ai-deployments/))
Why the investor list matters more than the press release
The investor roster is the giveaway here.
Morgan Stanley is not investing because it wants to play startup bingo. M12 is Microsoft’s venture fund, which gives it a direct view into where enterprise AI workloads are heading. Booz Allen Ventures brings a line of sight into government, defence and regulated customers. Ten Eleven Ventures is a specialist cybersecurity investor. Delta-v Capital led the deal.
That combination does not prove HiddenLayer wins. It does prove that the buyers closest to high-consequence data and systems expect AI security to become a proper budget line.
HiddenLayer says it already serves customers across securities brokerage, banking, insurance, accounting, government, technology, pharmaceuticals, airlines and the US defence and intelligence communities. It also says it supports a frontier-model provider serving more than 700 million weekly users, though it has not named that customer. ([hiddenlayer.com](https://www.hiddenlayer.com/news/hiddenlayer-100m-series-b-ai-security))
Read that carefully. The big opportunity is not selling a bolt-on tool to a bloke running a two-person marketing agency. The big opportunity is becoming part of the permissioning, monitoring and governance layer inside organisations where one bad AI action can become a legal, financial or national-security headache.
That is why US$100 million can make sense. Enterprise security companies are not won through a viral launch. They are won through product depth, trust, integrations, sales coverage, compliance work and the patience to survive a buyer’s 12-month procurement circus.
The overlooked angle: security is becoming an AI distribution advantage
Here is the contrarian bit: security is not merely a defensive cost. For the best operators, it becomes a sales weapon.
Most founders still pitch AI with a version of “look how much faster this is”. Fine. Every competitor says that. The stronger pitch is: “Here is what the system can access, here is what it cannot do, here is how every action is logged, here is how we detect manipulation, and here is how you switch it off.”
That is not boring enterprise plumbing. That is how you get past the chief information security officer, legal team, procurement team and board without spending nine months being politely ignored.
HiddenLayer’s challenge is that its category is attractive enough to draw bigger predators. TechCrunch notes that Cisco, Palo Alto Networks and Check Point often buy security technology rather than build it, while other startups including Noma and Zenity have raised more than US$100 million in adjacent AI-security areas. ([techcrunch.com](https://techcrunch.com/2026/09/02/hiddenlayer-nabs-100m-as-enterprises-rush-to-secure-their-ai-deployments/))
The risk for HiddenLayer is obvious: Microsoft, OpenAI, AWS or a traditional security giant may bundle basic AI protections into platforms customers already use. If that happens, standalone vendors with superficial features get flattened.
But the opportunity is equally obvious. Bundled security is usually broad. High-value security is specific, deeply integrated and built for the awkward edge cases that create disasters. HiddenLayer is betting it can own that higher-value layer — particularly at runtime, when a model or agent is actually doing work.
I reckon that is the right bet, with one caveat: raising US$100 million is not a moat. It is a timer. The company now has more runway, more expectations and more competitors watching its every move.
What this means for you
If you are a founder, stop treating security as the department that arrives after product-market fit. Build a basic AI control map now:
1. List every AI tool and agent touching your business. Include the shadow stuff employees bought on a credit card. You cannot protect what you pretend does not exist. 2. Define permissions before capability. For each agent, write down exactly what data it can read, what tools it can use and what actions require human approval. 3. Keep high-consequence actions human-gated. Payments, production code releases, customer-record changes and legal commitments should not be handed to an eager machine because a demo looked impressive. 4. Test for hostile inputs. Ask how your system behaves when a document, email, webpage or customer message contains instructions designed to override it. If nobody knows, you have work to do. 5. Sell trust, not just speed. If you are building an AI product, make safety, visibility and control part of the commercial pitch. Your buyer wants productivity; their risk team wants a reason not to kill the deal.
The lazy view is that AI security slows innovation down. Rubbish. Uncontrolled AI slows it down, because one serious screw-up can turn a promising rollout into a board-level ban.
HiddenLayer’s US$100 million Series B is a reminder that the next pile of venture money will not only chase the companies building more autonomous machines. It will chase the companies making those machines safe enough for grown-up businesses to use.