When AI security startup HiddenLayer raised its $50 million Series A three years ago, one of the big questions in the space was whether the AI threats the startup was protecting against would manifest in enough quantity to make for a real market. As my former colleague Kyle Wiggers noted at the time, it was difficult to pin down real examples of attacks against AI at scale. How quickly things have changed.
Security companies are now scrambling to build products that can monitor not just agents but also the tools and add-ons they use. While there still aren’t many headlines about agents being exploited, the risk of agents going haywire during production is nevertheless real. And so the market for tools to prevent that from happening has exploded: Gartner estimates companies will spend $2.83 billion this year on products meant to secure AI tools, 83% more than 2025, and expects spending to reach nearly $4.78 billion next year.
HiddenLayer, which makes tools to protect AI models, agents, and workflows from adversarial attacks, vulnerabilities, and malicious code injections, has been able to take good advantage of that shift. Its co-founder and CEO, Chris Sestito, tells TechCrunch that the startup’s annual recurring revenue grew more than 10x over the past year. He declined to give an exact number but said ARR is now in the “tens of millions” of dollars, and over 90% of that growth was driven by new customers signing in the past year.
Financial services and large tech companies building AI products are currently the company’s largest verticals, and it also has contracts with the Department of Defense and intelligence community. One of its customers is apparently a “leading frontier model provider” with “more than 700 million weekly users,” which sounds like OpenAI or Anthropic to me. To make the most of that momentum, the startup has now raised $100 million in a Series B funding round that was led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, Microsoft’s M12, Booz Allen Hamilton, and others.
The Austin-based startup broadly still sells what it used to in 2023, but Sestito told TechCrunch that the biggest change it’s had to make was to extend its existing products — discovery, runtime protection, attack simulation, and supply chain security — to address prompt injection, agent manipulation, and malicious tool use. So whether it’s on a traditional machine learning model, whether it’s GenAI, whether it’s an agentic work stream, a lot of our technology still applied. So really, we haven’t had to pivot, but we’ve had to grow our scope … from traditional modeling to GenAI to agentic,” he said.
Sestito stressed that runtime security has especially become a priority as AI deployments grow common across businesses and likened it to traditional endpoint detection and response (EDR) solutions, but specifically for AI. The company’s new products reflect that shift, and Sestito highlighted a new opportunity for attackers in exploiting open source models. We’re looking at things like models purporting to be one thing, but they’re another — hidden models inside of models,” he said.
Extract — continue reading at the source.