HiddenLayer, an Austin-based company that sells security software for AI models, said Tuesday it raised $100 million in a Series B round led by Delta-v Capital. Ten Eleven Ventures, Morgan Stanley, Microsoft’s M12 venture arm and Booz Allen Hamilton also participated, the company said.
The company protects the AI systems themselves rather than just the networks around them: it detects adversarial inputs designed to fool models, blocks prompt-injection attacks that slip hidden instructions into the text a model processes, and watches for components compromised through supply chains before they reach production.
The growth numbers explain investor interest. Chief executive Chris Sestito told TechCrunch that annual recurring revenue has grown more than tenfold over the past year and now sits in the tens of millions of dollars. Customers include the U.S. Department of Defense and intelligence agencies, Sestito said.
The customer mix spans two buying patterns. Government agencies tend to buy model assurance before deployment, testing whether systems can be attacked before they are trusted with sensitive work; commercial customers often arrive after an incident, looking for tools to keep it from happening again. Both groups are spending faster than vendors in older security categories.
He also described a customer without naming it: a leading frontier-model provider whose products are used by more than 700 million people each week. The description points toward the largest consumer AI platforms, suggesting that the companies building the most visible models are themselves buying protection for them.
The market backdrop supports the round. Gartner forecasts that enterprise spending on AI security will reach $2.83 billion this year, up 83% from last year, and about $4.78 billion in 2027.
The forecasts measure a category that barely existed a few years ago. Security vendors long treated AI as a feature of their products, using it for anomaly detection and automation, rather than as a system that itself needs protecting. The new spending line treats models as assets worth defending, and that shift has created room for specialists.
The spending reflects how AI has moved inside the enterprise. Models no longer sit in experiments; they read mail, draft code, answer customers and, increasingly, act on their own through agents. Each integration opens new routes for attackers: text sent to a model can carry hidden instructions, and a model’s answers can leak data it was never meant to reveal.
The techniques HiddenLayer tracks are evolving quickly. Prompt injection, in which a model is tricked by instructions buried in the text it processes, has become a practical problem for any company exposing a chatbot or agent to the public; supply-chain attacks hide inside the model files and components that developers download like any other dependency.
The defense and intelligence customers reflect a particular worry: adversaries stealing or corrupting models, or probing them for weaknesses before deploying their own. Agencies that put AI near sensitive work want to know, before they do, how the model can be attacked. Booz Allen’s participation, for its part, ties the company to federal contracting, where model-assurance work has expanded alongside government adoption of AI.
The company takes its name from the hidden layers of a neural network, the internal stages where a model builds its answers. Its software watches those systems for signs that someone is probing them, a form of protection that looks different from the firewalls and endpoint agents of conventional security.
HiddenLayer shares the field with security incumbents layering AI protections onto broad platforms and with other startups selling model security as a stand-alone product. Microsoft’s participation is notable because the company sells both AI and security at enterprise scale; its venture arm’s investment is a bet that the category grows large enough for specialists to thrive alongside the giants.
Investors are treating AI security as a category that will earn its own budget line rather than a feature absorbed into existing products. The round’s size suggests conviction that the market Gartner describes is real and growing, and that the vendors serving it are not yet settled.
The round’s backers span pure security investors and generalist institutions, and the participation of Morgan Stanley and Microsoft’s M12 suggests the category has moved beyond specialist conviction into mainstream portfolios.
The category is young and its standards are still forming. Buyers are not always certain what an AI-security product should cover, and the boundaries between application security, data protection and model assurance are still being drawn, analysts said. Early vendors have room to define the market precisely because nobody has defined it yet.
For HiddenLayer, the round funds a race. AI adoption is spreading faster than the security tools around it, and the company’s growth suggests customers have started budgeting for the gap. Whether the market reaches Gartner’s forecasts will depend on whether the attacks AI-security vendors describe arrive at enterprise scale, and how many companies are prepared when they do.
The wager of the round is timing. If agentic AI spreads as quickly as vendors expect, the number of systems making decisions on their own will multiply the attack surface faster than security teams can staff up, and tools that watch the models themselves will look like a necessity rather than a luxury.


