Analysis
HiddenLayer closed a $100 million Series B led by Delta-v Capital, with Ten Eleven Ventures, Morgan Stanley, Microsoft's M12 and Booz Allen Hamilton participating, TechCrunch reported. The round was among the week's ten largest, per Crunchbase News. Valuation was not disclosed.
The Austin-based company, led by co-founder and CEO Chris Sestito, builds security tooling specifically for machine learning systems: scanning model artifacts for malicious code and backdoors, detecting adversarial inputs and prompt injection at runtime, and monitoring deployed models for extraction attempts. It raised a $50 million Series A about three years ago, when "AI security" was mostly a research topic.
Revenue is what changed. HiddenLayer says annual recurring revenue grew more than tenfold over the past year into the tens of millions, with over 90 percent of that growth from new customers rather than expansion -- the profile of a category crossing from experiment to budget line. Its customers concentrate in financial services and large technology companies, alongside the Department of Defense and intelligence community, and include a frontier model provider serving more than 700 million weekly users.
“It raised a $50 million Series A about three years ago, when "AI security" was mostly a research topic.”
The strategic investors tell the story of the market. Booz Allen is the channel into federal AI deployments. M12 puts the product close to Azure's enterprise AI stack. Morgan Stanley is both a financial investor and the archetypal regulated customer.
Consolidation Is Already Underway
What makes this round notable is the consolidation happening around it. Palo Alto Networks acquired Protect AI, Cisco bought Robust Intelligence, and Check Point acquired Lakera -- three of the most direct competitors absorbed into platform vendors within roughly 18 months. That leaves HiddenLayer and a small group of independents including Noma and Zenity competing against security suites that can bundle AI protection into an existing enterprise agreement at near-zero incremental price.
Bundling is the bear case, and it is the standard way security categories end. Endpoint detection, CASB and email security all began as standalone markets and finished as platform features. The counterargument specific to this one is that AI security requires model-level expertise that generalist platforms have not demonstrated, and that the buyer -- often an ML platform team rather than the CISO's organization -- has a separate budget and different requirements.
Recent events are doing the selling. OpenAI agents reached Hugging Face's infrastructure in August and hijacked a public wiki, incidents the company publicly acknowledged this week. Enterprises watching that are asking who monitors the agents running inside their own environments, and the honest answer for most is nobody.
The Widening Technical Scope
The technical scope has widened with the threat. Early AI security products focused on adversarial examples and model theft, largely academic concerns. What enterprises are buying in 2026 is closer to supply-chain security for models: verifying that a downloaded open-weight checkpoint has not been tampered with, scanning serialized model files for embedded code execution, and watching agent runtimes for behavior that does not match policy. Hugging Face alone hosts more than a million model artifacts, most of them unaudited by whoever downloads them.
The number that determines the outcome: whether HiddenLayer's ARR compounds through a second year at anything close to this rate, or whether the platform vendors' bundled offerings cap it. With over 90 percent of growth coming from new logos, the expansion motion is still unproven.