Illustration for: HiddenLayer Raises $100M as AI Security Consolidates

HiddenLayer Raises $100M as AI Security Consolidates

The Austin startup that scans models for tampering and attacks grew ARR more than tenfold in a year and drew Delta-v Capital, Microsoft's M12, Morgan Stanley and Booz Allen into a $100 million round.

TC
By the Funding Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
2 min read
ShareXLinkedInEmail
TC

The VC Read · Trace's Take

Trace Cohen

Three of HiddenLayer's closest competitors got acquired by platform vendors in 18 months, which is either validation or the countdown clock -- and 90% of growth coming from new logos rather than expansion tells me it is too early to know. The diligence item is net revenue retention on cohorts older than a year. If existing customers are not expanding, this is a category being bought rather than a company being built, and Palo Alto's bundle wins on price.

Analysis

HiddenLayer closed a $100 million Series B led by Delta-v Capital, with Ten Eleven Ventures, Morgan Stanley, Microsoft's M12 and Booz Allen Hamilton participating, TechCrunch reported. The round was among the week's ten largest, per Crunchbase News. Valuation was not disclosed.

The Austin-based company, led by co-founder and CEO Chris Sestito, builds security tooling specifically for machine learning systems: scanning model artifacts for malicious code and backdoors, detecting adversarial inputs and prompt injection at runtime, and monitoring deployed models for extraction attempts. It raised a $50 million Series A about three years ago, when "AI security" was mostly a research topic.

Revenue is what changed. HiddenLayer says annual recurring revenue grew more than tenfold over the past year into the tens of millions, with over 90 percent of that growth from new customers rather than expansion -- the profile of a category crossing from experiment to budget line. Its customers concentrate in financial services and large technology companies, alongside the Department of Defense and intelligence community, and include a frontier model provider serving more than 700 million weekly users.

It raised a $50 million Series A about three years ago, when "AI security" was mostly a research topic.

The strategic investors tell the story of the market. Booz Allen is the channel into federal AI deployments. M12 puts the product close to Azure's enterprise AI stack. Morgan Stanley is both a financial investor and the archetypal regulated customer.

Consolidation Is Already Underway

What makes this round notable is the consolidation happening around it. Palo Alto Networks acquired Protect AI, Cisco bought Robust Intelligence, and Check Point acquired Lakera -- three of the most direct competitors absorbed into platform vendors within roughly 18 months. That leaves HiddenLayer and a small group of independents including Noma and Zenity competing against security suites that can bundle AI protection into an existing enterprise agreement at near-zero incremental price.

Bundling is the bear case, and it is the standard way security categories end. Endpoint detection, CASB and email security all began as standalone markets and finished as platform features. The counterargument specific to this one is that AI security requires model-level expertise that generalist platforms have not demonstrated, and that the buyer -- often an ML platform team rather than the CISO's organization -- has a separate budget and different requirements.

Recent events are doing the selling. OpenAI agents reached Hugging Face's infrastructure in August and hijacked a public wiki, incidents the company publicly acknowledged this week. Enterprises watching that are asking who monitors the agents running inside their own environments, and the honest answer for most is nobody.

The Widening Technical Scope

The technical scope has widened with the threat. Early AI security products focused on adversarial examples and model theft, largely academic concerns. What enterprises are buying in 2026 is closer to supply-chain security for models: verifying that a downloaded open-weight checkpoint has not been tampered with, scanning serialized model files for embedded code execution, and watching agent runtimes for behavior that does not match policy. Hugging Face alone hosts more than a million model artifacts, most of them unaudited by whoever downloads them.

The number that determines the outcome: whether HiddenLayer's ARR compounds through a second year at anything close to this rate, or whether the platform vendors' bundled offerings cap it. With over 90 percent of growth coming from new logos, the expansion motion is still unproven.

ShareXLinkedInEmail

Key Sources

2 sources

Reported by TechCrunch · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.