HiddenLayer raised $100 million in a Series B round, led by Delta-v Capital with participation from Microsoft’s M12, Morgan Stanley and Ten Eleven Ventures. The cash will fuel its AI runtime security platform as enterprises push generative AI and autonomous agents into production.
The attack surface around AI models is exploding. Companies that once ran proof-of-concept notebooks now embed large language models and agentic workflows into customer-facing services, internal decision pipelines and even defense-grade systems. Every new endpoint—prompt interface, tool integration, model version—offers a foothold for adversaries, and the market for tools that defend those endpoints is outpacing the technology itself.
Why AI security moved from theory to necessity
Three years ago most security analysts treated AI-specific threats as a research curiosity. The idea that adversarial attacks would scale was debated more than acted upon. Gartner now forecasts enterprise spending on AI security tools will hit $2.83 billion this year, an 83 percent jump from last year, and climb toward $4.78 billion by next year. Those numbers show a shift from experimental pilots to mission-critical deployments and signal that organisations realize a compromised model can cost far more than preventative tooling.
HiddenLayer’s growth mirrors that trend. CEO Chris Sestito says the company’s annual recurring revenue has multiplied more than tenfold in the past twelve months, now sitting in the “tens of millions” range. Over 90 percent of that increase comes from new customers—financial institutions, large tech firms, the U.S. Department of Defense and the intelligence community. One undisclosed client, which supplies a frontier model to more than 700 million weekly users, has also signed on, underscoring the breadth of the problem.
From model hardening to protecting autonomous agents
Traditional machine-learning security focused on securing the training pipeline and detecting adversarial inputs that subtly distort predictions. HiddenLayer still covers those basics—discovery, runtime protection, attack simulation and supply-chain checks—but it now tackles the unique risks of generative AI.
- Prompt injection – Malicious inputs that coerce a model into executing unintended commands or revealing confidential data. The platform sanitises prompts before they reach the model and monitors output for policy violations.
- Agent manipulation – Autonomous agents that chain tools, APIs and data sources can be hijacked mid-execution, causing harmful actions or data leaks. HiddenLayer injects policy checks at each workflow step, aborting actions that breach defined rules.
- Malicious tool use – AI agents increasingly rely on external plugins, code interpreters or retrieval modules. The solution watches these integrations for anomalous behaviour, such as a retrieval module returning unexpected payloads.
Open-source and open-weight models present a particular headache. Because the model files are freely distributable, threat actors can embed hidden code or malicious weights that execute once the model loads. HiddenLayer parses and scans roughly 50 AI file formats, looking for “hidden models inside of models” that could act as backdoors. This supply-chain defence stops compromised artifacts before they ever run in production.
How the new capital will be spent
HiddenLayer will allocate the $100 million to three thrusts:
- Sales and distribution – Transform a niche go-to-market effort into a broader enterprise sales engine, reaching sectors just beginning to adopt AI at scale.
- Engineering research – Double down on detection logic for emerging attack vectors, such as multi-modal prompt injection and cross-agent coordination attacks.
- Geographic expansion – Build a presence in Europe, the Middle East and Africa (EMEA), where regulatory pressures around AI transparency and security are tightening.
Sestito likens HiddenLayer’s offering to “Endpoint Detection and Response (EDR) for AI.” Just as EDR agents watch operating-system processes for malicious activity, HiddenLayer’s runtime guard watches model inference calls, tool invocations and data flows for policy breaches.
The counter-point: could the cloud giants swallow the niche?
이 회사는 AWS, Azure, Google Cloud와 같은 대형 클라우드 제공업체들이 관리형 AI 서비스에 유사한 런타임 보호 기능을 내장할 수 있다는 점을 인정합니다. 클라우드 벤더가 내장된 프롬프트 인젝션 필터나 에이전트 정책 강제 기능을 제공한다면, 기업들은 제3자 애드온의 가치를 낮게 평가할 수도 있습니다.
Sestito는 거버넌스, ID 및 정책 제어가 전문화된 솔루션을 정당화할 만큼 충분히 복잡하게 유지될 것이라고 주장합니다. 그는 “조직의 경계를 넘나드는 멀티 테넌트 방식의 고가치 워크로드를 다룰 때, 범용적인 클라우드 서비스만으로는 모든 컴플라이언스의 세부 사항을 해결할 수 없다”라고 말합니다. 그는 전용 보안 계층이 하이퍼스케일러들의 거대한 제품 주기보다 더 빠르게 움직일 수 있으며, 기존의 보안 정보 및 이벤트 관리(SIEM) 도구와의 깊은 통합이 플랫폼의 관련성을 유지해 줄 것이라고 믿습니다.
향후 몇 달간 주목해야 할 점
- 도입 속도 – 만약 HiddenLayer의 보안 도구가 AI 조달 계약의 전제 조건이 된다면, 특히 규제 산업 분야에서 기업용 라이선스가 급증할 수 있습니다.
- 경쟁 동향 – 주요 클라우드 제공업체가 네이티브 AI 런타임 강화(hardening)에 대해 발표하는지 주목하십시오. 번들링된 서비스가 제공될 경우, HiddenLayer는 하이브리드 클라우드나 온프레미스 배포로 피벗해야 할 수도 있습니다.
- 규제 압박 – 정부가 AI 특화 보안 표준을 마련함에 따라, 컴플라이언스 요구 사항이 런타임 보호를 명시적으로 언급하게 될 수 있으며, 이는 HiddenLayer와 같은 벤더에게 규제적 호재가 될 것입니다.
- 위협의 진화 – 여러 에이전트에 걸친 조직적인 프롬프트 인젝션이나 대규모로 모델 가중치를 오염시키는 공급망 공격과 같은 새로운 공격 기법은 모든 탐지 엔진을 시험대에 올릴 것입니다. HiddenLayer가 탐지 모델을 얼마나 빠르게 적응시키느냐가 핵심 차별화 요소가 될 것입니다.
결론
HiddenLayer의 1억 달러 규모 투자 유치는 AI 특화 런타임 보안 시장이 학술적 논쟁을 넘어 상업적 필수 과제로 이동했음을 보여줍니다. 기업용 AI가 고립된 모델을 넘어 복잡하고 도구가 풍부한 에이전트로 확장됨에 따라, 지속적이고 정책 기반의 보호는 전통적인 엔드포인트 보안만큼이나 필수적이 되고 있습니다. 이 스타트업이 정교한 공격자들과 클라우드 거물들 사이의 보안 군비 경쟁에서 앞서 나갈 수 있을지가, 이 회사가 'AI를 위한 EDR'로 남을지 아니면 더 큰 플랫폼에 포함된 또 하나의 기능으로 전락할지를 결정할 것입니다. 다음 분기는 전용 AI 보안 벤더들이 여전히 경계가 정의되고 있는 생태계에서 지속 가능한 틈새 시장을 확보할 수 있을지를 보여줄 것입니다.
