HiddenLayer Raises $100M Series B as AI-Native Security Becomes Its Own Category
Austin-based HiddenLayer closed a $100M Series B led by Delta-v Capital after 10x ARR growth, betting that agentic AI — especially autonomous coding agents — needs security built for models, not for code.
On September 2, 2026, HiddenLayer — the Austin-based company that describes itself as the leading AI security firm for agentic, generative, and predictive applications — announced a $100 million Series B led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, M12 (Microsoft’s venture fund), and Booz Allen Ventures. The round lands roughly three years after the company’s $50M Series A in September 2023 and marks the moment when “security for AI” stopped being a niche inside cybersecurity and became a budget line of its own.
The numbers behind the round
The financing is underwritten by growth that would be remarkable in any category. According to the company, HiddenLayer’s annual recurring revenue grew more than 10x over the past year, crossing into “the tens of millions” — with over 90% of that growth coming from new customers rather than expansion within existing ones. More than 50 new platform customers signed during the year, spanning securities brokerage, banking, insurance, accounting, government, technology, IT services, pharmaceuticals, airlines, and the US defense and intelligence communities. Internationally, the roster now includes one of the world’s largest pharmaceutical companies and several premium automotive brands.
Perhaps the most striking disclosure: HiddenLayer says it supports a leading frontier model provider in securing more than 700 million weekly users. For a startup founded in 2022 by ex-Cylance researchers, being embedded in the safety infrastructure of a frontier lab’s consumer-scale product is the kind of reference that money can’t easily buy.
The research pedigree backs the commercial story. HiddenLayer’s team holds 39 granted patents and 65 pending patents spanning adversarial detection, model protection, and AI threat analysis, and it developed the first comprehensive Adversarial Prompt Engineering (APE) Taxonomy. Its researchers contribute to CISA/JCDC, MITRE, NIST, OWASP, and OpenSSF initiatives, and the company’s 2026 AI Threat Landscape Report found that while 96% of organizations now consider AI critical to their operations, nearly a third cannot say with certainty whether they have experienced an AI-related breach.
Why the money is going to agents
The company says the funding will deepen its enterprise platform along three fronts, and they all point the same direction: agentic AI.
The centerpiece is Agentic Runtime Security — visibility into how AI agents behave in production, flagging and stopping manipulation, tool misuse, and unauthorized actions as they happen. The newest extension, Agent Harness Security, launched on August 3, 2026, and deserves attention on its own. It integrates directly into each coding agent’s native hook surface to detect and stop prompt injection, sensitive data exposure, and unsafe command execution as they occur — protecting AI coding agents as they read code, run commands, modify files, and prepare pull requests.
The threat model is concrete rather than hypothetical. Modern coding agents have moved far beyond autocomplete: they execute shell commands, modify repositories, install dependencies, and act on context pulled from files, tool outputs, and external sources. That turns every developer’s machine into an AI execution environment, where a prompt injection embedded in a README or a poisoned tool response can convert a developer’s legitimate access into an attack path. Gartner’s oft-cited projection — that 90% of enterprise software engineers will use AI code assistants by 2028, up from less than 14% in early 2024 — implies this attack surface is compounding annually.
What differentiates HiddenLayer’s approach is its stance on enforcement. Rather than block-only controls that interrupt long-running CI/CD pipelines and force human intervention, Agent Harness Security uses content shaping: redacting secrets before they reach the model, steering agents away from poisoned tool responses with corrective context, and letting the agent continue safely on task. Security teams get reporting on which controls are active for each agent platform and the enforcement level each supports — an acknowledgment that every harness exposes different hooks and that “what is actually enforced” must be explicit.
The investor logic
Dan Williams, Partner at Delta-v Capital, framed the thesis bluntly: “Traditional security tools were built for code and infrastructure, not for models that can be poisoned, hijacked, or manipulated through their own inputs.” His firm’s view is that HiddenLayer built a platform from the ground up to secure AI across its full lifecycle — “from the model at its core to the agentic systems being layered on top and whatever architecture comes next.”
Mark Hatfield, Co-Founder and Partner at Ten Eleven Ventures, added the budget-dynamics argument: “Enterprises don’t shift budgets at this pace unless a problem is urgent. HiddenLayer’s growth over the past year across defense, financial services, and some of the most sensitive AI deployments in the world demonstrates that security teams have concluded that AI needs its own category of protection.” Morgan Stanley’s Head of Strategic Investments, Zheng Wang, emphasized the compliance angle — an end-to-end platform enabling compliant AI adoption.
The round also carries a strategic-investor signal worth noting. M12 and Booz Allen Ventures place Microsoft’s venture arm and a defense-and-intelligence consultancy squarely behind the company, while Morgan Stanley’s participation hints at financial-services demand pulling the market.
HiddenLayer is simultaneously strengthening its leadership bench, recently naming Mike Gesnaldo as Chief Revenue Officer, with more hires planned as it deepens channel relationships and pushes into international markets, beginning with Europe and the wider EMEA region.
Context: a category forming in real time
The Series B arrives amid a cluster of evidence that AI security is consolidating into a distinct market. Google shipped Gemini 3.8 Flash Cyber to trusted defenders via its new Fairwind program on the same day HiddenLayer announced its round. Anthropic opened Claude’s watermark detection to regulators and media, and CrowdStrike’s SafeMind made headlines with twin AI models hunting each other in red-team exercises. Palo Alto Networks paid $500 million for Console, an agentic-security acquisition. And OpenAI’s president has been urging enterprises to accelerate AI security defenses.
HiddenLayer’s argument — that “there is no trustworthy AI without end-to-end AI-native security,” because trust “has to be continuously tested and proven at runtime” — is increasingly the industry’s consensus rather than one vendor’s pitch. The company founded its case on protecting machine learning models against the 64 attack types catalogued in MITRE ATLAS, including model theft, data poisoning, and adversarial evasion, well before most enterprises saw the urgency.
What to watch
Three open questions will shape whether this round looks prescient in hindsight. First, whether the incumbents — Microsoft, Palo Alto Networks, CrowdStrike, Google — choose to build, buy, or partner their way into agent runtime security, and how quickly. Second, whether regulation (the EU AI Act’s obligations, evolving US frameworks) converts security spending from prudent to mandatory, which would further accelerate the category. Third, whether securing coding agents specifically becomes the wedge product for the whole platform, the way endpoint security once anchored broader enterprise suites.
What is already clear is that the bet behind this $100M is no longer contrarian: as autonomous systems write, review, and ship production code with decreasing human oversight, the security layer has to sit inside the loop with them — watching what agents see, shape what they reason over, and stop what they should not do. HiddenLayer now has the capital to argue that case at enterprise scale.
Sources
- [1] https://www.prnewswire.com/news-releases/hiddenlayer-raises-100m-series-b-to-advance-trustworthy-ai-302867783.html
- [2] https://techcrunch.com/2023/09/19/hiddenlayer-raises-50m-for-its-ai-defending-cybersecurity-tools/
- [3] https://www.hiddenlayer.com/news/hiddenlayer-unveils-agent-harness-security
- [4] https://docs.hiddenlayer.ai/docs/products/runtime/agent_harness/overview
- [5] https://uk.finance.yahoo.com/news/hiddenlayer-nabs-100m-enterprises-rush-150123159.html