Chris Sestito helped turn what once seemed like a distant concern for many companies into a concrete market opportunity. HiddenLayer raised $100 million in a Series B round while its annual recurring revenue grew more than tenfold, signaling that security is no longer simply a barrier to AI adoption but part of the infrastructure required to put AI into production.
HiddenLayer found a market inside the risk of AI
HiddenLayer, the AI security company co-founded and led by Chris Sestito, announced a $100 million Series B round led by Delta-v Capital. Ten Eleven Ventures, Morgan Stanley, M12, Microsoft’s venture fund, and Booz Allen Ventures also participated.
The move comes as companies move beyond testing AI in experimental projects and begin incorporating it into products, software development, and critical operations. The greater the presence of AI in these environments, the greater the potential cost of a security failure.
HiddenLayer’s trajectory stands out because the company did not need to abandon its original focus to keep up with this shift. Instead, it expanded the scope of its protection as AI systems themselves evolved.
From models to autonomous agents
The company initially focused on protecting models against adversarial attacks, but has expanded into generative applications, agents, and automated workflows.
That shift matters because an AI agent does more than produce a response. Depending on its architecture, it can access tools, retrieve data, execute code, and carry out a sequence of actions without human intervention at every step.
That autonomy is precisely what creates a new layer of risk for businesses.
Chris Sestito saw the threat become enterprise demand

HiddenLayer’s growth reflects how AI security is becoming an operational requirement for companies putting models and agents into production.
HiddenLayer’s growth helps explain why investors are putting capital into security specifically designed for AI. According to the company, its annual recurring revenue grew more than 10 times over the past year, while more than 50 new customers were added to the platform.
CEO Chris Sestito said the company now serves organizations across sectors including financial services, insurance, government, technology, pharmaceuticals, aviation, and defense.
The most important figure, however, is not simply the size of the funding round. It is the combination of revenue growth, new customers, and the expanding problem the company aims to solve.
The money follows a change in priorities
The funding will be used to deepen the company’s enterprise platform, with a particular focus on Agentic Runtime Security, as well as expanding a solution designed to protect coding agents while they are running.
That puts runtime security at the center of the company’s strategy.
In traditional systems, many security controls focus on identifying threats across devices, networks, applications, or identities. In the AI world, an additional question emerges: what exactly is the model or agent doing while it is operating?
Recurring revenue shows willingness to pay
ARR, or annual recurring revenue, is particularly relevant because its growth indicates that the problem is no longer being treated merely as an experimental concern.
According to company disclosures and reports about the funding round, ARR reached the tens of millions of dollars, although HiddenLayer has not disclosed the exact figure.
More than 90% of the growth reportedly came from new customers acquired over the past year. That suggests the company’s expansion is not simply driven by selling more to its existing customer base, but by rapidly developing enterprise demand.
The new target is agents that can act on their own
The most important transformation in the AI security market is the shift from systems that simply respond to systems capable of taking action.
An agent can receive an instruction, retrieve information, call tools, modify files, and move through multiple steps to accomplish a goal. If an attacker manages to manipulate that process, the problem is no longer simply an incorrect response.
It can become an unauthorized action.
Prompt injection and misuse of tools
Among the risks HiddenLayer has begun addressing are prompt injection, agent manipulation, and the malicious use of tools connected to AI systems.
These threats are particularly relevant to businesses because agents can receive permissions that were previously restricted to employees or traditional applications.
The issue, therefore, is not simply preventing a model from producing inappropriate content. It is controlling what an automated system can do when it receives malicious instructions or becomes compromised.
Security has to follow execution
That logic explains HiddenLayer’s focus on protecting agents while they are running. The company aims to provide visibility into system behavior and identify suspicious actions as they happen.
The move is part of a broader concern among major technology companies. Microsoft has also warned that new governance structures will be necessary as agents begin operating inside businesses, a topic explored in the debate over AI agent governance in businesses.
AI security starts before a model enters production

Models, dependencies, and external components expand the attack surface before an AI application even begins operating.
Another strategic area for HiddenLayer is the AI supply chain. Models and components used by businesses can come from public repositories or third parties, creating risks that did not exist in quite the same way in traditional applications.
The company says it analyzes dozens of AI file frameworks to identify tampered models or components that do not match what they appear to be.
This is particularly important in the open-source and open-weight model ecosystem, where organizations can incorporate external components into their own systems.
The problem does not end with training
An organization can evaluate a model before putting it into operation and still face security risks during actual use.
An agent may receive new data, interact with different tools, or operate within a workflow that did not exist during the initial evaluation.
That is why HiddenLayer’s strategy combines discovery, attack simulation, model supply chain security, and runtime protection.
This approach moves AI security toward a continuous discipline rather than an audit performed only before launch.
The capital also reveals where investors see opportunity
The $100 million funding round comes as the market begins attracting competition from traditional security companies and specialized startups.
According to an estimate cited by TechCrunch based on Gartner data, companies are expected to spend $2.83 billion in 2026 on products designed to secure AI tools, an 83% increase from the previous year. The forecast rises to nearly $4.78 billion in 2027.
That environment helps explain why investors are willing to fund companies occupying a specialized position within the AI infrastructure stack.
The competition will not come only from startups
Chris Sestito himself acknowledges that some AI security capabilities could eventually become part of major technology companies’ platforms.
Microsoft, OpenAI, and AWS have infrastructure capabilities that could absorb functions related to discovery, identity, policies, and governance.
HiddenLayer’s opportunity lies in going deeper into a specialized layer: understanding the behavior of models and agents and identifying threats specific to artificial intelligence.
The challenge will be turning that specialization into a durable position before major infrastructure providers consolidate these capabilities into their own platforms.
The broader expansion of autonomous enterprise systems, including developments covered in SAP’s push toward autonomous enterprises, also shows why this security layer could become increasingly important.
Chris Sestito bets security will follow AI’s expansion

For companies delegating tasks to AI agents, controlling system behavior is becoming part of the infrastructure required to scale the technology.
HiddenLayer’s strategy reflects an important shift in the market. At the beginning of the generative AI race, security could be treated as an additional condition for putting models into production.
As agents gain autonomy, security is becoming part of the operational architecture itself.
The Chris Sestito case also shows how a technological threat can become a market when the risk becomes concrete enough for enterprise buyers to act on it.
HiddenLayer still needs to prove that it can maintain its advantage as major cybersecurity companies and AI infrastructure providers enter the space. But the combination of $100 million in new capital, more than tenfold recurring revenue growth, and expansion into agents indicates that AI security is no longer an exclusively technical discussion.
It is beginning to occupy its own place in the budgets of companies seeking to turn AI agents and models into production systems.

Comentários
Os comentários utilizam autenticação via GitHub para manter um ambiente mais qualificado, seguro e livre de spam.
Entrar ou criar conta no GitHub