For years the running question in the AI world was whether autonomous agents would ever be trusted with real work. The market just answered with money. HiddenLayer, an Austin-based startup that builds security tools specifically for AI, just closed a $100 million Series B, and the numbers around it read less like a single company’s win and more like a whole new category finally getting its own budget line.

Conceptual illustration of enterprise AI agents protected by a digital security shield
Image: AI-generated conceptual illustration for this article.

Here’s the part that gets me. This isn’t another funding round for a chatbot wrapper. It’s a bet that the tools keeping your AI deployment safe deserve their own defence category, separate from the firewalls and endpoint protection you already run. And the market data backs that bet up hard.

Why a whole security market is suddenly forming

HiddenLayer’s round, announced September 2 and led by Delta-v Capital with participation from Ten Eleven Ventures, Morgan Stanley, M12 (Microsoft’s venture arm), and Booz Allen Ventures, lands at a moment when the analysts are openly forecasting a boom. Gartner now tracks “securing AI” as its own market, distinct from cybersecurity products that merely use AI. It expects the category to reach almost $4.8 billion in 2027, up 68.7% from 2026, and nearly $7.7 billion by 2028.

The breakdown tells the story. Gartner splits securing AI into AI application security, AI usage control, AI governance platforms, and AI gateways. AI application security stays the largest segment at roughly $851 million in 2027, while AI usage control grows fastest at 73%. The analyst firm also predicts that by 2029, more than half of successful cyberattacks on AI agents will exploit access-control weaknesses and prompt injections.

That last line is the key. Traditional security treats AI like any other software. But an AI agent taking actions on your behalf operates in a completely different threat model — one where the attack isn’t against your server, but against the way the model reasons, the tools it can reach, and the instructions it trusts.

AI agents are now the ones doing the work

HiddenLayer’s own growth explains why investors are piling in. Its annual recurring revenue grew more than tenfold over the past year, now sitting in the tens of millions of dollars, with over 90% of that growth coming from customers signed in the last twelve months. The startup says it added more than 50 new platform customers across securities, banking, insurance, accounting, government, tech, pharmaceuticals, and airlines.

One detail jumped out at me: a “leading frontier model provider” is a customer, securing more than 700 million weekly users. That’s a scale where you can’t just cross your fingers — and the fact that they lean on a dedicated AI-security vendor is a signal about how seriously the biggest labs take this.

The reason customers are finally spending, CEO Chris Sestito told TechCrunch, is that the risk of agents going haywire in production is real. He reframed runtime security for AI as the equivalent of endpoint detection and response — the modern EDR for models and agents, catching attacks while they happen instead of after the fact.

“Traditional security tools were built for code and infrastructure, not for models that can be poisoned, hijacked, or manipulated through their own inputs,” said Dan Williams, partner at Delta-v Capital.

What this looks like for people who actually ship software

This isn’t abstract for developers. If you’ve let an AI coding agent write or review code for your project, you already live in this world. HiddenLayer’s newest product extends its runtime protection to secure coding agents while they work — monitoring the tools, add-ons, and commands those agents reach for, because that surface is where a malicious plugin or a poisoned library does its damage.

The deeper worry is the open-weight supply chain. Sestito pointed out that HiddenLayer scans roughly 50 different AI file frameworks to verify that the open-source model you’re loading is actually the one it claims to be, guarding against “hidden models inside of models” — an attacker smuggling a modified weight file planted inside a believable name. If you’ve spent any time watching AI coding assistants hallucinate package names, you know exactly how believable those traps can be.

That same supply-chain anxiety is why I keep hammering on this theme. Earlier this year I wrote about detecting compromised npm packages and the $1 billion wake-up call around AI agent security. The lesson keeps getting reinforced: the attack surface moves faster than the defenses do.

Everyone wants a piece of this

HiddenLayer is far from alone. Zenity raised $125 million in a Series C, Noma pulled in a $100 million round, and the big incumbents prefer to buy rather than build — Cisco snapped up Robust Intelligence, Palo Alto Networks is acquiring Protect AI, and Check Point bought Lakera. Sestito acknowledged that bits of this may eventually get bundled into platforms from Microsoft, OpenAI, or AWS, but he expects the core challenge to shift toward governance — discovery, identity, and policy — rather than raw runtime tools.

For now, his stated plan is to “scale vertically alongside artificial intelligence” before expanding horizontally into areas of cybersecurity that increasingly depend on AI. That is a candid admission that this category is still defining itself in real time.

What this means for you

The practical takeaway is straightforward. If your organisation is putting AI agents anywhere near production — approving code, handling data, talking to customers — you need a plan for their security the same way you already have one for your servers. That means discovering every AI model and agent in use, monitoring what tools and add-ons they reach for, and treating their inputs as untrusted.

Take the AI-agent hacks seriously. We’ve already seen Anthropic’s Claude publish malware to PyPI and AI running the attacks now, so this isn’t hypothetical. And when it comes to your overall posture, zero trust isn’t enough for the AI era — the old controls weren’t built to protect a system whose inputs are natural language.

None of this means you should stop using AI agents. Used well, they’re wildly productive. But the moment you trust an agent with something that matters, you’ve created a new asset that needs its own perimeter. That’s exactly the moment HiddenLayer and its investors are betting on.

I’d rather see a crowded market of dedicated AI-security vendors than the alternative — a world where agents ship code and make deals with nobody specifically watching them. Give me scrutiny every time.

Filed under Tech & Gadgets
Last Update: September 13, 2026 by Felix AlterEgo
0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted