The AI Security Gold Rush Just Hit $2.8 Billion

If you had told me three years ago that companies would be spending billions to secure AI systems, I would have asked what they were securing them from. Back then, the threats were mostly theoretical — researchers demoing prompt injection on stage, academics publishing papers about model poisoning that sounded alarming but didn’t have real victims.

Conceptual illustration of AI security protection and monitoring for enterprise AI deployments
Image via Wikimedia Commons (CC BY-SA 4.0)

That changed fast.

HiddenLayer, an HiddenLayer’s $100M Signal: AI Agents Need Their Own Security that builds security tools for AI models and agents, just raised $100 million in Series B funding. The company says its annual recurring revenue grew more than 10x over the past year. Its CEO, Chris Sestito, told TechCrunch that ARR is now in the “tens of millions” — and more than 90% of that growth came from new customers signing in the last twelve months.

This isn’t a story about one startup hitting a milestone. It’s a story about an entire market that went from “is this even a real problem?” to “how soon can we buy?” in roughly two years.

A market that didn’t exist until it did

When HiddenLayer raised its $50 million Series A in 2023, TechCrunch’s Kyle Wiggers noted the obvious problem: it was hard to point to real examples of AI attacks happening at scale. The threats existed in research papers and conference demos, not in production systems with actual victims.

Today, the landscape looks different. Gartner estimates companies will spend $2.83 billion this year on products to secure AI tools — an 83% increase over 2025. Next year, that number is projected to reach nearly $4.78 billion. These aren’t startup fantasies; Gartner’s numbers reflect what enterprises are actually budgeting for.

The shift happened because the threat surface expanded. It wasn’t enough for attackers to target the model itself. Now they target the tools the model uses — the plugins, the agents, the add-ons, the systems the AI is allowed to call. And enterprises are realizing that a compromised AI agent isn’t just a cosmetically weird output — it can be an agent with access to your email, your database, your internal APIs, doing things it shouldn’t.

What HiddenLayer actually sells

The company’s product set hasn’t fundamentally changed since 2023. It still sells four core capabilities: discovery (knowing what AI tools exist in your environment), runtime protection (monitoring what they do while they’re running), attack simulation (testing your defenses before someone else does), and supply chain security (making sure the models and tools you’re using are what they claim to be).

What changed is the scope. Sestito told TechCrunch that the biggest shift was extending existing products to cover prompt injection, agent manipulation, and malicious tool use. The underlying technology — inference monitoring, anomaly detection, model fingerprinting — applies across traditional machine learning, generative AI, and agentic workflows. The threat evolved; the defense didn’t need to be reinvented, just expanded.

That expansion matters because the attack surface has become genuinely scary. AI Doesn’t Help Hackers Anymore. It Runs the Attacks Now — how AI agent frameworks can be weaponized for remote code execution. HiddenLayer’s job is to sit between the agent and the damage and notice when something is going wrong before it goes very wrong.

The customers are telling the story

HiddenLayer says its largest customer verticals are financial services and large tech companies building AI products. It also has contracts with the Department of Defense and intelligence community. And it claims one customer is a “leading frontier model provider” with “more than 700 million weekly users” — a description that almost certainly means OpenAI or Anthropic.

Think about that for a second. The companies building the most powerful AI models in the world are buying security tools from a startup to protect those models. That’s a signal that the builders themselves don’t think their own safeguards are enough.

It also tells you something about the market. When the customer is the same company whose model you’re protecting, you’re not selling fear — you’re selling acknowledgment that the problem is real, expensive, and not going away.

The bigger players are circling

HiddenLayer isn’t alone in this space, and it isn’t the biggest player. Cisco announced intentions to acquire Robust Intelligence. Palo Alto Networks announced intentions to acquire Protect AI. Check Point acquired Lakera. These are billion-dollar cybersecurity incumbents deciding that AI security is worth buying rather than building.

Other startups have raised comparable amounts: Noma raised $100 million, Zenity raised $125 million in Series C. The space is heating up, and consolidation is coming — the question is who consolidates whom.

Sestito acknowledged the platform risk openly. He expects that some parts of AI security will eventually be bundled into the platforms built by Microsoft, OpenAI, and AWS. But he sees AI infrastructure evolving toward governance features — discovery, identity, policy controls — rather than the runtime protection and attack simulation that HiddenLayer specializes in. In his framing, the platforms will handle the compliance layer and the specialists will handle the threat layer.

That’s a reasonable bet, but it’s also a bet. The history of security markets is full of specialists who thought their niche was too specific for the platforms to absorb, only to watch the platforms expand.

What this means for the people actually deploying AI

If you’re a team lead or an engineer putting AI systems into production, this market movement has practical implications.

The tooling is maturing fast. Two years ago, if you wanted to monitor your AI deployment for adversarial behavior, you were probably building custom tooling or hoping your existing security stack covered it. Today, there are funded companies with production customers offering discovery, runtime monitoring, attack simulation, and supply chain vetting as actual products you can buy.

The threat model has expanded beyond the model. Prompt injection alone is a problem. But prompt injection combined with tool access — an agent that can read your email, call your APIs, modify your database — is a different magnitude of risk. The security conversation has to cover the whole chain: the model, the agent framework, the tools, the permissions, the data flows.

Supply chain security for AI is real. HiddenLayer parses and scans about 50 different AI file frameworks to verify that open-weight models are what they claim to be. The company specifically looks for hidden models inside other models — a supply chain attack vector that didn’t exist as a product category three years ago. If you’re downloading models from OpenAI Paused Astra After It Hit a Critical Cyber Threshold Hugging Face or anywhere else, this isn’t optional anymore.

The other $100 million signals in this story

HiddenLayer’s funding didn’t happen in isolation. On the same day — September 2 — TechCrunch reported that another startup, Air, raised $50 million to help companies vet the skills and add-ons that AI agents use. The problem is adjacent: agents call tools, and not all tools are safe or well-behaved.

Reading these two announcements together tells you where the market thinks the risk is. It’s not just the model output being wrong or biased. It’s the model being manipulated into doing things through the tools and add-ons it has been given permission to use. That’s a fundamentally harder problem to solve because it requires understanding intent — what was the agent trying to do, was that intent legitimate, and did the tools it called do what it expected?

Gartner’s numbers tell the same story from a different angle. The jump from $1.55 billion (2025) to $2.83 billion (2026) to $4.78 billion (2027) isn’t gradual growth — it’s an explosion. Enterprises aren’t cautiously experimenting with AI security anymore. They’re budgeting for it as a core infrastructure cost.

The risk nobody wants to talk about

Here’s the uncomfortable question lurking behind all these funding announcements: AI CEOs Call for a Slowdown: What ‘Pacing the Frontier’ Means if AI security is a booming market, what does that say about the systems being secured?

100+ Companies Signed a Rogue AI Defense Letter. Here’s What It Means A booming security market is, by definition, a response to real risk. You don’t spend billions defending something that isn’t dangerous. The fact that this market exists — and is growing this fast — is an implicit acknowledgment that AI deployments carry risks that traditional security tooling wasn’t built to handle.

That isn’t an argument against deploying AI. It’s an argument for being honest about what you’re deploying and what could go wrong. The companies buying HiddenLayer’s products aren’t panicking — they’re making a calculated investment in a risk they can see and measure. The ones who aren’t buying anything yet are either ahead of the curve or behind it. It’s hard to tell which without looking closely.

Bottom line

HiddenLayer’s $100 million Series B is a milestone for one startup, but the bigger story is the market it sits in. AI security went from theoretical to essential in about two years. The companies building AI — including the frontier labs themselves — are buying tools to protect it. The platform companies are circling. The Gartner numbers are aggressive. And the attack surface keeps expanding as agents get more tools and more permissions.

For anyone running AI in production, the question isn’t whether this problem is real anymore. It’s whether they’re treating it with the same seriousness they treat every other security surface — or whether they’re still assuming the model will behave.

Given what we’ve seen from agents that didn’t, that assumption looks increasingly expensive.

Filed under Tech & Gadgets
Last Update: September 21, 2026 by Felix AlterEgo
0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted