A market analysis, product and technology audit, PM critique, and mock product strategy for HiddenLayer — the AI security platform that just raised $100M to prove it can out-run three of its acquired rivals into the agentic era.
HiddenLayer is an Austin-area (Leander, TX) cybersecurity startup, founded in 2022, that sells a single proposition to the enterprise: the models and agents you're putting into production are unaudited software with a novel attack surface, and nothing in your existing security stack — EDR, WAF, DLP, SIEM — was built to see it. Its AI Security Platform (AISec) spans the AI lifecycle: discovering shadow AI, scanning models before deployment, defending them at runtime, and red-teaming them continuously. In September 2026 it closed a $100M Series B, and its own numbers are the story: ARR up more than 10x in a year, 50+ new platform customers, and a customer list that reportedly includes a frontier model provider with 700M+ weekly users — almost certainly OpenAI or a peer at that scale, though HiddenLayer has not named the account.
Formerly led threat research at Cylance (the endpoint-security pioneer acquired by BlackBerry), giving HiddenLayer's research-first identity a direct lineage. The company's public voice on agentic AI risk via podcasts and press.
Runs go-to-market as the company pivots from a research-led, land-in-finance-and-government motion toward the broader enterprise and EMEA expansion the Series B is explicitly funding.
Public reporting is thin on the full founding team beyond Sestito; HiddenLayer's own materials emphasize the Cylance/adversarial-research pedigree over individual bios — a deliberate research-brand-over-founder-brand choice.
Gartner puts 2026 global spend on AI security tools at $2.83B — an 83% jump from 2025 — climbing to $4.78B in 2027 and roughly $7.7B by 2028. That is a real, fast-growing budget line, but it is still a rounding error next to the broader cybersecurity market, and Gartner's own analysts frame the driver bluntly: traditional tools "treat AI applications like any other software" and can't see AI-specific threats like prompt injection, model supply-chain compromise, or agentic misuse. The uncomfortable question for every vendor in this space, HiddenLayer included, is how much of that budget is genuinely new spend versus a reallocation that dries up once boards feel "covered" rather than actually protected.
$2.83B (2026) → $4.78B (2027, +69%) → ~$7.7B (2028) per Gartner. AI Application Security is the largest sub-segment ($851M by 2027); AI Usage Control is the fastest-growing (+73%).
Three of HiddenLayer's closest peers were acquired by platform vendors within roughly 18 months: Protect AI → Palo Alto Networks, Robust Intelligence → Cisco, Lakera → Check Point. Prompt Security was separately acquired by SentinelOne.
Agent-native entrants Noma Security and Zenity have each raised $100M+, meaning HiddenLayer's "agentic security" pivot is a contested land grab, not a walk-in.
| Company | Model | Moat | HiddenLayer Overlap | Threat |
|---|---|---|---|---|
| Protect AI (Palo Alto Networks) | Broad AI/ML security platform | Open-source tooling (ModelScan, LLM Guard, NB Defense), huntr.com bug bounty, now Palo Alto's distribution and bundling power | Full-platform: discovery, scanning, runtime | HIGH |
| Robust Intelligence (Cisco) | Model validation + AI firewall | Folded into Cisco AI Defense; rides Cisco's network-security install base | Runtime defense, red-teaming | HIGH |
| Lakera (Check Point) | LLM guardrails, prompt-injection detection | Viral developer mindshare via the "Gandalf" prompt-injection game; now Check Point's channel | Runtime guardrails — historically HiddenLayer's thinner spot | HIGH |
| CalypsoAI | Model validation & red-teaming, still independent | Deep government/defense relationships | Attack simulation, model risk scoring | MEDIUM |
| Noma Security | Agentic AI & data-pipeline security, built agent-native | $100M+ raised in 2025–26; no legacy model-scanning baggage to maintain | Direct collision on Agentic Runtime Security | HIGH |
| Zenity | AI agent governance (Copilot Studio, low-code agent builders) | Deep ties into the Microsoft Copilot ecosystem; $100M+ raised | Agent Harness Security | MEDIUM-HIGH |
| Hyperscaler-native guardrails (Azure AI Content Safety, Bedrock Guardrails, Google Model Armor) | Bundled cloud features | Zero switching cost, billed alongside compute buyers already pay for | Baseline runtime guardrails — the "good enough" substitute | MEDIUM |
Palo Alto, Cisco, Check Point, and SentinelOne each concluded it was faster to acquire AI-security depth than build it. That validates the category and removes independent alternatives — but it also means the buyer conversation increasingly starts with "what does our existing platform vendor already bundle for free," which is a harder pitch for a standalone vendor.
HiddenLayer's own 2026 AI Threat Landscape Report found 1 in 8 reported AI breaches already linked to agentic systems, even though most enterprises describe agentic deployment as early-stage. Autonomous coding agents (Claude Code, Cursor, Copilot-style tools) are a new, largely unmonitored execution surface.
85% of organizations in HiddenLayer's survey support mandatory AI-breach disclosure, yet 53% admit withholding reports out of fear of backlash and 31% don't even know if they've been breached. The EU AI Act and NIST AI RMF are pushing toward auditable inventories (AIBOMs) as a baseline requirement, not a nice-to-have.
91% of organizations added AI security budget for 2025, but 40%+ still allocate less than 10% of their total security spend to it. That's a market where the checkbox gets funded before the actual risk does — good for initial land deals, uncertain for expansion revenue.
Winning platforms cover discovery → supply chain → runtime → red-teaming without requiring model weights, retraining, or invasive integration — lowering the barrier for security teams who don't own the model.
CVE disclosures, novel attack research (like ShadowLogic), and MITRE ATLAS alignment aren't marketing exercises when they directly become new detection signatures — they're the actual moat in a market where detection logic ages fast.
Finance, government/defense, and frontier AI labs need more than hyperscaler-bundled guardrails to satisfy model-risk-management and audit requirements — creating a durable wedge above the "good enough" tier.
Every acquired competitor in this space had strong technology and thin distribution. GTM scale, not detection accuracy, is what has actually decided outcomes in this category so far.
The AISec Platform is organized around the AI lifecycle rather than around a single tool. HiddenLayer's own framing groups it into four pillars — Discovery, Supply Chain Security, Attack Simulation, and Runtime Security — with two newer modules (Agentic Runtime Security and Agent Harness Security) extending that coverage to autonomous agents specifically.
Identifies AI applications, models, and assets across cloud and on-prem environments that security teams don't already know about — the prerequisite for everything downstream, and the module that most directly surfaces the "76% call shadow AI a definite/probable problem" finding from HiddenLayer's own research.
Static analysis across 35+ model formats (PyTorch, TensorFlow, ONNX, Keras, GGUF, pickle, safetensors) for malicious code injection, pickle deserialization exploits, and architecture-level backdoors, before a model reaches production. Ships as a GitHub Action and integrates into Azure AI Foundry, AWS SageMaker, Databricks Unity Catalog, and Hugging Face workflows.
Continuously simulates adversarial attacks against production models and agents, mapped to MITRE ATLAS tactics — effectively automating what used to be a manual, expensive, point-in-time pentest engagement.
Agentless, model-agnostic monitoring of production inference for adversarial inputs, prompt injection, and extraction attempts, without requiring access to model weights or modifying the model itself.
Extends runtime monitoring to autonomous agents and, specifically, to the "harness" — the tool-calling and execution environment — that AI coding agents run inside. Funded directly out of the Series B and positioned as the next growth leg.
| Segment | Problem Solved | HiddenLayer Solution | Note |
|---|---|---|---|
| Financial services (banking, insurance, trading) | Fraud-detection and trading models are high-value, high-scrutiny attack targets; regulators expect model risk management | Model Scanner + Runtime Security + AIBOM for audit trails | Named as a primary vertical in the Series B announcement |
| Frontier AI / big tech | Public-facing LLMs are among the most-attacked surfaces on the internet | Runtime Security + Attack Simulation at hyperscale | Reportedly includes a model provider with 700M+ weekly users — an exceptional reference logo, and a concentration risk if it churns |
| US federal government, defense, intelligence | National-security AI systems need adversarial-hardened deployment beyond what hyperscaler tooling alone provides | Full AISec platform | Long sales cycles, high contract value, sticky multi-year relationships |
| Healthcare, pharma, insurance, airlines, accounting | Safety- or compliance-critical AI use cases with third-party/open-source model exposure | Discovery + Model Scanner | Named in Series B materials as newer verticals; smaller logo count than finance/gov so far |
| Platform & application developer teams (horizontal) | Shipping AI features via CI/CD without a security review gate | GitHub Action, Azure/AWS Marketplace listings | Developer-adjacent distribution, but still an enterprise, sales-led pricing motion — not self-serve |
The headline growth number behind the Series B — but HiddenLayer describes absolute ARR only as "tens of millions," meaning the multiple is impressive off a genuinely small base, against a market Gartner sizes at $2.83B in 2026.
New-logo-driven growth is a strong land signal, but with over 90% of ARR growth coming from new customers, the company discloses little about expansion revenue or net retention within its existing base — an open question, not a confirmed weakness.
Alongside 48–50+ disclosed CVEs across ML frameworks (figures vary slightly across company communications from 2024–2026). A genuine, hard-to-fake research output that converts into detection signatures.
Led by Delta-v Capital with Ten Eleven Ventures, Morgan Stanley, M12 (Microsoft), and Booz Allen Ventures — a strategic-investor bench that doubles as a potential channel into finance, defense, and Microsoft's ecosystem.
HiddenLayer's technical differentiation rests on one architectural choice: it operates as an agentless, model-agnostic layer, meaning it does not require access to model weights, training data, or prompts, and does not require retraining or modifying the model it protects. That lowers integration friction relative to approaches that need deep model access — but it also means detection is inherently probabilistic and signature/behavior-driven rather than based on inspecting the model's internals directly.
Model Scanner performs static analysis across serialized model files looking for known-malicious code patterns, unsafe deserialization calls (the classic pickle exploit class), and structurally anomalous computation graphs. Runtime/AIDR performs behavioral analysis on inference traffic — inputs and outputs — to flag adversarial or extraction-style patterns without touching the model itself.
HiddenLayer's own research team demonstrated that backdoors can be implanted in models saved in formats widely assumed to be "safe" — including safetensors and ONNX — not by injecting executable code, but by manipulating the model's computational graph itself. This is the single most important technical claim in HiddenLayer's marketing: it argues that format-level safety (the industry's default mitigation for the older pickle-deserialization problem) is not sufficient, which is precisely the gap Model Scanner and Runtime Security are built to close.
Auto-generates inventories of model components, datasets, and dependencies for compliance auditing — positioned squarely ahead of EU AI Act and NIST AI RMF documentation requirements that are still being finalized in most jurisdictions.
Native integrations with AWS SageMaker, Azure AI Foundry, Databricks Unity Catalog, Hugging Face, MLflow, CrowdStrike, and SIEM/SOAR platforms, plus AWS and Azure Marketplace listings and a GitHub Action for CI/CD. The strategy is to sit inside the MLOps and security-ops tools teams already use rather than asking them to adopt a new console.
HiddenLayer has built a genuinely credible, research-backed platform and just proved it can raise growth capital in a hot but still-small market. The PM-level critique is less about whether the technology works and more about whether the go-to-market, pricing, and category positioning are built for the market HiddenLayer will actually have to compete in over the next two years — one where its nearest peers now carry Palo Alto's, Cisco's, and Check Point's sales forces.
Vision: HiddenLayer becomes the default, neutral security layer that any enterprise plugs in the moment it puts a model or an agent into production — regardless of cloud, model vendor, or agent framework — the way CrowdStrike became the default answer for endpoints, not because it was bundled, but because buyers trusted it to be independent.
North Star Metric: Protected Surface Coverage — the percentage of an enterprise's total inventoried AI assets (models and agents surfaced by AI Discovery) that are under continuous runtime monitoring, not just scanned once. A platform that discovers shadow AI but leaves most of it unmonitored after the initial scan hasn't actually reduced risk. Target: 80%+ of discovered assets under continuous monitoring within 12 months of a Discovery deployment, treated as the leading indicator for both retention and expansion revenue.
The Strategic Pivot: From "we scan and monitor your models" to "we are the security layer every agent and model runs inside of" — winning the agentic wedge decisively before Noma or Zenity establish default status, while converting research credibility into a genuine top-of-funnel instead of a pure enterprise-sales asset.
Rather than a generic "agent monitoring" pitch, ship deep, best-in-class integrations with the specific agent frameworks enterprises are actually deploying — Claude Code, Cursor, GitHub Copilot Workspace, and internal LangGraph/AutoGen-style agents — before Noma or Zenity establish default status in each.
Open-source a lightweight scanner (mirroring Protect AI's pre-acquisition ModelScan playbook) and launch a public vulnerability disclosure program, converting HiddenLayer's genuine research credibility into bottom-up developer adoption rather than leaving it as purely a sales-enablement asset.
Free, hosted "scan this model" tool plus an open-sourced detection-only scanner (no fleet dashboard, no compliance reporting — the classic open-core split).
Public disclosure program modeled on huntr.com; developer community building around real CVE credit.
Every free-tier scan and community disclosure feeds the same detection-signature pipeline that already differentiates the paid platform — turning the funnel itself into R&D.
Package AIBOM generation and audit-ready reporting as a distinct, faster-close SKU aimed at EU AI Act and NIST AI RMF requirements, using the Series B's EMEA expansion capital to land in regulated European financial services and insurance before expanding those accounts into full runtime and red-teaming coverage.
| Risk | Severity | Likelihood | Mitigation |
|---|---|---|---|
| Noma or Zenity out-execute the agentic pivot | HIGH | MEDIUM | Ship narrow, best-in-class framework integrations fast rather than broad-but-shallow coverage; lean on research credibility to win technical evaluations head-to-head. |
| Hyperscaler guardrails commoditize the low end | MEDIUM | HIGH | Move up-market on depth — red-teaming, AIBOM, compliance — where a cloud vendor auditing its own AI stack neutrally is a structural conflict of interest. |
| HiddenLayer itself becomes the next acquisition target before reaching self-sustaining scale | MEDIUM | MEDIUM | Preserve platform neutrality as the core value proposition in any strategic conversation; treat independence itself as a sellable asset, not just an interim state. |
| Compliance SKU sells but doesn't expand into full platform | MEDIUM | MEDIUM | Design AIBOM/compliance reporting with an explicit technical path into runtime monitoring, not as a standalone report generator. |
| Open-sourcing the scanner cannibalizes the paid tier | LOW | MEDIUM | Scope the OSS tool to detection-only — no fleet-wide dashboard, no compliance reporting, no remediation workflow. |
Palo Alto, Cisco, and Check Point will always out-resource a pure feature race. Win on independence and depth in fewer, sharper wedges — agent security and compliance — rather than trying to match a broader bundled platform line for line.
Until Agentic Runtime Security is demonstrably strong on prompt injection specifically, keep marketing evidence-based and specific rather than comprehensive-platform claims that invite unfavorable specialist comparisons.
The CEO has floated eventually moving into cybersecurity domains that depend on AI. The AI security wedge itself is still barely funded relative to its total addressable market — a horizontal expansion now would repeat the classic mistake of a vision outrunning the product underneath it.
With over 90% of ARR growth coming from new logos and net revenue retention undisclosed, further GTM scale-up should wait on clearer evidence that the existing customer base expands, not just renews.
HiddenLayer earned its Series B. A genuine research pedigree, a platform that covers the full AI lifecycle without requiring model access, and a customer roster spanning finance, government, and at least one frontier AI lab are not easy things to build, and the 10x ARR growth is real evidence that enterprises are willing to pay for this specifically rather than settle for what's bundled elsewhere — at least for now.
But the same eighteen months that validated the category also stripped out three of HiddenLayer's closest independent peers, each folded into a platform vendor with an existing sales force and an existing customer relationship to sell into. HiddenLayer's remaining independence is simultaneously its best differentiator — "the neutral platform, not a bundled afterthought" — and the exact thing that makes it a plausible acquisition target the moment growth slows or a strategic buyer decides the agentic security wedge is worth paying up for. The Agent Harness Security bet is the right next move, aimed at the fastest-growing, least-defended surface in the market, but it lands in a field where Noma and Zenity started agent-native and are already funded to compete for the same design partners.
The next 18–24 months will likely decide which of two stories this becomes: a company that used its research credibility and fresh capital to build genuine distribution and win the agentic wedge outright — or a well-regarded, well-funded acquisition target whose independence was always a phase rather than a destination. Both are plausible outcomes for the investors who just wrote the check. Only one of them is the outcome a product organization should actually be building toward.
Sources: HiddenLayer.com, HiddenLayer press releases and Innovation Hub research (ShadowLogic, 2026 AI Threat Landscape Report, Forrester Opportunity Snapshot), TechCrunch, PR Newswire, Gartner newsroom (Aug 2026 AI security forecast), CB Insights, Tracxn, Microsoft Tech Community, appsecsanta.com, guptadeepak.com, Respan market map. Analysis as of September 2026. Funding, ARR-growth, and customer figures are company-stated; market-size figures are Gartner estimates and may be revised.