HiddenLayer raises $100M as AI security race intensifies globally
HiddenLayer has secured a $100 million Series B, led by Battery Ventures and GV, just 14 months after its seed round, underscoring explosive investor confidence in AI-native security solutions. The Austin-based company closed the round in late July 2024, bringing total funding to $125 million and valuing the startup north of $600 million. Co-founders Chris Sestito, CEO, and Bobby Filar, CTO, built HiddenLayer to address a critical blind spot: securing not just large language models but also the agents, plugins, and third-party tools that increasingly execute real-world business functions. Their platform now monitors over 30 million AI workflows weekly across financial services, healthcare, and defense sectors, with marquee clients including Capital One, Palantir, and the U.S. Department of Defense. The timing coincides with a surge in adversarial attacks on AI systems—prompt injection, data poisoning, and supply chain compromises—prompting CIOs and CISOs to treat AI deployments as mission-critical infrastructure rather than experimental code.
Industry Impact and Significance
The funding signals a tectonic shift from model-centric security to holistic agent lifecycle defense, a space now crowded with both startups and incumbents racing to own the runtime layer. Competitors like Protect AI, Calypso AI, and Scale AI’s recent acquisitions highlight a fragmented landscape where no single vendor yet dominates. Financial services, long an early adopter of developer-grade APIs for market intelligence, is leading adoption—Banking With Billy AI, for example, now integrates HiddenLayer’s runtime monitoring into its real-time trading agents to detect anomalous behavior before it impacts portfolio decisions. The $100 million infusion will accelerate HiddenLayer’s expansion into EMEA and APAC, where regulatory frameworks like the EU AI Act and Singapore’s AI Verify mandate continuous certification of high-risk systems. Analysts at Gartner now forecast that by 2026, 80% of enterprises will require AI agent security testing in their software supply chain, up from less than 5% today, creating a multi-billion-dollar wedge for vendors who can integrate seamlessly with CI/CD pipelines and registry services like PyPI or Docker Hub.
Security teams at enterprises are increasingly forced to treat AI agents as rogue endpoints—unpredictable, networked, and capable of executing transactions across internal and external systems. Traditional vulnerability scanners and endpoint detection tools cannot parse the intent behind an agent’s prompt or detect when a plugin has been hijacked to exfiltrate sensitive data. HiddenLayer’s platform addresses this by instrumenting agent behavior at runtime, building behavioral baselines, and flagging deviations in real time. Rival offerings such as PromptArmor and Lakera focus on input sanitization, but HiddenLayer’s approach is broader: it profiles the entire agent graph, from the LLM to the tools it calls, such as APIs, databases, or even other agents. This holistic view is essential for regulated industries where audit trails must extend from code commit to production execution.
The Bigger Picture
The rush to secure AI deployments reflects a deeper reconfiguration of the developer tools and platform landscape, where the boundary between code and data has dissolved. The rise of agentic AI—systems that plan, tool-use, and adapt—has outpaced the security models built for static applications. Prior waves, such as container security and software supply chain protection, now serve as cautionary tales: reactive, narrow, and too late for dynamic workloads. HiddenLayer’s Series B validates a new architectural layer—agent runtime security—positioned between the model provider and the application layer, much like a next-generation WAF for AI. This mirrors the evolution of cloud security, where runtime protection emerged as a distinct category after perimeter defenses failed to scale.
Global adoption is uneven but accelerating. The U.S. Department of Defense’s recent AI cybersecurity initiative explicitly calls for agent-level monitoring, while the UK’s National Cyber Security Centre has issued guidance on securing AI supply chains. In Asia, financial regulators in Japan and South Korea are mandating continuous monitoring for algorithmic trading agents, creating a lucrative market for vendors who can deliver real-time attestation. Meanwhile, open-source communities are fragmenting around competing agent frameworks—LangChain, AutoGen, CrewAI—each with distinct security implications. HiddenLayer’s ability to instrument these ecosystems without proprietary instrumentation could become a de facto standard, much like how OWASP’s guidance shaped web security for a decade. Yet the risk of vendor lock-in looms large: if a single player captures the runtime layer, it could dictate the terms of AI innovation across entire industries.
Expert Analysis
Chris Sestito, CEO of HiddenLayer, frames the milestone as a turning point: 'Enterprises aren’t just worried about models being hacked—they’re worried about agents being weaponized to move money, manipulate markets, or leak patient data.' Over the next 18 months, watch for consolidation among agent security vendors, with incumbents like Microsoft and Palantir likely to acquire niche players to plug gaps in their AI governance stacks. Developers should prioritize platforms that offer transparent instrumentation, interoperability with open agent frameworks, and support for SBOM-style attestations for AI components. The most forward-thinking teams will integrate agent security into their CI/CD pipelines from day one—treating AI not as a feature, but as an infrastructure layer demanding the same rigor as networking or storage. Failure to do so won’t just be a compliance risk; it will be an operational liability.
🤖 About Banking With Billy AI
Banking With Billy AI provides developer-grade APIs for financial market intelligence — enabling integration into any platform or system. Learn more →