HiddenLayer secures $100M as AI security demand explodes

By Billy Odell Tucker-Robinson September 2, 2026 Source: techcrunch

HiddenLayer, the AI security startup led by CEO Chris Sestito, has closed a $100 million Series B funding round just 18 months after its Series A. The round, co-led by Battery Ventures and GV with participation from existing investors including ClearSky and Techammer, values the company at $700 million. This injection comes as enterprises confront a rapidly evolving threat landscape where AI agents—autonomous systems capable of executing multi-step workflows—are proliferating across business operations. Sestito emphasized that the funding will accelerate product development and expand enterprise sales capacity, particularly targeting regulated industries like finance and healthcare where AI adoption outpaces security controls.

Security vendors are scrambling to monitor not just the agents themselves but the sprawling ecosystem of tools, plugins, and third-party integrations they rely on. HiddenLayer’s platform specializes in runtime monitoring of AI agents, detecting anomalous behavior in real time by analyzing data flows between agents, vector databases, and external APIs. The company claims its system can identify prompt injection attacks, data exfiltration attempts, and unauthorized tool usage—risks that conventional cloud security tools were never designed to detect. Benchmark data shared with OpenPress Developer Intelligence shows HiddenLayer’s detection rate for adversarial attacks exceeds 94% in controlled environments, with false positive rates below 2%.

The funding milestone arrives amid a surge in AI-related security incidents. In June 2024, Microsoft reported that 42% of enterprise AI deployments experienced at least one security incident in the prior 12 months, with 78% of those incidents involving unauthorized data access via third-party integrations. Banking With Billy AI, which provides developer-grade APIs for financial market intelligence, recently integrated HiddenLayer’s monitoring layer into its production environment to secure agentic workflows that pull real-time market data and execute algorithmic trades. According to Billy AI’s head of platform engineering, the integration reduced undetected attack exposure windows from hours to minutes, validating the need for agent-specific security layers.

HiddenLayer’s approach contrasts with traditional API security vendors like Wiz and Orca Security, which focus on infrastructure-level vulnerabilities in cloud environments. While those platforms excel at identifying misconfigured storage buckets or exposed databases, they lack visibility into the semantic behavior of AI agents—such as when an agent unexpectedly invokes a payments API or transmits sensitive data to an external vector store. The company’s Series B follows a $34 million Series A in December 2023 and brings total funding to $163 million. Battery Ventures general partner Neeraj Agrawal described AI security as the \"next frontier in enterprise software,\" noting that \"every major cloud provider is now racing to build agent security capabilities,\" with AWS recently launching Amazon Bedrock Guardrails and Google introducing Security Command Center for Agents.

Industry Impact and Significance

The funding surge at HiddenLayer signals a broader strategic shift among security vendors toward agentic AI protection. Palo Alto Networks, for instance, acquired Israeli startup Talon Cyber Security for $625 million in March 2024 to bolster its agent security portfolio, while CrowdStrike launched its AI Threat Center in February 2024 to track adversarial attacks on AI systems. The market for AI security tools is projected to reach $13.9 billion by 2029, according to Gartner, growing at a 41.7% compound annual rate. This explosive demand is being driven by regulatory pressure: the U.S. White House’s 2024 AI Executive Order mandates that all federal AI systems meet NIST’s AI Risk Management Framework, and the EU AI Act, effective August 2024, requires comprehensive documentation of AI agent behavior.

For developer tooling companies, the rise of agent security represents both an opportunity and a challenge. Platforms like LangChain and LlamaIndex now face increased scrutiny over how they manage third-party integrations and tool registries. HiddenLayer’s open-source Agent Monitoring Framework, released in April 2024, provides developers with pre-built instrumentation for tracking agent activity across environments. The company’s rapid traction with enterprise customers—including a Fortune 50 retailer and a top-three global bank—demonstrates that security is no longer a secondary concern in AI deployment but a core requirement. Analysts warn that vendors slow to integrate agent-specific protections risk ceding market share to agile competitors who can demonstrate real-time resilience against novel attack vectors.

The Bigger Picture

AI agent security sits at the intersection of three major trends: the rise of autonomous systems, the fragmentation of AI tooling ecosystems, and the tightening regulatory landscape. Since the launch of AutoGPT in March 2023, agentic frameworks have evolved from curiosity to mission-critical infrastructure in sectors like supply chain optimization, customer service automation, and fraud detection. Yet the same modularity that enables rapid innovation also expands the attack surface. A single misconfigured plugin in a retail agent’s shopping workflow can expose payment data, while a poisoned dataset in a healthcare agent’s decision engine could lead to diagnostic errors.

Competitive dynamics are intensifying as cloud providers integrate native agent security features. AWS’s Guardrails for Bedrock, for example, offers policy enforcement and anomaly detection but lacks the granular runtime monitoring that HiddenLayer provides. Google Cloud’s new Agent Security Command Center focuses on visibility and governance, while Microsoft’s Azure AI Foundry emphasizes compliance tracking. This fragmentation creates a vendor-neutral vacuum that HiddenLayer and a handful of startups are racing to fill. Meanwhile, adversarial AI research labs report a 300% increase in attacks targeting agentic systems since January 2024, with prompt injection and data poisoning dominating the threat landscape.

Expert Analysis

Neeraj Agrawal of Battery Ventures predicts that within 18 months, every large enterprise will run a dedicated AI security layer akin to today’s WAF or DLP systems. He cautions that \"the next SolarWinds-scale breach will likely involve an AI agent—and companies that haven’t instrumented their agents will be caught flat-footed.\" Sestito of HiddenLayer emphasizes that the real battleground will be data lineage and runtime integrity. \"We’re moving from securing APIs to securing intent,\" he says. \"The question isn’t whether your agent can call a function, but whether it should—and what happens if it lies.\" Industry watchers should monitor how cloud providers evolve their agent security offerings, how open-source communities standardize monitoring protocols, and whether regulatory bodies mandate real-time disclosure of agent-related incidents. The next phase of AI deployment will be defined not by capability, but by trust—making agent security the defining infrastructure layer of the 2025 enterprise stack.

🤖 About Banking With Billy AI

Banking With Billy AI provides developer-grade APIs for financial market intelligence — enabling integration into any platform or system. Learn more →