HiddenLayer raised $100 million in a Series B round, led by Delta-v Capital with participation from Microsoft’s M12, Morgan Stanley and Ten Eleven Ventures. The cash will fuel its AI runtime security platform as enterprises push generative AI and autonomous agents into production.

The attack surface around AI models is exploding. Companies that once ran proof-of-concept notebooks now embed large language models and agentic workflows into customer-facing services, internal decision pipelines and even defense-grade systems. Every new endpoint—prompt interface, tool integration, model version—offers a foothold for adversaries, and the market for tools that defend those endpoints is outpacing the technology itself.

Why AI security moved from theory to necessity

Three years ago most security analysts treated AI-specific threats as a research curiosity. The idea that adversarial attacks would scale was debated more than acted upon. Gartner now forecasts enterprise spending on AI security tools will hit $2.83 billion this year, an 83 percent jump from last year, and climb toward $4.78 billion by next year. Those numbers show a shift from experimental pilots to mission-critical deployments and signal that organisations realize a compromised model can cost far more than preventative tooling.

HiddenLayer’s growth mirrors that trend. CEO Chris Sestito says the company’s annual recurring revenue has multiplied more than tenfold in the past twelve months, now sitting in the “tens of millions” range. Over 90 percent of that increase comes from new customers—financial institutions, large tech firms, the U.S. Department of Defense and the intelligence community. One undisclosed client, which supplies a frontier model to more than 700 million weekly users, has also signed on, underscoring the breadth of the problem.

From model hardening to protecting autonomous agents

Traditional machine-learning security focused on securing the training pipeline and detecting adversarial inputs that subtly distort predictions. HiddenLayer still covers those basics—discovery, runtime protection, attack simulation and supply-chain checks—but it now tackles the unique risks of generative AI.

  • Prompt injection – Malicious inputs that coerce a model into executing unintended commands or revealing confidential data. The platform sanitises prompts before they reach the model and monitors output for policy violations.
  • Agent manipulation – Autonomous agents that chain tools, APIs and data sources can be hijacked mid-execution, causing harmful actions or data leaks. HiddenLayer injects policy checks at each workflow step, aborting actions that breach defined rules.
  • Malicious tool use – AI agents increasingly rely on external plugins, code interpreters or retrieval modules. The solution watches these integrations for anomalous behaviour, such as a retrieval module returning unexpected payloads.

Open-source and open-weight models present a particular headache. Because the model files are freely distributable, threat actors can embed hidden code or malicious weights that execute once the model loads. HiddenLayer parses and scans roughly 50 AI file formats, looking for “hidden models inside of models” that could act as backdoors. This supply-chain defence stops compromised artifacts before they ever run in production.

How the new capital will be spent

HiddenLayer will allocate the $100 million to three thrusts:

  1. Sales and distribution – Transform a niche go-to-market effort into a broader enterprise sales engine, reaching sectors just beginning to adopt AI at scale.
  2. Engineering research – Double down on detection logic for emerging attack vectors, such as multi-modal prompt injection and cross-agent coordination attacks.
  3. Geographic expansion – Build a presence in Europe, the Middle East and Africa (EMEA), where regulatory pressures around AI transparency and security are tightening.

Sestito likens HiddenLayer’s offering to “Endpoint Detection and Response (EDR) for AI.” Just as EDR agents watch operating-system processes for malicious activity, HiddenLayer’s runtime guard watches model inference calls, tool invocations and data flows for policy breaches.

The counter-point: could the cloud giants swallow the niche?

AWS, Azure, Google Cloud പോലുള്ള വലിയ ക്ലൗഡ് സേവനദാതാക്കൾ തങ്ങളുടെ മാനേജ്ഡ് AI സേവനങ്ങളിൽ സമാനമായ റൺടൈം സംരക്ഷണം ഉൾപ്പെടുത്തിയേക്കാം എന്ന് കമ്പനി സമ്മതിക്കുന്നു. ഒരു ക്ലൗഡ് വെണ്ടർ ഇൻ-ബിൽറ്റ് പ്രോംപ്റ്റ്-ഇഞ്ചക്ഷൻ ഫിൽട്ടറുകളോ ഏജന്റ്-പോളിസി എൻഫോഴ്‌സ്‌മെന്റോ വാഗ്ദാനം ചെയ്യുന്നുണ്ടെങ്കിൽ, തേർഡ് പാർട്ടി ആഡ്-ഓണുകൾക്ക് എന്റർപ്രൈസുകൾ നൽകുന്ന മൂല്യം കുറഞ്ഞേക്കാം.

ഗവേണൻസ്, ഐഡന്റിറ്റി, പോളിസി നിയന്ത്രണങ്ങൾ എന്നിവ സങ്കീർണ്ണമായി തുടരുമെന്നും അതിനാൽ പ്രത്യേക പരിഹാരങ്ങൾ ആവശ്യമാണെന്നും സെസ്റ്റിറ്റോ വാദിക്കുന്നു. “മൾട്ടി-ടെനന്റ് ആയതും, സംഘടനാപരമായ അതിരുകൾ കടന്നുള്ളതും, ഉയർന്ന മൂല്യമുള്ളതുമായ വർക്ക്ലോഡുകൾ കൈകാര്യം ചെയ്യുമ്പോൾ, ഒരു പൊതുവായ ക്ലൗഡ് ഓഫറിംഗിലൂടെ എല്ലാ കംപ്ലയൻസ് സൂക്ഷ്മതകളും പരിഹരിക്കാൻ കഴിയില്ല,” അദ്ദേഹം പറയുന്നു. ഹൈപ്പർസ്കെയിലറുകളുടെ വലിയ ഉൽപ്പന്ന ചക്രങ്ങളേക്കാൾ വേഗത്തിൽ ഒരു പ്രത്യേക സുരക്ഷാ പാളിക്ക് പ്രവർത്തിക്കാൻ കഴിയുമെന്നും, നിലവിലുള്ള SIEM ടൂളുകളുമായുള്ള ആഴത്തിലുള്ള സംയോജനം പ്ലാറ്റ്‌ഫോമിനെ പ്രസക്തമായി നിലനിർത്തുമെന്നും അദ്ദേഹം വിശ്വസിക്കുന്നു.

വരും മാസങ്ങളിൽ ശ്രദ്ധിക്കേണ്ട കാര്യങ്ങൾ

  • അഡോപ്ഷൻ വേഗത (Adoption velocity) – AI സംഭരണ കരാറുകൾക്ക് (procurement contracts) HiddenLayer സുരക്ഷാ ടൂളുകൾ ഒരു മുൻവ്യവസ്ഥയായി മാറുകയാണെങ്കിൽ, പ്രത്യേകിച്ച് നിയന്ത്രിത മേഖലകളിൽ എന്റർപ്രൈസ് ലൈസൻസുകൾ വർദ്ധിച്ചേക്കാം.
  • മത്സരപരമായ നീക്കങ്ങൾ – നേറ്റീവ് AI റൺടൈം ഹാർഡനിംഗിനെക്കുറിച്ച് പ്രധാന ക്ലൗഡ് സേവനദാതാക്കളുടെ അറിയിപ്പുകൾ ശ്രദ്ധിക്കുക. ഒരു ബണ്ടിൽഡ് ഓഫറിംഗ് വന്നാൽ, HiddenLayer ഹൈബ്രിഡ്-ക്ലൗഡ് അല്ലെങ്കിൽ ഓൺ-പ്രെമിസസ് ഡിപ്ലോയ്‌മെന്റുകളിലേക്ക് മാറാൻ നിർബന്ധിതരായേക്കാം.
  • നിയമപരമായ സമ്മർദ്ദം – ഗവൺമെന്റുകൾ AI-പ്രത്യേക സുരക്ഷാ മാനദണ്ഡങ്ങൾ തയ്യാറാക്കുമ്പോൾ, കംപ്ലയൻസ് ആവശ്യകതകൾ റൺടൈം സംരക്ഷണത്തെക്കുറിച്ച് വ്യക്തമായി പരാമർശിച്ചേക്കാം, ഇത് HiddenLayer പോലുള്ള വെണ്ടർമാർക്ക് നിയമപരമായ അനുകൂല സാഹചര്യം നൽകും.
  • ഭീഷണി പരിണാമം – പുതിയ ആക്രമണ രീതികൾ—ഒന്നിലധികം ഏജന്റുകൾക്കിടയിലുള്ള ഏകോപിത പ്രോംപ്റ്റ് ഇഞ്ചക്ഷൻ അല്ലെങ്കിൽ മോഡൽ വെയ്റ്റുകളെ വലിയ തോതിൽ വിഷലിമയമാക്കുന്ന സപ്ലൈ-ചെയിൻ ആക്രമണങ്ങൾ—ഏതൊരു ഡിറ്റക്ഷൻ എഞ്ചിനെയും പരീക്ഷിക്കും. HiddenLayer അതിന്റെ ഡിറ്റക്ഷൻ മോഡലുകൾ എത്ര വേഗത്തിൽ മാറ്റം വരുത്തുന്നു എന്നത് ഒരു പ്രധാന വ്യത്യാസമായിരിക്കും.

ചുരുക്കത്തിൽ

HiddenLayer-ന്റെ 100 മില്യൺ ഡോളറിന്റെ ഫണ്ടിംഗ് കാണിക്കുന്നത് AI-പ്രത്യേക റൺടൈം സുരക്ഷയ്ക്കായുള്ള വിപണി അക്കാദമിക് ചർച്ചകളിൽ നിന്ന് വാണിജ്യപരമായ അനിവാര്യതയിലേക്ക് മാറിയിരിക്കുന്നു എന്നാണ്. എന്റർപ്രൈസ് AI ഒറ്റപ്പെട്ട മോഡലുകളിൽ നിന്ന് സങ്കീർണ്ണവും ടൂൾ-റിച്ച് ആയ ഏജന്റുകളിലേക്ക് വികസിക്കുമ്പോൾ, തുടർച്ചയായതും പോളിസി അധിഷ്ഠിതവുമായ സംരക്ഷണം പരമ്പരാഗത എൻഡ്പോയിന്റ് സുരക്ഷ പോലെ തന്നെ അത്യന്താപേക്ഷിതമായി മാറുന്നു. സങ്കീർണ്ണമായ ശത്രുക്കളെയും ക്ലൗഡ് ഭീമന്മാർക്കിടയിലെ സുരക്ഷാ മത്സരങ്ങളെയും മറികടന്ന് മുന്നേറാൻ സ്റ്റാർട്ടപ്പിന് കഴിയുമോ എന്നത്, അത് “AI-യ്ക്കായുള്ള EDR” ആയി തുടരുമോ അതോ ഒരു വലിയ പ്ലാറ്റ്‌ഫോമിന്റെ ഭാഗമായ മറ്റൊരു ഫീച്ചർ മാത്രമായി മാറുമോ എന്ന് തീരുമാനിക്കും. സ്വന്തം അതിരുകൾ നിർണ്ണയിച്ചുകൊണ്ടിരിക്കുന്ന ഒരു ഇക്കോസിസ്റ്റത്തിൽ, പ്രത്യേക AI സുരക്ഷാ വെണ്ടർമാർക്ക് ഒരു സ്ഥിരമായ ഇടം കണ്ടെത്താൻ കഴിയുമോ എന്ന് അടുത്ത പാദം വെളിപ്പെടുത്തും.