The archive · AI & Models · Strategic decision · 2023–2026
HiddenLayer bet AI attacks would become a real market; a $100M Series B proved it
Skeptics doubted AI-specific attacks in 2023; three years later ARR grew 10x into a $100M Series B as Gartner sized AI security at $2.83B.
HiddenLayer
What the business is
Cybersecurity platform protecting AI models, agents, and workflows from adversarial attacks, prompt injection, and malicious code.
Starting capital:$50M Series A (Sept 2023, M12 + Moore Strategic Ventures) then $100M Series B (Sept 2026, Delta-v Capital)
How it started
Chris Sestito, Tanner Burns, and James Ballard founded HiddenLayer in Austin to shield AI models from hacking. By Sept 2023 it closed a $50M Series A led by Microsoft's M12 and Moore Strategic Ventures, with Ten Eleven, Booz Allen, IBM, and Capital One. The open question then: would AI attacks materialize at scale?
What happened
For three years the market stayed quiet on front-page attacks, but HiddenLayer never pivoted — it extended the same inference-time protections to generative AI and agentic workflows. By 2026 enterprises rushed to secure deployments: Gartner estimated $2.83B of AI-security spending this year, up 83% year over year and heading to $4.78B in 2027. ARR grew more than 10x in the past year, over 90% from new customers, with DoD and intelligence contracts and a frontier model provider with 700M+ weekly users as a customer.
How it ended up
Sept 2, 2026: $100M Series B led by Delta-v Capital, with Ten Eleven Ventures, Morgan Stanley, Microsoft's M12, and Booz Allen joining. Funding goes to sales, distribution, engineering, and EMEA expansion.
Background
HiddenLayer was founded in Austin by Chris Sestito, Tanner Burns, and James Ballard on a contrarian read: enterprises were adopting AI faster than any prior technology, and no security product existed for the models themselves. The startup built detection and runtime protection that watch the inputs and outputs of neural networks, isolate compromised models, and scan for vulnerabilities — a category nobody else owned.
In Sept 2023 the company raised a $50M Series A from Microsoft's M12 and Moore Strategic Ventures, joined by Ten Eleven, Booz Allen, IBM, and Capital One. At the time TechCrunch flagged that concrete examples of attacks against AI were hard to pin down — the market was a hypothesis. HiddenLayer held the course, extending the same inference-time technology from traditional models to generative AI and agentic workflows rather than pivoting.
The bet paid off as enterprises pushed AI into production. Gartner now estimates companies will spend $2.83B securing AI in 2026, 83% more than 2025, reaching $4.78B in 2027. HiddenLayer says ARR grew more than 10x over the past year to the tens of millions, with over 90% of that from new customers, and counts the DoD, intelligence agencies, and a frontier model provider with 700M+ weekly users among its customers.
On Sept 2, 2026 it closed a $100M Series B led by Delta-v Capital with Ten Eleven, Morgan Stanley, M12, and Booz Allen — a market-timing bet that took three years to validate, and one that rivals are now chasing with $100M+ rounds of their own.
What has to be true
- HiddenLayer chose a defensible wedge: security tuned per-model rather than bolted onto existing firewalls, so the platform's core technology stayed applicable as AI itself evolved.
- It refused to pivot while the market was unproven, which meant it had a fully built product and reference customers when spending finally exploded.
- Early investors supplied credibility and enterprise contacts (M12, Moore, Booz Allen), which translated into the DoD and intelligence contracts that later anchored growth.
- The category timing was right: security spending followed AI deployment, and by 2026 deployment had reached the point where Gartner sized the market in the billions.
What can be applied
Betting on a market before its trigger events appear is only safe if you can wait out the doubt — HiddenLayer spent three years as the AI-attack skeptic before the market came to it.
Aftermath
As of Sept 2026 HiddenLayer is scaling: tens of millions in ARR, a $100M war chest, expansion into Europe and EMEA, and scope now covering prompt injection, agent manipulation, and open-weight model scanning. Its biggest risk is competition: Cisco, Palo Alto Networks, and Check Point are buying AI-security startups, while Noma and Zenity each raised over $100M. Sestito concedes part of the product could be bundled into Microsoft, OpenAI, or AWS platforms; his answer is to scale vertically alongside AI first, then expand into the cybersecurity folds AI depends on.
Sources
- HiddenLayer nabs $100M as enterprises rush to secure their AI deployments
- AI cybersecurity startup HiddenLayer raises $50M
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card