Enterprise AI is currently crossing a dangerous threshold. For the past year, the industry has focused on the perimeter—filtering prompts and scrubbing outputs to prevent hallucinations or leaks. But the conversation is shifting rapidly toward autonomy. As companies move from static chatbots to AI agents that can execute code, call APIs, and manage workflows, they are inadvertently opening a massive new attack surface. The risk is no longer just a leaked secret in a chat window; it is the possibility of an autonomous agent being manipulated into executing malicious commands across a corporate network.

The Capital Surge and the Agentic Pivot

HiddenLayer has positioned itself at the center of this transition, recently securing $100 million in Series B funding. The round was led by Delta-v Capital, with significant participation from Microsoft's M12, Morgan Stanley, and Ten Eleven Ventures. This influx of capital follows a period of explosive commercial growth for the startup. According to CEO Chris Sestito, the company's annual recurring revenue (ARR) has grown more than tenfold over the last year, pushing the figure into the tens of millions of dollars. Notably, over 90 percent of this growth has been driven by new contracts signed within the past twelve months, signaling a sudden, sharp spike in market urgency.

The customer profile for HiddenLayer reflects the high-stakes nature of AI security. Their portfolio includes financial services firms, big tech enterprises, and the United States Department of Defense (DoD) and the broader intelligence community. Perhaps most telling is the inclusion of a leading frontier model provider that boasts over 700 million weekly users, suggesting that even the creators of the world's largest models require external, specialized security layers to protect their ecosystems.

This funding arrives as the broader market for AI security tools enters a hyper-growth phase. Gartner estimates that spending on AI security tools will reach $2.83 billion this year, climbing to approximately $4.78 billion by next year. While the industry struggled three years ago to identify large-scale, real-world AI attacks, the rise of agentic workflows has turned theoretical vulnerabilities into immediate operational risks. In response, HiddenLayer has expanded its product scope. While it began with basic model protection, it now covers the entire generative AI and agent-based workstream, integrating discovery, runtime protection, attack simulation, and supply chain security to combat prompt injection and agent manipulation.

From Static Filtering to AI Runtime Security

The critical evolution here is the move toward runtime security. In traditional cybersecurity, Endpoint Detection and Response (EDR) tools monitor the behavior of a device in real-time to catch anomalies that static antivirus software misses. HiddenLayer is essentially applying the EDR philosophy to the AI stack. The goal is not just to check if a prompt is "bad," but to monitor what the AI agent is actually doing while it runs. If an agent suddenly attempts to use a tool in an unauthorized way or exhibits abnormal behavior during a workflow, the runtime security layer intercepts the action before it can cause systemic damage.

This becomes particularly vital for organizations adopting open-weight models. The open-source nature of these models introduces a significant supply chain risk: the possibility of "model nesting," where a malicious model is hidden inside another, or a model is deployed under a false identity. To mitigate this, HiddenLayer analyzes and scans approximately 50 different AI file frameworks to verify the integrity of the model before it ever hits production. This level of deep inspection is a stark contrast to the basic governance tools provided by cloud service providers.

This creates a distinct competitive tension in the market. On one side, legacy security giants like Cisco, Palo Alto Networks, and Check Point are pursuing an acquisition-heavy strategy, preferring to buy specialized AI security firms rather than build the technology from scratch. On the other side, platform titans like Microsoft, AWS, and OpenAI are bundling security features into their core offerings. However, Sestito argues that there is a fundamental difference between governance and security. While platform providers focus on identity management, policy control, and high-level governance, HiddenLayer is building the specialized, deep-technical tools required to stop adversarial attacks at the execution level.

The shift in focus from the model itself to the agentic workflow represents a professionalization of the AI stack. For developers and security officers, the priority is no longer just preventing a model from saying something offensive, but ensuring that an agent with API access cannot be tricked into deleting a database or exfiltrating sensitive data through a manipulated tool call.

The willingness of the market to pay a premium for specialized security, as evidenced by HiddenLayer's growth, suggests that built-in cloud governance is no longer sufficient for the enterprise.