Three years ago, when HiddenLayer raised its Series A, one of the most frequent questions was almost existential: is there really a large enough market for AI model security? In 2026, that question seems turned on its head. The adoption of agents, open-weight models, retrieval pipelines, and automated coding tools has multiplied the points where an AI system can be manipulated, replaced, poisoned, or tricked into executing unintended code and operations. HiddenLayer has raised $100 million in a Series B round led by Delta-v Capital, with participation from Ten Eleven Ventures, Morgan Stanley, Microsoft's M12, and Booz Allen Ventures, among others.

The capital arrives as the company claims to have grown its ARR more than tenfold over the past year, taking it into the tens of millions. The figure is self-reported and does not replace public financial statements, but it signals that AI security is moving from the experimental phase to corporate spending. Gartner, cited by TechCrunch, estimates that in 2026 enterprises will spend roughly $2.83 billion on products designed to secure AI tools, up 83% from 2025, with potential growth to nearly $4.78 billion the following year.

The model itself has become an attack surface

Traditional cybersecurity protects applications, networks, identities, and data. An AI system adds a new type of object: the model. It can contain altered weights, malicious dependencies, hidden components, or behaviors triggered by specific inputs. HiddenLayer claims to analyze dozens of AI formats to verify that what an organization downloads or deploys actually matches what it claims to be.

The issue is particularly critical in the open-weight ecosystem, where models and adapters are exchanged with an ease similar to that of software packages. Openness accelerates research and lowers barriers, but it creates a supply chain. If a team treats a model file as a simple mathematical asset rather than potentially risky code, it can import something into its environment that it has not truly verified.

Agents amplify the potential damage

Security becomes even more complex when the model does not just respond, but uses tools. A coding agent can write and deploy code, a financial agent can query sensitive systems, and an enterprise assistant can read documents and send messages. Prompt injection attacks, which in an isolated chat might simply produce an incorrect answer, become far more serious when they manage to influence a system with real-world permissions.

HiddenLayer is therefore expanding its product toward runtime protection and agent harness security. The idea is to monitor what happens while the agent operates and block sequences that point to manipulation or dangerous behavior. It is a shift similar to the one experienced by traditional software: scanning code before deployment is not enough; you need to understand what happens in production.

The market is growing as AI enters core processes

As long as artificial intelligence was mainly used to draft text or summarize documents, the fallout from most errors was confined to productivity. When AI moves into security, software development, customer service with access to personal data, finance, or operations, the risk profile changes. Enterprises are beginning to demand audits, access control, logging, and specific policies.

HiddenLayer counts financial, tech, and government organizations among its customers, including contracts with the Department of Defense and the US intelligence community. This signals the kind of buyer that is emerging: not the innovation team testing a demo, but business functions with formal security requirements.

A crowded sector that could soon consolidate

Growth inevitably attracts competitors. Startups such as Noma, Zenity, AIR, and Cymphony are tackling adjacent areas: agent security, non-human identities, MCP components, plugins, and runtimes. At the same time, major vendors like Cisco, Palo Alto Networks, and Check Point may decide to build similar capabilities or acquire specialized companies.

For HiddenLayer, the Series B is therefore both a validation and a race against time. It must turn its early-mover advantage into distribution, integrations, and enterprise trust before AI security features simply become a module within platforms already deployed across companies.

The problem is not inventing an antivirus for AI

The temptation is to describe these companies as an "antivirus for models," but the analogy falls short. A model does not merely execute deterministic instructions; it responds to context, prompts, tools, and external data. An effective defense must therefore simultaneously evaluate asset integrity, inputs, outputs, and actions.

Moreover, many threats are not traditional malware. A seemingly innocuous document can contain instructions that convince an agent to ignore its original task. An authorized plugin can have excessive privileges. A genuine model can be misconfigured. Security must shift from simply identifying "bad files" to managing behavior.

AI security risks becoming too fragmented

Every new risk category tends to produce a new tool. For security leaders, this can become a problem: dozens of dashboards, duplicate alerts, and inconsistent policies. HiddenLayer will therefore have to prove not only that it can detect new threats, but also integrate with existing identity systems, SIEM, cloud security, and software development workflows.

The value of a platform is not measured by the number of alerts it generates. It is measured by its ability to reduce risk without disrupting work. If controls make every AI experiment too slow, users will look for shortcuts; if they are too permissive, they become purely cosmetic.

Security always follows money and adoption

HiddenLayer's growth reflects, above all, a historical rule of technology: security becomes a market when the underlying technology becomes important enough to be worth attacking. The internet created firewalls, e-commerce created fraud prevention, and the cloud created new posture management platforms. Agents and frontier models are now giving rise to their own defensive industry.

The 100 million Series B does not prove that HiddenLayer will win this category. It does prove, however, that the category exists. The more companies entrust AI with data, code, and decisions, the more the question shifts from "can we use this model?" to "can we trust what it will do once connected to our systems?". It is around that second question that one of the most important cybersecurity markets of the coming years is taking shape.

Sources